2 Intern

 • 

5.9K Posts

September 6th, 2005 22:00

The following lines are from the WinFixer Bug. 
Unfortunately you can't just check them and Fix Checked.  They will just come back with new names.
O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\WINDOWS\system32\ddaya.dll
O20 - Winlogon Notify: ddaya - C:\WINDOWS\system32\ddaya.dll
IF the above line wraps and doesn't work use:  http://tinyurl.com/7n5f8

http://tinyurl.com/72khc  (See Rawe's procedure in Post#2)

The first is rather complex but is pretty certain to succeed and I presume it is safe.  Haven't used it but
usually bleepingcomputer is very good.
The second is the standard procedure I have been using and is a bit simpler.  It has worked about 10 times with no problems but 1 user reported
he had to reload windows after use, another had some odd problems and one said it didn't do anything.
The text file with it says you have to have internet access when you run it.  It might work better in Safe Mode with Networking.
In either case you will need to adjust the procedure for your particular infection.  By that I mean you will need to not the lines
I gave you above and substitute them for the lines he tells you to check.
XP only:
Make sure before you do anything that your System Restore is working and that you have a recent Restore Point. 
That way if something goes wrong you have a chance to recover.
http://www.microsoft.com/windowsxp/using/helpandsupport/learnmore/systemrestore.mspx
Let me know which method you used and how it worked for you.
Ron
 

2 Intern

 • 

5.9K Posts

September 7th, 2005 20:00

The second option has been replaced today by a new program.
 
See:
 
http://www.atribune.org/forums/index.php?showtopic=447&hl=killvundo
 
The paths the program asks you for would be:
 
C:\WINDOWS\system32\ddaya.dll
and
 
C:\WINDOWS\system32\ayadd.*
 
This one now automatically checks and Fix Checkeds the entries in HijackTHis for you.
 
Ron
 

7 Posts

September 8th, 2005 21:00

Thanks so much for all your help. I was able to fix the problem before your new post, but its nice to now there is something easier now. Those pop-ups where a nightmare and i don't wish them on anyone. (except the jerks who wrote the code for them maybe).  Agian thank you so much for your help.
No Events found!

Top