Rootkit.TmpHider - USB infecting without using autorun.inf file

BLACKLIST_MEMBER

Well-known member
  • Feb 9, 2008
    37,854
    14,810
    113
    127.0.0.1
    Rootkit.TmpHider(new virus) - USB infecting without using autorun.inf file

    Modules of current malware were first time detected by "VirusBlokAda" (anti-virus.by) company specialists on the 17th of June, 2010 and were added to the anti-virus bases as Trojan-Spy.0485 and Malware-Cryptor.Win32.Inject.gen.2. During the analysis of malware there was revealed that it uses USB storage device for propagation.

    You should take into consideration that virus infects Operation System in unusual way through vulnerability in processing lnk-files (without usage of autorun.inf file).

    So you just have to open infected USB storage device using Microsoft Explorer or any other file manager which can display icons (for i.e. Total Commander) to infect your Operating System and allow execution of the malware.

    Malware installs two drivers: mrxnet.sys and mrxcls.sys. They are used to inject code into systems processes and hide malware itself. That's the reason why you can't see malware files on the infected USB storage device. We have added those drivers to anti-virus bases as Rootkit.TmpHider and SScope.Rookit.TmpHider.2. Note that both drivers are signed with digital signature of Realtek Semiconductor Corp. (www.realtek.com).

    Thus, current malware should be added to very dangerous category causes the risk of the virus epidemic at the current moment.

    After we have added a new recordes to the anti-virus bases we are admitting a lot of detections of Rootkit.TmpHider and SScope.Rookit.TmpHider.2 all over the world.

    src: anti-virus.by
     
    Last edited:

    tckrockz

    Member
    Sep 24, 2006
    26,754
    13
    0
    I think this type of malware is more dangerous compared to the rest since most of us will just install this kind of driver all the time when we want to install our sound card, network card etc. , have they released updated drivers yet?