CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 934
Comments: 25
block bottom
spacer spacer

129 FPs in latest PrevxCSI Free Scanner
Goto page Previous  1, 2
 
Post new topic   Reply to topic       All -> FavForums -> Prevx [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
ctrlaltdelete

Corporal
Corporal


Joined: Nov 26, 2006
Posts: 66
Location: Netherlands

PostPosted: Sat Feb 23, 2008 11:00 am    Post subject:
Reply with quote

"probably a variant of Win32/Genetik" was a False Positive from ESET's NOD32 which was solved the next day.

Rootkit is a technique which can be used by Malware, rootkit is NOT another name for Malware.

Several good security products also use rootkit techniques, i even got another security product (AČ) on my machine that uses mchInjDrv.sys

Back to top
View users profile Send private message Visit posters website
Anonymouss

Guest
IP: 83.251.*.*






PostPosted: Sat Feb 23, 2008 5:41 pm    Post subject: re..
Reply with quote

Yes i Know differents between malware and rootkit, what i trying to describe here is that mchInjDrv.sys is not a rootkit it is a bad trojan. as i said earlier when i used nod32 as an example yes it was the very latest of nod32 i got Trojan "True positives - win32trojan ... modified"

btw it has nothing to do with nod32 its just alerted....
mchInjDrv.sys will install anyway without nod32.

let me explain this in this way...

It will install an Rootkit that hides "mchInjDrv.sys" so its become invincible and it WILL always be
active in memory even if you restart your comp.
"mchInjDrv.sys" will not be found anywhere because its under rootkits safety.

But with a rku rootkitunhoker...
verify this for yourself in a clean system...
you will see this file under drivers in a rku link under ...

http://forum.sysinternals.com/uploads/20071210_182632_rku37300509.rar

and if you check little more with rku you see that it is running
in memory..

funny when prevx csi in some circumstances finds it itself
but without a license as i dont ove i couldnt remove that.

try
Uninstall prevx CSI, and you see its still there. why?
its all up to you if you take this serious and not...
But it has your compo under control....

but you can always buy the product. i will not!

I think its bad that when peoducts install bad files when trying a new security program of anykind. Just to nearly force you to get ridth with the bad things... that is ugly....

Back to top
horseman

Lieutenant
Lieutenant
Premium Member

Joined: Apr 15, 2003
Posts: 230

Premium

PostPosted: Sun Feb 24, 2008 12:45 am    Post subject: Re: re..
Reply with quote

Anonymouss wrote:


I think its bad that when peoducts install bad files when trying a new security program of anykind. Just to nearly force you to get ridth with the bad things... that is ugly....


Tad strong.... bit like rubbishing ABBA's musical contribution without listening to any of their records perhaps?

I appreciate that English probably isn't your native language but then it's probably better than both my Swedish and Swahili....

So please forgive my limited linquistic comprehension but BabelFish defined "peoducts" as a "luxury cruising aquatic fowl" and "Mad Code Hook Injection Driver" as an insane cryptograhic pirate doctor from UK's Top Gear motoring program!

Still having said that I'm sure we're all indebted to you for this mind blowing expose of Prevx's sharp business practises.
Immediately explains why Prevx are conspicuously absent from this fora as obviously they're too busy briefing Retento's corporate lawyers on how to defend the class action suits that will inevitably follow now you've publically exposed their devilish scam!

Naturally I'm somewhat dissappointed you didn't raise this earlier as I only recently renewed my Prevx CSI business license from this seedy looking guy on our local Derby miniature golf course. What a cad he must have been!

Anyway all this techno babble is quite a bit beyond me so I asked my dentist about rootkits and he explained something about MD5 hashes, using VirusTotal, PX build versions,getting a signed false positive affadavit from NODdy (or was that BigEars?) and frightening Prevx by writing directly to Darren's Aunty with your fillings..... sorry teeth playing up again - I meant filings?

Anyway must go - the nurse has just spotted I'm out of bed without my restraints and I've got to rest before my cheap snow boarding holiday in Majorca this week-end.


