Search
Search titles only
By:
Search titles only
By:
Log in
Register
Search
Search titles only
By:
Search titles only
By:
Menu
Install the app
Install
Forums
New posts
All threads
Latest threads
New posts
Trending threads
Trending
Search forums
What's new
New posts
New ads
New profile posts
Latest activity
Free Ads
Latest reviews
Search ads
Members
Current visitors
New profile posts
Search profile posts
Contact us
Latest ads
Ad icon
Sell your Land, House on idamata.lk for FREE
sajith.xp.pk
Updated:
Thursday at 9:03 AM
Handmade Character Soft Toys
anil1961
Updated:
Tuesday at 2:11 PM
Bodim.lk out now !
Manoj Suranga Bandara
Updated:
Sunday at 3:05 AM
Power Lifting Lever Belt
SkullVamp
Updated:
Jun 13, 2026
Ad icon
port.lk Domain for sale
Lankan-Tech
Updated:
Jun 13, 2026
Electronics
Vehicles
Property
Search
Reply to thread
Forums
General
ElaKiri Talk!
Rootkit.TmpHider - USB infecting without using autorun.inf file
Get the App
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Message
<blockquote data-quote="BLACKLIST_MEMBER" data-source="post: 8315515" data-attributes="member: 79414"><p><strong>Rootkit.TmpHider(new virus) - USB infecting without using autorun.inf file</strong></p><p></p><p>Modules of current malware were first time detected by "VirusBlokAda" (anti-virus.by) company specialists on the 17th of June, 2010 and were added to the anti-virus bases as <strong>Trojan-Spy.0485</strong> and <strong>Malware-Cryptor.Win32.Inject.gen.2</strong>. During the analysis of malware there was revealed that it uses USB storage device for propagation. </p><p></p><p>You should take into consideration that virus infects Operation System in unusual way through vulnerability in processing lnk-files (without usage of autorun.inf file). </p><p></p><p>So you just have to open infected USB storage device using Microsoft Explorer or any other file manager which can display icons (for i.e. Total Commander) to infect your Operating System and allow execution of the malware. </p><p></p><p>Malware installs two drivers: mrxnet.sys and mrxcls.sys. They are used to inject code into systems processes and hide malware itself. That's the reason why you can't see malware files on the infected USB storage device. We have added those drivers to anti-virus bases as <strong>Rootkit.TmpHider</strong> and <strong>SScope.Rookit.TmpHider.2</strong>. Note that both drivers are signed with digital signature of Realtek Semiconductor Corp. (<a href="http://www.realtek.com/" target="_blank">www.realtek.com</a>). </p><p></p><p>Thus, current malware should be added to very dangerous category causes the risk of the virus epidemic at the current moment. </p><p></p><p>After we have added a new recordes to the anti-virus bases we are admitting a lot of detections of <strong>Rootkit.TmpHider</strong> and <strong>SScope.Rookit.TmpHider.2</strong> all over the world.</p><p></p><p>src: anti-virus.by</p></blockquote><p></p>
[QUOTE="BLACKLIST_MEMBER, post: 8315515, member: 79414"] [b]Rootkit.TmpHider(new virus) - USB infecting without using autorun.inf file[/b] Modules of current malware were first time detected by "VirusBlokAda" (anti-virus.by) company specialists on the 17th of June, 2010 and were added to the anti-virus bases as [B]Trojan-Spy.0485[/B] and [B]Malware-Cryptor.Win32.Inject.gen.2[/B]. During the analysis of malware there was revealed that it uses USB storage device for propagation. You should take into consideration that virus infects Operation System in unusual way through vulnerability in processing lnk-files (without usage of autorun.inf file). So you just have to open infected USB storage device using Microsoft Explorer or any other file manager which can display icons (for i.e. Total Commander) to infect your Operating System and allow execution of the malware. Malware installs two drivers: mrxnet.sys and mrxcls.sys. They are used to inject code into systems processes and hide malware itself. That's the reason why you can't see malware files on the infected USB storage device. We have added those drivers to anti-virus bases as [B]Rootkit.TmpHider[/B] and [B]SScope.Rookit.TmpHider.2[/B]. Note that both drivers are signed with digital signature of Realtek Semiconductor Corp. ([URL="http://www.realtek.com/"]www.realtek.com[/URL]). Thus, current malware should be added to very dangerous category causes the risk of the virus epidemic at the current moment. After we have added a new recordes to the anti-virus bases we are admitting a lot of detections of [B]Rootkit.TmpHider[/B] and [B]SScope.Rookit.TmpHider.2[/B] all over the world. src: anti-virus.by [/QUOTE]
Insert quotes…
Verification
Nawa warak dahaya keeyada? (Namaya wadi kireema dahaya)
Post reply
Top
Bottom