|  | 
| 
 | |||||||
| Plagegeister aller Art und deren Bekämpfung: Maus bewegt sich selbstständigWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. | 
|  10.05.2014, 20:18 | #1 | 
|  |   Maus bewegt sich selbstständig Hallo liebes Trojanerboard, seit heute hab ich gemerkt dass sich meine Maus manchmal selbstständig bewegt. Die letzten paar Tage hat mein Malwarebytes viele IPs geblockt. Viele davon wollten auch über einen geöffneten Port zugreifen. Ich hatten den 27015 geöffnet um einen Garry´s Mod Server laufen zu lassen. Erst seitdem wurden die IPs geblockt. EDIT: Die angehängten Dateien bitte nicht beachten wusste erst nicht wie man die Logs anders postet Hier die Logs von Malwarebytes: Code: 
  ATTFilter 2014/05/07 02:40:45 +0200    FRANZ-PC    (null)    MESSAGE    Starting protection
2014/05/07 02:40:45 +0200    FRANZ-PC    (null)    MESSAGE    Protection started successfully
2014/05/07 02:40:45 +0200    FRANZ-PC    (null)    MESSAGE    Starting IP protection
2014/05/07 02:40:47 +0200    FRANZ-PC    (null)    MESSAGE    IP Protection started successfully
2014/05/07 03:01:51 +0200    FRANZ-PC    Franz    MESSAGE    Starting protection
2014/05/07 03:01:51 +0200    FRANZ-PC    Franz    MESSAGE    Protection started successfully
2014/05/07 03:01:51 +0200    FRANZ-PC    Franz    MESSAGE    Starting IP protection
2014/05/07 03:01:53 +0200    FRANZ-PC    Franz    MESSAGE    IP Protection started successfully
2014/05/07 14:35:43 +0200    FRANZ-PC    Franz    MESSAGE    Starting protection
2014/05/07 14:35:43 +0200    FRANZ-PC    Franz    MESSAGE    Protection started successfully
2014/05/07 14:35:43 +0200    FRANZ-PC    Franz    MESSAGE    Starting IP protection
2014/05/07 14:35:45 +0200    FRANZ-PC    Franz    MESSAGE    IP Protection started successfully
2014/05/07 15:36:34 +0200    FRANZ-PC    Franz    MESSAGE    Executing scheduled update:  Daily
2014/05/07 15:36:45 +0200    FRANZ-PC    Franz    MESSAGE    Scheduled update executed successfully:  database updated from version v2014.05.06.05 to version v2014.05.07.03
2014/05/07 15:36:45 +0200    FRANZ-PC    Franz    MESSAGE    Starting database refresh
2014/05/07 15:36:45 +0200    FRANZ-PC    Franz    MESSAGE    Stopping IP protection
2014/05/07 15:36:45 +0200    FRANZ-PC    Franz    MESSAGE    IP Protection stopped successfully
2014/05/07 15:36:56 +0200    FRANZ-PC    Franz    MESSAGE    Database refreshed successfully
2014/05/07 15:36:56 +0200    FRANZ-PC    Franz    MESSAGE    Starting IP protection
2014/05/07 15:36:58 +0200    FRANZ-PC    Franz    MESSAGE    IP Protection started successfully
2014/05/07 15:42:50 +0200    FRANZ-PC    Franz    IP-BLOCK    84.22.98.59 (Type: outgoing, Port: 59280, Process: hl2.exe)
2014/05/07 15:42:58 +0200    FRANZ-PC    Franz    IP-BLOCK    217.23.11.160 (Type: outgoing, Port: 59280, Process: hl2.exe)
2014/05/07 15:43:07 +0200    FRANZ-PC    Franz    IP-BLOCK    46.246.94.108 (Type: outgoing, Port: 59280, Process: hl2.exe)
2014/05/07 15:43:15 +0200    FRANZ-PC    Franz    IP-BLOCK    195.88.209.185 (Type: outgoing, Port: 59280, Process: hl2.exe)
2014/05/07 15:43:23 +0200    FRANZ-PC    Franz    IP-BLOCK    46.254.16.63 (Type: outgoing, Port: 59280, Process: hl2.exe)
2014/05/07 15:43:31 +0200    FRANZ-PC    Franz    IP-BLOCK    66.150.155.74 (Type: outgoing, Port: 59280, Process: hl2.exe)
2014/05/07 16:30:42 +0200    FRANZ-PC    Franz    IP-BLOCK    84.22.98.59 (Type: outgoing, Port: 60159, Process: hl2.exe)
2014/05/07 16:30:42 +0200    FRANZ-PC    Franz    IP-BLOCK    217.23.11.160 (Type: outgoing, Port: 60159, Process: hl2.exe)
2014/05/07 16:30:42 +0200    FRANZ-PC    Franz    IP-BLOCK    217.23.11.160 (Type: outgoing, Port: 60159, Process: hl2.exe)
2014/05/07 16:30:50 +0200    FRANZ-PC    Franz    IP-BLOCK    109.107.83.154 (Type: outgoing, Port: 60159, Process: hl2.exe)
2014/05/07 16:30:50 +0200    FRANZ-PC    Franz    IP-BLOCK    46.246.94.108 (Type: outgoing, Port: 60159, Process: hl2.exe)
2014/05/07 16:30:58 +0200    FRANZ-PC    Franz    IP-BLOCK    195.88.209.185 (Type: outgoing, Port: 60159, Process: hl2.exe)
2014/05/07 16:31:14 +0200    FRANZ-PC    Franz    IP-BLOCK    46.254.16.63 (Type: outgoing, Port: 60159, Process: hl2.exe)
2014/05/07 16:31:14 +0200    FRANZ-PC    Franz    IP-BLOCK    66.150.155.74 (Type: outgoing, Port: 60159, Process: hl2.exe)
2014/05/07 16:54:09 +0200    FRANZ-PC    Franz    IP-BLOCK    91.188.46.86 (Type: incoming, Port: 27015, Process: hl2.exe)
2014/05/07 17:16:56 +0200    FRANZ-PC    Franz    IP-BLOCK    89.28.116.21 (Type: incoming, Port: 27015, Process: hl2.exe)
2014/05/07 18:37:07 +0200    FRANZ-PC    Franz    IP-BLOCK    89.28.75.123 (Type: incoming, Port: 27015, Process: hl2.exe)
2014/05/07 18:51:10 +0200    FRANZ-PC    Franz    IP-BLOCK    89.28.84.229 (Type: incoming, Port: 27015, Process: hl2.exe)
2014/05/07 21:00:46 +0200    FRANZ-PC    Franz    IP-BLOCK    79.135.143.62 (Type: incoming, Port: 27015, Process: hl2.exe)
         Code: 
  ATTFilter 2014/05/08 06:04:00 +0200    FRANZ-PC    Franz    MESSAGE    Starting protection
2014/05/08 06:04:00 +0200    FRANZ-PC    Franz    MESSAGE    Protection started successfully
2014/05/08 06:04:00 +0200    FRANZ-PC    Franz    MESSAGE    Starting IP protection
2014/05/08 06:04:02 +0200    FRANZ-PC    Franz    MESSAGE    IP Protection started successfully
2014/05/08 14:19:10 +0200    FRANZ-PC    Franz    MESSAGE    Starting protection
2014/05/08 14:19:10 +0200    FRANZ-PC    Franz    MESSAGE    Protection started successfully
2014/05/08 14:19:10 +0200    FRANZ-PC    Franz    MESSAGE    Starting IP protection
2014/05/08 14:19:13 +0200    FRANZ-PC    Franz    MESSAGE    IP Protection started successfully
2014/05/08 15:33:17 +0200    FRANZ-PC    Franz    MESSAGE    Executing scheduled update:  Daily
2014/05/08 15:33:27 +0200    FRANZ-PC    Franz    MESSAGE    Scheduled update executed successfully:  database updated from version v2014.05.07.03 to version v2014.05.08.05
2014/05/08 15:33:27 +0200    FRANZ-PC    Franz    MESSAGE    Starting database refresh
2014/05/08 15:33:27 +0200    FRANZ-PC    Franz    MESSAGE    Stopping IP protection
2014/05/08 15:33:27 +0200    FRANZ-PC    Franz    MESSAGE    IP Protection stopped successfully
2014/05/08 15:33:30 +0200    FRANZ-PC    Franz    MESSAGE    Database refreshed successfully
2014/05/08 15:33:30 +0200    FRANZ-PC    Franz    MESSAGE    Starting IP protection
2014/05/08 15:33:31 +0200    FRANZ-PC    Franz    MESSAGE    IP Protection started successfully
2014/05/08 18:37:29 +0200    FRANZ-PC    Franz    IP-BLOCK    89.28.123.153 (Type: incoming, Port: 27015, Process: hl2.exe)
2014/05/08 18:37:29 +0200    FRANZ-PC    Franz    IP-BLOCK    89.28.123.153 (Type: incoming, Port: 27015, Process: svchost.exe)
2014/05/08 18:37:29 +0200    FRANZ-PC    Franz    IP-BLOCK    89.28.123.153 (Type: incoming, Port: 27015, Process: svchost.exe)
2014/05/08 18:37:53 +0200    FRANZ-PC    Franz    IP-BLOCK    89.28.116.21 (Type: incoming, Port: 27015, Process: hl2.exe)
2014/05/08 18:37:53 +0200    FRANZ-PC    Franz    IP-BLOCK    89.28.116.21 (Type: incoming, Port: 27015, Process: svchost.exe)
2014/05/08 18:37:53 +0200    FRANZ-PC    Franz    IP-BLOCK    89.28.116.21 (Type: incoming, Port: 27015, Process: svchost.exe)
2014/05/08 18:53:58 +0200    FRANZ-PC    Franz    IP-BLOCK    93.170.147.243 (Type: incoming, Port: 27015, Process: hl2.exe)
2014/05/08 18:53:58 +0200    FRANZ-PC    Franz    IP-BLOCK    93.170.147.243 (Type: incoming, Port: 27015, Process: svchost.exe)
2014/05/08 19:17:00 +0200    FRANZ-PC    Franz    IP-BLOCK    89.28.123.153 (Type: incoming, Port: 27015, Process: hl2.exe)
2014/05/08 19:17:00 +0200    FRANZ-PC    Franz    IP-BLOCK    89.28.123.153 (Type: incoming, Port: 27015, Process: svchost.exe)
2014/05/08 19:19:16 +0200    FRANZ-PC    Franz    IP-BLOCK    89.28.123.153 (Type: incoming, Port: 27015, Process: hl2.exe)
2014/05/08 19:19:16 +0200    FRANZ-PC    Franz    IP-BLOCK    89.28.123.153 (Type: incoming, Port: 27015, Process: svchost.exe)
2014/05/08 19:19:16 +0200    FRANZ-PC    Franz    IP-BLOCK    89.28.123.153 (Type: incoming, Port: 27015, Process: svchost.exe)
2014/05/08 20:36:20 +0200    FRANZ-PC    Franz    IP-BLOCK    91.188.46.86 (Type: incoming, Port: 27015, Process: hl2.exe)
2014/05/08 20:36:20 +0200    FRANZ-PC    Franz    IP-BLOCK    91.188.46.86 (Type: incoming, Port: 27015, Process: svchost.exe)
2014/05/08 20:55:37 +0200    FRANZ-PC    Franz    IP-BLOCK    89.28.116.21 (Type: incoming, Port: 27015, Process: hl2.exe)
2014/05/08 20:55:37 +0200    FRANZ-PC    Franz    IP-BLOCK    89.28.116.21 (Type: incoming, Port: 27015, Process: svchost.exe)
         Code: 
  ATTFilter 2014/05/09 06:10:49 +0200    FRANZ-PC    Franz    MESSAGE    Starting protection
2014/05/09 06:10:49 +0200    FRANZ-PC    Franz    MESSAGE    Protection started successfully
2014/05/09 06:10:49 +0200    FRANZ-PC    Franz    MESSAGE    Starting IP protection
2014/05/09 06:10:51 +0200    FRANZ-PC    Franz    MESSAGE    IP Protection started successfully
2014/05/09 13:08:12 +0200    FRANZ-PC    (null)    MESSAGE    Starting protection
2014/05/09 13:08:12 +0200    FRANZ-PC    (null)    MESSAGE    Protection started successfully
2014/05/09 13:08:12 +0200    FRANZ-PC    (null)    MESSAGE    Starting IP protection
2014/05/09 13:08:15 +0200    FRANZ-PC    (null)    MESSAGE    IP Protection started successfully
2014/05/09 14:13:15 +0200    FRANZ-PC    Franz    IP-BLOCK    84.22.98.59 (Type: outgoing, Port: 58066, Process: hl2.exe)
2014/05/09 14:13:15 +0200    FRANZ-PC    Franz    IP-BLOCK    217.23.11.160 (Type: outgoing, Port: 58066, Process: hl2.exe)
2014/05/09 14:13:15 +0200    FRANZ-PC    Franz    IP-BLOCK    217.23.11.160 (Type: outgoing, Port: 58066, Process: hl2.exe)
2014/05/09 14:13:23 +0200    FRANZ-PC    Franz    IP-BLOCK    46.246.94.108 (Type: outgoing, Port: 58066, Process: hl2.exe)
2014/05/09 14:13:40 +0200    FRANZ-PC    Franz    IP-BLOCK    195.88.209.185 (Type: outgoing, Port: 58066, Process: hl2.exe)
2014/05/09 14:13:56 +0200    FRANZ-PC    Franz    IP-BLOCK    46.254.16.63 (Type: outgoing, Port: 58066, Process: hl2.exe)
2014/05/09 14:13:56 +0200    FRANZ-PC    Franz    IP-BLOCK    66.150.155.74 (Type: outgoing, Port: 58066, Process: hl2.exe)
2014/05/09 15:00:29 +0200    FRANZ-PC    Franz    IP-BLOCK    84.22.98.59 (Type: outgoing, Port: 63085, Process: hl2.exe)
2014/05/09 15:00:29 +0200    FRANZ-PC    Franz    IP-BLOCK    217.23.11.160 (Type: outgoing, Port: 63085, Process: hl2.exe)
2014/05/09 15:00:29 +0200    FRANZ-PC    Franz    IP-BLOCK    217.23.11.160 (Type: outgoing, Port: 63085, Process: hl2.exe)
2014/05/09 15:00:46 +0200    FRANZ-PC    Franz    IP-BLOCK    46.246.94.108 (Type: outgoing, Port: 63085, Process: hl2.exe)
2014/05/09 15:00:54 +0200    FRANZ-PC    Franz    IP-BLOCK    195.88.209.185 (Type: outgoing, Port: 63085, Process: hl2.exe)
2014/05/09 15:01:10 +0200    FRANZ-PC    Franz    IP-BLOCK    46.254.16.63 (Type: outgoing, Port: 63085, Process: hl2.exe)
2014/05/09 15:01:18 +0200    FRANZ-PC    Franz    IP-BLOCK    66.150.155.74 (Type: outgoing, Port: 63085, Process: hl2.exe)
2014/05/09 15:16:41 +0200    FRANZ-PC    Franz    MESSAGE    Executing scheduled update:  Daily
2014/05/09 15:16:53 +0200    FRANZ-PC    Franz    MESSAGE    Scheduled update executed successfully:  database updated from version v2014.05.08.05 to version v2014.05.09.06
2014/05/09 15:16:53 +0200    FRANZ-PC    Franz    MESSAGE    Starting database refresh
2014/05/09 15:16:53 +0200    FRANZ-PC    Franz    MESSAGE    Stopping IP protection
2014/05/09 15:16:53 +0200    FRANZ-PC    Franz    MESSAGE    IP Protection stopped successfully
2014/05/09 15:16:57 +0200    FRANZ-PC    Franz    MESSAGE    Database refreshed successfully
2014/05/09 15:16:57 +0200    FRANZ-PC    Franz    MESSAGE    Starting IP protection
2014/05/09 15:16:59 +0200    FRANZ-PC    Franz    MESSAGE    IP Protection started successfully
          | 
| Themen zu Maus bewegt sich selbstständig | 
| .exe, bewegt, gemerkt, geöffnete, ip-block, malwarebytes, message, port, process, seitdem, selbstständig, server, svchost.exe, troja, trojanerboard, update, updated, version, win32/downloadsponsor.a, win32/installmonetizer.aq, win32/toolbar.conduit, zugreife |