![]() |
|
Plagegeister aller Art und deren Bekämpfung: Maus bewegt sich selbstständigWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #1 |
| ![]() Maus bewegt sich selbstständig Hallo liebes Trojanerboard, seit heute hab ich gemerkt dass sich meine Maus manchmal selbstständig bewegt. Die letzten paar Tage hat mein Malwarebytes viele IPs geblockt. Viele davon wollten auch über einen geöffneten Port zugreifen. Ich hatten den 27015 geöffnet um einen Garry´s Mod Server laufen zu lassen. Erst seitdem wurden die IPs geblockt. EDIT: Die angehängten Dateien bitte nicht beachten wusste erst nicht wie man die Logs anders postet Hier die Logs von Malwarebytes: Code:
ATTFilter 2014/05/07 02:40:45 +0200 FRANZ-PC (null) MESSAGE Starting protection 2014/05/07 02:40:45 +0200 FRANZ-PC (null) MESSAGE Protection started successfully 2014/05/07 02:40:45 +0200 FRANZ-PC (null) MESSAGE Starting IP protection 2014/05/07 02:40:47 +0200 FRANZ-PC (null) MESSAGE IP Protection started successfully 2014/05/07 03:01:51 +0200 FRANZ-PC Franz MESSAGE Starting protection 2014/05/07 03:01:51 +0200 FRANZ-PC Franz MESSAGE Protection started successfully 2014/05/07 03:01:51 +0200 FRANZ-PC Franz MESSAGE Starting IP protection 2014/05/07 03:01:53 +0200 FRANZ-PC Franz MESSAGE IP Protection started successfully 2014/05/07 14:35:43 +0200 FRANZ-PC Franz MESSAGE Starting protection 2014/05/07 14:35:43 +0200 FRANZ-PC Franz MESSAGE Protection started successfully 2014/05/07 14:35:43 +0200 FRANZ-PC Franz MESSAGE Starting IP protection 2014/05/07 14:35:45 +0200 FRANZ-PC Franz MESSAGE IP Protection started successfully 2014/05/07 15:36:34 +0200 FRANZ-PC Franz MESSAGE Executing scheduled update: Daily 2014/05/07 15:36:45 +0200 FRANZ-PC Franz MESSAGE Scheduled update executed successfully: database updated from version v2014.05.06.05 to version v2014.05.07.03 2014/05/07 15:36:45 +0200 FRANZ-PC Franz MESSAGE Starting database refresh 2014/05/07 15:36:45 +0200 FRANZ-PC Franz MESSAGE Stopping IP protection 2014/05/07 15:36:45 +0200 FRANZ-PC Franz MESSAGE IP Protection stopped successfully 2014/05/07 15:36:56 +0200 FRANZ-PC Franz MESSAGE Database refreshed successfully 2014/05/07 15:36:56 +0200 FRANZ-PC Franz MESSAGE Starting IP protection 2014/05/07 15:36:58 +0200 FRANZ-PC Franz MESSAGE IP Protection started successfully 2014/05/07 15:42:50 +0200 FRANZ-PC Franz IP-BLOCK 84.22.98.59 (Type: outgoing, Port: 59280, Process: hl2.exe) 2014/05/07 15:42:58 +0200 FRANZ-PC Franz IP-BLOCK 217.23.11.160 (Type: outgoing, Port: 59280, Process: hl2.exe) 2014/05/07 15:43:07 +0200 FRANZ-PC Franz IP-BLOCK 46.246.94.108 (Type: outgoing, Port: 59280, Process: hl2.exe) 2014/05/07 15:43:15 +0200 FRANZ-PC Franz IP-BLOCK 195.88.209.185 (Type: outgoing, Port: 59280, Process: hl2.exe) 2014/05/07 15:43:23 +0200 FRANZ-PC Franz IP-BLOCK 46.254.16.63 (Type: outgoing, Port: 59280, Process: hl2.exe) 2014/05/07 15:43:31 +0200 FRANZ-PC Franz IP-BLOCK 66.150.155.74 (Type: outgoing, Port: 59280, Process: hl2.exe) 2014/05/07 16:30:42 +0200 FRANZ-PC Franz IP-BLOCK 84.22.98.59 (Type: outgoing, Port: 60159, Process: hl2.exe) 2014/05/07 16:30:42 +0200 FRANZ-PC Franz IP-BLOCK 217.23.11.160 (Type: outgoing, Port: 60159, Process: hl2.exe) 2014/05/07 16:30:42 +0200 FRANZ-PC Franz IP-BLOCK 217.23.11.160 (Type: outgoing, Port: 60159, Process: hl2.exe) 2014/05/07 16:30:50 +0200 FRANZ-PC Franz IP-BLOCK 109.107.83.154 (Type: outgoing, Port: 60159, Process: hl2.exe) 2014/05/07 16:30:50 +0200 FRANZ-PC Franz IP-BLOCK 46.246.94.108 (Type: outgoing, Port: 60159, Process: hl2.exe) 2014/05/07 16:30:58 +0200 FRANZ-PC Franz IP-BLOCK 195.88.209.185 (Type: outgoing, Port: 60159, Process: hl2.exe) 2014/05/07 16:31:14 +0200 FRANZ-PC Franz IP-BLOCK 46.254.16.63 (Type: outgoing, Port: 60159, Process: hl2.exe) 2014/05/07 16:31:14 +0200 FRANZ-PC Franz IP-BLOCK 66.150.155.74 (Type: outgoing, Port: 60159, Process: hl2.exe) 2014/05/07 16:54:09 +0200 FRANZ-PC Franz IP-BLOCK 91.188.46.86 (Type: incoming, Port: 27015, Process: hl2.exe) 2014/05/07 17:16:56 +0200 FRANZ-PC Franz IP-BLOCK 89.28.116.21 (Type: incoming, Port: 27015, Process: hl2.exe) 2014/05/07 18:37:07 +0200 FRANZ-PC Franz IP-BLOCK 89.28.75.123 (Type: incoming, Port: 27015, Process: hl2.exe) 2014/05/07 18:51:10 +0200 FRANZ-PC Franz IP-BLOCK 89.28.84.229 (Type: incoming, Port: 27015, Process: hl2.exe) 2014/05/07 21:00:46 +0200 FRANZ-PC Franz IP-BLOCK 79.135.143.62 (Type: incoming, Port: 27015, Process: hl2.exe) Code:
ATTFilter 2014/05/08 06:04:00 +0200 FRANZ-PC Franz MESSAGE Starting protection 2014/05/08 06:04:00 +0200 FRANZ-PC Franz MESSAGE Protection started successfully 2014/05/08 06:04:00 +0200 FRANZ-PC Franz MESSAGE Starting IP protection 2014/05/08 06:04:02 +0200 FRANZ-PC Franz MESSAGE IP Protection started successfully 2014/05/08 14:19:10 +0200 FRANZ-PC Franz MESSAGE Starting protection 2014/05/08 14:19:10 +0200 FRANZ-PC Franz MESSAGE Protection started successfully 2014/05/08 14:19:10 +0200 FRANZ-PC Franz MESSAGE Starting IP protection 2014/05/08 14:19:13 +0200 FRANZ-PC Franz MESSAGE IP Protection started successfully 2014/05/08 15:33:17 +0200 FRANZ-PC Franz MESSAGE Executing scheduled update: Daily 2014/05/08 15:33:27 +0200 FRANZ-PC Franz MESSAGE Scheduled update executed successfully: database updated from version v2014.05.07.03 to version v2014.05.08.05 2014/05/08 15:33:27 +0200 FRANZ-PC Franz MESSAGE Starting database refresh 2014/05/08 15:33:27 +0200 FRANZ-PC Franz MESSAGE Stopping IP protection 2014/05/08 15:33:27 +0200 FRANZ-PC Franz MESSAGE IP Protection stopped successfully 2014/05/08 15:33:30 +0200 FRANZ-PC Franz MESSAGE Database refreshed successfully 2014/05/08 15:33:30 +0200 FRANZ-PC Franz MESSAGE Starting IP protection 2014/05/08 15:33:31 +0200 FRANZ-PC Franz MESSAGE IP Protection started successfully 2014/05/08 18:37:29 +0200 FRANZ-PC Franz IP-BLOCK 89.28.123.153 (Type: incoming, Port: 27015, Process: hl2.exe) 2014/05/08 18:37:29 +0200 FRANZ-PC Franz IP-BLOCK 89.28.123.153 (Type: incoming, Port: 27015, Process: svchost.exe) 2014/05/08 18:37:29 +0200 FRANZ-PC Franz IP-BLOCK 89.28.123.153 (Type: incoming, Port: 27015, Process: svchost.exe) 2014/05/08 18:37:53 +0200 FRANZ-PC Franz IP-BLOCK 89.28.116.21 (Type: incoming, Port: 27015, Process: hl2.exe) 2014/05/08 18:37:53 +0200 FRANZ-PC Franz IP-BLOCK 89.28.116.21 (Type: incoming, Port: 27015, Process: svchost.exe) 2014/05/08 18:37:53 +0200 FRANZ-PC Franz IP-BLOCK 89.28.116.21 (Type: incoming, Port: 27015, Process: svchost.exe) 2014/05/08 18:53:58 +0200 FRANZ-PC Franz IP-BLOCK 93.170.147.243 (Type: incoming, Port: 27015, Process: hl2.exe) 2014/05/08 18:53:58 +0200 FRANZ-PC Franz IP-BLOCK 93.170.147.243 (Type: incoming, Port: 27015, Process: svchost.exe) 2014/05/08 19:17:00 +0200 FRANZ-PC Franz IP-BLOCK 89.28.123.153 (Type: incoming, Port: 27015, Process: hl2.exe) 2014/05/08 19:17:00 +0200 FRANZ-PC Franz IP-BLOCK 89.28.123.153 (Type: incoming, Port: 27015, Process: svchost.exe) 2014/05/08 19:19:16 +0200 FRANZ-PC Franz IP-BLOCK 89.28.123.153 (Type: incoming, Port: 27015, Process: hl2.exe) 2014/05/08 19:19:16 +0200 FRANZ-PC Franz IP-BLOCK 89.28.123.153 (Type: incoming, Port: 27015, Process: svchost.exe) 2014/05/08 19:19:16 +0200 FRANZ-PC Franz IP-BLOCK 89.28.123.153 (Type: incoming, Port: 27015, Process: svchost.exe) 2014/05/08 20:36:20 +0200 FRANZ-PC Franz IP-BLOCK 91.188.46.86 (Type: incoming, Port: 27015, Process: hl2.exe) 2014/05/08 20:36:20 +0200 FRANZ-PC Franz IP-BLOCK 91.188.46.86 (Type: incoming, Port: 27015, Process: svchost.exe) 2014/05/08 20:55:37 +0200 FRANZ-PC Franz IP-BLOCK 89.28.116.21 (Type: incoming, Port: 27015, Process: hl2.exe) 2014/05/08 20:55:37 +0200 FRANZ-PC Franz IP-BLOCK 89.28.116.21 (Type: incoming, Port: 27015, Process: svchost.exe) Code:
ATTFilter 2014/05/09 06:10:49 +0200 FRANZ-PC Franz MESSAGE Starting protection 2014/05/09 06:10:49 +0200 FRANZ-PC Franz MESSAGE Protection started successfully 2014/05/09 06:10:49 +0200 FRANZ-PC Franz MESSAGE Starting IP protection 2014/05/09 06:10:51 +0200 FRANZ-PC Franz MESSAGE IP Protection started successfully 2014/05/09 13:08:12 +0200 FRANZ-PC (null) MESSAGE Starting protection 2014/05/09 13:08:12 +0200 FRANZ-PC (null) MESSAGE Protection started successfully 2014/05/09 13:08:12 +0200 FRANZ-PC (null) MESSAGE Starting IP protection 2014/05/09 13:08:15 +0200 FRANZ-PC (null) MESSAGE IP Protection started successfully 2014/05/09 14:13:15 +0200 FRANZ-PC Franz IP-BLOCK 84.22.98.59 (Type: outgoing, Port: 58066, Process: hl2.exe) 2014/05/09 14:13:15 +0200 FRANZ-PC Franz IP-BLOCK 217.23.11.160 (Type: outgoing, Port: 58066, Process: hl2.exe) 2014/05/09 14:13:15 +0200 FRANZ-PC Franz IP-BLOCK 217.23.11.160 (Type: outgoing, Port: 58066, Process: hl2.exe) 2014/05/09 14:13:23 +0200 FRANZ-PC Franz IP-BLOCK 46.246.94.108 (Type: outgoing, Port: 58066, Process: hl2.exe) 2014/05/09 14:13:40 +0200 FRANZ-PC Franz IP-BLOCK 195.88.209.185 (Type: outgoing, Port: 58066, Process: hl2.exe) 2014/05/09 14:13:56 +0200 FRANZ-PC Franz IP-BLOCK 46.254.16.63 (Type: outgoing, Port: 58066, Process: hl2.exe) 2014/05/09 14:13:56 +0200 FRANZ-PC Franz IP-BLOCK 66.150.155.74 (Type: outgoing, Port: 58066, Process: hl2.exe) 2014/05/09 15:00:29 +0200 FRANZ-PC Franz IP-BLOCK 84.22.98.59 (Type: outgoing, Port: 63085, Process: hl2.exe) 2014/05/09 15:00:29 +0200 FRANZ-PC Franz IP-BLOCK 217.23.11.160 (Type: outgoing, Port: 63085, Process: hl2.exe) 2014/05/09 15:00:29 +0200 FRANZ-PC Franz IP-BLOCK 217.23.11.160 (Type: outgoing, Port: 63085, Process: hl2.exe) 2014/05/09 15:00:46 +0200 FRANZ-PC Franz IP-BLOCK 46.246.94.108 (Type: outgoing, Port: 63085, Process: hl2.exe) 2014/05/09 15:00:54 +0200 FRANZ-PC Franz IP-BLOCK 195.88.209.185 (Type: outgoing, Port: 63085, Process: hl2.exe) 2014/05/09 15:01:10 +0200 FRANZ-PC Franz IP-BLOCK 46.254.16.63 (Type: outgoing, Port: 63085, Process: hl2.exe) 2014/05/09 15:01:18 +0200 FRANZ-PC Franz IP-BLOCK 66.150.155.74 (Type: outgoing, Port: 63085, Process: hl2.exe) 2014/05/09 15:16:41 +0200 FRANZ-PC Franz MESSAGE Executing scheduled update: Daily 2014/05/09 15:16:53 +0200 FRANZ-PC Franz MESSAGE Scheduled update executed successfully: database updated from version v2014.05.08.05 to version v2014.05.09.06 2014/05/09 15:16:53 +0200 FRANZ-PC Franz MESSAGE Starting database refresh 2014/05/09 15:16:53 +0200 FRANZ-PC Franz MESSAGE Stopping IP protection 2014/05/09 15:16:53 +0200 FRANZ-PC Franz MESSAGE IP Protection stopped successfully 2014/05/09 15:16:57 +0200 FRANZ-PC Franz MESSAGE Database refreshed successfully 2014/05/09 15:16:57 +0200 FRANZ-PC Franz MESSAGE Starting IP protection 2014/05/09 15:16:59 +0200 FRANZ-PC Franz MESSAGE IP Protection started successfully |
Themen zu Maus bewegt sich selbstständig |
.exe, bewegt, gemerkt, geöffnete, ip-block, malwarebytes, message, port, process, seitdem, selbstständig, server, svchost.exe, troja, trojanerboard, update, updated, version, win32/downloadsponsor.a, win32/installmonetizer.aq, win32/toolbar.conduit, zugreife |