The Notebook Review forums were hosted by TechTarget, who shut down them down on January 31, 2022. This static read-only archive was pulled by NBR forum users between January 20 and January 31, 2022, in an effort to make sure that the valuable technical information that had been posted on the forums is preserved. For current discussions, many NBR forum users moved over to NotebookTalk.net after the shutdown.
Problems? See this thread at archive.org.

    service:mchInjDrv - Windows Defender False Positive?

    Discussion in 'Security and Anti-Virus Software' started by fonduekid, Aug 17, 2009.

  1. fonduekid

    fonduekid JSUTAONHTERBIRCKINTEHWLAL

    Reputations:
    1,407
    Messages:
    3,396
    Likes Received:
    0
    Trophy Points:
    105
    Hi People,

    Since August 11, I have been having this warning in the event viewer, every time the laptop starts up.

    driver:mchInjDrv
    service:mchInjDrv
    (screen shots coming up)

    I googled the last few days and came across many many entries like this 'mad code hook injection driver' belonging to various anti-SW, like threatfire, etc. for monitoring the programs, and that Windows Defender give' a false positive on this while doing a real-time protection scan.

    Some of the search results in google date back a long time and so I am not sure if WD still gives a false positive on this.

    First, what I could not find was, is there any way to know which program is installing this or to which program does this belong to?

    Second, I found a registy key entry in

    "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_MCHINJDRV" (I'll get in a screenshot soon) and I have no idea what this means.

    Third, this warning is shown up only by WD and not by NIS or threatfire or any other scanner.

    There were posts / reports online I found through google that this is legit and only WD gives a false positive, but I am not sure about this. There was even a forum thread saying this belongs to threatfire!!

    Any suggestions people? Many thanks in advance.

    Caps: http://img10.imageshack.us/gal.php?g=eventviewerwarning.jpg

    Warning seen in event logs: http://img10.imageshack.us/img10/7955/eventviewerwarning.jpg

    Reg Entry: http://img10.imageshack.us/img10/854/registryentry.jpg

    Edit: I cannot find anything in the history of WD either. So I am like super confused :(
     
  2. Baserk

    Baserk Notebook user

    Reputations:
    2,503
    Messages:
    1,794
    Likes Received:
    1
    Trophy Points:
    56
    If it's (been) used by a legitimate program, you should have a mchInjDrv.sys in Windows\system32\Drivers.
    Not in Windows or Windows\System32.
    You can upload it to VirusTotal or Jotti's malwarescanner.
     
  3. fonduekid

    fonduekid JSUTAONHTERBIRCKINTEHWLAL

    Reputations:
    1,407
    Messages:
    3,396
    Likes Received:
    0
    Trophy Points:
    105
    Thanks Baserk.

    Strange, but I can't find it anywhere - not in Windows\system32\Drivers or Windows or Windows\System32

    What' happening here? :confused:

    I ran some more complete scan' too, but nothing turned up!!
     
  4. Baserk

    Baserk Notebook user

    Reputations:
    2,503
    Messages:
    1,794
    Likes Received:
    1
    Trophy Points:
    56
    If an online scanner and/or SAS/MBAM doesn't find anything, I'd say WD is giving you the willies with a false positive.
     
  5. fonduekid

    fonduekid JSUTAONHTERBIRCKINTEHWLAL

    Reputations:
    1,407
    Messages:
    3,396
    Likes Received:
    0
    Trophy Points:
    105
    Yes - I got nothing with both in-house / online scanners, as well as SAS, S&D, MBAM.. Right now, running a TF scan, and also wanted to do a WD full scan, just for the heck of it.

    Btw, is there any chance, running a HijackThis would show up the culprit, if there is one? Thanks again.
     
  6. fonduekid

    fonduekid JSUTAONHTERBIRCKINTEHWLAL

    Reputations:
    1,407
    Messages:
    3,396
    Likes Received:
    0
    Trophy Points:
    105
    Update: None of the scans brought up anything. I guess, as Baserk said, and as other info from google, it' a false positive from WD.