Home Malware Programs Rootkits Trojan Rootkit Tmphider

Trojan Rootkit Tmphider

Posted: November 14, 2011

Threat Metric

Threat Level: 10/10
Infected PCs: 40
First Seen: November 14, 2011
Last Seen: September 27, 2019
OS(es) Affected: Windows

Trojan Rootkit Tmphider is a dangerous rootkit malware. Trojan Rootkit Tmphider is known for spreading through removable drives such as USB drives. Trojan Rootkit Tmphider is related to the W32.Temphid worm that downloads malware onto a system without any indication to the user. Most times Trojan Rootkit Tmphider will run undetected avoiding detection from common security tools such as known antivirus tools. It is important to utilize an updated spyware removal tool to safely detect and remove Trojan Rootkit Tmphider completely.

Use SpyHunter to Detect and Remove PC Threats

If you are concerned that malware or PC threats similar to Trojan Rootkit Tmphider may have infected your computer, we recommend you start an in-depth system scan with SpyHunter. SpyHunter is an advanced malware protection and remediation application that offers subscribers a comprehensive method for protecting PCs from malware, in addition to providing one-on-one technical support service.

Download SpyHunter's Malware Scanner*

* See Free Trial offer below. EULA and Privacy/Cookie Policy.

Why can't I open any program including SpyHunter? You may have a malware file running in memory that kills any programs that you try to launch on your PC. Tip: Download SpyHunter from a clean computer, copy it to a USB thumb drive, DVD or CD, then install it on the infected PC and run SpyHunter's malware scanner.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%WINDIR%\system32\drivers\mrxnet.sys File name: mrxnet.sys
Size: 1.41 MB (1417760 bytes)
MD5: acfe00193adb9128f6166640c16bee40
Detection count: 46
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\system32\drivers\
Group: Malware file
Last Updated: November 15, 2011
%WINDIR%\system32\Drivers\mrxcls.sys File name: mrxcls.sys
Size: 19.84 KB (19840 bytes)
MD5: ca9eabeab482524e5797c684398335d5
Detection count: 16
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\system32\Drivers\
Group: Malware file
Last Updated: November 15, 2011
%WINDIR%\system32\Drivers\mrxcls.sys File name: mrxcls.sys
Size: 26.61 KB (26616 bytes)
MD5: a143379c449a7da024b203ca80153418
Detection count: 9
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\system32\Drivers\
Group: Malware file
Last Updated: May 16, 2014
%WINDIR%\system32\Drivers\mrxnet.sys File name: mrxnet.sys
Size: 17.4 KB (17400 bytes)
MD5: 2e37615e2c960091d94db91dc758376c
Detection count: 9
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\system32\Drivers\
Group: Malware file
Last Updated: May 16, 2014
%System%\drivers\mrxcls.sys File name: %System%\drivers\mrxcls.sys
File type: System file
Mime Type: unknown/sys
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MRxNet\"ImagePath" = "%System%\drivers\mrxnet.sys"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MRxCls\"ImagePath" = "%System%\drivers\mrxcls.sys"
Loading...