|
 |
 |
Unknown Task In Task Scheduler
|
 |
 |
 |
 |
| Author |
Message |
surfdude156 Member



 Joined: 19 Nov 2007 Posts: 34
|
|
 |
| I was looking through task schedular and I saw this task. It didnt look like any legit program but i wanted to see if it was. The name for it was: "{124410CA-53AF-4F63-B036-D8FA1716511B}" and it triggered opening an exe which was: "C:\Windows\system32\pcalua.exe -a "C:\Users\Dakota\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VEJV3ZXD\sp39951[1].exe" -d C:\Windows\system32". Im not sure if its a virus or not. Any info on what it is is appreciated. |
_________________
"Sometimes the very measures we put into safeguard our liberties, become threats to liberty itself." - Eagle Eye (2008)
 |
|
Date Posted:Fri Apr 24, 2009 12:11 amThanks: 15Thanked 2 Times In 1 Posts
|
| Author |
Message |
Klean Super Moderator



 Joined: 04 May 2007 Posts: 4645 Location: 192.168.1.1
|
|
 |
pcalua.exe appears to be related to Microsoft's Program Compatibility Assistant:
| Astatalk download freehost links: |
| Code: |
| http://windowshelp.microsoft.com/Windows/en-US/82c0440d-553e-47e9-b4bd-6c2d10df4de71033.mspx#EVC |
|
Therefore, I think it is legit.
However, I would take another look at it - upload pcalua.exe to:
| Astatalk download freehost links: |
|
|
Please post a screenshot of the results if you take the (above) upload option...
sp39951[1].exe is the HP w1907 LCD Monitor Driver ...You may also want to upload this exe as well.
If you would like me to look into your computer to see if anything is wrong...
Download a copy of HijackThis and save it to your desktop in a folder. Do a scan and save the HijackThis logfile. Do not remove anything. Post your log file here. Link to HijackThis>
| Astatalk download freehost links: |
| Code: |
| http://download.hijackthis.eu/HJTInstall.exe |
|
I will look at it later or a staff member from this section will help you.
Please give us updates by replying in this thread... But it appears everything is legit.
In plain terms, windows is checking to see if your monitor works with Vista at startup. Why? I'm not sure ... Is it needed? I'm not sure.  |
_________________
A candle loses nothing by sharing its flame.
 |
|
Date Posted:Fri Apr 24, 2009 2:06 amThanks: 48Thanked 1751 Times In 841 Posts
|
| Author |
Message |
surfdude156 Member



 Joined: 19 Nov 2007 Posts: 34
|
|
 |
Haha ok thats cool. And yea i think that the program is legit, but im not sure about the temporary file thats attatched to it. I checked to see if sp39951[1].exe was even i file i had and it wasnt . Ok so here's my hijackthis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:30:04 AM, on 4/24/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18226)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O1 - Hosts: ::1 localhost
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O13 - Gopher Prefix:
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc. - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
--
End of file - 2172 bytes
Oh and i uploaded the file to virustotal and here's the results
| Astatalk download freehost links: |
| Code: |
| http://www.virustotal.com/analisis/0562d22c95e1b397e70bfceadb6752d5 |
|
|
_________________
"Sometimes the very measures we put into safeguard our liberties, become threats to liberty itself." - Eagle Eye (2008)
 |
|
Date Posted:Fri Apr 24, 2009 3:39 pmThanks: 15Thanked 2 Times In 1 Posts
|
| Author |
Message |
Klean Super Moderator



 Joined: 04 May 2007 Posts: 4645 Location: 192.168.1.1
|
|
 |
Everything is clean. I believe sp39951[1].exe belongs to your monitor.
I get no baddies.
*************************************************************************************************
This subject has been addressed or corrected. The subject is closed and if the original topic author needs to add to it please P.M. a staff member from this section.
************************************************************************************************* |
_________________
A candle loses nothing by sharing its flame.
 |
|
Date Posted:Sun Apr 26, 2009 5:31 amThanks: 48Thanked 1751 Times In 841 Posts
|
Astalavista Forum Index :: Windows O/S Support :: Unknown Task In Task Scheduler
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
|
|