| | |
Re: I keep getting redirected to random web pages...
![]() |
•
•
Join Date: Mar 2009
Posts: 11
Reputation:
Solved Threads: 0
Thank you jholland1964 for your reply. I was running the latest version of MBA-M as you can see from my previous post, I did update right before I clicked full-scan. I do not have Virus Doctor entry under Add/Remove programs and Search came up with nothing. So I do not think that I have 'Virus Doctor' installed on my computer. Also don't you think 'Virus Doctor' would have shown up on the HijackThis log? Somewhere on the internet I read that the popups can be launched from a trojan hiding on the machine - do you think this might be where its coming from?
If the pop ups and redirects are there then chance of you having it on the computer are pretty good. You won't necessarily see it in Add/Remove.
Your logs show clean, both of them but that doesn't mean it isn't there.
check the Task Manager for ANY or ALL of the following processes:
VirusDoctor.exe
VDocf360.exe
unins000.exe
VDo[RANDOM].exe - the RANDOM means then name can be anything at all.
I noticed in your HJT log that taskeng.exe was running, this is a scheduled task. Check in your Task Scheduler for unusually named scheduled tasks
Your logs show clean, both of them but that doesn't mean it isn't there.
check the Task Manager for ANY or ALL of the following processes:
VirusDoctor.exe
VDocf360.exe
unins000.exe
VDo[RANDOM].exe - the RANDOM means then name can be anything at all.
I noticed in your HJT log that taskeng.exe was running, this is a scheduled task. Check in your Task Scheduler for unusually named scheduled tasks
•
•
Join Date: Mar 2009
Posts: 11
Reputation:
Solved Threads: 0
I looked in task manager and saw no processes by those names. Then I checked Task Scheduler and found 4 suspicious tasks whose name is a GUID. I'm not sure what they are for?
Here is the name and action of the tasks:
Name: {56B404BE-4B0C-4965-90E3-4F0FE52D093A}
<Command>C:\Windows\system32\pcalua.exe</Command>
<Arguments>-a "C:\Users\jzelenak\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JF6T2N5G\sp40702[1].exe" -d C:\Users\jzelenak</Arguments>
Name: {BD8D371B-A791-4AB7-853B-784FC7146413}
<Command>C:\Windows\system32\pcalua.exe</Command>
<Arguments>-a "C:\Users\jzelenak\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I51H596T\sp37093[1].exe" -d C:\Users\jzelenak</Arguments>
Name {DC17124A-5505-4BFB-8D4F-D439D397C35A}
<Command>C:\Windows\system32\pcalua.exe</Command>
<Arguments>-a "C:\Users\jzelenak\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6VF6RG9R\sp39689[1].exe" -d C:\Users\jzelenak</Arguments>
Name: {F9E2DDA7-832A-4D05-8DEC-51D66FB64A4A}
<Command>C:\Windows\system32\pcalua.exe</Command>
<Arguments>-a C:\Users\jzelenak\Downloads\med\Install_Netter.exe -d C:\Users\jzelenak\Downloads\med</Arguments>
Can you please tell me what these tasks are for and should I delete them?
Here is the name and action of the tasks:
Name: {56B404BE-4B0C-4965-90E3-4F0FE52D093A}
<Command>C:\Windows\system32\pcalua.exe</Command>
<Arguments>-a "C:\Users\jzelenak\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JF6T2N5G\sp40702[1].exe" -d C:\Users\jzelenak</Arguments>
Name: {BD8D371B-A791-4AB7-853B-784FC7146413}
<Command>C:\Windows\system32\pcalua.exe</Command>
<Arguments>-a "C:\Users\jzelenak\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I51H596T\sp37093[1].exe" -d C:\Users\jzelenak</Arguments>
Name {DC17124A-5505-4BFB-8D4F-D439D397C35A}
<Command>C:\Windows\system32\pcalua.exe</Command>
<Arguments>-a "C:\Users\jzelenak\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6VF6RG9R\sp39689[1].exe" -d C:\Users\jzelenak</Arguments>
Name: {F9E2DDA7-832A-4D05-8DEC-51D66FB64A4A}
<Command>C:\Windows\system32\pcalua.exe</Command>
<Arguments>-a C:\Users\jzelenak\Downloads\med\Install_Netter.exe -d C:\Users\jzelenak\Downloads\med</Arguments>
Can you please tell me what these tasks are for and should I delete them?
All list <Command>C:\Windows\system32\pcalua.exe</Command>
usually this refers to the Program Compatibility Assistant
The first three listed may be:
sp37093.exe Broadcom driver
sp39689.exe Fax Modem
sp40702.exe possibly an HP NIC drive.
Did you download and install some new drivers from someplace other than the manufacturer's websites? All references also are pointing to temporary internet files..
The last one which is however listed in Downloads\med...meaning medical? Did you install some medical reference material? Possibly via P2P file sharing?
usually this refers to the Program Compatibility Assistant
The first three listed may be:
sp37093.exe Broadcom driver
sp39689.exe Fax Modem
sp40702.exe possibly an HP NIC drive.
Did you download and install some new drivers from someplace other than the manufacturer's websites? All references also are pointing to temporary internet files..
The last one which is however listed in Downloads\med...meaning medical? Did you install some medical reference material? Possibly via P2P file sharing?
Last edited by jholland1964; Mar 18th, 2009 at 2:38 am.
From WindowsHelp Microsoft
The link above gives other information so you can check all that on that site. Sounds to me though that these drivers you were installing were older drivers than Vista normally requires.
Here is also the Vista Compatibility Center
•
•
•
•
The Program Compatibility Assistant detects known compatibility issues in older programs. After you have run an older program in this version of Windows, it notifies you if there is a problem and offers to fix it the next time you run the program. If the compatibility issue is serious, the Program Compatibility Assistant might warn you or block the program from running. If that happens, you'll have the option to check online for possible solutions.....The Program Compatibility Assistant runs automatically when it detects an older program that has a compatibility problem.
Here is also the Vista Compatibility Center
Last edited by jholland1964; Mar 18th, 2009 at 11:19 am.
There have been several versions of malware going around that can cause this. Malwarebytes takes care of most of them. Some alter the hosts file at windows\system32\drivers\etc. Right-click, select open, from the list of programs select notepad. If there are a lot of IP addresses followed by websites, this may be your problem. Just delete the entries, or rename the file.
![]() |
Similar Threads
- I keep getting redirected to random web pages... (Viruses, Spyware and other Nasties)
- Search Engines (i.e., Google/Yahoo) Hijacked (Viruses, Spyware and other Nasties)
- Browser Redirects to "go.google.com" (or nowhere at all) (Viruses, Spyware and other Nasties)
- Browser Hijack Problem (Viruses, Spyware and other Nasties)
Other Threads in the Viruses, Spyware and other Nasties Forum
- Previous Thread: Hijack this log help?
- Next Thread: Hijack this Help!
| Thread Tools | Search this Thread |
adware anti-malware anti-virussitesaccessissue antivirus attack audio avg backtoschoolspeech bar blackhat botnet botnets censorship china commercial commercials conficker connect control crosssitescripting cyber cybercrime cyberwarfare ddos domains e-mafia education email europe exam exploit facebook fake fancheckvirus gaming gumblar halloween herss.exe hijack hosting internet kaspersky legal logfiles mail malware mcafee mega-d messagelabs microsoft mobile nazi news obama onlinethreats paedophile panel parents patch phishing police policeprovirusmba-mblockedinternetaccess president privacy pro problem redirect redirecting reliability report research risk rogueantivirus samhain sans scareware school search security seopoisoning software spam spyware spywareexternalwindows7adminstratortrojans sqlinjection symantec trojan unwanted update usa virus viruses vista volume war warning windows worm yahoo zeroday






