Wilders Security Forums  

Go Back   Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archive of DiamondCS Support Forums > ProcessGuard
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old September 6th, 2004, 06:59 PM
Rainwalker's Avatar
Rainwalker Rainwalker is offline
Very Frequent Poster
 
Join Date: May 2003
Posts: 1,680
Default MchInjDrv

Anyone else have this showing up lately ..... MchInjDrv
Any thoughts
  #2  
Old September 6th, 2004, 11:54 PM
Gavin - DiamondCS's Avatar
Gavin - DiamondCS Gavin - DiamondCS is offline
Former DCS Moderator
 
Join Date: Feb 2002
Location: Perth, Western Australia
Posts: 2,080
Default Re: MchInjDrv

Hi,

This is used by those programs with injection based on MadCodeHook - usermode injection and hooking technologies. You should ALLOW this if you trust the program doing it - to prevent any incompatibilies

If this happened with an unknown program or possible trojan, you can send the file to submit(at)diamondcs.com.au for analysis
  #3  
Old September 7th, 2004, 12:04 AM
Rainwalker's Avatar
Rainwalker Rainwalker is offline
Very Frequent Poster
 
Join Date: May 2003
Posts: 1,680
Default Re: MchInjDrv

Thanks Gavin....There are two 'trusted' problems that want to use it. One is Spy Sweeper. It has been trying for the past two days and i have been using SS a lot longer then that with no sign of that driver and have not received any updates for awhile. Same with the other program....only these past two days....seems a bit strange.
  #4  
Old September 7th, 2004, 04:37 AM
Pilli's Avatar
Pilli Pilli is offline
Incredibly Massive Poster
 
Join Date: Feb 2002
Location: Hampshire UK
Posts: 6,218
Default Re: MchInjDrv

Hi RainWalker, It may be to do with your SS settings. Have you changed some setting in SS that might initiate another process? If so PG is probably catching that.
I give SS all allows.

Pilli
__________________
"Education is not the filling of a pail, but the lighting of a fire"
Pilli's website http://www.pilliwinks.net
  #5  
Old September 7th, 2004, 11:42 AM
Rainwalker's Avatar
Rainwalker Rainwalker is offline
Very Frequent Poster
 
Join Date: May 2003
Posts: 1,680
Default Re: MchInjDrv

Hey Pilli ....changed nutt'n ....Have YOU seen that driver request prior to allowing?
  #6  
Old September 7th, 2004, 12:04 PM
Pilli's Avatar
Pilli Pilli is offline
Incredibly Massive Poster
 
Join Date: Feb 2002
Location: Hampshire UK
Posts: 6,218
Default Re: MchInjDrv

Yep, I'm sure I saw it the first time I fired SS up after install but I cannot find it now using windows explorer
__________________
"Education is not the filling of a pail, but the lighting of a fire"
Pilli's website http://www.pilliwinks.net
  #7  
Old September 7th, 2004, 12:23 PM
Don Pelotas's Avatar
Don Pelotas Don Pelotas is offline
Very Frequent Poster
 
Join Date: Jun 2004
Posts: 2,255
Default Re: MchInjDrv

Pilli is right, i noticed it right after installing 3.0.
__________________
Errare humanum est
  #8  
Old September 7th, 2004, 10:10 PM
Rainwalker's Avatar
Rainwalker Rainwalker is offline
Very Frequent Poster
 
Join Date: May 2003
Posts: 1,680
Default Re: MchInjDrv

Quote:
Originally Posted by Pilli
Yep, I'm sure I saw it the first time I fired SS up after install but I cannot find it now using windows explorer

Ok....hate to keep beating that proverbial horse but isn't a bit odd you can't locate it
  #9  
Old September 7th, 2004, 10:14 PM
Rainwalker's Avatar
Rainwalker Rainwalker is offline
Very Frequent Poster
 
Join Date: May 2003
Posts: 1,680
Default Re: MchInjDrv

Opps sorry Don.....meant to thank you for your comment
  #10  
Old September 7th, 2004, 10:22 PM
Rainwalker's Avatar
Rainwalker Rainwalker is offline
Very Frequent Poster
 
Join Date: May 2003
Posts: 1,680
Default Re: MchInjDrv

BTW..i wrote Web...root yesterday and so far have heard nada.
  #11  
Old September 7th, 2004, 11:36 PM
Gavin - DiamondCS's Avatar
Gavin - DiamondCS Gavin - DiamondCS is offline
Former DCS Moderator
 
Join Date: Feb 2002
Location: Perth, Western Australia
Posts: 2,080
Default Re: MchInjDrv

You can't locate it because it is "dropped" by the EXE, then loaded into memory. It could likely then be deleted, the system only needs the memory image of the file
  #12  
Old September 8th, 2004, 03:02 AM
Bowserman's Avatar
Bowserman Bowserman is offline
Forum Moderator
 
Join Date: Apr 2003
Location: South Australia
Posts: 510
Default Re: MchInjDrv

Yep, tested earlier. spysweeper.exe attempted to "drop" mchInjDrv after install and upon SS being run for the first time (at least for me)....I logged it . I imagine it would be used for the Shields, judging by what Gavin said.

Code:
Wed 08 - 12:34:56 [DRIVER/SERVICE] c:\program files\webroot\spy sweeper\spysweeper.exe [652] Tried to install a driver/service named mchInjDrv Wed 08 - 12:34:56 [DRIVER/SERVICE] c:\program files\webroot\spy sweeper\spysweeper.exe [652] Tried to install a driver/service named mchInjDrv


Regards,
Jade.

Last edited by Bowserman : September 8th, 2004 at 04:11 AM.
  #13  
Old September 11th, 2004, 07:52 AM
Rainwalker's Avatar
Rainwalker Rainwalker is offline
Very Frequent Poster
 
Join Date: May 2003
Posts: 1,680
Default Re: MchInjDrv

I just received this from Webroot:

Solution: We apologize for the trouble that you've had. Spy
Sweeper does not have the ability to add drivers to your system, it is
not necessary for use, however we will still look into the name of this
file, and hopefully we can determine it's source. SHould we find any
more information, we'll let you know.
  #14  
Old September 11th, 2004, 11:56 AM
quaduong
 
Posts: n/a
Default Re: MchInjDrv

Quote:
Originally Posted by Rainwalker
I just received this from Webroot:

Solution: We apologize for the trouble that you've had. Spy
Sweeper does not have the ability to add drivers to your system, it is
not necessary for use, however we will still look into the name of this
file, and hopefully we can determine it's source. SHould we find any
more information, we'll let you know.

Thankx for the info from webroot.
In my view, it is kind of weird since they have made their softwares which they have not known details/components of softwares they have made?
- is it that they have used some existing source code from others?
- spysweeper 3x is infected already? it is kind of silly to say this, just anyway.

Looking forward to experts to clarify it out.
.
  #15  
Old September 11th, 2004, 12:04 PM
Pilli's Avatar
Pilli Pilli is offline
Incredibly Massive Poster
 
Join Date: Feb 2002
Location: Hampshire UK
Posts: 6,218
Default Re: MchInjDrv

Hi quaduong, I doubt the person responding had any idea about RainWalkers question and has passed it on to a tech for a proper and more authoritive response.
I definately saw what Bowserman shows in his screenshot.
__________________
"Education is not the filling of a pail, but the lighting of a fire"
Pilli's website http://www.pilliwinks.net
  #16  
Old September 11th, 2004, 12:50 PM
Rainwalker's Avatar
Rainwalker Rainwalker is offline
Very Frequent Poster
 
Join Date: May 2003
Posts: 1,680
Default Re: MchInjDrv

I will follow this up
  #17  
Old September 11th, 2004, 01:07 PM
Pilli's Avatar
Pilli Pilli is offline
Incredibly Massive Poster
 
Join Date: Feb 2002
Location: Hampshire UK
Posts: 6,218
Default Re: MchInjDrv

Thanks Rainwalker, Don't you just love these little mysteries

Cheers Pilli
__________________
"Education is not the filling of a pail, but the lighting of a fire"
Pilli's website http://www.pilliwinks.net
  #18  
Old September 11th, 2004, 01:17 PM
Rainwalker's Avatar
Rainwalker Rainwalker is offline
Very Frequent Poster
 
Join Date: May 2003
Posts: 1,680
Default Re: MchInjDrv

Quote:
Originally Posted by Pilli
Thanks Rainwalker, Don't you just love these little mysteries

Cheers Pilli
Yes indeedy, and i always prefer to err on the side of paranoia
  #19  
Old September 14th, 2004, 10:06 PM
Rainwalker's Avatar
Rainwalker Rainwalker is offline
Very Frequent Poster
 
Join Date: May 2003
Posts: 1,680
Default Re: MchInjDrv

Just to say i have heard nothing back from Webroot as of today
  #20  
Old September 15th, 2004, 03:12 AM
Pilli's Avatar
Pilli Pilli is offline
Incredibly Massive Poster
 
Join Date: Feb 2002
Location: Hampshire UK
Posts: 6,218
Default Re: MchInjDrv

Thanks for keeping us updated RainWalker
__________________
"Education is not the filling of a pail, but the lighting of a fire"
Pilli's website http://www.pilliwinks.net
  #21  
Old September 15th, 2004, 04:50 AM
Gavin - DiamondCS's Avatar
Gavin - DiamondCS Gavin - DiamondCS is offline
Former DCS Moderator
 
Join Date: Feb 2002
Location: Perth, Western Australia
Posts: 2,080
Default Re: MchInjDrv

It might be that they have used the "Madshi" libraries and not noticed what it is actually capable of. Well.. it seems like the only explanation to me
  #22  
Old September 15th, 2004, 12:41 PM
Rainwalker's Avatar
Rainwalker Rainwalker is offline
Very Frequent Poster
 
Join Date: May 2003
Posts: 1,680
Default Re: MchInjDrv

Quote:
Originally Posted by Gavin - DiamondCS
It might be that they have used the "Madshi" libraries and not noticed what it is actually capable of. Well.. it seems like the only explanation to me

I understand this is 'Madshi' stuff but nonetheless .............waiting to hear...i'll try them again sometime soon...they outta be knowing what they are selling better then they appear to, before they put it on the market.
  #23  
Old September 17th, 2004, 11:31 PM
Rainwalker's Avatar
Rainwalker Rainwalker is offline
Very Frequent Poster
 
Join Date: May 2003
Posts: 1,680
Default Re: MchInjDrv

UPDATE:
Wrote them 2 days ago (9-15-04).....still nothing......waiting
  #24  
Old September 21st, 2004, 01:49 AM
worldcitizen's Avatar
worldcitizen worldcitizen is offline
Frequent Poster
 
Join Date: May 2003
Posts: 530
Default Re: MchInjDrv

I got the same so should I give Spy Sweeper all alows or what?

Dave
  #25  
Old September 21st, 2004, 02:29 AM
Pilli's Avatar
Pilli Pilli is offline
Incredibly Massive Poster
 
Join Date: Feb 2002
Location: Hampshire UK
Posts: 6,218
Default Re: MchInjDrv

I have found that SpySweeper needs the install driver / service allow.
Watch the alerts to ensure the necessary allows.

HTH Pilli
__________________
"Education is not the filling of a pail, but the lighting of a fire"
Pilli's website http://www.pilliwinks.net
 

Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archive of DiamondCS Support Forums > ProcessGuard « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 06:51 AM.


Powered by vBulletin® Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2010, Wilders Security Forums