BTW. If already infected what's the recovery tool available then..
remove it like this
Locate and delete "Rootkit.TmpHider" registry entries:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MRxNet\"ImagePath" = "%System%\drivers\mrxnet.sys"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MRxCls\"ImagePath" = "%System%\drivers\mrxcls.sys"


thnxx hode! 

