![]() |
|
#1
|
||||
|
||||
|
Anyone else have this showing up lately ..... MchInjDrv
Any thoughts |
|
#2
|
||||
|
||||
|
Hi,
This is used by those programs with injection based on MadCodeHook - usermode injection and hooking technologies. You should ALLOW this if you trust the program doing it - to prevent any incompatibilies If this happened with an unknown program or possible trojan, you can send the file to submit(at)diamondcs.com.au for analysis |
|
#3
|
||||
|
||||
|
Thanks Gavin....There are two 'trusted' problems that want to use it. One is Spy Sweeper. It has been trying for the past two days and i have been using SS a lot longer then that with no sign of that driver and have not received any updates for awhile. Same with the other program....only these past two days....seems a bit strange.
|
|
#4
|
||||
|
||||
|
Hi RainWalker, It may be to do with your SS settings. Have you changed some setting in SS that might initiate another process? If so PG is probably catching that.
I give SS all allows. Pilli
__________________
"Education is not the filling of a pail, but the lighting of a fire" Pilli's website http://www.pilliwinks.net |
|
#5
|
||||
|
||||
|
Hey Pilli
....changed nutt'n ....Have YOU seen that driver request prior to allowing? |
|
#6
|
||||
|
||||
|
Yep, I'm sure I saw it the first time I fired SS up after install but I cannot find it now using windows explorer
![]()
__________________
"Education is not the filling of a pail, but the lighting of a fire" Pilli's website http://www.pilliwinks.net |
|
#7
|
||||
|
||||
|
Pilli is right, i noticed it right after installing 3.0.
![]()
__________________
Errare humanum est |
|
#8
|
||||
|
||||
|
Quote:
Ok....hate to keep beating that proverbial horse but isn't a bit odd you can't locate it ![]() |
|
#9
|
||||
|
||||
|
Opps sorry Don.....meant to thank you for your comment
![]() |
|
#10
|
||||
|
||||
|
BTW..i wrote Web...root yesterday and so far have heard nada.
|
|
#11
|
||||
|
||||
|
You can't locate it because it is "dropped" by the EXE, then loaded into memory. It could likely then be deleted, the system only needs the memory image of the file
|
|
#12
|
||||
|
||||
|
Yep, tested earlier. spysweeper.exe attempted to "drop" mchInjDrv after install and upon SS being run for the first time (at least for me)....I logged it
. I imagine it would be used for the Shields, judging by what Gavin said.Code:
Regards, Jade.
__________________
Ghost Security Products DiamondCS Products -------- Trojan/Malware Submission Last edited by Bowserman : September 8th, 2004 at 04:11 AM. |
|
#13
|
||||
|
||||
|
I just received this from Webroot:
Solution: We apologize for the trouble that you've had. Spy Sweeper does not have the ability to add drivers to your system, it is not necessary for use, however we will still look into the name of this file, and hopefully we can determine it's source. SHould we find any more information, we'll let you know. |
|
#14
|
|||
|
|||
|
Quote:
Thankx for the info from webroot. In my view, it is kind of weird since they have made their softwares which they have not known details/components of softwares they have made? - is it that they have used some existing source code from others? - spysweeper 3x is infected already? it is kind of silly to say this, just anyway. Looking forward to experts to clarify it out. . |
|
#15
|
||||
|
||||
|
Hi quaduong, I doubt the person responding had any idea about RainWalkers question and has passed it on to a tech for a proper and more authoritive response.
I definately saw what Bowserman shows in his screenshot.
__________________
"Education is not the filling of a pail, but the lighting of a fire" Pilli's website http://www.pilliwinks.net |
|
#16
|
||||
|
||||
|
I will follow this up
|
|
#17
|
||||
|
||||
|
Thanks Rainwalker, Don't you just love these little mysteries
Cheers Pilli
__________________
"Education is not the filling of a pail, but the lighting of a fire" Pilli's website http://www.pilliwinks.net |
|
#18
|
||||
|
||||
|
Quote:
![]() |
|
#19
|
||||
|
||||
|
Just to say i have heard nothing back from Webroot as of today
![]() |
|
#20
|
||||
|
||||
|
Thanks for keeping us updated RainWalker
![]()
__________________
"Education is not the filling of a pail, but the lighting of a fire" Pilli's website http://www.pilliwinks.net |
|
#21
|
||||
|
||||
|
It might be that they have used the "Madshi" libraries and not noticed what it is actually capable of. Well.. it seems like the only explanation to me
|
|
#22
|
||||
|
||||
|
Quote:
I understand this is 'Madshi' stuff but nonetheless .............waiting to hear...i'll try them again sometime soon...they outta be knowing what they are selling better then they appear to, before they put it on the market. |
|
#23
|
||||
|
||||
|
UPDATE:
Wrote them 2 days ago (9-15-04).....still nothing......waiting ![]() |
|
#24
|
||||
|
||||
|
I got the same so should I give Spy Sweeper all alows or what?
Dave |
|
#25
|
||||
|
||||
|
I have found that SpySweeper needs the install driver / service allow.
Watch the alerts to ensure the necessary allows. HTH Pilli
__________________
"Education is not the filling of a pail, but the lighting of a fire" Pilli's website http://www.pilliwinks.net |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|