Ok this will be long as I'm going to take you step by step with what we've done to try to get midADdle off of my partner's computer.
First, we realized something was wrong on July 31, 2004 when she opened an email from a trusted friend that had an attachment. When she went to send the email to her son, **it hit the fan with her computer and it began popping up 3 and 4 instances of the same window and sending the email 3-4 times to her son. She immedatily called him and told him to simply delete any email from her until further notice and we sent an email from my computer which hasn't been affected to let anyone on her email list know to delete all emails from her until further notice.
I began searching to find what could be the problem and midaddle jumped out for some reason, and so we searched her computer to see if it was on it and found several instances of it. I then began searching for ways to rid her computer of it. Following is the detailed list of what we have done and things we've discovered in the process. We also found these and were able to remove successfully.
- Program Files/SEP/SEP.dll
- Software/Memory Watcher
- C: Documentandsettings/sharonbass/localsettings/temp/fixit.exe
- Docummentandsettings/sharonbass/localsettings/temp/middaddle.exe
We began by running her adaware and it found several instances also of MidADdle and so we deleted/quaranteened them. That however did not solve the problem. I again began searching for even more information after realizeing that it is MalWare.
I found these instructions on 2 different sites that were talking specifically about MidADdle that others said worked for them. It did delete them, temporarliy, but it's come back. Here are the step by step instructions that I followed.
- Disconnect from the internet.
- Restart Computer
- Run
- Msconfig
- Select Diagnostic Startup
- click ok computer will restart
- Start
- Run
- Regedit
- Select Find
- Type MidADdle and find next
- Delete Files/keys that are specifically MidADdle
- Repeat until all instances are removed
- After deleting all of these, go to
- C: PRogram Files/Common Files
- Find MidADdle and delete (SOmetimes it would let us delete and sometimes it would not)
- Go to start
- Run
- Msconfig
- Normal Start up (Her's was in selective startup)
These are the things that I found with MidADdle while in the registry.
- HKEY_LocalMachines.software/{E8EAEB34-F7B5-4C55-87FF-7s0FAF53D84}
- HKEY_Classes_ROOT:CLSID\{E8EAEB34-F7B5-4C55-87FF-7s0FAF53D84}
- HKEY_CLASSES_ROOT:TYPELIB WINAFFILIATE BHO.WINAFFILIATE.IEEXTENS.1
- {E8EAEB34-F7B5-4C55-87FF-7s0FAF53D841}
- C: Documents and SEtting/SharonBass/Local Setting/Temporary INternet/Content.ie5/0v1266v
- C:Program files/common files/Midaddle/midaddle.dll
- Something about File Rename that had midaddle in it, so we deleted it.
- Something about Threading with Midaddle and apartment in it, so we deleted it.
We deleted these and then went back into normal mode. Here is some fun begins, but we learned something in the process. We found that while in Diagnositc or Safe Mode, these could be deleted. Last night, after making certian that all things were off the computer concerning MidADdle, we turned off her computer and this morning turned it back on, and went straight to the Programfiles/Common files and this is what we found Midaddle.dll 116KB
They at first reappeared only when she went to Neopets.com or Roadrunner. This morning they reappeared simply when she turned on her computer. She hadn't even gone on the net.
She runs AVG and keeps it updated faithfully. She is using XP's Firewall. (This is where we differ, I also use ZONELABS and my computer has not been affected by any of this).
Does anyone have a reliable way to rid her computer of this crap? I've let her know that you all will most likely recommend that she download Hijack This to be able to read what is on her pc, and she's hesitienat, but I think she is finally reaching a point where she will allow me to get it set up and run on her computer.
Thanks in advance for all your help.