The first is rather complex but is pretty certain to succeed and I presume it is safe. Haven't used it but
usually bleepingcomputer is very good.
The second is the standard procedure I have been using and is a bit simpler. It has worked about 10 times with no problems but 1 user reported
he had to reload windows after use, another had some odd problems and one said it didn't do anything.
The text file with it says you have to have internet access when you run it. It might work better in Safe Mode with Networking.
In either case you will need to adjust the procedure for your particular infection. By that I mean you will need to not the lines
I gave you above and substitute them for the lines he tells you to check.
Thanks so much for all your help. I was able to fix the problem before your new post, but its nice to now there is something easier now. Those pop-ups where a nightmare and i don't wish them on anyone. (except the jerks who wrote the code for them maybe). Agian thank you so much for your help.
RKinner
2 Intern
•
5.9K Posts
0
September 6th, 2005 22:00
Unfortunately you can't just check them and Fix Checked. They will just come back with new names.
O20 - Winlogon Notify: ddaya - C:\WINDOWS\system32\ddaya.dll
I have two fixes:
http://www.bleepingcomputer.com/forums/How-to-remove-the-TrojanVundoB-Search42com-MSevents-t18610.html
http://tinyurl.com/72khc (See Rawe's procedure in Post#2)
The first is rather complex but is pretty certain to succeed and I presume it is safe. Haven't used it but
usually bleepingcomputer is very good.
he had to reload windows after use, another had some odd problems and one said it didn't do anything.
The text file with it says you have to have internet access when you run it. It might work better in Safe Mode with Networking.
I gave you above and substitute them for the lines he tells you to check.
That way if something goes wrong you have a chance to recover.
http://www.microsoft.com/windowsxp/using/helpandsupport/learnmore/systemrestore.mspx
RKinner
2 Intern
•
5.9K Posts
0
September 7th, 2005 20:00
See:
http://www.atribune.org/forums/index.php?showtopic=447&hl=killvundo
The paths the program asks you for would be:
C:\WINDOWS\system32\ddaya.dll
and
C:\WINDOWS\system32\ayadd.*
Ron
Kirtap76
7 Posts
0
September 8th, 2005 21:00