System32/ssqpn.exe

Discussion in 'Malware Help (A Specialist Will Reply)' started by jordan9524, Jan 19, 2008.

  1. jordan9524

    jordan9524 Private E-2

    Hello!

    Can someone please help! I started getting this message on start up and i'm guessing it is a virius. Sooo..can someone please help get this thing gone.

    I can't even access the interent from the computer the virius is on. Luckily i have another computer to use in the house to access the internet.

    So can anyone help?

    Thanks!
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi and Welcome to Majorgeeks


    Could you tell us what this message is you recieve?


    But please follow the below information in the Read & Run Me guide and collect the logs requested, then after these are attached our malware experts will review these to see if your OK, if not they will issue you some further removal instructions,

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide

    So logs that you will get to attach are:

    MGlogs.zip (which has 5 logs inside it, including Hijackthis, just attach the whole Zip )
    AVG log. ( Which is the report scan txt file )
    Combofix logs.

    http://img117.imageshack.us/img117/829/60272555mm4.jpg

    plus a guide on how to attach the logs HOW TO: Attach Items To Your Post
     
  3. jordan9524

    jordan9524 Private E-2

    Sorry for the delay and thanks a bunch for your help!!

    Attached are the test results.
     

    Attached Files:

  4. jordan9524

    jordan9524 Private E-2

    attached also is a removal log from avg from yesterday where a deleted a lot of viruses.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not install AVG Antispyware as requested in the READ & RUN ME. We did not ask for a log from AVG Antivirus. Please run AVG Antispyware as requested and attach the requested log. Make sure you have it Quarantine or Delete what it finds.

    Also you must put your PC in Normal Startup mode as requested in step 1 of the READ ME. You must not use MSconfig to control startups. Do this now.

    Your HJT log looks way to small, some of this is due to using MSconfig, but I have to ask the below.
    1. did your start removing things using HijackThis on your own?? If so, you should restore them from backups.
    2. or are you using HijackThis's ability to filter known lines. If so, you must not do this.
    After doing all of the above you will need to attach a new MGlogs.zip file by doing the below.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created.
     
  6. jordan9524

    jordan9524 Private E-2

    Ok, i will do this, but the problem is I can't access the internet from the infected computer, so i can't download uploads for the software.

    Just letting you know.
     
  7. jordan9524

    jordan9524 Private E-2

    Ok, sooo..the attached is my logs and like i said before, i can't access the internet through the infected computer therefore, avag anti-spyware is probably not updated fully. I don't know if it is or not? I went to the website and downloaded the lastest spyware so maybe it is.

    Also in a early post on this thread, i attached a log from avg that listed all of the viruses i removed yesterday.

    Thanks!
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not answer my question
    Also I said this
    You did not do this! You must put your system into Normal Startup mode and then attach a new MGlogs.zip file. DO NOT attach any other logs! Just a new MGlogs.zip file but you have to be in normal startup mode first.
     
  9. jordan9524

    jordan9524 Private E-2

    Look....I did everything you said to do!

    Yes...I used Hijack this to remove some things and no i can't restore backups because i don't have any!

    And on number #2...Ok i won't do that anymore!

    And the normal startup question...I checked and it was booting in normal startup mode...now if there is another way to do this, then tell me and I will!!

    The last zip file I just attached was in normal startup mode. Not safe mode, but normal start up mode!
     
  10. jordan9524

    jordan9524 Private E-2

    Here is the newest log which was ran in normal start up mode!
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No you are still using selective startup. You need to run MSconfig and on the General tab select the top item that says
    • Normal Startup - load all device drivers and services
    Then do the below.


    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3
    Java(TM) SE Runtime Environment 6 Update 1
    LiveUpdate 2.6 (Symantec Corporation)
    SpyHunter <-- should have been uninstalled in step 0 of the READ ME

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  12. jordan9524

    jordan9524 Private E-2

    here are the logs. I still can't log onto the internet or check email and my computer is still acting the same when starting up. Very weird.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well your problems are not due to malware and they are not weird. They are most likely just due to all the things your did on your own using HijackThis or other programs to delete things that are required for your PC and software to work properly.

    As I see it you could have two or three choices:
    1. Fix the things you removed and only you know what that was. But since you imply you do not have HijackThis backups, that may not be possible. Not sure why you say you do not have backups as HijackThis creates them automatically. And a ton of them show in your MGtools\backups folder. These were all things you remove as we did not ask you to fix anything with HijackThis
    2. Try using Windows System Restore to go back to an old Restore Point to see if that helps.
    3. Reinstall.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds