Home Malware Programs Trojans Infostealer.Vskim

Infostealer.Vskim

Posted: January 29, 2013

Threat Metric

Threat Level: 9/10
Infected PCs: 38
First Seen: January 29, 2013
OS(es) Affected: Windows

Infostealer.Vskim is a Trojan that steals information from the affected computer system. Once executed, Infostealer.Vskim copies itself by dropping the malicious file on the infected computer. Infostealer.Vskim creates the registry entry so that it can run automatically every time you start Windows. Infostealer.Vskim also creates the registry entry to bypass the Windows firewall. Infostealer.Vskim transmits the grabbed information to the remote location.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



sopp.exe File name: sopp.exe
Size: 71.16 KB (71168 bytes)
MD5: a99d5d1652dfcda190c3d412828dcf6d
Detection count: 60
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 12, 2013
%UserProfile%\Application Data\svchost.exe File name: %UserProfile%\Application Data\svchost.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"PCI Compliant SCard" = "%UserProfile%\Application Data\svchost.exe"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\"%UserProfile%\Application Data\svchost.exe" = "%UserProfile%\Application Data\svchost.exe:*:Enabled:svchost"
Loading...