mskl.exe - Dangerous
%sysdir%\mskl.exe
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
mskl.exe is a user mode rootkit.
mskl.exe hide files containing the string "_new!_full+crack.zip".
mskl.exe is used to hide registry keys containing the string "{22235B37-92F6-915C-DE5B-3B3D4DBC5730}".
Hooking the following Windows APIs:
FindFirstFile
FindNextFile
RegEnumEx
RegEnumKey
RegEnumValue
mskl.exe spreads by e-mail and via open network shares.
Related files:
%SysDir%\mskl32.dll
%SysDir%\mskl.exe
Added to registry:
HKEY_CLASSES_ROOT\CLSID\{22235B37-92F6-915C-DE5B-3B3D4DBC5730}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{22235B37-92F6-915C-DE5B-3B3D4DBC5730}
@="%Windir%\%SYSDIR%\mskl32.dll"
Adds the value:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
"mskl32.dll" = "{22235B37-92F6-915C-DE5B-3B3D4DBC5730}"
to the Windows startup registry keys.