Verdacht auf Trojaner    Hallo zusammen,  
gestern habe ich ein Windows SP3 update ducrhgeführt. Die Installation war soweit erfolgreich bis auf folgendes: spybot meldete sowohl gestern (vorm reboot) als auch heute noch (nach dem neustart, welcher viel länger dauerte als sonst)jedoch 3 oder 4 Änderungen in der registry-Einträgen. Leider weiß ich nur noch die letzten beiden Bezeichnungen von heute: "cscript%systemroot%\Installer\TSCLientMsiTrans\tscdsl.bat" und  
"cscript %systemroot%\Installer\ TSClientMsiTrans\tscuinst.vbs" 
 Da ich angenommen habe, dies hänge mit dem Update zusammen habe ich "erlauben" geklickt. Nun bin ich jedoch ins zweifeln gekommen, ob dies der richtige Schritt war oder sich doch ein Trojaner bei mir eingeschlcihen hat!!  
Anbei hab ich den hijackthis logFile... 
Kann mir jmd sagen ob anhand dieses logs ein Trojaner ausgeschlossen ist oder was ich tun muss, falls es denn überhaupt ein Trojaner ist! 
(ich weiß nicht ob das wichtig ist, aber als inet browser nutze ich stets den firefox)  
Vielen Dank      Code:  
 Logfile of Trend Micro HijackThis v2.0.2 
Scan saved at 14:28:35, on 04.10.2008 
Platform: Windows XP SP3 (WinNT 5.01.2600) 
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512) 
Boot mode: Normal   
Running processes: 
C:\WINDOWS\System32\smss.exe 
C:\WINDOWS\system32\winlogon.exe 
C:\WINDOWS\system32\services.exe 
C:\WINDOWS\system32\lsass.exe 
C:\WINDOWS\system32\ibmpmsvc.exe 
C:\WINDOWS\system32\Ati2evxx.exe 
C:\WINDOWS\system32\svchost.exe 
C:\WINDOWS\System32\svchost.exe 
C:\Programme\Intel\Wireless\Bin\EvtEng.exe 
C:\Programme\Intel\Wireless\Bin\S24EvMon.exe 
C:\WINDOWS\system32\spoolsv.exe 
C:\Programme\Avira\AntiVir PersonalEdition Classic\avguard.exe 
C:\WINDOWS\system32\Ati2evxx.exe 
C:\WINDOWS\system32\IPSSVC.EXE 
C:\Programme\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe 
C:\Programme\Avira\AntiVir PersonalEdition Classic\sched.exe 
C:\Programme\ThinkPad\Bluetooth Software\bin\btwdins.exe 
C:\Programme\Diskeeper Corporation\Diskeeper\DkService.exe 
C:\Programme\Intel\Wireless\Bin\RegSrvc.exe 
C:\WINDOWS\system32\svchost.exe 
c:\programme\lenovo\system update\suservice.exe 
C:\Programme\Gemeinsame Dateien\Lenovo\tvt_reg_monitor_svc.exe 
C:\WINDOWS\System32\TPHDEXLG.EXE 
C:\WINDOWS\system32\TpKmpSVC.exe 
C:\Programme\Lenovo\Rescue and Recovery\rrservice.exe 
C:\Programme\Gemeinsame Dateien\Lenovo\Scheduler\tvtsched.exe 
C:\Programme\Lenovo\Rescue and Recovery\ADM\IUService.exe 
C:\Programme\Gemeinsame Dateien\Lenovo\Logger\logmon.exe 
C:\Programme\ThinkPad\ConnectUtilities\AcSvc.exe 
C:\WINDOWS\system32\wbem\wmiapsrv.exe 
C:\Programme\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe 
C:\WINDOWS\Explorer.EXE 
C:\Programme\Intel\Wireless\Bin\Dot1XCfg.exe 
C:\WINDOWS\system32\rundll32.exe 
C:\Programme\Synaptics\SynTP\SynTPLpr.exe 
C:\Programme\Synaptics\SynTP\SynTPEnh.exe 
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe 
C:\WINDOWS\system32\TpShocks.exe 
C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe 
C:\Programme\Analog Devices\Core\smax4pnp.exe 
C:\Programme\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe 
C:\Programme\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe 
C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe 
C:\Programme\Java\jre1.6.0_05\bin\jusched.exe 
C:\Programme\ATI Technologies\ATI.ACE\CLI.EXE 
C:\Programme\ThinkVantage\AMSG\Amsg.exe 
C:\WINDOWS\System32\DLA\DLACTRLW.EXE 
C:\Programme\Gemeinsame Dateien\InstallShield\UpdateService\issch.exe 
C:\Programme\Lenovo\AwayTask\AwaySch.EXE 
C:\Programme\Gemeinsame Dateien\Lenovo\Scheduler\scheduler_proxy.exe 
C:\Programme\ThinkPad\ConnectUtilities\ACTray.exe 
C:\Programme\ThinkPad\ConnectUtilities\ACWLIcon.exe 
C:\Programme\Picasa2\PicasaMediaDetector.exe 
C:\Programme\Lenovo\SafeGuard PrivateDisk\pdservice.exe 
C:\Programme\Lenovo\Client Security Solution\cssauth.exe 
C:\Programme\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe 
C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe 
C:\Programme\DAEMON Tools\daemon.exe 
C:\Programme\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe 
C:\WINDOWS\system32\ctfmon.exe 
C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe 
C:\Programme\Messenger\msmsgs.exe 
C:\Programme\Spybot - Search & Destroy\TeaTimer.exe 
c:\programme\avira\antivir personaledition classic\avcenter.exe 
C:\Programme\ThinkPad\Bluetooth Software\BTTray.exe 
C:\Program Files\Digital Line Detect\DLG.exe 
C:\Programme\Avira\AntiVir PersonalEdition Classic\avscan.exe 
C:\Programme\ATI Technologies\ATI.ACE\cli.exe 
C:\Programme\Mozilla Firefox\firefox.exe 
C:\Programme\Gemeinsame Dateien\Teleca Shared\Generic.exe 
C:\Programme\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe 
C:\Programme\Diskeeper Corporation\Diskeeper\DkIcon.exe 
C:\Programme\Java\jre1.6.0_05\bin\jucheck.exe 
C:\Dokumente und Einstellungen\Anwender\Eigene Dateien\HiJackThis.exe   
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =  
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.lenovo.com/welcome/thinkpad 
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=10.0.0.193:3128; 
O2 - BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll 
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll 
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL 
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.6.0_05\bin\ssv.dll 
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programme\google\googletoolbar2.dll 
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programme\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll 
O2 - BHO: ThinkVantage Password Manager - {F040E541-A427-4CF7-85D8-75E3E0F476C5} - C:\Programme\Lenovo\Client Security Solution\tvtpwm_ie_com.dll 
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programme\google\googletoolbar2.dll 
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor 
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog 
O4 - HKLM\..\Run: [SynTPLpr] C:\Programme\Synaptics\SynTP\SynTPLpr.exe 
O4 - HKLM\..\Run: [SynTPEnh] C:\Programme\Synaptics\SynTP\SynTPEnh.exe 
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe 
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Programme\ThinkPad\Utilities\TpKmapAp.exe -helper 
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe 
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe 
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe 
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Programme\Analog Devices\Core\smax4pnp.exe 
O4 - HKLM\..\Run: [SoundMAX] C:\Programme\Analog Devices\SoundMAX\Smax4.exe /tray 
O4 - HKLM\..\Run: [ATICCC] "C:\Programme\ATI Technologies\ATI.ACE\CLIStart.exe" 
O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe 
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programme\Java\jre1.6.0_05\bin\jusched.exe" 
O4 - HKLM\..\Run: [AMSG] C:\Programme\ThinkVantage\AMSG\Amsg.exe 
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE 
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\GEMEIN~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup 
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Programme\Gemeinsame Dateien\InstallShield\UpdateService\issch.exe" -start 
O4 - HKLM\..\Run: [AwaySch] C:\Programme\Lenovo\AwayTask\AwaySch.EXE 
O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Programme\Gemeinsame Dateien\Lenovo\Scheduler\scheduler_proxy.exe 
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Programme\Diskeeper Corporation\Diskeeper\DkIcon.exe" 
O4 - HKLM\..\Run: [ACTray] C:\Programme\ThinkPad\ConnectUtilities\ACTray.exe 
O4 - HKLM\..\Run: [ACWLIcon] C:\Programme\ThinkPad\ConnectUtilities\ACWLIcon.exe 
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Programme\Picasa2\PicasaMediaDetector.exe 
O4 - HKLM\..\Run: [PDService.exe] "C:\Programme\Lenovo\SafeGuard PrivateDisk\pdservice.exe" 
O4 - HKLM\..\Run: [cssauth] "C:\Programme\Lenovo\Client Security Solution\cssauth.exe" silent 
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programme\Adobe\Reader 8.0\Reader\Reader_sl.exe" 
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Programme\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" 
O4 - HKLM\..\Run: [avgnt] "C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min 
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Programme\DAEMON Tools\daemon.exe" -lang 1033 
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Programme\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions 
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe 
O4 - HKCU\..\Run: [swg] C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe 
O4 - HKCU\..\Run: [MSMSGS] "C:\Programme\Messenger\msmsgs.exe" /background 
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Programme\DAEMON Tools\daemon.exe" -lang 1033 
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programme\Spybot - Search & Destroy\TeaTimer.exe 
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKALER DIENST') 
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETZWERKDIENST') 
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') 
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') 
O4 - Global Startup: BTTray.lnk = ? 
O4 - Global Startup: Digital Line Detect.lnk = ? 
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 
O8 - Extra context menu item: Senden an &Bluetooth-Gerät... - C:\Programme\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm 
O9 - Extra button: (no name) - {0045D4BC-5189-4b67-969C-83BB1906C421} - C:\Programme\Lenovo\Client Security Solution\tvtpwm_ie_com.dll 
O9 - Extra 'Tools' menuitem: ThinkVantage Password Manager... - {0045D4BC-5189-4b67-969C-83BB1906C421} - C:\Programme\Lenovo\Client Security Solution\tvtpwm_ie_com.dll 
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_05\bin\ssv.dll 
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_05\bin\ssv.dll 
O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL 
O9 - Extra button: System Update - {DA320635-F48C-4613-8325-D75A933C549E} - C:\Programme\Lenovo\System Update\sulauncher.exe 
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll 
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll 
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe 
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe 
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe 
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe 
O14 - IERESET.INF: START_PAGE_URL=http://www.lenovo.com/welcome/thinkpad 
O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing) 
O20 - Winlogon Notify: AwayNotify - C:\Programme\Lenovo\AwayTask\AwayNotify.dll 
O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Unknown owner - C:\Programme\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe 
O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Programme\ThinkPad\ConnectUtilities\AcSvc.exe 
O23 - Service: AntiVir PersonalEdition Classic Planer (AntiVirScheduler) - Avira GmbH - C:\Programme\Avira\AntiVir PersonalEdition Classic\sched.exe 
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Programme\Avira\AntiVir PersonalEdition Classic\avguard.exe 
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe 
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Programme\ThinkPad\Bluetooth Software\bin\btwdins.exe 
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Programme\Diskeeper Corporation\Diskeeper\DkService.exe 
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Programme\Intel\Wireless\Bin\EvtEng.exe 
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programme\Google\Common\Google Updater\GoogleUpdaterService.exe 
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe 
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe 
O23 - Service: IPS-Basisservice (IPSSVC) - Lenovo Group Limited - C:\WINDOWS\system32\IPSSVC.EXE 
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe 
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Programme\Intel\Wireless\Bin\RegSrvc.exe 
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Programme\Intel\Wireless\Bin\S24EvMon.exe 
O23 - Service: System Update (SUService) -   - c:\programme\lenovo\system update\suservice.exe 
O23 - Service: ThinkVantage Registry Monitor Service - Unknown owner - C:\Programme\Gemeinsame Dateien\Lenovo\tvt_reg_monitor_svc.exe 
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.EXE 
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe 
O23 - Service: TSS Core Service (TSSCoreService) - IBM - C:\Programme\Lenovo\Client Security Solution\tvttcsd.exe 
O23 - Service: TVT Backup Service - Lenovo Group Limited - C:\Programme\Lenovo\Rescue and Recovery\rrservice.exe 
O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Programme\Gemeinsame Dateien\Lenovo\Scheduler\tvtsched.exe 
O23 - Service: tvtnetwk - Unknown owner - C:\Programme\Lenovo\Rescue and Recovery\ADM\IUService.exe   -- 
End of file - 13342 bytes    |