Re: I keep getting redirected to random web pages...

Reply

Join Date: Mar 2009
Posts: 11
Reputation: chessplayer is an unknown quantity at this point 
Solved Threads: 0
chessplayer chessplayer is offline Offline
Newbie Poster

Re: I keep getting redirected to random web pages...

 
0
  #11
Mar 9th, 2009
Thank you jholland1964 for your reply. I was running the latest version of MBA-M as you can see from my previous post, I did update right before I clicked full-scan. I do not have Virus Doctor entry under Add/Remove programs and Search came up with nothing. So I do not think that I have 'Virus Doctor' installed on my computer. Also don't you think 'Virus Doctor' would have shown up on the HijackThis log? Somewhere on the internet I read that the popups can be launched from a trojan hiding on the machine - do you think this might be where its coming from?
Reply With Quote Quick reply to this message  
Join Date: Jul 2008
Posts: 3,061
Reputation: jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all 
Solved Threads: 174
Moderator
Featured Poster
jholland1964 jholland1964 is offline Offline
Posting Sensei

Re: I keep getting redirected to random web pages...

 
0
  #12
Mar 9th, 2009
If the pop ups and redirects are there then chance of you having it on the computer are pretty good. You won't necessarily see it in Add/Remove.
Your logs show clean, both of them but that doesn't mean it isn't there.
check the Task Manager for ANY or ALL of the following processes:
VirusDoctor.exe
VDocf360.exe
unins000.exe
VDo[RANDOM].exe - the RANDOM means then name can be anything at all.
I noticed in your HJT log that taskeng.exe was running, this is a scheduled task. Check in your Task Scheduler for unusually named scheduled tasks
Reply With Quote Quick reply to this message  
Join Date: Mar 2009
Posts: 11
Reputation: chessplayer is an unknown quantity at this point 
Solved Threads: 0
chessplayer chessplayer is offline Offline
Newbie Poster

Re: I keep getting redirected to random web pages...

 
0
  #13
Mar 18th, 2009
I looked in task manager and saw no processes by those names. Then I checked Task Scheduler and found 4 suspicious tasks whose name is a GUID. I'm not sure what they are for?

Here is the name and action of the tasks:
Name: {56B404BE-4B0C-4965-90E3-4F0FE52D093A}
<Command>C:\Windows\system32\pcalua.exe</Command>
<Arguments>-a "C:\Users\jzelenak\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JF6T2N5G\sp40702[1].exe" -d C:\Users\jzelenak</Arguments>

Name: {BD8D371B-A791-4AB7-853B-784FC7146413}
<Command>C:\Windows\system32\pcalua.exe</Command>
<Arguments>-a "C:\Users\jzelenak\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I51H596T\sp37093[1].exe" -d C:\Users\jzelenak</Arguments>

Name {DC17124A-5505-4BFB-8D4F-D439D397C35A}
<Command>C:\Windows\system32\pcalua.exe</Command>
<Arguments>-a "C:\Users\jzelenak\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6VF6RG9R\sp39689[1].exe" -d C:\Users\jzelenak</Arguments>

Name: {F9E2DDA7-832A-4D05-8DEC-51D66FB64A4A}
<Command>C:\Windows\system32\pcalua.exe</Command>
<Arguments>-a C:\Users\jzelenak\Downloads\med\Install_Netter.exe -d C:\Users\jzelenak\Downloads\med</Arguments>

Can you please tell me what these tasks are for and should I delete them?
Reply With Quote Quick reply to this message  
Join Date: Jul 2008
Posts: 3,061
Reputation: jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all 
Solved Threads: 174
Moderator
Featured Poster
jholland1964 jholland1964 is offline Offline
Posting Sensei

Re: I keep getting redirected to random web pages...

 
0
  #14
Mar 18th, 2009
All list <Command>C:\Windows\system32\pcalua.exe</Command>
usually this refers to the Program Compatibility Assistant
The first three listed may be:
sp37093.exe Broadcom driver
sp39689.exe Fax Modem
sp40702.exe possibly an HP NIC drive.
Did you download and install some new drivers from someplace other than the manufacturer's websites? All references also are pointing to temporary internet files..
The last one which is however listed in Downloads\med...meaning medical? Did you install some medical reference material? Possibly via P2P file sharing?
Last edited by jholland1964; Mar 18th, 2009 at 2:38 am.
Reply With Quote Quick reply to this message  
Join Date: Mar 2009
Posts: 11
Reputation: chessplayer is an unknown quantity at this point 
Solved Threads: 0
chessplayer chessplayer is offline Offline
Newbie Poster

Re: I keep getting redirected to random web pages...

 
0
  #15
Mar 18th, 2009
I have HP laptop and I was installing drivers from their website and the med one was from a friend through network but it failed to install(don't know why, maybe corrupt file?), so I wonder can I delete all 4 of them?
Reply With Quote Quick reply to this message  
Join Date: Mar 2009
Posts: 11
Reputation: chessplayer is an unknown quantity at this point 
Solved Threads: 0
chessplayer chessplayer is offline Offline
Newbie Poster

Re: I keep getting redirected to random web pages...

 
0
  #16
Mar 18th, 2009
Oh and what does Program Compatibility Assistant do?
Reply With Quote Quick reply to this message  
Join Date: Jul 2008
Posts: 3,061
Reputation: jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all 
Solved Threads: 174
Moderator
Featured Poster
jholland1964 jholland1964 is offline Offline
Posting Sensei

Re: I keep getting redirected to random web pages...

 
0
  #17
Mar 18th, 2009
Originally Posted by chessplayer View Post
Oh and what does Program Compatibility Assistant do?
From WindowsHelp Microsoft
The Program Compatibility Assistant detects known compatibility issues in older programs. After you have run an older program in this version of Windows, it notifies you if there is a problem and offers to fix it the next time you run the program. If the compatibility issue is serious, the Program Compatibility Assistant might warn you or block the program from running. If that happens, you'll have the option to check online for possible solutions.....The Program Compatibility Assistant runs automatically when it detects an older program that has a compatibility problem.
The link above gives other information so you can check all that on that site. Sounds to me though that these drivers you were installing were older drivers than Vista normally requires.

Here is also the Vista Compatibility Center
Last edited by jholland1964; Mar 18th, 2009 at 11:19 am.
Reply With Quote Quick reply to this message  
Join Date: Oct 2009
Posts: 4
Reputation: techsheaven is an unknown quantity at this point 
Solved Threads: 0
techsheaven's Avatar
techsheaven techsheaven is offline Offline
Newbie Poster

hosts

 
0
  #18
5 Days Ago
There have been several versions of malware going around that can cause this. Malwarebytes takes care of most of them. Some alter the hosts file at windows\system32\drivers\etc. Right-click, select open, from the list of programs select notepad. If there are a lot of IP addresses followed by websites, this may be your problem. Just delete the entries, or rename the file.
Reply With Quote Quick reply to this message  
Reply

Message:



Similar Threads
Other Threads in the Viruses, Spyware and other Nasties Forum
Thread Tools Search this Thread



About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC