Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » False Positive with AVG Free?
Search Topic:
Uniqs:
1910
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Users open holes in company networks »
« Antivirus from usb drive?  
AuthorAll Replies


sammysnake
Never Forget 911
Premium
join:2002-01-19
Salt Lake City, UT
·Qwest.net
·Comcast Formerly ..

reply to caffeinator
Re: False Positive with AVG Free?

said by caffeinator See Profile :

It's "MadCodeHook" tool from a legit company, and can/may be used by malware...but is also used by legit programs.

Found this:

»www.softwaretipsandtricks.com/da···sys.html

quote:
MchInjDrv.sys is a driver for injecting code to other processes.
Publisher is legitimate:
»madshi.net
But it is often used by malicious software.
Kill the file mchInjDrv.sys and remove mchInjDrv.sys from Windows startup.
Another thread at Kaspersky: »forum.kaspersky.com/lofiversion/···351.html

I guess it depends on what you have installed, or may have installed recently.

You could try uploading to Jotti or Virustotal for more checks.

-CaFF
I would attempt to uplaod to Jotti or Virustotal but I do not have a file called "mchInjDrv.sys" anywhere on my system.


caffeinator
Coming soon to a cup near you..
Premium
join:2005-01-16
Spokane, WA
·WebBand


2 edits
reply to sammysnake
It's "MadCodeHook" tool from a legit company, and can/may be used by malware...but is also used by legit programs.

Found this:

»www.softwaretipsandtricks.com/da···sys.html

quote:
MchInjDrv.sys is a driver for injecting code to other processes.
Publisher is legitimate:
»madshi.net
But it is often used by malicious software.
Kill the file mchInjDrv.sys and remove mchInjDrv.sys from Windows startup.
Another thread at Kaspersky: »forum.kaspersky.com/lofiversion/···351.html

I guess it depends on what you have installed, or may have installed recently.

You could try uploading to Jotti or Virustotal for more checks.

-CaFF
--
"Only two things are infinite, the universe and human stupidity, and I'm not sure about the former." - A. Einstein

Need an Avatar? Check out Wafen's Avatar Pages

ezdsl

join:2002-03-13
Austin, TX

reply to sammysnake
I checked my AVG log and found what was reported to be a virus (don't remember exactly which as I'm at work at the moment) logged over the weekend.

Today, I ran a full scan and nothing was found. I checked the AVG forums (»forum.grisoft.cz/freeforum/list.php?4) and found several false positives in the last couple of days.

Glitch on a weekend update? Maybe???


sammysnake
Never Forget 911
Premium
join:2002-01-19
Salt Lake City, UT
·Qwest.net
·Comcast Formerly ..

  I turned on my computer today and in the history log of AVG Free I had the following listed:

"2007/07/16 16:07:29" user="SYSTEM" source="Virus"
@HL_ReportFindRS filename> C:\WINDOWS\system32\drivers\mchInjDrv.sys
finding > @EID_Id_trj
virusname > BackDoor.Generic7.NZJ

Now I do a complete scan with AVG Free, AVG Anti-Spyware, Ad-Aware, Spybot, Windows Defender, and Trojan Hunter on a weekly basis every Friday night. All of these scans were done on 7/13 and all came up clean. The computer was not even turned on over the weekend.

I got the above after doing a manual update of AVG Free after turning on the computer this evening. No one had access to the computer all weekend.

Just for the hell of it I have redone all of the above scans and they all come up clean.

This has got me baffled.

Any suggestions?

Sammy
Forums » Up and Running » Security » SecurityUsers open holes in company networks »
« Antivirus from usb drive?  


Sunday, 29-Nov 00:04:32 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [122] Time Warner Cable Fires Broadside At Broadcasters
· [112] New AT&T Ad Campaign Hits Back At Verizon
· [96] Apple Joins AT&T Verizon Snark Fest
· [87] New Bill Takes Aim At Higher Verizon ETFs
· [80] TiVo Sees Record Customer Losses
· [71] Weekend Open Thread
· [70] Verizon CEO: Hulu Will Be Dead Soon
· [69] In-Flight Internet Headed For Bumpy Landing?
· [62] Thanksgiving Open Thread
· [40] EFF Wages War On Fine Print
Most people now reading
· [How to] Install Asterisk on an Asus WL-520GU router [VOIP Tech Chat]
· Windows 7 boot manager editing questions [Microsoft Help]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· ToC 4th boss - Preliminary Strategy for Twin Valkyr [World of Warcraft]
· [Newsgroups] Newzleech down? [Filesharing Software]
· Why does it take so long? Mail question [General Questions]
· Why would I want an e reader? [General Questions]
· [ Classes] Druid tanking: rotation and glyphs [World of Warcraft]
· Linksys N routers: open to Cisco's snooping? [Security]