Recommended Posts

Hi all,

I have been asked by a friend to fix a few problems on their Home PC; one of the main things I dread. I have sorted most of the other problems out, but im falling behind on trying to remove a Virus which doesn't seem to die! ;)

The Virus first and foremost is one found in the DLL of SSTQR.dll found in C:\Windows\System32\ssqtr.dll, now I have browsed to that directory and tried to remove it muiltiple times with no-avail. (File is in use, etc). I have done a scan with NOD32 and tried removing it using NOD but that's failed which was frustrating, I have also tried going into Safe Mode which didn't work either and also tried removing the file via command line all saying access denied.

Renaming/moving also same problem, now I had a clever idea earlier which was to download Shift Linux (Neowin's own :)) and make a Live CD, now I booted using this, great stuff browsed to the file and tried to remove it, as I thought it won't be in use because im not in Windows surely. But no, didn't work; Shift said it couldn't remove the file because it was on a read only...? Also tried a removal tool, which starts when the PC first boots but that wouldn't get rid of it.

Now in Shift Linux is there a command I can put to get too the file, and hard-delete it or even rename it without if worrying about Permissions? (If there is I will need the program name, and what too type etc as im pretty much a Linux nub! :))

Or is there anything I can do in Windows, apart from formatting? :)

(I tried finding a website with some more information on this Virus, but the only thing I could find is what NOD32 displayed about it which was: sstqr.dll - WIN32/Trojan.ConHook)

Cheers people, really want to get this sorted.

JMann :)

Link to comment
https://www.neowin.net/forum/topic/593907-virus-outbreak/
Share on other sites

Hi all,

I have been asked by a friend to fix a few problems on their Home PC; one of the main things I dread. I have sorted most of the other problems out, but im falling behind on trying to remove a Virus which doesn't seem to die! ;)

The Virus first and foremost is one found in the DLL of SSTQR.dll found in C:\Windows\System32\ssqtr.dll, now I have browsed to that directory and tried to remove it muiltiple times with no-avail. (File is in use, etc). I have done a scan with NOD32 and tried removing it using NOD but that's failed which was frustrating, I have also tried going into Safe Mode which didn't work either and also tried removing the file via command line all saying access denied.

Renaming/moving also same problem, now I had a clever idea earlier which was to download Shift Linux (Neowin's own :)) and make a Live CD, now I booted using this, great stuff browsed to the file and tried to remove it, as I thought it won't be in use because im not in Windows surely. But no, didn't work; Shift said it couldn't remove the file because it was on a read only...? Also tried a removal tool, which starts when the PC first boots but that wouldn't get rid of it.

Now in Shift Linux is there a command I can put to get too the file, and hard-delete it or even rename it without if worrying about Permissions? (If there is I will need the program name, and what too type etc as im pretty much a Linux nub! :))

Or is there anything I can do in Windows, apart from formatting? :)

(I tried finding a website with some more information on this Virus, but the only thing I could find is what NOD32 displayed about it which was: sstqr.dll - WIN32/Trojan.ConHook)

Cheers people, really want to get this sorted.

JMann :)

By ben13010, Friday, January 20, 2006 at 6:05 p.m.: 11

Ok

O2-BHO: (no name) - (00DBDAC8-4691-4797-8E6A-7C6AB89BC441) - C: \ WINDOWS \ system32 \ awtqn.dll

And

O20 - Winlogon Notify: awtqn-C: \ WINDOWS \ SYSTEM32 \ awtqn.dll

You noted that these two lines are the same ugly dll

It is an infection vundo

You will be ca

Downloads: xp process here:

Http://www.sysinternals.com/files/procexpnt.zip

The decompressed

Disconnects you

Close all programs

Double clicking processxp.exe

* In the main window processxp double clicking winlogon.exe

In the new window that opens click threads

Select only the rows that contain the dll awtqn.dll then selects kill for each line found.

Once done, with valid ok

* In the main window processxp double clicking explorer.exe

In the new window that opens click threads

Select only the rows that contain the dll awtqn.dll then selects kill for each line found.

Once done, with valid ok

Then you open the box kill

Download: Pocket Killbox here

Http://www.downloads.subratam.org/KillBox.exe

Demo User (thanks to a Balltrap34 this achievement):

Http://pageperso.aol.fr/balltrap34/killbox.htm

You glue the dll suspicious and you deleted the

Like this:

Double click on killbox.exe (Killbox Pocket)

- Tick: delete reboot on

- "Full Path of File to Delete"

Copy and paste: C: \ WINDOWS \ SYSTEM32 \ awtqn.dll

- Click on the red cross

- A window will appear for confirmation clicks YES

- A second window may ask whether you want to restart clicks YES

Let the pc restarted.

And after a reposte HijackThis log. There's still some things to fix

Edited by woodson
Link to comment
https://www.neowin.net/forum/topic/593907-virus-outbreak/#findComment-588917987
Share on other sites

make a bartpe cd and boot off that and delete it from there

then go to the system32 diretory and arrange by date and delete all the newest files that look funky, you can just tell. then if you have nod32 burn the nod32 directory from c:\program files\ to a cd or a thumbstick and open it in bartpe and run the nod32.exe and do a scan from bartpe

Link to comment
https://www.neowin.net/forum/topic/593907-virus-outbreak/#findComment-588921846
Share on other sites

Hey everyone, thought I best update with the solution. I tried everything, downloaded and read up on all the tools before I started getting too work all seemed great. (Y) Killbox also looked fairly damn impressive. Same with Bart PE, but the first thing suggested Kaspersky solved the issue well. It did the scan, found the virus and after post boot removed the virus on command line with its own tool.

So impressed with it, im going to purchase a license for it after the trial expires on my own PC. I have kept the other tools for future PC's (if I ever get the courage to do them again!) and will use them if ever needed.

Thanks again. :)

Link to comment
https://www.neowin.net/forum/topic/593907-virus-outbreak/#findComment-588922217
Share on other sites

Just thought id say the reason shift linux probably couldnt delete it was because the drive is in NTFS and shiftlinux can only mount NTFS drives as read only right now, doing a delete on a file would require writing to the drive to overwrite the data.

Link to comment
https://www.neowin.net/forum/topic/593907-virus-outbreak/#findComment-588922318
Share on other sites

Better than NOD32, most definately. :p

I am sure a few folk would not be happy with the above statement! :laugh: There are two sides to this argument I would say! Have a look at this! I have never used Kaspersky but since the day I started using NOD32 I have never had a virus on any of my PC's! I suppose I am biased, I am a Eset NOD32 partner and probably have it running on at least 15 servers and plus minus 400 PC's. Glad to hear that the problem is solved!

Link to comment
https://www.neowin.net/forum/topic/593907-virus-outbreak/#findComment-588922434
Share on other sites

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Time to start going to the local church and play Bingo for a while.
    • NVIDIA announces 35 new AI HPC supercomputers across Europe by Fiza Ali NVIDIA has announced that 35 AI high-performance computing (HPC) supercomputers are planned to open throughout Europe this year. This marks what the company describes as the largest single-year expansion of AI infrastructure in the history of the continent. These new systems, unveiled at ISC High Performance 2026, will be placed at a number of national supercomputing centres, AI factories, and research institutes to provide advanced computing resources to more than three million researchers. Describing AI, NVIDIA founder and CEO Jensen Huang stated, "AI is the new instrument of science, and Europe is building the infrastructure to put it in the hands of millions of researchers." Built on NVIDIA's Blackwell and Hopper architectures, the new systems will support research in climate science, healthcare, clean energy, quantum computing, and other scientific fields. Among the major projects are the Barcelona Supercomputing Center's MareNostrum 5 AI upgrade, BavariaAI's Blue Swan platform in Germany, Italy's IT4LIA AI factory, Germany's HammerHAI project, and Sweden's Mimer AI Factory. The Barcelona Supercomputing Center plans to expand MareNostrum 5 with NVIDIA GB300 NVL72 and GB200 NVL4 systems. In total, the BSC expects to deliver up to 20 exaflops of AI training performance and 33 exaflops of AI inference performance. This increased computational capability will support research efforts related to climate modelling, biotechnology, energy systems, etc. Furthermore, as part of the IT4LIA project, more than 8,000 GPUs, each based on NVIDIA’s GB200 NVL4 architecture, will be used in Italy. This represents one of the largest AI factory initiatives announced to date. Additionally, the Blue Swan platform from BavariaAI will include about 1,000 GPUs to help develop multimodal AI models for use in the medical field, robotics, and various areas of scientific research. NVIDIA also emphasized in the announcement how rapidly growth of accelerated computing usage is taking place within both energy and climate-related research. The company said Siemens Energy uses NVIDIA-powered technologies to significantly accelerate the process of designing and simulating hydrogen-capable gas turbines. Using those same acceleration technologies, Siemens was able to reduce simulation time by up to 77 percent. The company also highlighted several quantum computing initiatives across Europe. CINECA, EuroHPC, and Pasqal are integrating a quantum processing unit into Italy's CINECA supercomputing centre using NVIDIA's CUDA-Q platform. Meanwhile, researchers at Germany's Julich Supercomputing Centre recently simulated a universal 50-qubit quantum computer on the JUPITER supercomputer. The announcement demonstrates Europe's continued commitment to building out its infrastructure supporting AI and supercomputing as governments, research organizations, and technology companies compete to build out their respective computing capacities and secure their positions in advanced scientific research.
    • It's about to become harder to turn off your Samsung TV, thanks to Instagram by Aditya Tiwari Meta announced that its Instagram for TV app has arrived on Samsung TVs in the US as part of its latest expansion, giving users one more way to scroll through Reels. The social media giant often comes under scrutiny for the "addictiveness" of its features, which leads people to spend excessive time on the platform. Interestingly, Instagram boss Adam Mosseri described spending 16 hours on the platform as "problematic use" but not "clinical addiction." Mosseri also compared scrolling on Instagram to binge-watching a show on Netflix. Instagram for TV is now available on Samsung TV models released in 2020 or later. The app is already available on Amazon Fire TV and Google TV in the US, which together account for the majority of connected TV devices. The company said it will test several new features to improve the living room and family experience while using Instagram on the big screen. Watching vertical videos on a big screen isn't something many would be excited about. Probably that's why Meta is testing a dedicated home for horizontal videos. Creators will get the opportunity to design content for TV screens and get more ways to reach audiences, according to Meta. If you found an interesting Reel while doomscrolling on your phone, you'll be able to cast it to your TV. The feature is available for testing on Instagram for TV on Google TV and Amazon Fire TV, and it will also support videos from the Saved tab. Instagram for TV will be testing Channels organized around user interests, across genres such as comedy and sports, as well as content from favorite creators. Moreover, you can watch Stories on your TV. While Instagram is known for short-form videos, it's knocking on more doors to keep the audience hooked. The company said it's exploring new content formats for the big screen, including long-form creator content to cover topics in detail, episodic series to build suspense across multiple episodes, and creator live sessions on TV. All of the new updates put Instagram in competition with established giants like YouTube (and Netflix), which already have a robust presence on the big screen. In recent updates, Instagram added the ability to write an individual caption for each carousel image, manually re-order posts, and a paid version of the app.
    • I know RAM and storage prices are high right now, but I think it would have been better to have 1TB as the base level storage, especially as it's supposed to be for gaming. Plus a 2.5gbe ethernet port rather than only 1gbe.
  • Recent Achievements

    • Dedicated
      tuben earned a badge
      Dedicated
    • Week One Done
      mnsgroup earned a badge
      Week One Done
    • Conversation Starter
      sumytbe earned a badge
      Conversation Starter
    • One Year In
      B4dM1k3 earned a badge
      One Year In
    • One Year In
      DarkWun earned a badge
      One Year In
  • Popular Contributors

    1. 1
      +primortal
      513
    2. 2
      +Edouard
      204
    3. 3
      PsYcHoKiLLa
      98
    4. 4
      Michael Scrip
      82
    5. 5
      neufuse
      67
  • Tell a friend

    Love Neowin? Tell a friend!