mchlnjDrv

Discussion in 'Malware Help (A Specialist Will Reply)' started by dayvaux, Sep 4, 2005.

  1. dayvaux

    dayvaux Private E-2

    hey guys I have the following message coming up from secretmakers security watchdog componant.
    "A new SERVICE named mchlnjDrv attempts to install on your PC. Path \??\C:\DOCUMEN~1\ADMINI~1\LOCALS~1\temp\mc21.tmp"

    Secretmaker gives the option to reject it or rename it and reccomends to do the latter if you dont know what it is. I have tried both options but it keeps coming back, which leads me to think that something else is executing it.

    A google search comes up with only 5 hits the most useful ones are from the EU possibly holland but I can't translate the pages.

    Iam running w2k on a p3. I have followed Major Attitudes orders on spyware to the letter and also tried a few other things but the sucker still keeps cropping up. It may not be malicious and might even be related to secretmaker but it is persistant. I run Zonealarm security suite as well as secretmaker, trojan remover, registry mechanic,spywaredoctor,spyware guard, spyware blaster, ad aware & spybot.

    I've run the microsoft baseline security anyliser and have all the updates/patches. I have run hijack this and the log analysis has come back fine from all 3 recommended sources.

    Does anyone have any idea what this process is and what is trying to install it or perhaps translate whatcomes up on itavisen.

    thanks :confused:
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Some places indicate that this could be a false positive others indicate that it could be RiskWare.Tool.Madtol.c

    See: http://www.viruslist.com/en/viruses/encyclopedia?virusid=79341


    I'm surprised that Ccleaner (part of the READ ME FIRST) did not delete all files in this temp folder. Did you run Ccleaner?

    If you ran all of the READ ME FIRST then follow the steps below:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. dayvaux

    dayvaux Private E-2

    CCleaner initially got rid of it but the sucker keeps coming back. This is why I'm not sure if it might be something legitimate but it seems a little suspect, It could be part of one of the applications. mchlnj may may be a reference to the process and Drv could be drive?? :rolleyes:
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Complete the instructions in my previous message.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds