This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Computer Acting rather fishy.... Hmm.., Possible Infection

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

Unfortunately there lies something else to deal with…

When I followed the first set up directions and ran the combofix /uninstall, it said it uninstalled but before that I showed a message saying it detected Kaspersky and this would interrupt while performing the uninstall.

Kaspersky detected a virus now since I ran the combofix uninstall.

virus.HEUR: Trojan.Script.Iframer


The object read…

http://www.jeniferfurniture.com/



I felt it would be best to notify you before I continued cleaning up the tools, since I may or may not need them.
Alright, here's the log…






Date: Last week (events: 206)
My Protection (events: 9)
3/21/2010 8:55:04 PM Protection is not running Kaspersky Internet Security
3/21/2010 9:55:28 AM Your computer is protected Kaspersky Internet Security
3/21/2010 1:54:44 AM Protection is not running Kaspersky Internet Security
3/19/2010 4:18:52 PM Your computer is protected Kaspersky Internet Security
3/19/2010 12:48:49 PM Protection is not running Kaspersky Internet Security
3/19/2010 12:38:41 PM Your computer is protected Kaspersky Internet Security
3/19/2010 1:48:04 AM Protection is not running Kaspersky Internet Security
3/19/2010 12:33:33 AM Protection is not running Kaspersky Internet Security
3/18/2010 10:45:01 PM Databases are obsolete Kaspersky Internet Security
File Anti-Virus (events: 7)
3/21/2010 9:55:27 AM Task started Kaspersky Internet Security File Anti-Virus
3/19/2010 4:19:49 PM Processing error Absent D Read error
3/19/2010 4:18:51 PM Task started Kaspersky Internet Security File Anti-Virus
3/19/2010 12:38:38 PM Task started Kaspersky Internet Security File Anti-Virus
3/19/2010 12:34:49 AM Task started Kaspersky Internet Security File Anti-Virus
3/18/2010 11:22:27 PM Processing error Absent D Read error
3/18/2010 10:45:01 PM Task started Kaspersky Internet Security File Anti-Virus
Mail Anti-Virus (events: 5)
3/21/2010 9:55:27 AM Task started Kaspersky Internet Security Mail Anti-Virus
3/19/2010 4:18:51 PM Task started Kaspersky Internet Security Mail Anti-Virus
3/19/2010 12:38:39 PM Task started Kaspersky Internet Security Mail Anti-Virus
3/19/2010 12:34:50 AM Task started Kaspersky Internet Security Mail Anti-Virus
3/18/2010 10:45:01 PM Task started Kaspersky Internet Security Mail Anti-Virus
Web Anti-Virus (events: 9)
3/21/2010 8:49:51 PM Denied: HEUR:Trojan.Script.Iframer Firefox http://www.jenniferfurniture.com/
3/21/2010 8:49:51 PM Denied: HEUR:Trojan.Script.Iframer Firefox http://www.jenniferfurniture.com/
3/21/2010 8:49:51 PM Detected: HEUR:Trojan.Script.Iframer Firefox http://www.jenniferfurniture.com/
3/21/2010 8:49:50 PM Detected: HEUR:Trojan.Script.Iframer Firefox http://www.jenniferfurniture.com/
3/21/2010 9:55:28 AM Task started Kaspersky Internet Security Web Anti-Virus
3/19/2010 4:18:51 PM Task started Kaspersky Internet Security Web Anti-Virus
3/19/2010 12:38:39 PM Task started Kaspersky Internet Security Web Anti-Virus
3/19/2010 12:34:50 AM Task started Kaspersky Internet Security Web Anti-Virus
3/18/2010 10:45:03 PM Task started Kaspersky Internet Security Web Anti-Virus
Network Attack Blocker (events: 5)
3/21/2010 9:55:27 AM Task started Kaspersky Internet Security Network Attack Blocker
3/19/2010 4:18:51 PM Task started Kaspersky Internet Security Network Attack Blocker
3/19/2010 12:38:38 PM Task started Kaspersky Internet Security Network Attack Blocker
3/19/2010 12:34:50 AM Task started Kaspersky Internet Security Network Attack Blocker
3/18/2010 10:45:01 PM Task started Kaspersky Internet Security Network Attack Blocker
Anti-Spam (events: 5)
3/21/2010 9:55:27 AM Task started Kaspersky Internet Security Anti-Spam
3/19/2010 4:18:51 PM Task started Kaspersky Internet Security Anti-Spam
3/19/2010 12:38:38 PM Task started Kaspersky Internet Security Anti-Spam
3/19/2010 12:34:49 AM Task started Kaspersky Internet Security Anti-Spam
3/18/2010 10:45:01 PM Task started Kaspersky Internet Security Anti-Spam
Application Control (events: 104)
3/21/2010 4:59:47 PM Disk Defragmenter NTFS Module Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/21/2010 4:59:46 PM Disk Defragmenter Module Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/21/2010 10:39:01 AM Internet Explorer Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/21/2010 9:55:27 AM Task started Kaspersky Internet Security Application Control
3/20/2010 11:02:22 PM Microsoft Application Error Reporting Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/20/2010 11:01:37 PM Windows Error Reporting Dump Reporting Tool Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/20/2010 5:51:42 PM Allowed: Setting debug privileges Verify Class ID Setting debug privileges Setting debug privileges
3/20/2010 5:51:42 PM Allowed: Using program interfaces of other process Microsoft Word for Windows Using program interfaces of other process c:\program files\microsoft office\office\winword.exe Using program interfaces of other process
3/20/2010 5:51:04 PM Allowed: Setting debug privileges Microsoft Word for Windows Setting debug privileges Setting debug privileges
3/20/2010 5:51:02 PM Microsoft Word for Windows Placed in group Low Restricted High value of threat rating calculated heuristically
3/20/2010 5:49:45 PM Adobe Reader 9.3 Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/20/2010 10:23:58 AM Allowed: Access to password storage Warcraft III Access to protected storage Access to password storage
3/20/2010 10:23:58 AM Warcraft III Placed in group Trusted
3/20/2010 10:23:42 AM Allowed: Using system program interfaces (DNS) Warcraft III Use DNS caching system for conversion useast.battle.net Using system program interfaces (DNS)
3/20/2010 10:23:27 AM Allowed: Setting debug privileges Warcraft III Setting debug privileges Setting debug privileges
3/20/2010 9:43:04 AM Windows TaskManager Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/20/2010 12:48:59 AM Frozen Throne Placed in group Trusted Known on the database of the known software
3/20/2010 12:48:59 AM Startup Manager for Windows 9x/Me/NT/2000/XP/2003/Vista Placed in group Trusted Known on the database of the known software
3/20/2010 12:00:33 AM Allowed: Access to password storage Warcraft III Access to protected storage Access to password storage
3/20/2010 12:00:22 AM Allowed: Using system program interfaces (DNS) Warcraft III Use DNS caching system for conversion useast.battle.net Using system program interfaces (DNS)
3/20/2010 12:00:08 AM Allowed: Setting debug privileges Warcraft III Setting debug privileges Setting debug privileges
3/20/2010 12:00:01 AM Warcraft III Placed in group Low Restricted High value of threat rating calculated heuristically
3/19/2010 11:59:54 PM Frozen Throne Placed in group Trusted Known on the database of the known software
3/19/2010 6:10:51 PM Microsoft Help Center Service Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/19/2010 4:59:10 PM Windows Calculator application file Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/19/2010 4:34:04 PM Adobe Flash Player 10.0 r42 Placed in group Low Restricted High value of threat rating calculated heuristically
3/19/2010 4:19:03 PM Adobe Reader and Acrobat Manager Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/19/2010 4:19:03 PM Allowed: Start driver Absent Start driver C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
3/19/2010 4:18:58 PM Adobe Acrobat SpeedLauncher Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/19/2010 4:18:51 PM Task started Kaspersky Internet Security Application Control
3/19/2010 12:47:37 PM Startup Manager for Windows 9x/Me/NT/2000/XP/2003/Vista Placed in group Trusted Known on the database of the known software
3/19/2010 12:46:55 PM Microsoft© Register Server Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/19/2010 12:46:50 PM Windows Command Processor Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/19/2010 12:46:47 PM UNINSTALLPDFREADERPLUGIN.EXE Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/19/2010 12:46:44 PM FOX5A.EXE Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/19/2010 12:46:43 PM UNINSTALL.EXE Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/19/2010 12:43:54 PM Adobe Flash Player 10.0 r42 Placed in group Trusted Known on the database of the known software
3/19/2010 12:43:51 PM Adobe Updater Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/19/2010 12:43:02 PM ACROREAD.MSI Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/19/2010 12:43:01 PM SETUP.EXE Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/19/2010 12:42:37 PM ADBERDR930_EN_US(2).EXE Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/19/2010 12:38:45 PM Userinit Logon Application Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/19/2010 12:38:38 PM Task started Kaspersky Internet Security Application Control
3/19/2010 1:47:02 AM AOL Instant Messenger Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/19/2010 12:42:30 AM _IU14D2N.TMP Placed in group Trusted Known on the database of the known software
3/19/2010 12:42:29 AM UNINS000.EXE Placed in group Trusted Known on the database of the known software
3/19/2010 12:41:48 AM Paint Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/19/2010 12:40:56 AM ADBERDR930_EN_US.EXE Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/19/2010 12:40:29 AM Java™ Platform SE binary Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/19/2010 12:40:28 AM Java™ Update Checker Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/19/2010 12:40:11 AM Windows Shell Common Dll Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/19/2010 12:40:10 AM Verify Class ID Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/19/2010 12:35:34 AM Allowed: Start driver Absent Start driver C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
3/19/2010 12:35:30 AM Image Mastering API Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/19/2010 12:35:30 AM System settings protector Placed in group Trusted Known on the database of the known software
3/19/2010 12:35:25 AM igfxTray Module Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/19/2010 12:35:23 AM Allowed: Changing object access rights OTL.EXE Changing object access rights REGISTRY\MACHINE\SOFTWARE\OldTimer Tools\OTL\Files Changing object access rights
3/19/2010 12:35:19 AM Allowed: Setting debug privileges OTL.EXE Setting debug privileges Setting debug privileges
3/19/2010 12:34:56 AM Windows Update Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/19/2010 12:34:49 AM Task started Kaspersky Internet Security Application Control
3/19/2010 12:33:10 AM Windows Logon UI Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/19/2010 12:33:10 AM Allowed: Exiting Microsoft Windows OTL.EXE Windows shutdown Exiting Microsoft Windows
3/19/2010 12:30:39 AM Allowed: Changing object access rights OTL.EXE Changing object access rights REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\NoExplorer Changing object access rights
3/19/2010 12:30:19 AM Allowed: Setting debug privileges OTL.EXE Setting debug privileges Setting debug privileges
3/18/2010 11:43:57 PM Notepad Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/18/2010 11:20:46 PM Allowed: Setting debug privileges OTL.EXE Setting debug privileges Setting debug privileges
3/18/2010 11:20:46 PM OTL.EXE Placed in group Low Restricted High value of threat rating calculated heuristically
3/18/2010 11:19:38 PM WMI Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/18/2010 11:17:34 PM WebToolBar component Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/18/2010 11:17:32 PM Java™ Quick Starter binary Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/18/2010 11:17:08 PM Firefox Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/18/2010 10:55:25 PM Logon Screen Saver Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/18/2010 10:45:16 PM Kaspersky Anti-Virus GUI Windows part Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/18/2010 10:45:15 PM Kaspersky Internet Security Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/18/2010 10:45:15 PM Windows® installer Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/18/2010 10:45:15 PM Windows Security Center Notification App Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/18/2010 10:45:15 PM CTF Loader Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/18/2010 10:45:15 PM igfxsrvc Module Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/18/2010 10:45:15 PM ActiveSync RAPI Manager Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/18/2010 10:45:14 PM ActiveSync Connection Manager Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/18/2010 10:45:14 PM Java™ Update Scheduler Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/18/2010 10:45:14 PM Adobe Photo Downloader 3.0 component Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/18/2010 10:45:13 PM persistence Module Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/18/2010 10:45:13 PM hkcmd Module Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/18/2010 10:45:13 PM SMax4PNP MFC Application Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/18/2010 10:45:12 PM Windows Explorer Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/18/2010 10:45:11 PM Windows Genuine Advantage Notifications Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/18/2010 10:45:11 PM Application Layer Gateway Service Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/18/2010 10:45:11 PM AutoUpater Service Module Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/18/2010 10:45:10 PM User Mode Tablet Driver Placed in group Low Restricted High value of threat rating calculated heuristically
3/18/2010 10:45:09 PM WMDM PMSP Service Placed in group Trusted Known on the database of the known software
3/18/2010 10:45:09 PM ViewMgr Placed in group Trusted Known on the database of the known software
3/18/2010 10:45:08 PM Java™ Quick Starter Service Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/18/2010 10:45:08 PM EPSON Status Monitor 3 Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/18/2010 10:45:08 PM EPSON Status Monitor 3 Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/18/2010 10:45:07 PM PHOTOSHOPELEMENTSFILEAGENT.EXE Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/18/2010 10:45:06 PM Spooler SubSystem App Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/18/2010 10:45:06 PM Generic Host Process for Win32 Services Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/18/2010 10:45:06 PM LSA Shell (Export Version) Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/18/2010 10:45:06 PM Services and Controller app Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/18/2010 10:45:06 PM Windows NT Logon Application Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/18/2010 10:45:06 PM Client Server Runtime Process Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/18/2010 10:45:06 PM Windows NT Session Manager Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/18/2010 10:45:01 PM Task started Kaspersky Internet Security Application Control
Proactive Defense (events: 5)
3/21/2010 9:55:27 AM Task started Kaspersky Internet Security Proactive Defense
3/19/2010 4:18:51 PM Task started Kaspersky Internet Security Proactive Defense
3/19/2010 12:38:39 PM Task started Kaspersky Internet Security Proactive Defense
3/19/2010 12:34:50 AM Task started Kaspersky Internet Security Proactive Defense
3/18/2010 10:45:01 PM Task started Kaspersky Internet Security Proactive Defense
License manager (events: 1)
3/20/2010 12:04:04 AM License validity period expires soon Kaspersky Internet Security
Firewall (events: 5)
3/21/2010 9:55:27 AM Task started Kaspersky Internet Security Firewall
3/19/2010 4:18:51 PM Task started Kaspersky Internet Security Firewall
3/19/2010 12:38:38 PM Task started Kaspersky Internet Security Firewall
3/19/2010 12:34:49 AM Task started Kaspersky Internet Security Firewall
3/18/2010 10:45:01 PM Task started Kaspersky Internet Security Firewall
IM Anti-Virus (events: 5)
3/21/2010 9:55:27 AM Task started Kaspersky Internet Security IM Anti-Virus
3/19/2010 4:18:51 PM Task started Kaspersky Internet Security IM Anti-Virus
3/19/2010 12:38:39 PM Task started Kaspersky Internet Security IM Anti-Virus
3/19/2010 12:34:50 AM Task started Kaspersky Internet Security IM Anti-Virus
3/18/2010 10:45:01 PM Task started Kaspersky Internet Security IM Anti-Virus
Objects Scan (events: 10)
3/21/2010 10:31:34 AM Task completed Kaspersky Internet Security Rootkit Scan
3/21/2010 10:25:36 AM Task started Kaspersky Internet Security Rootkit Scan
3/20/2010 4:55:08 PM Task completed Kaspersky Internet Security Rootkit Scan
3/20/2010 4:48:59 PM Task started Kaspersky Internet Security Rootkit Scan
3/19/2010 4:55:59 PM Task completed Kaspersky Internet Security Rootkit Scan
3/19/2010 4:48:59 PM Task started Kaspersky Internet Security Rootkit Scan
3/19/2010 1:09:46 AM Task completed Kaspersky Internet Security Rootkit Scan
3/19/2010 1:04:53 AM Task started Kaspersky Internet Security Rootkit Scan
3/18/2010 11:22:40 PM Task completed Kaspersky Internet Security Rootkit Scan
3/18/2010 11:15:02 PM Task started Kaspersky Internet Security Rootkit Scan
My Update Center (events: 36)
3/21/2010 8:33:04 PM Task completed Kaspersky Internet Security My Update Center
3/21/2010 8:30:39 PM Task started Kaspersky Internet Security My Update Center
3/21/2010 6:13:50 PM Task completed Kaspersky Internet Security My Update Center
3/21/2010 6:11:33 PM Task started Kaspersky Internet Security My Update Center
3/21/2010 1:18:42 AM Task completed Kaspersky Internet Security My Update Center
3/21/2010 1:15:47 AM Task started Kaspersky Internet Security My Update Center
3/20/2010 11:02:19 PM Task completed Kaspersky Internet Security My Update Center Not all components were updated
3/20/2010 9:35:03 PM Task started Kaspersky Internet Security My Update Center
3/20/2010 7:17:04 PM Task completed Kaspersky Internet Security My Update Center
3/20/2010 7:15:02 PM Task started Kaspersky Internet Security My Update Center
3/20/2010 4:56:35 PM Task completed Kaspersky Internet Security My Update Center
3/20/2010 4:55:01 PM Task started Kaspersky Internet Security My Update Center
3/20/2010 2:37:03 PM Task completed Kaspersky Internet Security My Update Center
3/20/2010 2:35:01 PM Task started Kaspersky Internet Security My Update Center
3/20/2010 12:19:53 PM Task completed Kaspersky Internet Security My Update Center Not all components were updated
3/20/2010 11:14:51 AM Task started Kaspersky Internet Security My Update Center
3/20/2010 8:56:33 AM Task completed Kaspersky Internet Security My Update Center
3/20/2010 8:54:31 AM Task started Kaspersky Internet Security My Update Center
3/20/2010 6:35:59 AM Task completed Kaspersky Internet Security My Update Center
3/20/2010 6:34:31 AM Task started Kaspersky Internet Security My Update Center
3/20/2010 4:16:39 AM Task completed Kaspersky Internet Security My Update Center
3/20/2010 4:14:31 AM Task started Kaspersky Internet Security My Update Center
3/20/2010 1:56:48 AM Task completed Kaspersky Internet Security My Update Center
3/20/2010 1:54:31 AM Task started Kaspersky Internet Security My Update Center
3/19/2010 11:36:47 PM Task completed Kaspersky Internet Security My Update Center
3/19/2010 11:34:31 PM Task started Kaspersky Internet Security My Update Center
3/19/2010 9:16:44 PM Task completed Kaspersky Internet Security My Update Center
3/19/2010 9:14:31 PM Task started Kaspersky Internet Security My Update Center
3/19/2010 6:56:50 PM Task completed Kaspersky Internet Security My Update Center
3/19/2010 6:54:31 PM Task started Kaspersky Internet Security My Update Center
3/19/2010 4:36:32 PM Task completed Kaspersky Internet Security My Update Center
3/19/2010 4:34:04 PM Task started Kaspersky Internet Security My Update Center
3/19/2010 1:11:44 AM Task completed Kaspersky Internet Security My Update Center
3/19/2010 1:09:56 AM Task started Kaspersky Internet Security My Update Center
3/18/2010 10:50:02 PM Task completed Kaspersky Internet Security My Update Center Not all components were updated
3/18/2010 10:45:17 PM Task started Kaspersky Internet Security My Update Center
Date: Today (events: 90)
My Protection (events: 1)
3/22/2010 11:53:12 AM Your computer is protected Kaspersky Internet Security
File Anti-Virus (events: 11)
3/22/2010 3:29:04 PM Processing error User Mode Tablet Driver C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\Tablet\aiptbl.ini Read error
3/22/2010 3:28:05 PM Processing error User Mode Tablet Driver C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\Tablet\aiptbl.ini Read error
3/22/2010 3:27:33 PM Processing error User Mode Tablet Driver C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\Tablet\aiptbl.ini Read error
3/22/2010 3:25:23 PM Processing error User Mode Tablet Driver C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\Tablet\aiptbl.ini Read error
3/22/2010 3:25:05 PM Processing error User Mode Tablet Driver C:\WINDOWS\win.ini Read error
3/22/2010 3:24:38 PM Processing error User Mode Tablet Driver C:\WINDOWS\win.ini Read error
3/22/2010 3:21:56 PM Processing error User Mode Tablet Driver C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\Tablet\aiptbl.ini Read error
3/22/2010 3:21:26 PM Processing error User Mode Tablet Driver C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\Tablet\aiptbl.ini Read error
3/22/2010 3:20:48 PM Processing error User Mode Tablet Driver C:\WINDOWS\win.ini Read error
3/22/2010 2:03:42 PM Processing error Absent D Read error
3/22/2010 11:53:11 AM Task started Kaspersky Internet Security File Anti-Virus
Mail Anti-Virus (events: 1)
3/22/2010 11:53:11 AM Task started Kaspersky Internet Security Mail Anti-Virus
Web Anti-Virus (events: 1)
3/22/2010 11:53:11 AM Task started Kaspersky Internet Security Web Anti-Virus
Network Attack Blocker (events: 1)
3/22/2010 11:53:11 AM Task started Kaspersky Internet Security Network Attack Blocker
Anti-Spam (events: 1)
3/22/2010 11:53:11 AM Task started Kaspersky Internet Security Anti-Spam
Application Control (events: 65)
3/22/2010 3:42:00 PM Notepad Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/22/2010 2:58:16 PM Allowed: Changing object access rights SWREG.CFXXE Changing object access rights REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows Changing object access rights
3/22/2010 2:58:15 PM Allowed: Changing object access rights SWREG.CFXXE Changing object access rights REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows Changing object access rights
3/22/2010 2:58:15 PM NIRCMDB.EXE Placed in group Trusted Known on the database of the known software
3/22/2010 2:58:14 PM Allowed: Changing object access rights SWREG.CFXXE Changing object access rights REGISTRY\USER\S-1-5-21-2025429265-308236825-725345543-500\Console Changing object access rights
3/22/2010 2:58:13 PM FIN.DAT Placed in group Low Restricted High value of threat rating calculated heuristically
3/22/2010 2:58:13 PM Allowed: Setting debug privileges PEV.cfxxe Setting debug privileges Setting debug privileges
3/22/2010 2:57:59 PM NIRCMD.exe Placed in group Trusted Known on the database of the known software
3/22/2010 2:57:59 PM Allowed: Using program interfaces of other process CSCRIPT.CFXXE Using program interfaces of other process c:\combofix\cscript.cfxxe Using program interfaces of other process
3/22/2010 2:57:59 PM Allowed: Access to critical system objects CSCRIPT.CFXXE Access to critical system objects Access to critical system objects
3/22/2010 2:57:59 PM CSCRIPT.CFXXE Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/22/2010 2:57:56 PM SWXCACLS.CFXXE Placed in group Trusted Known on the database of the known software
3/22/2010 2:57:56 PM REHIDE.REG Placed in group Low Restricted High value of threat rating calculated heuristically
3/22/2010 2:57:54 PM Allowed: Setting debug privileges PV.CFXXE Setting debug privileges Setting debug privileges
3/22/2010 2:57:54 PM PV.CFXXE Placed in group Trusted Known on the database of the known software
3/22/2010 2:57:52 PM PEV.cfxxe Placed in group Low Restricted High value of threat rating calculated heuristically
