A little background. I’m running Avast 4. About 2 weeks ago, I got invaded by viruses. Seems my firewall was down (don’t remember disabling it, but I’m the only one using this 'puter, so it had to be me). Anyway, I ran a deep boot scan with Avast each time I got infected, and there were around 9 or 10 files infected, which I had Avast quarantine/put in chest. Computer is fine with the exception that I get two errors that pop up every time I boot up. They are both .dll files, one by the name of “ridewose.dll”, the other is “gisisema.dll”. I know both of these files were put in the chest/quarantined. This morning, I tried to print a document (I hadn’t used the printer, to my memory, since my virus infection). An error box popped up and told me the computer cannot communicate with the printer. I’ve checked all connections, everything seems fine. I’ve tried to print out of Word, my AOL email account, etc. Same error. So, thinking that a file was quarantined that the 'puter needs to communicate with my printer, I attempted to open Avast and get into the chest and repair the files there in an attempt to get the printer to work. So, I did as I always do, double clicked the desktop icon to bring up the Avast dashboard, it went through its memory test as always, told me the program was now going to run, and promptly disappeared. I tried it again via desktop, then via my program menu, with the same results. I think these two problems are related somehow. Can anyone help?
Hi kmdavis511, welcome to the forum ![]()
It looks like you were hit by a Vundo infection, and that could explain some of the problems you have. Can you please follow the directions in this topic :
http://forum.avast.com/index.php?topic=53253.0
and post/attach the requested logs here ? I will pm essexboy with a link to this topic, so he can help you ![]()
Greetz, Red.
Thanks for your help Red. I am so frustrated right now, I don’t know what to do. I’ve tried a cut and paste on the MBAM log and no matter how I try to chop it up, the message board software comes back and tells me my post is past the 10,000 character limit. I have looked for the MBAM log as a file that I can attach, and I can’t find it. Any suggestions? (It’s right there in MBAM’s log file, I have it open right now in another window, but can’t find it when I browse for it in attachments). I tried to attach both OTL files and evidently they are too big as well, so I’m going to attach one now, and then do another reply and attach the second one. Help!
Okay. Evidently that worked…
Now the second OTL log…
I can’t find any way to get you the MBAM log in a coherent form. Suggestions?
Lets try this first and then re-run MBAM the log will be smaller then
Run OTL.exe
[*]Under the Custom Scans/Fixes box at the bottom, paste in the following
:OTL
FF - prefs.js..browser.search.selectedEngine: "MyWebSearch"
FF - prefs.js..extensions.mywebsearch.prevKwdURL: "data:text/plain,keyword.URL=http://www.google.com/search?ie=UTF-8&oe=UTF-8&gfns=1&sourceid=navclient&rls=com.google:en-US:official&q="
FF - prefs.js..keyword.URL: "http://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZUxdm553YYUS&fl=0&ptb=rP6lHvhNx..ai5ew8iAMSw&url=http://search.mywebsearch.com/mywebsearch/dft_redir.jhtml&st=kwd&si=38297&searchfor="
[2009/06/03 05:33:04 | 000,009,949 | ---- | M] () -- C:\Users\Kevin M. Davis\AppData\Roaming\Mozilla\Firefox\Profiles\wu57z8cj.default\searchplugins\mywebsearch.xml
O3 - HKLM\..\Toolbar: (The jokwmp) - {51F0D2B7-06E2-40D0-B8B8-39E630888B30} - C:\Windows\jokwmp.dll File not found
O4 - HKCU..\Run: [puyirigih] c:\PROGRA~2\gisisema\gisisema.DLL File not found
O21 - SSODL: sapnet - {67858FB6-AF67-48AC-BF11-D5A7B11C2FA5} - C:\Windows\sapnet.dll File not found
2010/02/06 08:59:13 | 007,117,204 | ---- | M] () -- C:\Users\Kevin M. Davis\Documents\TheRedSparrows.wmv.wmv
[2099/01/01 12:00:00 | 000,006,456 | -H-- | C] () -- C:\ProgramData\juzopadu
:Files
c:\PROGRA~2\gisisema
:Commands
[purity]
[emptytemp]
[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot when it is done
[*]Then post a new OTL log ( don’t check the boxes beside LOP Check or Purity this time )