MidADdle MUST DIE
Results 1 to 15 of 39

Thread: MidADdle MUST DIE

Hybrid View

  1. #1
    Registered User Darlid01's Avatar
    Join Date
    Jun 2004
    Posts
    26
    Yep you have pretty much neutered MidADdle but you now have W97M.Gogaru.A
    http://securityresponse.symantec.com....gogaru.a.html

    I don't recognise the vONa.exe

    Quote Originally Posted by hudsonsmith
    These are bad:
    O2 - BHO: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - (no file)
    O2 - BHO: WinPage Affiliate - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Program Files\Common Files\midaddle\midaddle.dll (file missing)
    O4 - HKLM\..\Run: [vONa] C:\docume~1\sharon~1\locals~1\temp\vONa.exe
    O4 - HKLM\..\Run: [S] C:\documents and settings\sharon bass\local settings\temp\S.exe

    Boot into safe mode and run hijack again. Kill the registry entries and delete the files as well.

  2. #2
    Driver Terrier NooNoo's Avatar
    Join Date
    Dec 2000
    Location
    UK
    Posts
    31,824
    someone has been porn surfing
    C:\docume~1\sharon~1\locals~1\temp\vONa.exe
    C:\documents and settings\sharon bass\local settings\temp\S.exe

    Kill both of them

  3. #3
    Registered User Dshadna's Avatar
    Join Date
    Jun 2004
    Location
    ~Somewhere In Time~
    Posts
    30
    Quote Originally Posted by NooNoo
    someone has been porn surfing
    C:\docume~1\sharon~1\locals~1\temp\vONa.exe
    C:\documents and settings\sharon bass\local settings\temp\S.exe

    Kill both of them
    There are only two of us who use either computer and neither of us has ever porn surfed. I will kill both of those immidatly.

    Thanks you all.

    After doing this I will post the new HJT Log.

  4. #4
    Registered User Dshadna's Avatar
    Join Date
    Jun 2004
    Location
    ~Somewhere In Time~
    Posts
    30
    Quote Originally Posted by Dshadna
    There are only two of us who use either computer and neither of us has ever porn surfed. I will kill both of those immidatly.

    Thanks you all.

    After doing this I will post the new HJT Log.
    Allow me to ask a stupid question before I mess anything up.

    Exactly HOW do you "KILL PROCESS" with HJT? Please give step by step instructions as if I were a dunce. I want to be certian I don't do something wrong.

    I think I know how, but would much rather have you all tell me exactly what to do.

    Thanks ya'll.
    D

  5. #5
    Registered User hudsonsmith's Avatar
    Join Date
    Feb 2003
    Location
    New York
    Posts
    2,276
    You are trying to delete the file itself, as well as the registry references to it. Before you can do that, you have to stop it from running. You can either boot into safe mode, which bypasses the list of programs scheduled to run at startup, or you can go into task manager, find the process, and click the end process button.

    After you have done that, you would go into hijack, check the boxes next to the items you want to remove, and click the fix checked button. Then browse the directory to find the actual files and delete them.
    Probability factor of one to one...we have normality, I repeat we have normality. Anything you still can't cope with is therefore your own problem.

  6. #6
    Registered User Dshadna's Avatar
    Join Date
    Jun 2004
    Location
    ~Somewhere In Time~
    Posts
    30
    Quote Originally Posted by hudsonsmith
    You are trying to delete the file itself, as well as the registry references to it. Before you can do that, you have to stop it from running. You can either boot into safe mode, which bypasses the list of programs scheduled to run at startup, or you can go into task manager, find the process, and click the end process button.

    After you have done that, you would go into hijack, check the boxes next to the items you want to remove, and click the fix checked button. Then browse the directory to find the actual files and delete them.
    Thank you that was exactly what I needed to know. I took the time last night to be certian that I wrote everything down exactly so that this morning I could get to it when I was refreshed and not stressing out. It took about 2 hours of searching the registry, and then searching for all files related to everything you all recommened be shut down. I made sure before doing anything that I was certian of what I was doing. I found the [s] and [vONa] files almost immediatly and was able to get them out and then find any files they were hidden in. I also checked with "dates created" to be certian, because I had a relativly vauge idea of when problems appeared to start.

    I've now got it all cleared off the pc and restarted the computer. The one problem I had was that midaddle kept unchecking itself in the spyblasters, so I've told my partner to make certain when she turns her pc on to go immideatly to that program and make certian that everything is checked and protect against them. The other thing, and you all can tell me if it's a problem or not is that when I took the computer out of safe mode (diagnostic) and let it restart; it went straight to selective startup rather than Normal startup. It appears to be running just fine this way and in fact is where it was when this all began; but without all the programs that you all recommended.

    We've now got spybot installed (had to exclude wild tangent from the search or the thing wouldn't work. (Which reminds me; we now are getting an error report about a dll for WT missing whenever the computer starts.....any recommendations or suggestions?) We've also got zonelabs installed and we're slowly getting in configured to where it won't appear to be so intrusive. Also with spybots, we did the "Teatimer" thingie. I've been running it for some time and haven't experienced any problems that I'm aware of. When we installed the firewall, we had to restart the pc and I had her immidatly go to spyblasters and see if midADdle was checked or unchecked; this time it stayed checked. I had her select all and protect again just to be certain. We went to common files to see if the folder was back with MidADdle and it was finally gone. We went to Neopets and Roadrunner and then went to check and no problems. It appears at this time that all of your suggestions and such may have done the trick this time.

    So once again. A big Southern THANK YA'LL for your hard work and your patience with us as we solved this problem. I'm sure that I'll be back again as you've helped me with some other problems and I have NO complaints.

  7. #7
    Driver Terrier NooNoo's Avatar
    Join Date
    Dec 2000
    Location
    UK
    Posts
    31,824
    wt.dll looks like its a leftover. I found no information about it.

    Search the registry for reference to it and remove the key if found. Also start, run, type in sysedit and check in win.ini for references there.

Similar Threads

  1. Old Server just wanted to die!
    By Daemon in forum Tech Lounge & Tales
    Replies: 0
    Last Post: January 4th, 2002, 10:30 AM
  2. When are you going to die?
    By Daemon in forum Tech Lounge & Tales
    Replies: 35
    Last Post: August 14th, 2001, 11:32 AM
  3. chipped die..
    By fathead in forum AMD
    Replies: 3
    Last Post: August 7th, 2001, 05:58 PM
  4. Clean die on athlon 1000
    By jak1966 in forum AMD
    Replies: 1
    Last Post: June 24th, 2001, 10:14 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •