Search
Search titles only
By:
Search titles only
By:
Log in
Register
Search
Search titles only
By:
Search titles only
By:
Menu
Install the app
Install
Forums
New posts
All threads
Latest threads
New posts
Trending threads
Trending
Search forums
What's new
New posts
New ads
New profile posts
Latest activity
Free Ads
Latest reviews
Search ads
Members
Current visitors
New profile posts
Search profile posts
Contact us
Latest ads
Ad icon
ව්යාපාර, Tuition පන්ති සහ Personal Portfolios සඳහා Web Setup එකක් රු. 9,099/- කට (වාර්ෂික renewal ර
thathsilura
Updated:
Thursday at 6:17 PM
AWS Certified Solutions Architect-Associate + AWS Certified Cloud Practitioner
Sanjeewani95
Updated:
Aug 19, 2026
🚀 එක පැකේජ් එකයි - මාසෙටම Unlimited Internet! 🌐
sayuru bandara
Updated:
Aug 18, 2026
🎬 CapCut Pro 1 Month Access! LKR 600
sayuru bandara
Updated:
Aug 18, 2026
🚀 Google One AI PRO Plan (Gemini Pro Activation) – 18 Months Access! LKR 2200
sayuru bandara
Updated:
Aug 18, 2026
Electronics
Vehicles
Property
Search
Reply to thread
Forums
General
ElaKiri Talk!
Rootkit.TmpHider - USB infecting without using autorun.inf file
Get the App
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Message
<blockquote data-quote="BLACKLIST_MEMBER" data-source="post: 8315515" data-attributes="member: 79414"><p><strong>Rootkit.TmpHider(new virus) - USB infecting without using autorun.inf file</strong></p><p></p><p>Modules of current malware were first time detected by "VirusBlokAda" (anti-virus.by) company specialists on the 17th of June, 2010 and were added to the anti-virus bases as <strong>Trojan-Spy.0485</strong> and <strong>Malware-Cryptor.Win32.Inject.gen.2</strong>. During the analysis of malware there was revealed that it uses USB storage device for propagation. </p><p></p><p>You should take into consideration that virus infects Operation System in unusual way through vulnerability in processing lnk-files (without usage of autorun.inf file). </p><p></p><p>So you just have to open infected USB storage device using Microsoft Explorer or any other file manager which can display icons (for i.e. Total Commander) to infect your Operating System and allow execution of the malware. </p><p></p><p>Malware installs two drivers: mrxnet.sys and mrxcls.sys. They are used to inject code into systems processes and hide malware itself. That's the reason why you can't see malware files on the infected USB storage device. We have added those drivers to anti-virus bases as <strong>Rootkit.TmpHider</strong> and <strong>SScope.Rookit.TmpHider.2</strong>. Note that both drivers are signed with digital signature of Realtek Semiconductor Corp. (<a href="http://www.realtek.com/" target="_blank">www.realtek.com</a>). </p><p></p><p>Thus, current malware should be added to very dangerous category causes the risk of the virus epidemic at the current moment. </p><p></p><p>After we have added a new recordes to the anti-virus bases we are admitting a lot of detections of <strong>Rootkit.TmpHider</strong> and <strong>SScope.Rookit.TmpHider.2</strong> all over the world.</p><p></p><p>src: anti-virus.by</p></blockquote><p></p>
[QUOTE="BLACKLIST_MEMBER, post: 8315515, member: 79414"] [b]Rootkit.TmpHider(new virus) - USB infecting without using autorun.inf file[/b] Modules of current malware were first time detected by "VirusBlokAda" (anti-virus.by) company specialists on the 17th of June, 2010 and were added to the anti-virus bases as [B]Trojan-Spy.0485[/B] and [B]Malware-Cryptor.Win32.Inject.gen.2[/B]. During the analysis of malware there was revealed that it uses USB storage device for propagation. You should take into consideration that virus infects Operation System in unusual way through vulnerability in processing lnk-files (without usage of autorun.inf file). So you just have to open infected USB storage device using Microsoft Explorer or any other file manager which can display icons (for i.e. Total Commander) to infect your Operating System and allow execution of the malware. Malware installs two drivers: mrxnet.sys and mrxcls.sys. They are used to inject code into systems processes and hide malware itself. That's the reason why you can't see malware files on the infected USB storage device. We have added those drivers to anti-virus bases as [B]Rootkit.TmpHider[/B] and [B]SScope.Rookit.TmpHider.2[/B]. Note that both drivers are signed with digital signature of Realtek Semiconductor Corp. ([URL="http://www.realtek.com/"]www.realtek.com[/URL]). Thus, current malware should be added to very dangerous category causes the risk of the virus epidemic at the current moment. After we have added a new recordes to the anti-virus bases we are admitting a lot of detections of [B]Rootkit.TmpHider[/B] and [B]SScope.Rookit.TmpHider.2[/B] all over the world. src: anti-virus.by [/QUOTE]
Insert quotes…
Verification
Hata thunen beduwama keeyada? (60 bedeema thuna)
Post reply
Top
Bottom