Dieser gelockte Thread hier, hat meine Aufmerksamkeit erregt, ich habe das identische Problem und würde gerne dort ansetzten, wo Koi aufgegeben hat - Jeder andere Weg der das Problem löst ist mir allerdings auch recht
http://www.informationsarchiv.net/foren ... -sqle.html
Es hat noch nicht so richtig funktioniert, die datei sqle.dll so loszuwerden, unten also meine Log1.txt:
Lieben Dank für Eure Hilfe
-Steffi
Log.txt:
*System:
Microsoft Windows XP Home Edition 5.1 Service Pack 2 (Build 2600)
*IE version:
6.0.2900.2180 SP2
___________________________________________
!!Restoring backups!!
The operation completed successfully
The operation completed successfully
17:03:27,81 22.09.2004
___________________________________________
*Local time:
Mittwoch, 22. September 2004 (22.09.2004)
17:03, Westeuropäische Normalzeit
*Uptime:
17:03:36 up 0 days, 0:04:54
*path:
c:\FINDnFIX
Running in WORKSTATION MODE.
SystemDrive is C:
SystemRoot is C:\WINDOWS
Logon Domain is USER
Administrator's Name is no name
Computer Name is COMPUTERNAME
LOGON SERVER is \\BLANK
------------------------------------------
This log will confirm if the file was successfully moved, and/or
the right file was selected...
Scanning for file(s) in System32...
»»»»»»» (1) »»»»»»»
\\?\C:\WINDOWS\SYSTEM32\SQLE.DLL +++ File read error
C:\WINDOWS\System32\SQLE.DLL +++ File read error
»»»»»»» (2) »»»»»»»
SQLE.DLL Can't Open!
»»»»»»» (3) »»»»»»»
C:\WINDOWS\SYSTEM32\
sqle.dll Tue 15 Jun 2004 16:04:44 A...R 57.344 56,00 K
1 item found: 1 file, 0 directories.
Total of file sizes: 57.344 bytes 56,00 K
Unknown/hidden files...
No matches found.
»»»»»»» (4) »»»»»»»
Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.
Sniffed -> C:\WINDOWS\SYSTEM32\SQLE.DLL
SNiF 1.34 statistics
Matching files : 1 Amount in bytes : 57344
Directories searched : 1 Commands executed : 0
Masks sniffed for: *.DLL
»»»»»(5)»»»»»
¯ Access denied ® ..................... SQLE.DLL .....57344 15.06.2004
»»»»»(6)»»»»»
fgrep: can't open input C:\WINDOWS\SYSTEM32\SQLE.DLL
»»»»»»» Search by size And Date...
*List of files specs according to size:
*Note: Not all files listed here are infected!
____________________________________________________________________________
Path: C:\WINDOWS\SYSTEM32 Including: *.DLL
717. Msasn1 Dll 57,344 . . . . A 8-04-04 12:57 am
749. Mshtmler Dll 57,344 . . . . A 8-04-04 12:55 am
1168. Sqle Dll 57,344 . . R . A 6-15-04 4:04 pm
230. Dmloader Dll 35,840 . . . . A 8-04-04 12:57 am
396. Imgutil Dll 35,840 . . . . A 8-04-04 12:57 am
260. Dpvacm Dll 21,504 . . . . A 8-04-04 12:57 am
312. Feclient Dll 21,504 . . . . A 8-04-04 12:57 am
____________________________________________________________________________
C:\WINDOWS\SYSTEM32\
msasn1.dll Wed 4 Aug 2004 0:57:26 A.... 57.344 56,00 K
mshtmler.dll Wed 4 Aug 2004 0:55:32 A.... 57.344 56,00 K
sqle.dll Tue 15 Jun 2004 16:04:44 A...R 57.344 56,00 K
3 items found: 3 files, 0 directories.
Total of file sizes: 172.032 bytes 168,00 K
C:\WINDOWS\SYSTEM32\
dmloader.dll Wed 4 Aug 2004 0:57:18 A.... 35.840 35,00 K
imgutil.dll Wed 4 Aug 2004 0:57:22 A.... 35.840 35,00 K
2 items found: 2 files, 0 directories.
Total of file sizes: 71.680 bytes 70,00 K
C:\WINDOWS\SYSTEM32\
dpvacm.dll Wed 4 Aug 2004 0:57:18 A.... 21.504 21,00 K
feclient.dll Wed 4 Aug 2004 0:57:20 A.... 21.504 21,00 K
2 items found: 2 files, 0 directories.
Total of file sizes: 43.008 bytes 42,00 K
Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.
Sniffed -> C:\WINDOWS\SYSTEM32\MSASN1.DLL
Sniffed -> C:\WINDOWS\SYSTEM32\MSHTMLER.DLL
Sniffed -> C:\WINDOWS\SYSTEM32\SQLE.DLL
SNiF 1.34 statistics
Matching files : 3 Amount in bytes : 172032
Directories searched : 1 Commands executed : 0
Masks sniffed for: *.DLL
Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.
Sniffed -> C:\WINDOWS\SYSTEM32\DMLOADER.DLL
Sniffed -> C:\WINDOWS\SYSTEM32\IMGUTIL.DLL
SNiF 1.34 statistics
Matching files : 2 Amount in bytes : 71680
Directories searched : 1 Commands executed : 0
Masks sniffed for: *.DLL
Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.
Sniffed -> C:\WINDOWS\SYSTEM32\DPVACM.DLL
Sniffed -> C:\WINDOWS\SYSTEM32\FECLIENT.DLL
SNiF 1.34 statistics
Matching files : 2 Amount in bytes : 43008
Directories searched : 1 Commands executed : 0
Masks sniffed for: *.DLL
»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»
BHO search and other files...
fgrep: can't open input C:\WINDOWS\SYSTEM32\SQLE.DLL
No matches found.
"C:\WINDOWS\system32\"
rtipxmib.dll 4 Aug 2004 31744 "rtipxmib.dll"
1 item found: 1 file, 0 directories.
Total of file sizes: 31.744 bytes 31,00 K
No matches found.
--*sp.html in temp folder was NOT FOUND!--
*Filter keys search...
REGDMP: Unable to open key 'HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\text/html' (2)
--(*text/html Subkey was NOT FOUND!)--
REGDMP: Unable to open key 'HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\text/plain' (2)
--(*text/plain Subkey was NOT FOUND!)--
»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»
»»»*»»» Scanning for moved file... »»»*»»»
No matches found.
Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.
SNiF 1.34 statistics
Matching files : 0 Amount in bytes : 0
Directories searched : 1 Commands executed : 0
Masks sniffed for: *.*
fgrep: no files found for C:\FINDNFIX\JUNKXXX\*.*
Analyzer v1.36 by Boogie Copyright (C) 1997 ESP Team
Files: C:\FINDNFIX\JUNKXXX\*.*
Ä
Ä
Volume: VAIO * DDIR * 5:12 pm | Wed, 9-22-04
Ser #: 80AD-0A53 DOS Ver. 5.00 0% Used space
Path: C:\FINDNFIX\JUNKXXX All files selected
No files found.
No. of files: 0 | List size: 0
Disk size: 976.5 M | Actual spc: 0
Bytes free: 976.5 M | Conserved space: 0
Datei C:\FINDnFIX\junkxxx\*.* nicht gefunden
CHK-SAFE.EXE Ver 2.51 by Bill Lambdin Don Peters and Robert Bullock.
MD5 Message Digest Algorithm by RSA Data Security, Inc.
File name Size Date Time MD5 Hash
________________________________________________________________________
CRC-Cyclic Redundancy Checker, Version 1.20, 08-Feb-92, rtk
C:\FINDNFIX\JUNKXXX
No files found
#######################################################
*Known files are...
--------------------
File: ((56k; (57,344 bytes)
CRC-32 : D5C9FB2E
MD5 : C185B36F 9969D3A6 D2122BA7 CBC02249
--------------------
File: ((35k; (35,840 bytes)
CRC-32 : 33081C8B
MD5 : 1DE9A8E2 4C826006 7A479B09 577D9CAE
--------------------
File: ((21k; (21,504 bytes)
CRC-32 : 2258F59E
MD5 : EFEE2CB3 B342A351 51802356 9637F8E6
#######################################################
»»Permissions:
ERROR: Es sind keine weiteren Dateien vorhanden.
Directory "C:\FINDnFIX\junkxxx\."
Permissions:
Type Flags Inh. Mask Gen. Std. File Group or User
======= ======== ==== ======== ==== ==== ==== ================
Allow 00000010 t--- 001F01FF ---- DSPO rw+x VORDEFINIERT\Administratoren
Allow 0000001B -co- 10000000 ---A ---- ---- VORDEFINIERT\Administratoren
Allow 00000010 t--- 001F01FF ---- DSPO rw+x NT-AUTORITÄT\SYSTEM
Allow 0000001B -co- 10000000 ---A ---- ---- NT-AUTORITÄT\SYSTEM
Allow 00000010 t--- 001F01FF ---- DSPO rw+x COMPUTERNAME\no name
Allow 0000001B -co- 10000000 ---A ---- ---- \ERSTELLER-BESITZER
Allow 00000010 t--- 001200A9 ---- -S-- r--x VORDEFINIERT\Benutzer
Allow 0000001B -co- A0000000 R-X- ---- ---- VORDEFINIERT\Benutzer
Allow 00000012 tc-- 00000004 ---- ---- --+- VORDEFINIERT\Benutzer
Allow 00000012 tc-- 00000002 ---- ---- -w-- VORDEFINIERT\Benutzer
Owner: COMPUTERNAME\no name
Primary Group: COMPUTERNAME\Kein
Directory "C:\FINDnFIX\junkxxx\.."
Permissions:
Type Flags Inh. Mask Gen. Std. File Group or User
======= ======== ==== ======== ==== ==== ==== ================
Allow 00000010 t--- 001F01FF ---- DSPO rw+x VORDEFINIERT\Administratoren
Allow 0000001B -co- 10000000 ---A ---- ---- VORDEFINIERT\Administratoren
Allow 00000010 t--- 001F01FF ---- DSPO rw+x NT-AUTORITÄT\SYSTEM
Allow 0000001B -co- 10000000 ---A ---- ---- NT-AUTORITÄT\SYSTEM
Allow 00000010 t--- 001F01FF ---- DSPO rw+x COMPUTERNAME\no name
Allow 0000001B -co- 10000000 ---A ---- ---- \ERSTELLER-BESITZER
Allow 00000010 t--- 001200A9 ---- -S-- r--x VORDEFINIERT\Benutzer
Allow 0000001B -co- A0000000 R-X- ---- ---- VORDEFINIERT\Benutzer
Allow 00000012 tc-- 00000004 ---- ---- --+- VORDEFINIERT\Benutzer
Allow 00000012 tc-- 00000002 ---- ---- -w-- VORDEFINIERT\Benutzer
Owner: COMPUTERNAME\no name
Primary Group: COMPUTERNAME\Kein
»»Size of Windows key:
(*Default-450 *No AppInit-398 *fake(infected)-448,504,512...)
Size of HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Windows: 450
»»Checking for AppInit_DLLs (empty) value...
________________________________
!"AppInit_DLLs"=""!
Value Matches
________________________________
»»Comparing *saved* key with *original*...
REGDIFF 2.1 - Freeware written by Gerson Kurz (http://www.p-nand-q.com)
Comparing File #1 (Keys1\winkey.reg) with File #2 (HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows).
Value "AppInit_DLLs" in key "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows" is missing in file #1
»»Dumping Values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\DeviceNotSelectedTimeout SZ 15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\GDIProcessHandleQuota DWORD 00002710
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Spooler SZ yes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\swapdisk SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\TransmissionRetryTimeout SZ 90
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\USERProcessHandleQuota DWORD 00002710
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
DeviceNotSelectedTimeout = 15
GDIProcessHandleQuota = REG_DWORD 0x00002710
Spooler = yes
swapdisk =
TransmissionRetryTimeout = 90
USERProcessHandleQuota = REG_DWORD 0x00002710
AppInit_DLLs =
»»Security settings for 'Windows' key:
RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright (C) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!
Access Control List for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows:
(ID-NI) ALLOW Read VORDEFINIERT\Benutzer
(ID-IO) ALLOW Read VORDEFINIERT\Benutzer
(ID-NI) ALLOW Full access VORDEFINIERT\Administratoren
(ID-IO) ALLOW Full access VORDEFINIERT\Administratoren
(ID-NI) ALLOW Full access NT-AUTORITŽT\SYSTEM
(ID-IO) ALLOW Full access NT-AUTORITŽT\SYSTEM
(ID-NI) ALLOW Full access COMPUTERNAME\no name
(ID-IO) ALLOW Full access ERSTELLER-BESITZER
Effective permissions for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows:
Read VORDEFINIERT\Benutzer
Full access VORDEFINIERT\Administratoren
Full access NT-AUTORITŽT\SYSTEM
Full access COMPUTERNAME\no name
00001150:
00001190: vk } DeviceNotSelecte
000011D0:dTimeout 1 5 0 vk ' z GDIProce
00001210:ssHandleQuota%} 9 0 } H$} vk P Spooler
00001250: y e s andl vk > swapdisk 0
00001290:` vk NoTransmissionRetryTimeout vk
000012D0: ' ceUSERProcessHandleQuota 0 `
00001310: vk AppInit_DLLsxB
00001350:
00001390:
000013D0:
00001410:
00001450:
00001490:
000014D0:
00001510:
00001550:
---------- NEWWIN.TXT
AppInit_DLLsxBØ
--------------
--------------
$011C0: DeviceNotSelectedTimeout
$01208: GDIProcessHandleQuota
$012AE: NoTransmissionRetryTimeout
$012DE: ceUSERProcessHandleQuota
$01330: AppInit_DLLsxB
--------------
--------------
OWS\SYSTEM32\DRIVERS\ARP1394.SYS
\DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\ASYNCMAC.SYS
\DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\ATAPI.SYS
\DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRI
--------------
--------------
d.... 0 Sep 22 16:57 .
d.... 0 Sep 22 16:57 ..
2 files found occupying -1024 bytes
===============================================================================
0 bytes 0 cps
Files: 0 Records: 0 Matches: 0 Elapsed Time: 00:00:00.06
VDIR v1.00
Path: C:\FINDNFIX\JUNKXXX\*.*
---------------------------------------+---------------------------------------
. <dir> 09-22-:4 16:57|.. <dir> 09-22-:4 16:57
---------------------------------------+---------------------------------------
2 files totaling 0 bytes consuming 0 bytes of disk space.
17299968 bytes available on Drive C: Volume label: VAIO
...File dump...
Detecting...
C:\FINDnFIX\junkxxx
Finished Detecting...
=========================================
0 C:\FINDnFIX\junkxxx (DIR Total)
Owner No. Files Total Size
=========================================
________________________________________________________________________________
***THE FIX IS NOT COMPATIBLE WITH EARLIER;UNPATCHED VERSIONS OF WIN2K'(SP3 and BELLOW)'
AND/OR LAX OF SECURITY UPDATES AND SERVICE PACKS FOR ALL PLATFORMS!
MINIMAL REQUIREMENTS INCLUDE:
_________XP HOME/PRO; SP1; IE6/SP1
_________2K/SP4; IE6/SP1
________________________________________________________________________________
»»»»»»»»*** www10.brinkster.com/expl0iter/freeatlast/FNF/ ***»»»»»»»
Wed 22 Sep 04 17:12:31
-----END-----