berikken
2009-02-17, 22:01
I can read member "rokut" had the same question as me about this annoying "mchInjDrv.sys" file that keep on beeing written after reboot and I can see that he didn't get any respons either.
My question to the expertise panel:
Is MadInjection.rtk unremoveable???
So far on the internet I've found two ways that's suppose to work, but the problem is that none of them actually work???
What is this file and what does it do.....anyone....please ;-)
If it's harmeless I'll sleep better at night :-)
I quote from the file "mchInjDrv.sys" from what I can read:
-This program cannot be run in DOS mode
-B a s e N a m e d O b j e c t s \ m c h I n j D r v M a p
-Close YZwUnmapViewOfSection memcpy @ ExAllocatePoolWithTag ZwMapViewOfSection ZwOpenSection RtlInitUnicodeString %ObfDereferenceObject ZwAllocateVirtualMemory ObOpenObjectByPointer rPsLookupProcessByProcessId IofCompleteRequest PsSetCreateProcessNotifyRoutine ntoskrnl.exe
Is there anybody who can tell me what this file is doing from this???
My question to the expertise panel:
Is MadInjection.rtk unremoveable???
So far on the internet I've found two ways that's suppose to work, but the problem is that none of them actually work???
What is this file and what does it do.....anyone....please ;-)
If it's harmeless I'll sleep better at night :-)
I quote from the file "mchInjDrv.sys" from what I can read:
-This program cannot be run in DOS mode
-B a s e N a m e d O b j e c t s \ m c h I n j D r v M a p
-Close YZwUnmapViewOfSection memcpy @ ExAllocatePoolWithTag ZwMapViewOfSection ZwOpenSection RtlInitUnicodeString %ObfDereferenceObject ZwAllocateVirtualMemory ObOpenObjectByPointer rPsLookupProcessByProcessId IofCompleteRequest PsSetCreateProcessNotifyRoutine ntoskrnl.exe
Is there anybody who can tell me what this file is doing from this???