Member Panel


Sponsors and Ads

Live Tag Cloud

PC Forum PC Help Forum » Security & Safety » Security Watch » [Resolved] Rootkit

Security Watch - [Resolved] Rootkit posted in the Security & Safety forums; I just downloaded and ran the AVG Anti-rootkit. It reported a file. C:\Windows\systems32\Drivers\mcjInjDrv.sys When I told the program to remove it, it warned me that removal might be dangerous in ...

JOIN US NOW to remove these Ads

PC Help Forum, the number one FREE computer support website in the search engines
Post New Thread  Reply
  #1  
Old 05-17-2007
Gandalf's Avatar
Tech Support Team
My PC
 
Join Date: Apr 2007
Location: South Korea
Posts: 1,829
PC Experience: PC Guru
Gandalf - See this Members User comments on their Profile page Gandalf - See this Members User comments on their Profile page Gandalf - See this Members User comments on their Profile page Gandalf - See this Members User comments on their Profile page Gandalf - See this Members User comments on their Profile page Gandalf - See this Members User comments on their Profile page Gandalf - See this Members User comments on their Profile page Gandalf - See this Members User comments on their Profile page Gandalf - See this Members User comments on their Profile page Gandalf - See this Members User comments on their Profile page Gandalf - See this Members User comments on their Profile page
Question [Resolved] Rootkit

I just downloaded and ran the AVG Anti-rootkit. It reported a file.

C:\Windows\systems32\Drivers\mcjInjDrv.sys

When I told the program to remove it, it warned me that removal might be dangerous in that removal might leave me in an unbootable state.

So, I come to the experts.

Can I delete it?
If not, why did it report it in the first place. Is this a Catch 22 situation?

Thanks


__________________
Klaatu Barada Nikto

  #2  
Old 05-17-2007
Wadd's Avatar
Tech Support Team
My PC
 
Join Date: Mar 2007
Location: Florida
Posts: 611
PC Experience: I know my way around a computer...
Wadd - See this Members User comments on their Profile page Wadd - See this Members User comments on their Profile page Wadd - See this Members User comments on their Profile page Wadd - See this Members User comments on their Profile page Wadd - See this Members User comments on their Profile page Wadd - See this Members User comments on their Profile page Wadd - See this Members User comments on their Profile page Wadd - See this Members User comments on their Profile page Wadd - See this Members User comments on their Profile page Wadd - See this Members User comments on their Profile page Wadd - See this Members User comments on their Profile page
Default

My suggestion would be to create an image of your hard drive and save it to another hard drive or even DVDs (Acronis True Image lets you choose to split up the image to certain file sizes which would allow you to burn them to DVDs).

Then go ahead with the removal process.

All the research I've done on that file shows it to be a dangerous file. However, you may have spelled it wrong cause your exact spelling came up with nothing. The research I did was for mchinjdrv.sys.

Regardless, if you create a good image of your drive, the very worst case scenario is you remove the file, your OS becomes too corrupted to save, then you just load your image back up.

Also, back up all your important data separately to DVDs in case you have a problem with the image restore.


  #3  
Old 05-17-2007
Gandalf's Avatar
Tech Support Team
My PC
 
Join Date: Apr 2007
Location: South Korea
Posts: 1,829
PC Experience: PC Guru
Gandalf - See this Members User comments on their Profile page Gandalf - See this Members User comments on their Profile page Gandalf - See this Members User comments on their Profile page Gandalf - See this Members User comments on their Profile page Gandalf - See this Members User comments on their Profile page Gandalf - See this Members User comments on their Profile page Gandalf - See this Members User comments on their Profile page Gandalf - See this Members User comments on their Profile page Gandalf - See this Members User comments on their Profile page Gandalf - See this Members User comments on their Profile page Gandalf - See this Members User comments on their Profile page
Default

Originally Posted by Wadd
My suggestion would be to create an image of your hard drive and save it to another hard drive or even DVDs (Acronis True Image lets you choose to split up the image to certain file sizes which would allow you to burn them to DVDs).

Then go ahead with the removal process.

All the research I've done on that file shows it to be a dangerous file. However, you may have spelled it wrong cause your exact spelling came up with nothing. The research I did was for mchinjdrv.sys.

Regardless, if you create a good image of your drive, the very worst case scenario is you remove the file, your OS becomes too corrupted to save, then you just load your image back up.

Also, back up all your important data separately to DVDs in case you have a problem with the image restore.
Yea. Misspelled.

mchInjDrv.sys

That's it. Sorry, typing is not my forte. They almost kicked me out of the military because of it. But, I'm never that lucky...


__________________
Klaatu Barada Nikto

  #4  
Old 05-21-2007
Gandalf's Avatar
Tech Support Team
My PC
 
Join Date: Apr 2007
Location: South Korea
Posts: 1,829
PC Experience: PC Guru
Gandalf - See this Members User comments on their Profile page Gandalf - See this Members User comments on their Profile page Gandalf - See this Members User comments on their Profile page Gandalf - See this Members User comments on their Profile page Gandalf - See this Members User comments on their Profile page Gandalf - See this Members User comments on their Profile page Gandalf - See this Members User comments on their Profile page Gandalf - See this Members User comments on their Profile page Gandalf - See this Members User comments on their Profile page Gandalf - See this Members User comments on their Profile page Gandalf - See this Members User comments on their Profile page
Default

Twilight Zone has just landed on my PC. When I run the AVG Anti-rootkit straight, I get the (hidden) mchInjDrv.sys file report almost immediately. I tried to delete the file and AVG Anti-rootkit could not delete the file. Then, I thought maybe it needs to be run as Admin. So, I ran it under Admin. Guess what, no file. Clean report.

This is just backward. That explains why AVG Anti-rootkit couldn't delete the file. It wasn't there. But, why report it when NOT ran as Admin?

Confused


__________________
Klaatu Barada Nikto

  #5  
Old 05-28-2007
Gandalf's Avatar
Tech Support Team
My PC
 
Join Date: Apr 2007
Location: South Korea
Posts: 1,829
PC Experience: PC Guru
Gandalf - See this Members User comments on their Profile page Gandalf - See this Members User comments on their Profile page Gandalf - See this Members User comments on their Profile page Gandalf - See this Members User comments on their Profile page Gandalf - See this Members User comments on their Profile page Gandalf - See this Members User comments on their Profile page Gandalf - See this Members User comments on their Profile page Gandalf - See this Members User comments on their Profile page Gandalf - See this Members User comments on their Profile page Gandalf - See this Members User comments on their Profile page Gandalf - See this Members User comments on their Profile page
Question

The Event Viewer come up with an occurance of mchInjDrv

Source: Windows Defender
Event Id: 3004

Windows Defender Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. Windows Defender can't undo changes that you allow.
For more information please see the following:
Not Applicable
Scan ID: {BEB5FB92-6C1A-467A-9546-718420A2945C}
User: BlackKnight\XXXXXX
Name: Unknown
ID:
Severity ID:
Category ID:
Path Found: service:mchInjDrv
Alert Type: Unclassified software
Detection Type:

AVG Anti-Rootkit-Free came up clean. No presence of mchInjDrv.
A search of the HDDs for mchInjdrv came up clean as well.
The Windows Defender recorded...something.
How do I "analyze the software that made these changes" when you don't even know what the changes were. If it is saying the mchInjDrv make the changes, I can't even find that file.

H E L P.... Please.


__________________
Klaatu Barada Nikto


Reply
New! Norton Internet Security 2008 – Download Now Click Here

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On


All times are GMT +1. The time now is 01:24 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top