Page 2 of 2 FirstFirst 12
Results 11 to 14 of 14

Thread: HKLM cmd srvce settings

  1. #11
    Junior Member
    Join Date
    Dec 2005
    Location
    Portsmouth, UK
    Posts
    3

    Default

    Deleted the key without any errors and it has not come back after about 10 hours continuous running.

    I have 2 accounts on this m/c. My normal one which is set up as a LUA which is for everday use, and an Admin account which I use for backups, software install/updates and similar.
    Logging on and off each account - without booting - does not bring back the registry keys either.

    I've looked back through the SD history logs. Last clean run was on 25/11 at 13:28. Next run was on 26/11 at 16:43, that found the 3 keys.

    Between those two date/times I downloaded 2 sets of SD updates -
    spybotsd.ini, english.zip, includes.zip, includesb.zip on 25/11: and includesb.zip on 26/11.
    Is it possible that those mchinjdrv keys had been appearing on my machine for a long time, but only show up now after new searches were added to SD in one of those downloads?

    Mike

  2. #12
    Esteemed Member
    Join Date
    Oct 2005
    Posts
    554

    Default

    Lonny:

    Might want to look at this thread in the Spybot S&D forum. Looks like these keys may be included with some security apps, though I haven't confirmed this myself.
    http://forums.spybot.info/showthread...ight=mchinjdrv

    Fermat:

    What you're asking seems to match exactly with what others are seeing. These entries appeared along with recent updates and might be false positives if you have any of the software mentioned below.

    Quote Originally Posted by dadkins
    I have these as well, haven't tried to Fix them yet...

    EDIT: TrojanHunter, spysweeper, a2 all add this registry entry, probably more security apps also.
    mchInjDrv (Mad code hook injection driver)
    Malware can use it, but if you use any of the above security apps, then it's a false positive.

  3. #13
    Junior Member
    Join Date
    Dec 2005
    Location
    Portsmouth, UK
    Posts
    3

    Default

    Funny, my reply yesterday evening hasn't appeared here.

    Yes, I have had a2 installed for a long time. (tried Trojanhunter but only after Spybot started reporting mchinjdrv).

    Anyway, thanks a lot for your time and your help. I'm impressed. Definitely calls for a donation.

    Mike

  4. #14
    Member of Team Spybot tashi's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    30,959

    Default

    This topic will now be archived.
    If you need the thread reopened please pm me.
    Microsoft MVP Reconnect 2018-
    Windows Insider MVP 2016-2018
    Microsoft Consumer Security MVP 2006-2016

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •