Author Topic: MCHINJDRV - What is this?  (Read 5324 times)

0 Members and 1 Guest are viewing this topic.

thorn108

  • Guest
MCHINJDRV - What is this?
« on: June 09, 2006, 02:47:37 AM »
Hi
My firewall shows that avast!Web Scanner is trying to install a new driver or service: MCHINJDRV. What is that? Is there enything to worry about?

Thanks

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: MCHINJDRV - What is this?
« Reply #1 on: June 09, 2006, 02:51:10 AM »
Which is your operational system?
I can't find a driver called MCHINJDRV in my computer...  ::) ???
The best things in life are free.

thorn108

  • Guest
Re: MCHINJDRV - What is this?
« Reply #2 on: June 09, 2006, 02:58:42 AM »
Its Windows XP Home Edition

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: MCHINJDRV - What is this?
« Reply #3 on: June 09, 2006, 03:15:01 AM »
I have XP Professional SP2+ and don't have a trouble...
Tryed to search again and did not find that file...
Are you sure it's correct spelled?
Can you post a screenshot of the error message?
The best things in life are free.

thorn108

  • Guest
Re: MCHINJDRV - What is this?
« Reply #4 on: June 09, 2006, 04:24:45 AM »
I've denied installing this driver/service so firewall message disappeared. The message about suspicious behavior was exactly: avast!Web Scanner is trying to install a new driver or service: MCHINJDRV. I found the information on the internet that MCHINJDRV has something common with trojan Backdoor.Win32.Delf.zc but I don't know why avast! Webscaner wanted to install this? ???

Spiritsongs

  • Guest
Re: MCHINJDRV - What is this?
« Reply #5 on: June 09, 2006, 04:44:10 AM »
 :)  Hi Thorn :

      Like you, I have Win XP Home Edition ; however, my
      firewall has not given me a similar "alert", so it appears
      something was "using" Avast Web Scanner "name" .
      If you click "Run", type "services.msc", click "OK" , what is
      the "Startup Type" setting for "Avast Web Scanner" ?
      Hopefully it is "Manual" . What firewall do you have ?

Negeltu

  • Guest
Re: MCHINJDRV - What is this?
« Reply #6 on: June 09, 2006, 05:23:50 AM »
From CastleCops forum...

"There's a lot of concern at the moment about MchInjDrv. MchInjDrv is a third-party driver/library used by many security applications to provide process-protection. MchInjDrv (or the Mad code hook injection driver) provides a library to allow security product developers to inject a DLL into every process from kernel-mode.

Products we believe use it include spysweeper, a2 and Trojan Hunter. There may be more applications that use this legitimately.

If you trust the process asking to do this, and your sure it hasn't been compromised, then you can allow this driver to be registered for that process. "

thorn108

  • Guest
Re: MCHINJDRV - What is this?
« Reply #7 on: June 09, 2006, 03:16:02 PM »
Hi
Thanks for informations.

I have ZoneAlarm firewall.
In "services.msc" setting for "Avast Web Scanner" is "manual".

I couldn't find any informations that avast! has something common with MchInjDrv
so I mistrust that and didn't allow to install.

Once again thanks for replies.
Hopefuly I'll findĀ  confirmation that avast! uses MchInjDrv legitimately

housi

  • Guest
Re: MCHINJDRV - What is this?
« Reply #8 on: June 10, 2006, 10:26:14 AM »
Hi
I've XP Pro SP2 a not such a file

JimTheMuso

  • Guest
Re: MCHINJDRV - What is this?
« Reply #9 on: September 26, 2007, 03:36:42 PM »
I now have this problem due to FireThreat (formerly Cyberhawk). How can I tell Avast to ignore this particular file? I have tried to add the location of this file to the exclusions but, once it has done whatever it does, it cannot be found on the pc any more. I suspect it is deleted once it has finished but the warning every time I boot up is very annoying.

AKAJohnDoe

  • Guest
Re: MCHINJDRV - What is this?
« Reply #10 on: September 26, 2007, 07:30:06 PM »
It is also a part of PC Tools Spyware Doctor, used as part of the keylogger.

AKAJohnDoe

  • Guest
Re: MCHINJDRV - What is this?
« Reply #11 on: September 26, 2007, 08:47:31 PM »
Although, SOMETHING HAS CHANGED within the past two days, as AVAST! did not used to flag it at boot-up.