Associated Malware Groups
The filename is associated with the malware groups:
- Fraudulent Security Program
- Malicious Software
File Behavior
SSTQO.DLL has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- The Process is polymorphic and can change its structure
- Creation and Registers a Browser Helper Object in Internet Explorer
- Adds a Winlogon Notification DLL to automatically load on system start up
- Adds a Registry Key (EXPLORER) to auto start Programs on system start Boot up
SSTQO.DLL has been the subject of the following behavior:
- Created as a process on disk
- Registered as a Dynamic Link Library File
- Enabled as an In Process Object/Server - Common with DLL Injections
- Created and Registered as a Browser Helper Object in Internet Explorer
- Deleted as a process from disk
- The process is hooked into all running processes which could allow it to take control of the system or record keyboard input, mouse activity and screen contents
- Added as a Winlogon Notification DLL to automatically load on system start up
Country Of Origin
The filename SSTQO.DLL was first seen on Jun 20 2007 in the following geographical regions of the Webroot community:
- The United States on Jun 20 2007
- Canada on Jul 4 2007
- Netherlands on Oct 11 2007
- Germany on Oct 11 2007
- Europe on Sep 5 2008
File Name Aliases
SSTQO.DLL can also use the following file names:
- MLLJJ.DLL
- GEEDA.DLL
- GEBYV.DLL
- JKHFF.DLL
- PMNNO.DLL
- SSTTR.DLL
Filesizes
The following file size has been seen:
- 263,220 bytes
- 278,528 bytes
- 35,341 bytes
- 266,336 bytes
- 282,720 bytes
- 272,896 bytes
- 285,273 bytes
File Type
The filename SSTQO.DLL refers to many versions of a dynamic link library.
Help the Webroot Community to fight cyber crime
We are always looking for ways to improve the quality and speed of research to help us protect you from malicious software and cyber crime.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.