Impove
boot up time

Run a free scan to diagnose your PC
Start Test!

MSLOOP.DLL is Rootkit Zero Access

January 12, 2012 by NightWatcher
Filed under: Rootkit 
Install UnHackMe Install RegRun

Rootkit MSLOOP.DLL is software that enables continued privileged access to a computer while actively hiding its presence.
Detection and removal of MSLOOP.DLL may be a very difficult process.
You should use anti-rootkit software to fix the MSLOOP.DLL problem.

Malware Analysis of MSLOOP.DLL
Full path on a computer: %SysDir%\msloop.dll

Detected by UnHackMe:

Item Name: shell
Author: Unknown
Related File: %Local Appdata%\3308c706\X
Type: User Shell

Item Name: Rootkit: ZeroAccess 32/64.5
Author: Unknown
Related File:
Type: Devices in Memory

Detected by RegRun Warrior:

Item Name: shell
Author: Unknown
Related File: %Local Appdata%\3308c706\X
Type: User Shell

Item Name: redbook.sys
Author: Unknown
Related File: %SYSDIR%\DRIVERS\REDBOOK.SYS
Type: System Drivers Infected by Rootkit

Item Name: DNE
Author: Iomega
Related File: %SYSDIR%\MSLOOP.DLL
Type: Svchost DLLs

Removal Results: Success
Number of reboot: 1

MSLOOP.DLL is known as:

Rootkit Zero Access

MSLOOP.DLL hash:

  • MD5: B89CFBE8CB247B57D8C10ADAA66B462B
How to quickly detect MSLOOP.DLL presence?

Registry:
  • HKLM\System\CurrentControlSet\Services\DNE\Parameters\ServiceDll: “%systemroot%\system32\msloop.dll”
  • HKLM\System\CurrentControlSet\Services\DNE\DisplayName: “Safety Settings Service”
Folders:
  • %WinDir%\$NtUninstallKB3057$
Files:
  • %Local Appdata%\3308c706\@
  • %Local Appdata%\3308c706\X
  • %SysDir%\msloop.dll

Remove it now!

Comments

Tell me what you're thinking...
and oh, if you want a pic to show with your comment, go get a gravatar!