_________________
Regards Tony

Draco Dormiens Nunquam Titillandus
Back to top
View users profile Send private message MSN Messenger
IP: 78.150.*.*

Guest






PostPosted: Sun Feb 24, 2008 1:17 am    Post subject:
Reply with quote

Nice one Tony Wink

Back to top
Anonymouss

Guest
IP: 83.251.*.*






PostPosted: Sun Feb 24, 2008 3:26 am    Post subject:
Reply with quote

He he you are a funny man Smile

yeah my english is not perfect and a wrongspelling there and there thats really something to peek floating away from facts.

its humans nature behaviors flee away subject with jokes. ha ha
serously it was quite fun to read it Smile)

as long as everyone is honest its fine by me.

Anyway look at this picture mr perfect... except for your mouth then Laughing




PrevxCSI in action found itself.JPG
 Description:
PrevxCSI in action found itself
 Filesize:  50.83 KB
 Viewed:  126 Time(s)

PrevxCSI in action found itself.JPG


Back to top
ctrlaltdelete

Corporal
Corporal


Joined: Nov 26, 2006
Posts: 66
Location: Netherlands

PostPosted: Sun Feb 24, 2008 7:55 am    Post subject:
Reply with quote

Strange location for the temp folder.


Check Prevx CSI log, find C:\0\Temp1\Tmp__(number)\prevxcsi.exe
And copy the MD5 and PX5 code






On my machine and this version of Prevx CSI it is;

C:\Documents and Settings\pc1\Local Settings\Temp\Tmp___2791\prevxcsi.exe
MD5: 166177AAE9C1AF94E35DB08031A58730
PX5: 8B1772F80012057182A4010BA27F6900D0ECF28A

Quick check in Prevx database;

This executable program has a file size of 98,816 bytes, it is most frequently called PREVXCSI.EXE and is most frequently located in the %programfiles%\prevxcsi\ folder.
The file header contains the following information:
Vendor : Prevx
Product: Prevx Computer Security Investigator
Version: 1, 0, 0,

This file is considered safe. It was first seen on Friday, Feb 22 2008

Back to top
View users profile Send private message Visit posters website
m_giuliani

Prevx Host
Premium Member

Joined: Sep 23, 2006
Posts: 56
Location: Italy
Premium

PostPosted: Sun Feb 24, 2008 8:37 am    Post subject:
Reply with quote

As *always* :

Before claiming we are the new CIA and we take under our control your pc, have you sent us your CSI log along with a support ticket asking what is happening?

We have nothing to do with that Madshi hook library nor with the other driver you reported before.

Where have you downloaded this version of Prevx CSI?
Sometimes ago a fake version of CSI was spreading around.


_________________
Prevx Research Lab
Back to top
View users profile Send private message Visit posters website MSN Messenger
Loafer

Trooper
Trooper
Premium Member

Joined: Jul 03, 2006
Posts: 12

Premium

PostPosted: Fri Jun 20, 2008 3:42 pm    Post subject: Prevx CSI - False Positives
Reply with quote

I had the paid-for version of this software. After three separate false positives, the last of which identified some software from Steve Gibson's site as 'dangerous', and deleted it, I removed Prevx CSI from my PC.

Back to top
View users profile Send private message
SteveEast9

Trooper
Trooper


Joined: Feb 13, 2008
Posts: 14
Location: UK

PostPosted: Thu Jul 17, 2008 3:06 pm    Post subject:
Reply with quote

I think we can safely say that Prevx 'official' support have abandoned this forum and any Prevx users that come here from their won website link! LOL

Back to top
View users profile Send private message
SteveEast9

Trooper
Trooper


Joined: Feb 13, 2008
Posts: 14
Location: UK

PostPosted: Thu Jul 17, 2008 3:16 pm    Post subject:
Reply with quote

I think we can safely say that Prevx 'official' support have abandoned this forum and any Prevx users that come here from their won website link! LOL

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Prevx All times are GMT
Goto page Previous  1, 2
Page 2 of 2

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer