| View previous topic :: View next topic |
| Author |
Message |
ctrlaltdelete
Corporal

 Joined: Nov 26, 2006 Posts: 66 Location: Netherlands
|
Posted: Sat Feb 23, 2008 11:00 am Post subject: |
|
|
"probably a variant of Win32/Genetik" was a False Positive from ESET's NOD32 which was solved the next day.
Rootkit is a technique which can be used by Malware, rootkit is NOT another name for Malware.
Several good security products also use rootkit techniques, i even got another security product (AČ) on my machine that uses mchInjDrv.sys
|
|
| Back to top |
|
 |
Anonymouss
Guest IP: 83.251.*.*
|
Posted: Sat Feb 23, 2008 5:41 pm Post subject: re.. |
|
|
Yes i Know differents between malware and rootkit, what i trying to describe here is that mchInjDrv.sys is not a rootkit it is a bad trojan. as i said earlier when i used nod32 as an example yes it was the very latest of nod32 i got Trojan "True positives - win32trojan ... modified"
btw it has nothing to do with nod32 its just alerted....
mchInjDrv.sys will install anyway without nod32.
let me explain this in this way...
It will install an Rootkit that hides "mchInjDrv.sys" so its become invincible and it WILL always be
active in memory even if you restart your comp.
"mchInjDrv.sys" will not be found anywhere because its under rootkits safety.
But with a rku rootkitunhoker...
verify this for yourself in a clean system...
you will see this file under drivers in a rku link under ...
http://forum.sysinternals.com/uploads/20071210_182632_rku37300509.rar
and if you check little more with rku you see that it is running
in memory..
funny when prevx csi in some circumstances finds it itself
but without a license as i dont ove i couldnt remove that.
try
Uninstall prevx CSI, and you see its still there. why?
its all up to you if you take this serious and not...
But it has your compo under control....
but you can always buy the product. i will not!
I think its bad that when peoducts install bad files when trying a new security program of anykind. Just to nearly force you to get ridth with the bad things... that is ugly....
|
|
| Back to top |
|
 |
horseman
Lieutenant
 Premium Member
 Joined: Apr 15, 2003 Posts: 230
|
Posted: Sun Feb 24, 2008 12:45 am Post subject: Re: re.. |
|
|
| Anonymouss wrote: |
I think its bad that when peoducts install bad files when trying a new security program of anykind. Just to nearly force you to get ridth with the bad things... that is ugly.... |
Tad strong.... bit like rubbishing ABBA's musical contribution without listening to any of their records perhaps?
I appreciate that English probably isn't your native language but then it's probably better than both my Swedish and Swahili....
So please forgive my limited linquistic comprehension but BabelFish defined "peoducts" as a "luxury cruising aquatic fowl" and "Mad Code Hook Injection Driver" as an insane cryptograhic pirate doctor from UK's Top Gear motoring program!
Still having said that I'm sure we're all indebted to you for this mind blowing expose of Prevx's sharp business practises.
Immediately explains why Prevx are conspicuously absent from this fora as obviously they're too busy briefing Retento's corporate lawyers on how to defend the class action suits that will inevitably follow now you've publically exposed their devilish scam!
Naturally I'm somewhat dissappointed you didn't raise this earlier as I only recently renewed my Prevx CSI business license from this seedy looking guy on our local Derby miniature golf course. What a cad he must have been!
Anyway all this techno babble is quite a bit beyond me so I asked my dentist about rootkits and he explained something about MD5 hashes, using VirusTotal, PX build versions,getting a signed false positive affadavit from NODdy (or was that BigEars?) and frightening Prevx by writing directly to Darren's Aunty with your fillings..... sorry teeth playing up again - I meant filings?
Anyway must go - the nurse has just spotted I'm out of bed without my restraints and I've got to rest before my cheap snow boarding holiday in Majorca this week-end. _________________ Regards Tony
Draco Dormiens Nunquam Titillandus
|
|
| Back to top |
|
 |
IP: 78.150.*.*
Guest
|
Posted: Sun Feb 24, 2008 1:17 am Post subject: |
|
|
Nice one Tony 
|
|
| Back to top |
|
 |
Anonymouss
Guest IP: 83.251.*.*
|
|
| Back to top |
|
 |
ctrlaltdelete
Corporal

 Joined: Nov 26, 2006 Posts: 66 Location: Netherlands
|
Posted: Sun Feb 24, 2008 7:55 am Post subject: |
|
|
Strange location for the temp folder.
Check Prevx CSI log, find C:\0\Temp1\Tmp__(number)\prevxcsi.exe
And copy the MD5 and PX5 code
On my machine and this version of Prevx CSI it is;
C:\Documents and Settings\pc1\Local Settings\Temp\Tmp___2791\prevxcsi.exe
MD5: 166177AAE9C1AF94E35DB08031A58730
PX5: 8B1772F80012057182A4010BA27F6900D0ECF28A
Quick check in Prevx database;
This executable program has a file size of 98,816 bytes, it is most frequently called PREVXCSI.EXE and is most frequently located in the %programfiles%\prevxcsi\ folder.
The file header contains the following information:
Vendor : Prevx
Product: Prevx Computer Security Investigator
Version: 1, 0, 0,
This file is considered safe. It was first seen on Friday, Feb 22 2008
|
|
| Back to top |
|
 |
m_giuliani
Prevx Host Premium Member
 Joined: Sep 23, 2006 Posts: 56 Location: Italy
|
Posted: Sun Feb 24, 2008 8:37 am Post subject: |
|
|
As *always* :
Before claiming we are the new CIA and we take under our control your pc, have you sent us your CSI log along with a support ticket asking what is happening?
We have nothing to do with that Madshi hook library nor with the other driver you reported before.
Where have you downloaded this version of Prevx CSI?
Sometimes ago a fake version of CSI was spreading around. _________________ Prevx Research Lab
|
|
| Back to top |
|
 |
Loafer
Trooper
 Premium Member
Joined: Jul 03, 2006 Posts: 12
|
Posted: Fri Jun 20, 2008 3:42 pm Post subject: Prevx CSI - False Positives |
|
|
I had the paid-for version of this software. After three separate false positives, the last of which identified some software from Steve Gibson's site as 'dangerous', and deleted it, I removed Prevx CSI from my PC.
|
|
| Back to top |
|
 |
SteveEast9
Trooper

 Joined: Feb 13, 2008 Posts: 14 Location: UK
|
Posted: Thu Jul 17, 2008 3:06 pm Post subject: |
|
|
I think we can safely say that Prevx 'official' support have abandoned this forum and any Prevx users that come here from their won website link! LOL
|
|
| Back to top |
|
 |
SteveEast9
Trooper

 Joined: Feb 13, 2008 Posts: 14 Location: UK
|
Posted: Thu Jul 17, 2008 3:16 pm Post subject: |
|
|
I think we can safely say that Prevx 'official' support have abandoned this forum and any Prevx users that come here from their won website link! LOL
|
|
| Back to top |
|
 |
|
|