Home Malware Programs Trojans Win32:SkiMorph

Win32:SkiMorph

Posted: May 5, 2010

Win32:SkiMorph is a malicious Trojan which attacks the Windows platform. Win32:SkiMorph changes configurations to give hackers access to user files on the victim machine. Win32:SkiMorph may also alter the Windows directory and download other malicious files from external servers. Win32:SkiMorph has the ability to monitor user activities to obtain valuable information, specifically login details. Win32:SkiMorph is a dangerous threat to any computer and should be terminated immediately.

Aliases

Virus.Win32.SkiMorph (Ikarus)

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %AppData%\Microsoft\Windows Media\9.0\WMSDKNSD.XML
    2 %AppData%\sotqciea.dat
    3 %AppData%\sotqciea.exe
    4 %Windir%\Temp\msksetup.log

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_CURRENT_USER\Software\Microsoft\Windows Media\WMSDK\Namespace]
Loading...