Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Mouse double clicking when single click


  • This topic is locked This topic is locked
16 replies to this topic

#1 KBEAST

KBEAST

  • Members
  • 93 posts
  • OFFLINE
  •  
  • Local time:03:10 PM

Posted 27 February 2017 - 12:49 PM

Hi,

 

I have this same issue back from last year.

 

https://www.bleepingcomputer.com/forums/t/600963/mouse-clicking-twice-sometimes-when-its-clicked-once/

 

And I've followed the same process on above thread but I am still having this issue where a single click becomes double click making things open twice and other annoying stuff.

 

As direction, I've ran FRST.log  see attach txt file

 

Thanks

Attached Files



BC AdBot (Login to Remove)

 


#2 nasdaq

nasdaq

  • Malware Response Team
  • 38,933 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:03:10 PM

Posted 28 February 2017 - 11:00 AM

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

Press the windows key Windows_Logo_key.gif+ r on your keyboard at the same time. This will open the RUN BOX.
Type Notepad and and click the OK key.

Please copy the entire contents of the code box below to a new file.


Start

CreateRestorePoint:
EmptyTemp:
CloseProcesses:

HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-2116333086-45548962-528574141-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
FF SearchPlugin: C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\r62ax7an.Default User\searchplugins\yahoo-avast.xml [2016-10-19]
CHR Plugin: (Widevine Content Decryption Module) - C:\Users\John\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.8.824\_platform_specific\win_x86\widevinecdmadapter.dll => No File
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\PepperFlash\pepflashplayer.dll => No File
CHR Extension: (Chrome Web Store Payments) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-01-20]
CHR Extension: (Chrome Media Router) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-13]
CHR HKLM-x32\...\Chrome\Extension: [eoalfhodgifhbkgmbbdafcihjpdldpll] - hxxps://clients2.google.com/service/update2/crx
U4 AvastVBoxSvc; "C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe" [X]
S3 dbx; system32\DRIVERS\dbx.sys [X]
U4 VBoxAswDrv; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [X]
Shortcut: C:\Users\John\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\G??gl? ?hr?m?.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.bat (No File)
Shortcut: C:\Users\John\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\L?un?h Int?rn?t ??pl?r?r ?r?ws?r.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.bat (No File)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\G??gl? ?hr?m?.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.bat (No File)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\?v?st S?f?Z?n? ?r?ws?r.lnk -> C:\Program Files\AVAST Software\SZBrowser\launcher.bat (No File)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\??zill? Fir?f??.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.bat (No File)

End
Save the file as fixlist.txt in the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the Farbar log you have submitted.

Run FRST and click Fix only once and wait.

The tool will create a log (Fixlog.txt) please post it to your reply.

Please let me know what problem persists with this computer.
===

#3 KBEAST

KBEAST
  • Topic Starter

  • Members
  • 93 posts
  • OFFLINE
  •  
  • Local time:03:10 PM

Posted 01 March 2017 - 03:48 PM

Hi,

 

Problem still exists. It's either double click or auto clicking. If I hold left mouse to highlight some line or paragraph, throughout the drag it will auto click on its own which it un-highlights

Click one tab window and sometimes 2 tab opens so something is running it seems.

Here's fixlog.txt

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 27-02-2017
Ran by John (28-02-2017 12:41:04) Run:5
Running from C:\Users\John\Desktop
Loaded Profiles: John (Available Profiles: John)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start

CreateRestorePoint:
EmptyTemp:
CloseProcesses:

HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-2116333086-45548962-528574141-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
FF SearchPlugin: C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\r62ax7an.Default User\searchplugins\yahoo-avast.xml [2016-10-19]
CHR Plugin: (Widevine Content Decryption Module) - C:\Users\John\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.8.824\_platform_specific\win_x86\widevinecdmadapter.dll => No File
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\PepperFlash\pepflashplayer.dll => No File
CHR Extension: (Chrome Web Store Payments) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-01-20]
CHR Extension: (Chrome Media Router) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-13]
CHR HKLM-x32\...\Chrome\Extension: [eoalfhodgifhbkgmbbdafcihjpdldpll] - hxxps://clients2.google.com/service/update2/crx
U4 AvastVBoxSvc; "C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe" [X]
S3 dbx; system32\DRIVERS\dbx.sys [X]
U4 VBoxAswDrv; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [X]
Shortcut: C:\Users\John\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\G??gl? ?hr?m?.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.bat (No File)
Shortcut: C:\Users\John\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\L?un?h Int?rn?t ??pl?r?r ?r?ws?r.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.bat (No File)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\G??gl? ?hr?m?.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.bat (No File)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\?v?st S?f?Z?n? ?r?ws?r.lnk -> C:\Program Files\AVAST Software\SZBrowser\launcher.bat (No File)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\??zill? Fir?f??.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.bat (No File)

End
*****************

Restore point was successfully created.
Processes closed successfully.
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer => key removed successfully
HKU\S-1-5-21-2116333086-45548962-528574141-1001\SOFTWARE\Policies\Microsoft\Internet Explorer => key removed successfully
C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\r62ax7an.Default User\searchplugins\yahoo-avast.xml => moved successfully
C:\Users\John\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.8.824\_platform_specific\win_x86\widevinecdmadapter.dll => not found.
C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\PepperFlash\pepflashplayer.dll => not found.
C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda => moved successfully
C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm => moved successfully
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\eoalfhodgifhbkgmbbdafcihjpdldpll => key removed successfully
HKLM\System\CurrentControlSet\Services\AvastVBoxSvc => key could not remove, key could be protected
HKLM\System\CurrentControlSet\Services\dbx => key removed successfully
dbx => service removed successfully
HKLM\System\CurrentControlSet\Services\VBoxAswDrv => key could not remove, key could be protected
"C:\Users\John\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\G??gl? ?hr?m?.lnk" => Could not move.
"C:\Users\John\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\L?un?h Int?rn?t ??pl?r?r ?r?ws?r.lnk" => Could not move.
"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\G??gl? ?hr?m?.lnk" => Could not move.
"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\?v?st S?f?Z?n? ?r?ws?r.lnk" => Could not move.
"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\??zill? Fir?f??.lnk" => Could not move.

=========== EmptyTemp: ==========

BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 6702208 B
Java, Flash, Steam htmlcache => 492 B
Windows/system/drivers => 321799 B
Edge => 0 B
Chrome => 0 B
Firefox => 13749513 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 128 B
systemprofile32 => 0 B
LocalService => 0 B
NetworkService => 0 B
John => 19674581 B
Admin => 0 B
UpdatusUser => 0 B

RecycleBin => 0 B
EmptyTemp: => 46.6 MB temporary data Removed.

================================

Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 28-02-2017 12:46:22)


Result of scheduled keys to remove after reboot:

HKLM\System\CurrentControlSet\Services\AvastVBoxSvc => key could not remove, key could be protected
HKLM\System\CurrentControlSet\Services\VBoxAswDrv => key could not remove, key could be protected

==== End of Fixlog 12:46:22 ====



#4 nasdaq

nasdaq

  • Malware Response Team
  • 38,933 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:03:10 PM

Posted 02 March 2017 - 08:04 AM

There is a possibility that the mouse is going bad.

Did you check the speed and the clicking options on the mouse in the Properties windows?
===

Reinstall the mouse.

Try an other mouse if you can.

===

Please download and run the following tool to help allow other programs to run. (courtesy of BleepingComputer.com)
There are 3 different versions. If one of them won't run then download and try to run the other one.
Vista and Win7 users need to right click and choose Run as Admin
You only need to get one of them to run, not all of them.

rkill.exe
rkill.com
rkill.scr

It is possible that the infection you are trying to remove will not allow you to download files on the infected computer. If this is the case, then you will need to download the files requested on another computer and then transfer them to the desktop of the infected computer. You can transfer the files via a CD/DVD, external drive, or USB flash drive.

When completed it will create a log. Please post the content on your next reply.
===

--RogueKiller--
  • Download & SAVE to your Desktop Download RogueKiller
  • Quit all programs that you may have started.
  • Please disconnect any USB or external drives from the computer before you run this scan!
  • For Vista or above, right-click the program file and select "Run as Administrator"
  • Accept the user agreements.
  • Execute the scan and wait until it has finished.
  • If a Windows opens to explain what [PUM's] are, read about it.
  • Click the RoguKiller icon on your taksbar to return to the report.
  • Click open the Report
  • Click Export TXT button
  • Save the file as ReportRogue.txt
  • Click the Remove button to delete the items in RED
  • Click Finish and close the program.
  • Locate the ReportRogue.txt file on your Desktop and copy/paste the contents in your next.
=======

#5 nasdaq

nasdaq

  • Malware Response Team
  • 38,933 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:03:10 PM

Posted 07 March 2017 - 08:18 AM

Are you still with me?

#6 KBEAST

KBEAST
  • Topic Starter

  • Members
  • 93 posts
  • OFFLINE
  •  
  • Local time:03:10 PM

Posted 07 March 2017 - 08:27 PM

RougKiller needed license ID but I was able to install without it.

When I scan, it just allowed me to remove few things but no log was created.

 

However, I have log for rkill

 

Rkill 2.8.4 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2017 BleepingComputer.com
More Information about Rkill can be found at this link:
 http://www.bleepingcomputer.com/forums/topic308364.html

Program started at: 03/07/2017 07:40:34 PM in x64 mode.
Windows Version: Windows 7 Professional Service Pack 1

Checking for Windows services to stop:

 * No malware services found to stop.

Checking for processes to terminate:

 * No malware processes found to kill.

Checking Registry for malware related settings:

 * No issues found in the Registry.

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.

Performing miscellaneous checks:

 * Windows Defender Disabled

   [HKLM\SOFTWARE\Policies\Microsoft\Windows Defender]
   "DisableAntiSpyware" = dword:00000001

Checking Windows Service Integrity:

 * Windows Defender (WinDefend) is not Running.
   Startup Type set to: Manual

 * TBS [Missing Service]

Searching for Missing Digital Signatures:

 * No issues found.

Checking HOSTS File:

 * Cannot edit the HOSTS file.
 * Permissions Fixed. Administrators can now edit the HOSTS file.

 * HOSTS file entries found:

  127.0.0.1    localhost
  0.0.0.1    mssplus.mcafee.com
  127.0.0.1    www.007guard.com
  127.0.0.1    007guard.com
  127.0.0.1    008i.com
  127.0.0.1    www.008k.com
  127.0.0.1    008k.com
  127.0.0.1    www.00hq.com
  127.0.0.1    00hq.com
  127.0.0.1    010402.com
  127.0.0.1    www.032439.com
  127.0.0.1    032439.com
  127.0.0.1    www.0scan.com
  127.0.0.1    0scan.com
  127.0.0.1    1000gratisproben.com
  127.0.0.1    www.1000gratisproben.com
  127.0.0.1    1001namen.com
  127.0.0.1    www.1001namen.com
  127.0.0.1    100888290cs.com
  127.0.0.1    www.100888290cs.com

  20 out of 15607 HOSTS entries shown.
  Please review HOSTS file for further entries.

Program finished at: 03/07/2017 07:41:45 PM
Execution time: 0 hours(s), 1 minute(s), and 10 seconds(s)
 



#7 nasdaq

nasdaq

  • Malware Response Team
  • 38,933 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:03:10 PM

Posted 08 March 2017 - 10:06 AM

Is you mouse problem persisting?

#8 KBEAST

KBEAST
  • Topic Starter

  • Members
  • 93 posts
  • OFFLINE
  •  
  • Local time:03:10 PM

Posted 12 March 2017 - 12:54 AM

Yes, issue still remains.

 

 

sometimes single click, but many times it double clicks on a single click.

This is for only left click. it is not mouse issue as I've tested out. And this happened before as I've pointed out on my first post with previous link.

 

No idea how I am getting this.

 

Thanks



#9 nasdaq

nasdaq

  • Malware Response Team
  • 38,933 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:03:10 PM

Posted 12 March 2017 - 08:09 AM


Find out if the problem persists in Safe Mode with networking.

http://support.eset.com/kb2268/?locale=en_US

====

Temporarily disable your AV program so it does not interfere.
Info on how to disable your security applications How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs - Security Mini-Guides.

Download Zoek tool from here

When the download appears, save to the Desktop.
On the Desktop, right-click the Zoek.exe file and select: Run as Administrator
(Give it a few seconds to appear.)

Next, copy/paste the entire script inside the code box below to the input field of Zoek:
createsrpoint;
autoclean;
emptyclsid;
emptyffcache;
FFdefaults;
emptyiecache;
iedefaults;
emptychrcache;
CHRdefaults;
emptyalltemp;
emptyfolderscheck;delete
ipconfig /flushdns;b
Now...
Close any open Browsers.
Click the Run script button, and wait. It takes a few minutes to run all the script.

When the tool finishes, the zoek-results.log is opened in Notepad.
The log is also found on the systemdrive, normally C:\
If a reboot is needed, the log is opened after the reboot.

Please attach the zoek-results.log in your reply.
===

Also, please provide an update on how the computer is behaving after running the above script.

#10 KBEAST

KBEAST
  • Topic Starter

  • Members
  • 93 posts
  • OFFLINE
  •  
  • Local time:03:10 PM

Posted 15 March 2017 - 10:01 PM

Is there some check box that i need to use? because this took about 6 hours and I ended up just force shut down.

 

problem still remains.

 

I'll try  one more with zoek in some other day when I have time.

 

This auto click still happen. When I try to highlight some text, it auto clicks throughout that it's hard to copy some text too...smh



#11 nasdaq

nasdaq

  • Malware Response Team
  • 38,933 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:03:10 PM

Posted 16 March 2017 - 07:28 AM



Did you try my suggestion to test the mouse in Safe Mode?


Run the Zoek tool. It should not take more then 30 minutes to complete.

The last time you close the process it might just be that a File was created pleasesearch for a zoek-results.log file on your computer.

What is the Model and Manfacturer's name of the mouse?

#12 KBEAST

KBEAST
  • Topic Starter

  • Members
  • 93 posts
  • OFFLINE
  •  
  • Local time:03:10 PM

Posted 24 March 2017 - 11:49 PM

Safe mode shows no issue so it is something that's running is causing it.

 

So this time, I've let it run about 2 and a half hours and stopped it. No error created.

 

but it seemed to it went further than when I first ran it.

 

And after that, problem seemed to fixed.

 

Mouse was just a cheap logitech M100



#13 nasdaq

nasdaq

  • Malware Response Team
  • 38,933 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:03:10 PM

Posted 25 March 2017 - 07:32 AM

If all is well.

To learn more about how to protect yourself while on the internet read this little guide best security practices keep safe.
http://www.bleepingcomputer.com/forums/t/407147/answers-to-common-security-questions-best-practices/


https://www.bleepingcomputer.com/tutorials/keep-your-computer-safe-online/
Simple and easy ways to keep your computer safe and secure on the Internet.
===

#14 KBEAST

KBEAST
  • Topic Starter

  • Members
  • 93 posts
  • OFFLINE
  •  
  • Local time:03:10 PM

Posted 25 March 2017 - 07:46 PM

Sorry, it looks like issue still remains.

 

I am going to try to run that zoek again but hopefully it runs and creates log this time...



#15 nasdaq

nasdaq

  • Malware Response Team
  • 38,933 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:03:10 PM

Posted 26 March 2017 - 07:19 AM

The only way you will make sure that the mouse is not the problem is by getting a new one.

If not already tries get the the driver for the mouse
http://www.solvusoft.com/en/update/drivers/mouse/logitech/mouse/m100/model-numbers/




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users