ssqrr.dll?

Discussion in 'Malware Help (A Specialist Will Reply)' started by fearful_syzygy, Sep 1, 2006.

  1. fearful_syzygy

    fearful_syzygy Private E-2

    Hi, I've done everything listed in the 'DO THIS FIRST' thing, several times, but the problem won't go away, so I figured I'd actually post the logs and see if you guys can help me out. It's not been doing anything (visibly) disastrous, just loading various pages in internet explorer when I'm running firefox, and then ultimately tries to get me to download diskcleaner or something to that effect. Anyway, the logs'll probably tell you more than my description, so here they are (part 1):
     

    Attached Files:

  2. fearful_syzygy

    fearful_syzygy Private E-2

    And here are the two online virus scanner logs, plus hijackthis:
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    You actually have quite a few problems! SmitFraud, Virtumonde, Winlogonhook, and a variety of other miscellaneous trojans.

    You are using an old version of ShowNew. Make sure you get the new version later at the end of the below procedure to get a new log.

    Is your copy of Pest Patrol a paid version or a free version?


    First install the current version of Sun Java from: Sun Java Runtime Environment

    Then uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 6


    Now Please download and install Registrar Lite Make sure you select a Majorgeeks download link and not the Authors!

    Run Registrar Lite navigate to the following key and take ownership of it (explained further down):

    HKEY_LOCAL_MACHINE\software\microsoft\mssmgr

    To take ownership of the key do the following:
    • Copy & Paste the registry key from above into the address bar of Registrar Lite and hit the enter key. This will bring you to the registry key.
    • Click-on Security in the Menu
    • Select Take Ownership
    • Now leave RegistrarLite running and continue
    • Now run the REGISTRY PATCH below in this message.
    • Tell me the results. Any error messages?
    • Now in RegistrarLite click View and then Refresh
    • Now navigate to HKEY_LOCAL_MACHINE\software\microsoft\mssmgr
    • Does the above mssmgr key still exist! If so, right click on it and select Delete.
    Here is the Registry Patch

    Now Copy the bold text below to notepad. Save it as fixWLK.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    After completing ALL of the above instructions, continue here!

    Start by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of ssqrr.dll once and then click the kill button. After you have killed all of the ssqrr.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    winmmt32.dll
    clbcatex.dll


    Next double click on explorer.exe and again click once on each instance of ssqrr.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    winmmt32.dll
    clbcatex.dll


    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {A4F94C0C-54A7-4DB1-9AF3-B22E63D00310} - C:\WINDOWS\system32\compstuid.dll
    O2 - BHO: (no name) - {AACD8A74-D24A-4DF1-BA35-F2F97FE131E3} - C:\WINDOWS\system32\ssqrr.dll
    O2 - BHO: (no name) - {D4DFC1D8-2D2E-4962-B0D0-389FBA0F76B5} - (no file)
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\clbcatix.dll (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\clbcatix.dll (file missing)
    O20 - Winlogon Notify: clbcatex - C:\WINDOWS\system32\clbcatix.dll (file missing)
    O20 - Winlogon Notify: ssqrr - C:\WINDOWS\system32\ssqrr.dll
    O20 - Winlogon Notify: winmmt32 - winmmt32.dll (file missing)
    O21 - SSODL: incestuously - {03413bf7-e34c-445b-bfc0-a2b127255871} - (no file)
    After clicking Fix, exit HJT.


    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    Now back on Killbox's main window, Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note some of the files listed below may not exist but we need to check for them anyway.

    C:\Program Files\Common Files\{0F40DBEA-06FE-1033-1107-05050926002c}\Update.exe
    C:\cc_20060826_0230.reg
    C:\WINDOWS\system32\gndmuukj.exe
    C:\WINDOWS\system32\lunjkiiq.exe
    C:\WINDOWS\system32\qwxiqtch.exe
    C:\WINDOWS\system32\wefoggna.exe
    C:\WINDOWS\system32\compstuid.dll
    C:\WINDOWS\system32\clbcatix.dll
    C:\WINDOWS\system32\ssqrr.dll
    C:\WINDOWS\system32\rrqss.tmp
    C:\WINDOWS\system32\rrqss.ini
    C:\WINDOWS\system32\rrqss.ini2

    If Killbox does not reboot or if you get a Pending Operations type error message just click OK to continue and then just reboot your PC yourself.

    After reboot locate the below folder and delete it if found:
    C:\Program Files\Common Files\{0F40DBEA-06FE-1033-1107-05050926002c}

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Kari\Local Settings\Temp

    Now attach a new HJT log and tell me how the steps went.

    Now download the new version of ShowNew ( Using ShowNew )

    Also attach a new log from ShowNew and a new log from GetRunKey.


    Make sure you tell me how things are working now!
     
  4. fearful_syzygy

    fearful_syzygy Private E-2

    Hi and thanks for the help,

    since I uploaded the logs, I'd already downloaded the latest version of Java. And my version of Pest Patrol is provided by the university at which I'm studying, so I assume that means it's paid for. My license key apparently expires in 365 days.

    In terms of the processes you specified, the only one I received an error message on was the following:

    I haven't done much on the computer since completing the steps specified, but it seems to be fine (but then problems weren't immediately apparent before either. And since installing the ZoneAlarm Firewall (again after I posted the log) it doesn't seem to have bothered me).

    Please let me know if there's anything thank you once again for you help.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Then uninstall Windows Defender now to avoid conflicts and excess use of System Resources.

    Now delete the two registry patch files from your Desktop ( fixme.reg and fixWLK.reg )
    Then delete all files in the C:\!KillBox folder

    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
    Last edited: Sep 2, 2006
  6. fearful_syzygy

    fearful_syzygy Private E-2

    Cool.

    Now I'm worried I have a new problem: I downloaded this program from your site today, and when I ran it PestPatrol told me it was infected with Trojan-Clicker.Win32.Small.bt

    I've run a few scans and nothing's come up, but could you please take a look at these logs and let me know if any damage has been done? Cheers.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is more than likely a false positive. I would like to see the log from Pest Patrol that showed what it found.

    Your logs are still clean.
     
  8. fearful_syzygy

    fearful_syzygy Private E-2

    OK, here's the log.

    I'll go disable system restore and all that stuff. Do you think I should switch from Symantec to AVG?
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As suspected, it is a false positive. They probably just don't like the name of the file.

    Ignore it!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds