View Full Version : Mouse gone bezerk! possible virus?
DevNull
February 20th, 2003, 03:38 PM
Help!
I am running windows 98se, and I am using an intellimouse 1.1a
I suppose this started a while back; but this is basically it.
Every sixth time I boot up windows; I get a registry error, and am taken to the registry repairer.
All is fixed, and I am allowed to return to windows.
All of the programs I have installed since no longer seem to work.
Each and every setting I have applied (i.e. desktop background) reverts to how it was six boots ago.
I can only install programs on the boot directly after a registry fix.
Anyhow, I am drawing you away from the point.
Lately, rather than fixing the registry, I have closed the regchecker from the close program window. I have only done this a few times, but do I regret it!
My mouse, which I believed was already jumpy, has started to control itself.
On occasion, it used to, when left unattended for a while crawl to the bottom of the screen. It also used to be sluggish on occasions, and unresponsive.
Now, when I start up windows I only have 1 in 4 chance, or thereabout of starting successfully, as the system usually hangs.
When the system does not hang, the mouse appears fine.
As it is moved, it becomes sluggish, stopping on occasions.
At random intervals now, more often than not when I am using the mouse, the system hangs. This can occur ten seconds, or five hours after start-up.
After this, it beings to fad away and appear at the opposite side of the screen, regardless as to weather I am using it or not.
After this, it becomes hard and harder to move, jumping at it's own free well.
After it has passed this stage, everything seems to go on its head.
Moving the mouse causes it to go haywire, jumping about the screen and opening random icons, folders and properties.
I believe, however that there is an order to this chaos - right click causes the mouse to crawl to the right, etc.
I have cleaned everything unwanted from my start-up via msconfig.
I have deleted the mouse drivers, and reinstalled.
I have reduced the monitor refresh rate.
NOTHING seems to work.
I am now stuck to MouseKeys, which do not seem to be affected.
Also, a long, long while back a friend reported to have seen the error message something like 'mpeg table is left dangling. Fix problem or it will fall off!!’
Any ideas?
VirtualMe
February 20th, 2003, 04:16 PM
Hi DevNull,
Welcome to CyperTechHelp,
Here is as good a place to start as any.
I guess you have checked for viruses, with updated virus updates? If not, you need to.
Also........
Free online Scan (http://housecall.antivirus.com/housecall/start_corp.asp)
===========================
What do you have running at startup?
Goto http://www.lurkhere.com/~nicefiles/
Download StartupList (http://www.lurkhere.com/~nicefiles/startuplist151.zip) and run it.
Copy & paste back in this post the list so someone can look at what you have running in the back ground.
DevNull
February 20th, 2003, 04:38 PM
I have run Panda, Bit ware AND trend online, several times to no avail.
I have tried my hardest to clean everything suspect from my startup, but this list shows one little blighter has got past me. Wonder if it is the problem?
StartupList report, 20/02/03, 16:12:41
StartupList version: 1.51
Started from : C:\UNZIPPED\STARTUPLIST151\STARTUPLIST.EXE
Detected: Windows 98 SE (Win9x 4.10.2222A)
Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
* Using default options
==================================================
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\ACCSTAT.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\PTSNOOP.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\MIXER.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\PROGRAM FILES\NO-IP\DUC20.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PIRCH98-MULTISERVER\PIRCH98.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\WINWORD.EXE
C:\PROGRAM FILES\MICROSOFT WORKS\MSWORKS.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\UNZIPPED\STARTUPLIST151\STARTUPLIST.EXE
--------------------------------------------------
Listing of startup folders:
Shell folders Startup:
[C:\WINDOWS\Start Menu\Programs\StartUp]
No-IP DUC.lnk = C:\Program Files\No-IP\DUC20.exe
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
ScanRegistry = "c:\windows\scanregw.exe " /autorun
TaskMonitor = "c:\windows\taskmon.exe"
SystemTray = "SysTray.Exe"
LoadPowerProfile = "Rundll32.exe " powrprof.dll,LoadCurrentPwrScheme
C-Media Mixer = "Mixer.exe " /startup
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
msnmsgr = "C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE" /background
--------------------------------------------------
C:\WINDOWS\WININIT.BAK listing:
(Created 13/2/2003, 18:59:12)
[Rename]
NUL=C:\PROGRA~1\XPLOSIV\CIVILI~1\GETINFO.DLL
NUL=C:\PROGRA~1\XPLOSIV\CIVILI~1\PLAYCTP.EXE
--------------------------------------------------
C:\AUTOEXEC.BAT listing:
c:\windows\COMMAND\doskey
mode con codepage prepare=((850) c:\windows\COMMAND\ega.cpi)
mode con codepage select=850
keyb uk,,c:\windows\COMMAND\keyboard.sys
PATH C:\BITWARE\
SET CLASSPATH="C:\Program Files\Java\j2re1.4.1_01\lib\ext\QTJava.zip"
SET QTJAVA="C:\Program Files\Java\j2re1.4.1_01\lib\ext\QTJava.zip"
--------------------------------------------------
Enumerating Browser Helper Objects:
(no name) - C:\PROGRAM FILES\YAHOO!\COMMON\YCOMP5_0_2_6.DLL - {02478D28-C3F9-4efb-9B51-7695ECA05670}
--------------------------------------------------
Enumerating Download Program Files:
[CV3 Class]
InProcServer32 = C:\WINDOWS\SYSTEM\WUV3IS.DLL
CODEBASE = http://windowsupdate.microsoft.com/R1108/V31Controls/x86/w98/en/actsetup.cab
[Update Class]
InProcServer32 = C:\WINDOWS\SYSTEM\IUCTL.DLL
CODEBASE = http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37570.0838541667
[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH.OCX
CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
[Shockwave ActiveX Control]
InProcServer32 = C:\WINDOWS\SYSTEM\MACROMED\SHOCKWAVE 8\DOWNLOAD.DLL
CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
[OPUCatalog Class]
InProcServer32 = C:\WINDOWS\SYSTEM\OPUC.DLL
CODEBASE = http://office.microsoft.com/productupdates/content/opuc.cab
[{8522F9B3-38C5-4AA4-AE40-7401F1BBC851}]
CODEBASE = http://www.crackheaven.com/serialorcrack.exe
[HouseCall Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\XSCAN53.OCX
CODEBASE = http://a840.g.akamai.net/7/840/537/2002121801/housecall.antivirus.com/housecall/xscan53.cab
[YInstStarter Class]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\YINSTHELPER.DLL
CODEBASE = http://download.yahoo.com/dl/installs/yinst.cab
[YahooYMailTo Class]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\YMMAPI.DLL
CODEBASE = http://us.dl1.yimg.com/download.yahoo.com/dl/installs/essentials/ymmapi_0727.dll
--------------------------------------------------
End of report, 4,901 bytes
Report generated in 0.410 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
:D thanks for the speedy reply, VirtualMe! :D
VirtualMe
February 20th, 2003, 06:06 PM
Could be. I can't find anything telling what serialorcrack.exe is.
You can goto back to http://www.lurkhere.com/~nicefiles/ and get,
SpyBot Search and Destroy v1.1 Rel 4 (http://www.lurkhere.com/~nicefiles/ssd14.exe)
And see if it will find anything that needs to be removed. Be sure and get the updates after you open it.
You click on the Online tab
then Search for updates
then put a check in the [ ] to download updates
then click on Download updates button
VirtualMe
February 20th, 2003, 06:38 PM
Hummm!
These have me wondering. Recently decovered. My need to be check out further.
http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.lovgate@mm.html
http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.tang@mm.html
The reason they have me wondering, is if you read them closely, they both have Cracks! or Password Cracker in the subjects lines.
Just trying to cover all bases. May be nothing.
ritchie31
February 20th, 2003, 06:45 PM
Having read your post, it brought back memories of the rodent problems I have had, 3 or 4 times I have had the same trouble you described "exactly", but you can be sure it is not a virus. Your best option is to put the poor animal to sleep, and get yourself a new pet, You will find that after you install a new mouse your troubles will be over, leaving only the memories of that little critter that went nuts on your desktop.
DevNull
February 20th, 2003, 08:46 PM
Thanks for all your replies!!
Tomorrow, I am going to go purchase a new mouse. If the problems continue, I will reformat C-drive.
I have c, d, e and f drives. I will simply copy all of my C information.
If this is a virus, are the any things I should leave behind; i.e. executable files?
I have had my little registry problem before. It has followed me through two clean sweeps.
I am thinking that it may be corrupt data on some sort of software cd; maybe even my windows 98 disk.
Since the error I receive never actually tells me where the error is, I may never know.
Is there ANY way that I can find out?
eh. a few suspicious registry entries that respawn on startup have not come back since i unplugged my mouse.
odd.
VirtualMe
February 21st, 2003, 05:52 AM
Hi DevNull,
ritchie31 is likely right, . You will know after you try a new mouse.
Did you ever get and run SpyBot Search & Destroy (http://www.lurkhere.com/~nicefiles/ssd14.exe)?