MidADdle MUST DIE
Results 1 to 15 of 39

Thread: MidADdle MUST DIE

Hybrid View

  1. #1
    Registered User Dshadna's Avatar
    Join Date
    Jun 2004
    Location
    ~Somewhere In Time~
    Posts
    30
    Quote Originally Posted by Darlid01
    OK, I won't disappoint. Download and run Hijack! Also, she has ad-aware, but it's obviously compromised since she has the virus. She should run an online scanner to check for the spyware, since it shouldn't be effected. Then, as much of a pain as it is, she should start installing those wonderful programs from Noonoo's sticky thread. I've only had one virus/trojan/malware not get stopped by the combination of those.
    Thank you for your quick answer. I'll have her do those things. We did go to PCPitstop and also the PANDA site to scan and neither one comes up with any virus or spyware. We've tried to download spybot several times to her computer but each time it says something aobut corrupted file. She's not a happy camper, but hopefully we can help her get happier. I'll write down the list of what's in the sticky and we'll start doing it and see what happens.

  2. #2
    Registered User GrandDad's Avatar
    Join Date
    Apr 2001
    Location
    Ft.Leonard Wood
    Posts
    2,112
    Yes , do all thats in NooNoo's sticky post .

    As for online scans you can try ;
    http://housecall.trendmicro.com/

    if nothing else the online scans will give you more of what could be on that PC .

    Don't know what Anti-virus your using but if you don't have this (AVG);
    http://www.grisoft.com/us/us_dwnl7.php

    it works great , and its free .

  3. #3
    Registered User corturbra's Avatar
    Join Date
    Oct 2000
    Location
    Just to the Right of Sanity..
    Posts
    1,424
    Switch off system restore before you start

    In Safe Mode
    Run Hi-jack this and Spybot
    Also check in Add/Remove programs and uninstall SEP/Middadle.
    Follow previous instructions that you've done to get rid of registry entries

    Scrap the MS firewall it is pants, install ZoneAlarms its free FFS and like yourself I run ZoneAlarms and AVG and I have never, repeat never gotten anything on my PC.

    Good luck. I had fun with this kiddy about a week or so ago and I did the above to get shot of it, so far it hasn't come back
    "Today is a Gift, thats why they call it the present"

  4. #4
    Registered User Dshadna's Avatar
    Join Date
    Jun 2004
    Location
    ~Somewhere In Time~
    Posts
    30
    Quote Originally Posted by corturbra
    Switch off system restore before you start

    In Safe Mode
    Run Hi-jack this and Spybot
    Also check in Add/Remove programs and uninstall SEP/Middadle.
    Follow previous instructions that you've done to get rid of registry entries

    Scrap the MS firewall it is pants, install ZoneAlarms its free FFS and like yourself I run ZoneAlarms and AVG and I have never, repeat never gotten anything on my PC.

    Good luck. I had fun with this kiddy about a week or so ago and I did the above to get shot of it, so far it hasn't come back
    Ok, I will run all these in safe mode (If I can get her computer into safe mode again, it's a b**ch to try to get it there). I have run them all in regular mode but nothing is found. Already removed the SEP/Middadle from the Control Panel and it's not come back. I'll try this with system restore off now though..

  5. #5
    Registered User Dshadna's Avatar
    Join Date
    Jun 2004
    Location
    ~Somewhere In Time~
    Posts
    30
    Had to put into 2 different posts as it was too long for one

    Logfile of HijackThis v1.97.7
    Scan saved at 2:55:53 PM, on 8/5/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)


    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\docume~1\sharon~1\locals~1\temp\vONa.exe
    C:\documents and settings\sharon bass\local settings\temp\S.exe
    C:\WINDOWS\System32\pctspk.exe
    C:\Program Files\Compaq\Easy Access Button Support\StartEAK.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\Compaq\Easy Access Button Support\CPQEADM.EXE
    C:\COMPAQ\CPQINET\CPQInet.exe
    C:\Compaq\EAKDRV\EAUSBKBD.EXE
    C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe
    C:\Program Files\Logitech\MouseWare\system\em_exec.exe
    C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
    C:\Program Files\QUICKENW\QWDLLS.EXE
    C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    C:\WINDOWS\System32\svchost.exe
    C:\PROGRA~1\Grisoft\AVG6\AVGCC32.EXE
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\Sharon Bass\My Documents\Downloaded Programs for PC\HijackThis.exe

  6. #6
    Registered User Dshadna's Avatar
    Join Date
    Jun 2004
    Location
    ~Somewhere In Time~
    Posts
    30
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://rd.yahoo.com/customize/ymsgr/defaults/sp/*http://www.yahoo.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://rd.yahoo.com/customize/ymsgr/defaults/*http://my.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/customize/ymsgr/defaults/sb/*http://www.yahoo.com/ext/search/search.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://rd.yahoo.com/customize/ymsgr/defaults/sp/*http://www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://rd.yahoo.com/customize/ymsgr/defaults/*http://my.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://rd.yahoo.com/customize/ymsgr/defaults/su/*http://www.yahoo.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Compaq
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
    http://rd.yahoo.com/customize/ymsgr/defaults/su/*http://www.yahoo.com
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - (no file)
    O2 - BHO: WinPage Affiliate - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Program Files\Common Files\midaddle\midaddle.dll (file missing)
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaE ngineMain
    O4 - HKLM\..\Run: [vONa] C:\docume~1\sharon~1\locals~1\temp\vONa.exe
    O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
    O4 - HKLM\..\Run: [S] C:\documents and settings\sharon bass\local settings\temp\S.exe
    O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
    O4 - HKLM\..\Run: [MMTray] C:\Program Files\MusicMatch\MusicMatch Jukebox\mm_tray.exe
    O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
    O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
    O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
    O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\Compaq\Easy Access Button Support\StartEAK.exe
    O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - Startup: Compaq VistaAccess.lnk = C:\VSTASCAN\vsaccess.exe
    O4 - Global Startup: Billminder.lnk = C:\Program Files\QUICKENW\BILLMIND.EXE
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
    O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
    O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\QUICKENW\QWDLLS.EXE
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Messenger (HKLM)
    O9 - Extra button: Support (HKCU)
    O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
    O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
    O14 - IERESET.INF: START_PAGE_URL=http://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=consumerfav&c=3c01&lc=0409
    O16 - DPF: Yahoo! Klondike Solitaire -
    http://yog55.games.scd.yahoo.com/yog/y/ks12_x.cab
    O16 - DPF: Yahoo! MahJong Solitaire - http://download.games.yahoo.com/games/clients/y/mjst3_x.cab
    O16 - DPF: Yahoo! Pyramids - http://download.games.yahoo.com/games/clients/y/pyt1_x.cab
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/swdir8d196a.cab
    O16 - DPF: {2A32B14F-4D29-4EA3-AC54-E9B19F436CE7} (Scanner Class) - http://www.trojanscan.com/trojanscan/TDECntrl.CAB
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37862.1682291667
    O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/essentials/ymmapi_0727.dll
    O16 - DPF: {B3872502-F9FD-4E96-93FF-0D37298F0689} (SOESysInfo Control) - http://everquest2.station.sony.com/beta_reg/soesysinfo.cab
    O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/autocomplete.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - http://us.dl1.yimg.com/download.yahoo.com/dl/toolbar/yiebio4.cab
    O16 - DPF: {EFAEF0E4-F044-4D57-9900-1C3FF18524C9} (AV Class) - http://pcpitstop.com/antivirus/PitPav.cab
    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab


  7. #7
    Registered User hudsonsmith's Avatar
    Join Date
    Feb 2003
    Location
    New York
    Posts
    2,276
    These are bad:
    O2 - BHO: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - (no file)
    O2 - BHO: WinPage Affiliate - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Program Files\Common Files\midaddle\midaddle.dll (file missing)
    O4 - HKLM\..\Run: [vONa] C:\docume~1\sharon~1\locals~1\temp\vONa.exe
    O4 - HKLM\..\Run: [S] C:\documents and settings\sharon bass\local settings\temp\S.exe

    Boot into safe mode and run hijack again. Kill the registry entries and delete the files as well.

Similar Threads

  1. Old Server just wanted to die!
    By Daemon in forum Tech Lounge & Tales
    Replies: 0
    Last Post: January 4th, 2002, 10:30 AM
  2. When are you going to die?
    By Daemon in forum Tech Lounge & Tales
    Replies: 35
    Last Post: August 14th, 2001, 11:32 AM
  3. chipped die..
    By fathead in forum AMD
    Replies: 3
    Last Post: August 7th, 2001, 05:58 PM
  4. Clean die on athlon 1000
    By jak1966 in forum AMD
    Replies: 1
    Last Post: June 24th, 2001, 10:14 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •