Rootkit.TmpHider - USB infecting without using autorun.inf file

Nic

Well-known member
  • Sep 8, 2007
    10,224
    165
    63
    GoogleLand
    BTW. If already infected what's the recovery tool available then..

    remove it like this


    Locate and delete "Rootkit.TmpHider" registry entries:
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MRxNet\"ImagePath" = "%System%\drivers\mrxnet.sys"
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MRxCls\"ImagePath" = "%System%\drivers\mrxcls.sys"
     
    • Like
    Reactions: EPCO