Windows Explorer problem...

Discussion in 'Computer Games and General Discussion' started by Rock Raiyu, Jun 30, 2008.

  1. Rock Raiyu
    OP

    Rock Raiyu Clock Up

    Member
    5,065
    38
    Jul 14, 2007
    United States
    Walking the path of heaven
    Every time I start up my computer, I get a Windows Explorer error. Its something about awvvsts.dll and its getting really annoying and I want to get rid of it. Can someone help? Thanks.
     
  2. Lee79

    Lee79 Hyper...Active...Team Fortress 2 Addict

    Member
    920
    0
    Jul 29, 2007
    ctf_2fort
    awvvsts.dll is part of a group of files put on your computer by a variant of the Vurtumond/Vundo Trojan virus this is a very common Trojan I have had it on my pc and i had NOD32 anti virus running on my PC and i still got infected. It is one of the hardest to remove you will have to do a lot of steps to get rid of it. You might have to scan and clean your pc several times to get rid of this because if you do not delete all the vundo files when you reboot it spreads again. It took me 5 hours of scanning and cleaning to get rid of it from my PC.

    Virtumonde/Vundo Removel Guide From http://www.virtumonde.net/

    "The first thing we will do is take your computer back in time to when you were not infected. Hit the windows Start button and select “All Programs” > Accessories > System Tools > System restore. Start the restore process. Choose a date when you KNOW you were not infected. If you just noticed you started having popups last week then go back 2 weeks. I would always go back an extra week. This will not fully remove the virus but undo damage done. You will not loose any pictures or documents but any software installed after the restore date you choose will be uninstalled along with some of the vundo traces. Your computer will auto reboot during the restore process.

    Once your computer re-boots log back in and wait till you see a box saying something like “System Restore Complete”. Re-boot your computer and enter into safe mode by pressing the F8 key on boot-up. Keep pressing the F8 Key until you see the DOS like screen and then select “Safe Mode with Networking”. If windows boots normal and you do not see the afore mentioned screen then re-boot and try the F8 thing again. When asked if you would like to continue or do a system restore just select YES to continue. Make sure you log in under your normal account User name.

    We are now ready to download and install the following programs. Just click the links below to download the programs.
    Vundo fix
    Spyware Doctor
    Spybot Search&Destroy
    (I also used Trojan Remover Simply Software very good)

    Save all three in a location were you will remember like the desktop. Go ahead and install Spyware Doctor first. Make sure you update the program. Spyware Doctor may try and run after you update the program. Spyware Doctor has a free 30 day trial but it will not remove anything until you purchase the program. If you want you can just purchase the program and then run the scan and be done with this guide. Your other choice is to stop the auto scan after you update the program. We will still be using this program regardless at the end of this guide to ensure you are vundo free. The reason we need it right now is so it will block vundo from working while we use other methods to clean the system. We will also be running the free scan at the end so you know you are vundo free.

    Now install Spybot Search and Destroy. Follow the on screen install instructions. Do what it says. When asked to make a registry backup say yes, when asked to update say yes, when asked to immunize say yes. DO NOT run the scan yet.

    Once installed reboot into "safe mode" NOT safe mode with networking.

    Run Vundofix.exe FIRST!!!! Just double click the file and then select "Scan for vuno". If any traces are found only then can you select "Remove Vundo". If not all traces could be removed then allow the program to run on re-boot. Remember you MUST BE IN SAFE MODE WITH NETWORKING!!!. If Spybot Tea timer or spyware doctor asks you if you want to allow the registry changes select YES to allow the change.

    Run Spybot S&D. Just double click the Spybot icon or launch the program from "All Programs" The scan should take about 30 minutes and if it finds anything select them all and remove them. If it says it could not remove all traces then allow the program to run on boot-up.

    Now run Spyware doctor. The scan is 100% free but to remove anything else it would cost money. The purpose of using Spyware doctor is because it is the best on the market and if you have any traces left over that program will find it. If it finds nothing then YHEAAAAAA!!! you are now Vundo free baby. If it just finds cookies and it will!!! Then there is no need to but the program to remove Vundo as it is already removed.

    Do a little clean up. If you purchase Spyware doctor you will want to un-install Spybot as it is not needed and will only slow your computer down. Also you may still need to change your home page back to normal. Surf the web a bit and see that you have no more pop-ups. Your home page may still be changed when you first launch IE or Firefox. If that is the case just go to "Tool" > Options and change your home page to your favourite site.

    Be sure and go to http://www.java.com/en/ to download the latest Java program as the old one has holes that might allow Vundo in."
     
  3. SavageWaffle

    SavageWaffle GBAtemp Maniac

    Member
    1,123
    1
    Jan 13, 2008
    United States
    New York
    Answer solved lol ^^
     
  4. Minox

    Minox Spytech Employee

    Supervisor
    6,022
    2,601
    Aug 27, 2007
    I hate that trojan, I've had it twice and it always takes me hours to get rid of it [​IMG]
     
  5. juggernaut911

    juggernaut911 GBAtemp Slut!

    Member
    4,153
    21
    Jul 13, 2006
    United States
    how do you get the trojan? I've never got one.
     
  6. Rock Raiyu
    OP

    Rock Raiyu Clock Up

    Member
    5,065
    38
    Jul 14, 2007
    United States
    Walking the path of heaven
    Alright awesome. I'm going to give it a try. Thanks for the help.
     
  7. fischju

    fischju Rehabilitated Jaywalker

    Member
    1,940
    0
    Jan 11, 2008
    United States
    You could also just do a clean install.
     
  8. juggernaut911

    juggernaut911 GBAtemp Slut!

    Member
    4,153
    21
    Jul 13, 2006
    United States
    In Soviet Russia, Virus catch you!


    IF you clean install, be real careful on what you back up. and if there is an installer on the internet, wait till you reinstall to download it.
     
  9. Rock Raiyu
    OP

    Rock Raiyu Clock Up

    Member
    5,065
    38
    Jul 14, 2007
    United States
    Walking the path of heaven
    I think I got rid of most of the vundo except for this sqqonnn.dll or something. I've scaneed countless time to get rid of all traces with Spy Sweeper. (I'm on dial-up right now and it takes like 3hrs to download Spyware and I'm download SpyBot now..) but I still get that error. Its not even comming up on the Vundo scan..
     
  10. Lee79

    Lee79 Hyper...Active...Team Fortress 2 Addict

    Member
    920
    0
    Jul 29, 2007
    ctf_2fort
    Use the Trojan remover from simply software to clear up the last bits.
     
  11. Rock Raiyu
    OP

    Rock Raiyu Clock Up

    Member
    5,065
    38
    Jul 14, 2007
    United States
    Walking the path of heaven
    Whats weird is that I run the trojan remover and all these other things. They come up nothing and it still doesn't get rid of the Windows Explorer error no matter what. I even did a HiJackThis and its still there (though the same file does appear on it, but I can't delete it..)
     
  12. AeroHex

    AeroHex Banned

    Banned
    498
    0
    Sep 8, 2008
    what about one of those symantec patches
     
  13. Holaitsme

    Holaitsme 10/10 would be loyal again

    Member
    846
    3
    May 14, 2008
    United States
    Why the fuck would you bump this?
     
  14. Sir-Fritz

    Sir-Fritz GBAtemp Maniac

    Member
    1,336
    8
    May 4, 2008
    Brisbane, Australia
    Its beve, what can you expect?