Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » False Positive with AVG Free?
Search Topic:
Uniqs:
1869
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Users open holes in company networks »
« Antivirus from usb drive?  
AuthorAll Replies


sammysnake
Never Forget 911
Premium
join:2002-01-19
Salt Lake City, UT
·Qwest.net
·Comcast Formerly ..

 False Positive with AVG Free?

I turned on my computer today and in the history log of AVG Free I had the following listed:

"2007/07/16 16:07:29" user="SYSTEM" source="Virus"
@HL_ReportFindRS filename> C:\WINDOWS\system32\drivers\mchInjDrv.sys
finding > @EID_Id_trj
virusname > BackDoor.Generic7.NZJ

Now I do a complete scan with AVG Free, AVG Anti-Spyware, Ad-Aware, Spybot, Windows Defender, and Trojan Hunter on a weekly basis every Friday night. All of these scans were done on 7/13 and all came up clean. The computer was not even turned on over the weekend.

I got the above after doing a manual update of AVG Free after turning on the computer this evening. No one had access to the computer all weekend.

Just for the hell of it I have redone all of the above scans and they all come up clean.

This has got me baffled.

Any suggestions?

Sammy

ezdsl

join:2002-03-13
Austin, TX

I checked my AVG log and found what was reported to be a virus (don't remember exactly which as I'm at work at the moment) logged over the weekend.

Today, I ran a full scan and nothing was found. I checked the AVG forums (»forum.grisoft.cz/freeforum/list.php?4) and found several false positives in the last couple of days.

Glitch on a weekend update? Maybe???


caffeinator
Coming soon to a cup near you..
Premium
join:2005-01-16
Spokane, WA
·WebBand


2 edits
reply to sammysnake
It's "MadCodeHook" tool from a legit company, and can/may be used by malware...but is also used by legit programs.

Found this:

»www.softwaretipsandtricks.com/da···sys.html

quote:
MchInjDrv.sys is a driver for injecting code to other processes.
Publisher is legitimate:
»madshi.net
But it is often used by malicious software.
Kill the file mchInjDrv.sys and remove mchInjDrv.sys from Windows startup.
Another thread at Kaspersky: »forum.kaspersky.com/lofiversion/···351.html

I guess it depends on what you have installed, or may have installed recently.

You could try uploading to Jotti or Virustotal for more checks.

-CaFF
--
"Only two things are infinite, the universe and human stupidity, and I'm not sure about the former." - A. Einstein

Need an Avatar? Check out Wafen's Avatar Pages


sammysnake
Never Forget 911
Premium
join:2002-01-19
Salt Lake City, UT
·Qwest.net
·Comcast Formerly ..

said by caffeinator See Profile :

It's "MadCodeHook" tool from a legit company, and can/may be used by malware...but is also used by legit programs.

Found this:

»www.softwaretipsandtricks.com/da···sys.html

quote:
MchInjDrv.sys is a driver for injecting code to other processes.
Publisher is legitimate:
»madshi.net
But it is often used by malicious software.
Kill the file mchInjDrv.sys and remove mchInjDrv.sys from Windows startup.
Another thread at Kaspersky: »forum.kaspersky.com/lofiversion/···351.html

I guess it depends on what you have installed, or may have installed recently.

You could try uploading to Jotti or Virustotal for more checks.

-CaFF
I would attempt to uplaod to Jotti or Virustotal but I do not have a file called "mchInjDrv.sys" anywhere on my system.
Forums » Up and Running » Security » SecurityUsers open holes in company networks »
« Antivirus from usb drive?  


Sunday, 08-Nov 22:04:06 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [156] Cable Uncapper Faces Criminal Charges
· [140] AT&T Sues Verizon Over 3G Ads
· [112] Why Run Fiber When You Can Run Ads That Pretend You Do?
· [108] Comcast Is Simply Getting Huge
· [93] Apple Cooking Up New $30 A Month TV Service?
· [83] Bits Of ACTA Agreement Leaking Out
· [80] Will 'Three Strikes' Come To The United States?
· [78] Verizon To Double Smartphone ETFs?
· [77] Verizon: Droid Tethering Will Cost $30 Extra
· [73] Comcast, NBC Deal Almost Complete
Most people now reading
· My cat is reluctant to exercise. [General Questions]
· Hit and run [General Questions]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· [WIN7] Which Services in Win 7 Have You Turned Off? [Microsoft Help]
· [NFL] Week 9 Games Thread [Sports Chat]
· What Are These? [Home Repair & Improvement]
· [FS] Motherboard + CPU + Hard Drive + Servers + More! [For Sale/Wanted]
· [How to] Install Asterisk on an Asus WL-520GU router [VOIP Tech Chat]
· [WIN7] Outlook express under Windows 7? [Microsoft Help]