G
Guest
Received alert this a.m. that this Backdoor/trojan was identified. Removed
it. Came back again 4 hours later with no browser access. Did a google on
it and suggests might be false positive &/or webroot spysweeper related. As
we run enterprise version of spysweeper, checked webroot support who deny
connection. Only found by M$ betas (1&2). Running copies of McAfee and
Webroot do not see. Removed registry entries. Showing up on 80% of pcs
registries in domain.
hklm\system\currentcontrolset\services\mchInjDrv
Legit or false from somewhere ? And why alert today if both M$ betas
installed for a while ?
it. Came back again 4 hours later with no browser access. Did a google on
it and suggests might be false positive &/or webroot spysweeper related. As
we run enterprise version of spysweeper, checked webroot support who deny
connection. Only found by M$ betas (1&2). Running copies of McAfee and
Webroot do not see. Removed registry entries. Showing up on 80% of pcs
registries in domain.
hklm\system\currentcontrolset\services\mchInjDrv
Legit or false from somewhere ? And why alert today if both M$ betas
installed for a while ?