MouseDriver in my startup - infected or not?

Status
Not open for further replies.

anskha

Commendable
Oct 1, 2016
9
0
1,510
Hi there,

I do regular check-ups of my Startup using CCleaner. Its been a few months since last I checked and today I was puzzled about a program called 'MouseDriver' by Pixart Imaging Inc in my Windows Startup. The entry looks very suspicious to me, so I googled it. Some say that its harmless, while others also find it suspicious. Searching 'MouseDriver' in your database, it says its connected to a virus, which got me really scared now.

I have made a file of my Windows Startup:

Yes HKCU:Run BlueStacks Agent BlueStack Systems, Inc. C:\Program Files (x86)\Bluestacks\HD-Agent.exe
Yes HKCU:Run CCleaner Monitoring Piriform Ltd "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
No HKCU:Run Lync Microsoft Corporation "C:\Program Files\Microsoft Office\Office15\lync.exe" /fromrunkey
No HKCU:Run OneDrive Microsoft Corporation "C:\Users\Andreas Skriver\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
No HKCU:Run Spotify Spotify Ltd "C:\Users\Andreas Skriver\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart
No HKCU:Run Spotify Web Helper Spotify Ltd "C:\Users\Andreas Skriver\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
No HKCU:Run Steam Valve Corporation "C:\Program Files (x86)\Steam\Steam.exe" -silent
No HKCU:Run Viber Viber Media S.a.r.l "C:\Users\Andreas Skriver\AppData\Local\Viber\Viber.exe" StartMinimized
Yes HKLM:Run Adobe Reader Speed Launcher Adobe Systems Incorporated "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
No HKLM:Run APSDaemon Apple Inc. "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
Yes HKLM:Run ASUS InstantKey ASUS C:\Program Files (x86)\ASUS\ASUS Instant Key\Ikey_start.exe
Yes HKLM:Run ASUSWebStorage C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.9.120\AsusWSPanel.exe /S
Yes HKLM:Run AVG_UI AVG Technologies CZ, s.r.o. "C:\Program Files (x86)\AVG\Av\avuirunnerx.exe" C:\Program Files (x86)\AVG\Av\avgui.exe
Yes HKLM:Run AvgUi AVG Technologies CZ, s.r.o. "C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe" /lps=fmw
Yes HKLM:Run BDRegion cyberlink C:\Program Files (x86)\Cyberlink\Shared files\brs.exe
No HKLM:Run BlueStacks Agent BlueStack Systems, Inc. C:\Program Files (x86)\BlueStacks\HD-Agent.exe
Yes HKLM:Run iTunesHelper Apple Inc. "C:\Program Files\iTunes\iTunesHelper.exe"
Yes HKLM:Run Malwarebytes Anti-Exploit Malwarebytes Corporation C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe
No HKLM:Run MouseDriver Pixart Imaging Inc TiltWheelMouse.exe
Yes HKLM:Run NvBackend NVIDIA Corporation "C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
No HKLM:Run QuickTime Task Apple Inc. "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
No HKLM:Run RemoteControl10 CyberLink Corp. "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
Yes HKLM:Run RtHDVBg Realtek Semiconductor "C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /MAXX3
Yes HKLM:Run RTHDVCPL Realtek Semiconductor "C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
Yes HKLM:Run ShadowPlay Microsoft Corporation "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
Yes HKLM:Run SunJavaUpdateSched Oracle Corporation "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
Yes HKLM:Run UpdatePSTShortCut CyberLink Corp. "C:\Program Files (x86)\Cyberlink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Cyberlink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"



As you may notice, the MouseDriver stands out in the Windows Startup.



Can you recommend me any actions?



Thanks!



Anskha
 

anskha

Commendable
Oct 1, 2016
9
0
1,510
Hi,

I did already run MalWareBytes and ESET online scan. Nothing found.
Two things:

1) What about the fact that the MouseDriver doesnt seem to be located anyware on my pc? I cannot see the location of it from CCleaner. Isnt that suspucious?

2) What program would you recommend that I disable/unintall from my startup?

Thank you!
 
"Description: TiltWheelMouse.exe is not essential for the Windows OS and causes relatively few problems. The TiltWheelMouse.exe file is located in the C:\Windows\System32 folder. The file size on Windows 8/7/XP is 241,152 bytes. [​IMG]
The program has no visible window. The application starts when Windows starts (see Registry key: MACHINE\Run). TiltWheelMouse.exe is not a Windows core file. The file is a trustworthy file from Microsoft. TiltWheelMouse.exe is able to record keyboard and mouse inputs and monitor applications.

I would disable all the Cyberlink, Adobe, Steam, iTunes, and any of the other third party softwares you don't use all the time. You would just need to start them when needed from their desktop icon or the Programs menu.
 

anskha

Commendable
Oct 1, 2016
9
0
1,510
Thank you very much! Im glad that its not a problem!

Also, I will disable all those processes that you suggest with CCleaner.

Btw, could I also have you take a quick look at my scheduled tasks shown by CCleaner?

Yes Task Adobe Acrobat Update Task Adobe Systems Incorporated C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
Yes Task Adobe Flash Player Updater Adobe Systems Incorporated C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Yes Task ASUS InstantOn Config ASUS C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnCfg.exe
Yes Task ASUS P4G ASUS C:\Program Files\ASUS\P4G\BatteryLife.exe
Yes Task ASUS Smart Gesture Launcher AsusTek C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLauncher.exe
Yes Task ASUS USB Charger Plus ASUSTek Computer Inc. "C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe"
Yes Task CCleanerSkipUAC Piriform Ltd "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
Yes Task CreateChoiceProcessTask C:\Windows\BrowserChoice\browserchoice.exe /launch
Yes Task OneDrive Standalone Update Task Microsoft Corporation C:\Users\Andreas Skriver\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\OneDriveStandaloneUpdater.exe
No Task Optimize Start Menu Cache Files-S-1-5-21-1137830355-1236294167-3788692297-1002
Yes Task Optimize Start Menu Cache Files-S-1-5-21-1137830355-1236294167-3788692297-500
No Task USER_ESRV_SVC_WILLAMETTE Microsoft Corporation "C:\WINDOWS\System32\Wscript.exe" //B //NoLogo "C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\task.vbs"
Yes Task {78CFD315-79C0-4D71-8DD8-EA0AA1D62418} Microsoft Corporation C:\WINDOWS\system32\pcalua.exe -a E:\INSTALL.EXE -d E:\

Anything suspicious there?

A.


 
Status
Not open for further replies.