have beta security software getting constant spy attack

  • Thread starter Thread starter Marv
  • Start date Start date
M

Marv

i am getting every 5 minutes a attack from a midadlle spy
ware. i keep removing it and even chosen to ignor remove
it. Any help on getting this spy to quit attacking my
comp?
 
Marv said:
i am getting every 5 minutes a attack from a midadlle spy
ware. i keep removing it and even chosen to ignor remove
it. Any help on getting this spy to quit attacking my
comp?

Hi

- Send a spywarereport to MS, menu tools.

- Firewall running ?

- Windowsupdate ? SP2 ?

- Antivirus, updated ?

- Follow this below, maybe a lot of work but there is no
"shortcuts".

--
plun

Hi,
No single malware removal program will remove everything.

Download and run CWShredder, Ad-aware, Spybot (in that order.)
See: http://mvps.org/winhelp2002/unwanted.htm
Also note the security tips and other important information
on that page.

Additional information at:
The Parasite Fight http://www.aumha.org/a/quickfix.htm
More security tips at http://www.aumha.org/a/parasite.htm
Bugs, Glitches & Stuffups:
http://www.mvps.org/inetexplorer/Darnit.htm

If unsuccessful with those programs, you may have to post a
HijackThis log
to one of the forums listed below. You will receive good
help at any of
these forums. You might look for a forum that doesn't have
too many
unanswered posts. You should also look for the proper forum
for HijackThis
logs and a message along the lines of "Important- Read This
First."

HijackThis instructions and download:
http://www.tomcoyote.org/hjt/
http://www.aumha.org/downloads/hijackthis.exe
(Additional information and warnings)
http://www.aumha.org/a/parasite.php#hjt

Forums:
http://forum.mvps.org/ Excellent help- low traffic. Visit
http://forum.aumha.org/viewtopic.php?t=4075 before posting
the log.

http://castlecops.com/forums.html
http://www.spywarewarrior.com/index.php
http://tomcoyote.com/forums/
http://www.spywareinfo.com/forums/

Hope this helps,
Don
[MVP- IE/OE]
 
Restart your computer in Safe Mode, run a full system scan using AntiSpyware
at least two times. On Scan Page choose Scan Options > Full System Scan.
Also disable system restore before you restart in Safe Mode. Enable Show
hidden folders under > Tools > Folder Options > View and empty your temp
directory.
 
i understand what your saying to a point. my problem is
that every 5 minutes my protector tells me that it wants
to be installed to my computer and i always say no. how
can i let know that i never want it to be loaded to avoid
these constant barrages of messages? ty
 
Make sure your internet connection is turned off or
unplug the connection, or this will not work! Failing
this Go into Safe mode(Reboot and tap F8 to you get the
option page and choose safe mode)

You need to find this folder:

C:/Documents and Settings/user1/Local Settings/Temp/

The user (example. user1 above) part of the folder name
will be different for you, depending on what you have
named your user account. Everything else should be the
same.

Once you have found that folder, open it up and delete
everything inside, but DO NOT delete the folder itself.

Since it's a TEMP folder, deleting everything will not
cause any harm to you computer, because temp files can
always be deleted.

You should get a few error messages that say something
like "Cannot delete file [name] it is already in use."
You need to press and hold ctrl+alt+delete to open up
your task manager. Click the "applications" tab. You need
to highlight the files that the error messages showed
were in use and select the button "end task" for each one
of them. Once you have done that, go back and delete
those files from the folder.

Now you need to find this folder, and do the same thing:
Either go to start>run > and type %temp%
Or

C:/Windows/Temp

Once you have found that folder, open it up and delete
everything inside, but do not delete the folder itself.
Since it's a TEMP folder, deleting everything will not
cause any harm to you computer, because temp files can
always be deleted.

Again You should get a few error messages that say
something like "Cannot delete file [name] it is already
in use." You need to press and hold ctrl+alt+delete to
open up your task manager. Click the "applications" tab.
You need to highlight the files that the error messages
showed were in use and select the button "end task" for
each one of them. Once you have done that, go back and
delete those files from the folder.

Now go the Start Menu

Select "Search"
Enable viewing of hidden files and folders and
extensions; Some programs can hide this way by not being
visible in Windows. Start Windows Explorer and click on
your main hard drive, usually c:\. Then select Tools from
the top of Windows Explorer and then Folder Options. Go
to the View tab. Scroll down to the folder icon that says
Hidden files and folders and check show hidden files and
folders. Also, right below it, uncheck the hide file
extensions for known types. Not doing this could allow
file extensions commonly used by trojans and spyware to
be hidden, for example a file ending in .exe or dll
making manually finding it, if needed Very difficult


Select "All Files and Folders"

Look in the C: drive

Search for the following files:

addit.exe
midaddle.exe
wildwintracker.exe

If they exist, delete them. If they do not, that's ok,
just move on.

Now search for these words:

midaddle
ads234

Delete anything that you find that has those names inside
of it. You will mostly find internet explorer pages that
you visited, but delete them anyway.

Now you need to open up Internet Explorer

On the top of the browser select the "Tools" menu
click on "Internet Options"
Click on "Delete Cookies" and when the dialog box pops up
select "OK."
Click on "Delete Files" and put a check next to "Delete
all offline content" then select "OK."
Click on "Clear History" and select "Yes" when the dialog
box pops up.

Check if this folder exists on your computer:

C:/Program Files/Common Files/Midaddle

If it exists, delete the entire folder, INCLUDING the
folder itself.

So after that's completed, hopefully the nightmare is
over. Restart your computer and go on the Internet. If
your browser goes directly to your homepage (and not
www.ads234.com first) you have finally beaten MidADdle.


Good Luck Andy
 
Very detailed Andy. :-)

--

Andre
http://spaces.msn.com/members/adacosta
FAQ for MS AntiSpy http://www.geocities.com/marfer_mvp/FAQ_MSantispy.htm

AndyManchesta said:
Make sure your internet connection is turned off or
unplug the connection, or this will not work! Failing
this Go into Safe mode(Reboot and tap F8 to you get the
option page and choose safe mode)

You need to find this folder:

C:/Documents and Settings/user1/Local Settings/Temp/

The user (example. user1 above) part of the folder name
will be different for you, depending on what you have
named your user account. Everything else should be the
same.

Once you have found that folder, open it up and delete
everything inside, but DO NOT delete the folder itself.

Since it's a TEMP folder, deleting everything will not
cause any harm to you computer, because temp files can
always be deleted.

You should get a few error messages that say something
like "Cannot delete file [name] it is already in use."
You need to press and hold ctrl+alt+delete to open up
your task manager. Click the "applications" tab. You need
to highlight the files that the error messages showed
were in use and select the button "end task" for each one
of them. Once you have done that, go back and delete
those files from the folder.

Now you need to find this folder, and do the same thing:
Either go to start>run > and type %temp%
Or

C:/Windows/Temp

Once you have found that folder, open it up and delete
everything inside, but do not delete the folder itself.
Since it's a TEMP folder, deleting everything will not
cause any harm to you computer, because temp files can
always be deleted.

Again You should get a few error messages that say
something like "Cannot delete file [name] it is already
in use." You need to press and hold ctrl+alt+delete to
open up your task manager. Click the "applications" tab.
You need to highlight the files that the error messages
showed were in use and select the button "end task" for
each one of them. Once you have done that, go back and
delete those files from the folder.

Now go the Start Menu

Select "Search"
Enable viewing of hidden files and folders and
extensions; Some programs can hide this way by not being
visible in Windows. Start Windows Explorer and click on
your main hard drive, usually c:\. Then select Tools from
the top of Windows Explorer and then Folder Options. Go
to the View tab. Scroll down to the folder icon that says
Hidden files and folders and check show hidden files and
folders. Also, right below it, uncheck the hide file
extensions for known types. Not doing this could allow
file extensions commonly used by trojans and spyware to
be hidden, for example a file ending in .exe or dll
making manually finding it, if needed Very difficult


Select "All Files and Folders"

Look in the C: drive

Search for the following files:

addit.exe
midaddle.exe
wildwintracker.exe

If they exist, delete them. If they do not, that's ok,
just move on.

Now search for these words:

midaddle
ads234

Delete anything that you find that has those names inside
of it. You will mostly find internet explorer pages that
you visited, but delete them anyway.

Now you need to open up Internet Explorer

On the top of the browser select the "Tools" menu
click on "Internet Options"
Click on "Delete Cookies" and when the dialog box pops up
select "OK."
Click on "Delete Files" and put a check next to "Delete
all offline content" then select "OK."
Click on "Clear History" and select "Yes" when the dialog
box pops up.

Check if this folder exists on your computer:

C:/Program Files/Common Files/Midaddle

If it exists, delete the entire folder, INCLUDING the
folder itself.

So after that's completed, hopefully the nightmare is
over. Restart your computer and go on the Internet. If
your browser goes directly to your homepage (and not
www.ads234.com first) you have finally beaten MidADdle.


Good Luck Andy
 
Back
Top