mskl.exe - Dangerous

%sysdir%\mskl.exe

Jeff's Story:

My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.

I sought a solution on the Internet and discovered your product and tried out the trial.

You quickly found the rootkit and SAVED my PC!

I haven't had any problems since, and I'm extremely grateful.

Manual removal instructions:

%sysdir%\mskl.exe
mskl.exe is a W32.Feebs!rootkit.
mskl.exe is a user mode rootkit.
mskl.exe hide files containing the string "_new!_full+crack.zip".
mskl.exe is used to hide registry keys containing the string "{22235B37-92F6-915C-DE5B-3B3D4DBC5730}".
Hooking the following Windows APIs:
FindFirstFile
FindNextFile
RegEnumEx
RegEnumKey
RegEnumValue
mskl.exe spreads by e-mail and via open network shares.

Related files:
%SysDir%\mskl32.dll
%SysDir%\mskl.exe

Added to registry:
HKEY_CLASSES_ROOT\CLSID\{22235B37-92F6-915C-DE5B-3B3D4DBC5730}\InprocServer32
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{22235B37-92F6-915C-DE5B-3B3D4DBC5730}
@="%Windir%\%SYSDIR%\mskl32.dll"

Adds the value:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
"mskl32.dll" = "{22235B37-92F6-915C-DE5B-3B3D4DBC5730}"
to the Windows startup registry keys.

Remove mskl.exe now!