Recommended Posts

Hi all,

I have been asked by a friend to fix a few problems on their Home PC; one of the main things I dread. I have sorted most of the other problems out, but im falling behind on trying to remove a Virus which doesn't seem to die! ;)

The Virus first and foremost is one found in the DLL of SSTQR.dll found in C:\Windows\System32\ssqtr.dll, now I have browsed to that directory and tried to remove it muiltiple times with no-avail. (File is in use, etc). I have done a scan with NOD32 and tried removing it using NOD but that's failed which was frustrating, I have also tried going into Safe Mode which didn't work either and also tried removing the file via command line all saying access denied.

Renaming/moving also same problem, now I had a clever idea earlier which was to download Shift Linux (Neowin's own :)) and make a Live CD, now I booted using this, great stuff browsed to the file and tried to remove it, as I thought it won't be in use because im not in Windows surely. But no, didn't work; Shift said it couldn't remove the file because it was on a read only...? Also tried a removal tool, which starts when the PC first boots but that wouldn't get rid of it.

Now in Shift Linux is there a command I can put to get too the file, and hard-delete it or even rename it without if worrying about Permissions? (If there is I will need the program name, and what too type etc as im pretty much a Linux nub! :))

Or is there anything I can do in Windows, apart from formatting? :)

(I tried finding a website with some more information on this Virus, but the only thing I could find is what NOD32 displayed about it which was: sstqr.dll - WIN32/Trojan.ConHook)

Cheers people, really want to get this sorted.

JMann :)

Link to comment
https://www.neowin.net/forum/topic/593907-virus-outbreak/
Share on other sites

Hi all,

I have been asked by a friend to fix a few problems on their Home PC; one of the main things I dread. I have sorted most of the other problems out, but im falling behind on trying to remove a Virus which doesn't seem to die! ;)

The Virus first and foremost is one found in the DLL of SSTQR.dll found in C:\Windows\System32\ssqtr.dll, now I have browsed to that directory and tried to remove it muiltiple times with no-avail. (File is in use, etc). I have done a scan with NOD32 and tried removing it using NOD but that's failed which was frustrating, I have also tried going into Safe Mode which didn't work either and also tried removing the file via command line all saying access denied.

Renaming/moving also same problem, now I had a clever idea earlier which was to download Shift Linux (Neowin's own :)) and make a Live CD, now I booted using this, great stuff browsed to the file and tried to remove it, as I thought it won't be in use because im not in Windows surely. But no, didn't work; Shift said it couldn't remove the file because it was on a read only...? Also tried a removal tool, which starts when the PC first boots but that wouldn't get rid of it.

Now in Shift Linux is there a command I can put to get too the file, and hard-delete it or even rename it without if worrying about Permissions? (If there is I will need the program name, and what too type etc as im pretty much a Linux nub! :))

Or is there anything I can do in Windows, apart from formatting? :)

(I tried finding a website with some more information on this Virus, but the only thing I could find is what NOD32 displayed about it which was: sstqr.dll - WIN32/Trojan.ConHook)

Cheers people, really want to get this sorted.

JMann :)

By ben13010, Friday, January 20, 2006 at 6:05 p.m.: 11

Ok

O2-BHO: (no name) - (00DBDAC8-4691-4797-8E6A-7C6AB89BC441) - C: \ WINDOWS \ system32 \ awtqn.dll

And

O20 - Winlogon Notify: awtqn-C: \ WINDOWS \ SYSTEM32 \ awtqn.dll

You noted that these two lines are the same ugly dll

It is an infection vundo

You will be ca

Downloads: xp process here:

Http://www.sysinternals.com/files/procexpnt.zip

The decompressed

Disconnects you

Close all programs

Double clicking processxp.exe

* In the main window processxp double clicking winlogon.exe

In the new window that opens click threads

Select only the rows that contain the dll awtqn.dll then selects kill for each line found.

Once done, with valid ok

* In the main window processxp double clicking explorer.exe

In the new window that opens click threads

Select only the rows that contain the dll awtqn.dll then selects kill for each line found.

Once done, with valid ok

Then you open the box kill

Download: Pocket Killbox here

Http://www.downloads.subratam.org/KillBox.exe

Demo User (thanks to a Balltrap34 this achievement):

Http://pageperso.aol.fr/balltrap34/killbox.htm

You glue the dll suspicious and you deleted the

Like this:

Double click on killbox.exe (Killbox Pocket)

- Tick: delete reboot on

- "Full Path of File to Delete"

Copy and paste: C: \ WINDOWS \ SYSTEM32 \ awtqn.dll

- Click on the red cross

- A window will appear for confirmation clicks YES

- A second window may ask whether you want to restart clicks YES

Let the pc restarted.

And after a reposte HijackThis log. There's still some things to fix

Edited by woodson
Link to comment
https://www.neowin.net/forum/topic/593907-virus-outbreak/#findComment-588917987
Share on other sites

make a bartpe cd and boot off that and delete it from there

then go to the system32 diretory and arrange by date and delete all the newest files that look funky, you can just tell. then if you have nod32 burn the nod32 directory from c:\program files\ to a cd or a thumbstick and open it in bartpe and run the nod32.exe and do a scan from bartpe

Link to comment
https://www.neowin.net/forum/topic/593907-virus-outbreak/#findComment-588921846
Share on other sites

Hey everyone, thought I best update with the solution. I tried everything, downloaded and read up on all the tools before I started getting too work all seemed great. (Y) Killbox also looked fairly damn impressive. Same with Bart PE, but the first thing suggested Kaspersky solved the issue well. It did the scan, found the virus and after post boot removed the virus on command line with its own tool.

So impressed with it, im going to purchase a license for it after the trial expires on my own PC. I have kept the other tools for future PC's (if I ever get the courage to do them again!) and will use them if ever needed.

Thanks again. :)

Link to comment
https://www.neowin.net/forum/topic/593907-virus-outbreak/#findComment-588922217
Share on other sites

Just thought id say the reason shift linux probably couldnt delete it was because the drive is in NTFS and shiftlinux can only mount NTFS drives as read only right now, doing a delete on a file would require writing to the drive to overwrite the data.

Link to comment
https://www.neowin.net/forum/topic/593907-virus-outbreak/#findComment-588922318
Share on other sites

Better than NOD32, most definately. :p

I am sure a few folk would not be happy with the above statement! :laugh: There are two sides to this argument I would say! Have a look at this! I have never used Kaspersky but since the day I started using NOD32 I have never had a virus on any of my PC's! I suppose I am biased, I am a Eset NOD32 partner and probably have it running on at least 15 servers and plus minus 400 PC's. Glad to hear that the problem is solved!

Link to comment
https://www.neowin.net/forum/topic/593907-virus-outbreak/#findComment-588922434
Share on other sites

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Microsoft admits one of the most crucial Outlook features is currently broken by Sayan Sen Microsoft is making some decent progress when it comes to Windows 11. Recently we have confirmed reports of some rather useful improvements landing in the next version of the OS, 26H2, wherein GPU driver TDR crashes may finally be fixed, plus the company is also allowing users to disable web content on the Search. On the Outlook front though things have not been so rosy. Last month in May we reported several problems affecting basic functionalities on the app. These included a problem where documents would open blank or corrupt themselves. Following that, Quick Steps, a very useful feature, would no longer work correctly, and finally, Microsoft acknowledged a problem wherein images would fail to load up properly inside the email. Microsoft had resolved those bugs later and almost exactly a month after we reported on them, the company has now admitted a new similarly basic issue, this time on Macs. Users recently started noticing that Outlook would no longer display email threads properly as the original message itself was not displayed. An affected user Tsoumpas, C (ngmb) nicely described the problem in a forum post they made on Microsoft's site. They wrote: "Description of the issue: After updating Outlook for Mac [Version 16.110 (26061317)] on 18/6/2026, replying to any email no longer includes the original message in the reply window. Prior to the update, replies correctly contained the original email text below my response. Expected behavior: The original message should be included in the reply, as in previous Outlook versions and according to the configured reply settings. Actual behavior: The reply window contains only a blank composition area (or only my response), with none of the original email text included." Obviously this must be a highly frustrating for users as noted by several in that thread. The post, at the time of writing, has also been upvoted by more than 40 users indicating that is a fairly widespread bug. Thankfully Microsoft seems to have acknowledged the problem right around that time as it opened a new issue on its official website. In the support article, the company recommends switching to Outlook for Mac from the legacy app, where the problem appears to be happening.
    • PotPlayer 260622 by Razvan Serea PotPlayer is an extremely light-weight multimedia player for Windows. It feels like the KMPlayer, but is in active development. Supports almost every available video formats out there. PotPlayer contains internal codecs and there is no need to install codecs manually. Other key features include WebCam/Analog/Digital TV devices support, gapless video playback, DXVA, live broadcasting. Distinctive features of the player is a high quality playback, support for all modern video and audio formats and a built DXVA video codecs. A wide range of subtitles are supported and you are also able to capture audio, video, and screenshots. A comprehensive video and audio player, that also supports TV channels, subtitles and skins. Its been described on the Internet as The KMPlayer redux, and it pretty much is. Daum PotPlayer 260622 (1.7.22963) changelog: Removed Kakao TV Added pause function when navigating via the navigation bar Significantly improved internal stability Fixed an issue where colors appeared strange during RGB24 processing Improved playback for some HTTP streams Improved sync processing for the built-in audio renderer Fixed an issue where certain MP4 files behaved abnormally during playback Download: Daum PotPlayer (64-bit) | 54.7 MB (Freeware) Download: Daum PotPlayer (32-bit) | 61.1 MB View: Daum PotPlayer Home Page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Tixati 3.44 is out.
    • Speccy 1.34.084 by Razvan Serea Speccy will give you detailed statistics on every piece of hardware in your computer. Including CPU, Motherboard, RAM, Graphics Cards, Hard Disks, Optical Drives, Audio support. Additionally Speccy adds the temperatures of your different components, so you can easily see if there's a problem! Processor brand and model Hard drive size and speed Amount of memory (RAM) Graphics card Operating system At first glance, Speccy may seem like an application for system administrators and power users. It certainly is, but Speccy can also help normal users, in everyday computing life. If you need to add more memory to your system, for example, you can check how many memory slots your computer has and what memory's already installed. Then you can go out and buy the right type of memory to add on or replace what you've already got. Download: Speccy 1.34.084 | 20.5 MB (Freeware) View: Speccy Website | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • ImgDrive 2.2.7 by Razvan Serea ImgDrive is a CD/DVD/BD emulator - a tool that allows you to mount optical disc images by simply clicking on them in Windows Explorer. If you have downloaded an ISO image and want to use it without burning it to a blank disc, ImgDrive is the easiest way to do it. ImgDrive features: One-click mounting of iso, cue, nrg, mds/mdf, ccd, isz images Runs on 32-bit and 64-bit Windows versions Mount ape, flac, m4a, wav, wavpack, tta file as AUDIO CD (16-bit/44.1kHz) Mount a folder as DVD/BD Mount images in command line Does not require rebooting after installation Support up to 7 virtual drives at the same time Support multi session disc image (ccd/mds/nrg) A special portable version is available Translated to more than 10 languages Support File Type: .ccd - CloneCD image files .cue - Cue sheets files of ape/flac/m4a/tta/wav/wv/bin .iso - Standard ISO image files .isz - Compressed ISO image files .nrg - Nero image files .mds - Media descriptor image files ImgDrive 2.2.7 changelog: Added command line parameter to set number of drives Added AACS-Auth support for HD DVD Bumped kernel driver version to 2.2.7 Download: ImgDrive 2.2.7 | 692 KB (Freeware, paid upgrade available) Download: ImgDrive Portable 535 KB View: ImgDrive Home Page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
  • Recent Achievements

    • Dedicated
      tuben earned a badge
      Dedicated
    • Week One Done
      mnsgroup earned a badge
      Week One Done
    • Conversation Starter
      sumytbe earned a badge
      Conversation Starter
    • One Year In
      B4dM1k3 earned a badge
      One Year In
    • One Year In
      DarkWun earned a badge
      One Year In
  • Popular Contributors

    1. 1
      +primortal
      522
    2. 2
      +Edouard
      199
    3. 3
      PsYcHoKiLLa
      94
    4. 4
      Michael Scrip
      82
    5. 5
      neufuse
      69
  • Tell a friend

    Love Neowin? Tell a friend!