3/22/2010 2:57:52 PM NIRCMDC.CFXXE Placed in group Trusted Known on the database of the known software
3/22/2010 2:57:51 PM ATTRIB.CFXXE Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/22/2010 2:57:51 PM SED.CFXXE Placed in group Trusted Known on the database of the known software
3/22/2010 2:57:51 PM SWREG.CFXXE Placed in group Trusted Known on the database of the known software
3/22/2010 2:57:50 PM GREP.CFXXE Placed in group Trusted Known on the database of the known software
3/22/2010 2:57:50 PM SWSC.CFXXE Placed in group Trusted Known on the database of the known software
3/22/2010 2:57:48 PM NIRCMD.CFXXE Placed in group Trusted Known on the database of the known software
3/22/2010 2:57:47 PM Attribute Utility Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/22/2010 2:57:46 PM CF17377.CFXXE Placed in group Low Restricted High value of threat rating calculated heuristically
3/22/2010 2:57:45 PM Allowed: Setting debug privileges PV.CFXXE Setting debug privileges Setting debug privileges
3/22/2010 2:57:40 PM Allowed: Setting debug privileges PV.CFXXE Setting debug privileges Setting debug privileges
3/22/2010 2:57:40 PM Allowed: Using program interfaces of other process CSCRIPT.CFXXE Using program interfaces of other process c:\32788r22fwjfw\cscript.cfxxe Using program interfaces of other process
3/22/2010 2:57:40 PM Allowed: Access to critical system objects CSCRIPT.CFXXE Access to critical system objects Access to critical system objects
3/22/2010 2:57:28 PM Allowed: Setting debug privileges PV.CFXXE Setting debug privileges Setting debug privileges
3/22/2010 2:57:28 PM PV.CFXXE Placed in group Trusted Known on the database of the known software
3/22/2010 2:57:27 PM Allowed: Using program interfaces of other process CSCRIPT.CFXXE Using program interfaces of other process c:\32788r22fwjfw\cscript.cfxxe Using program interfaces of other process
3/22/2010 2:57:27 PM Allowed: Access to critical system objects CSCRIPT.CFXXE Access to critical system objects Access to critical system objects
3/22/2010 2:57:26 PM CSCRIPT.CFXXE Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/22/2010 2:57:26 PM ATTRIB.CFXXE Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/22/2010 2:57:25 PM Allowed: Changing object access rights SWREG.cfxxe Changing object access rights REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows Changing object access rights
3/22/2010 2:57:24 PM Allowed: Changing object access rights SWREG.cfxxe Changing object access rights REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Changing object access rights
3/22/2010 2:57:22 PM Change CodePage Utility Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/22/2010 2:57:22 PM Allowed: Changing object access rights SWREG.cfxxe Changing object access rights REGISTRY\USER\S-1-5-21-2025429265-308236825-725345543-500\console_combofixbackup Changing object access rights
3/22/2010 2:57:21 PM PEV.cfxxe Placed in group Low Restricted High value of threat rating calculated heuristically
3/22/2010 2:57:20 PM sed.cfxxe Placed in group Trusted Known on the database of the known software
3/22/2010 2:57:16 PM SWREG.cfxxe Placed in group Trusted Known on the database of the known software
3/22/2010 2:57:15 PM GREP.CFXXE Placed in group Trusted Known on the database of the known software
3/22/2010 2:57:14 PM CMD.CFXXE Placed in group Low Restricted High value of threat rating calculated heuristically
3/22/2010 2:57:11 PM gsar.cfxxe Placed in group Trusted Known on the database of the known software
3/22/2010 2:57:11 PM Allowed: Changing object access rights swreg.exe Changing object access rights REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 Changing object access rights
3/22/2010 2:57:10 PM NirCmd.cfxxe Placed in group Trusted Known on the database of the known software
3/22/2010 2:57:09 PM Windows Progman Group Converter Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/22/2010 2:57:07 PM Allowed: Changing object access rights swreg.exe Changing object access rights REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows Changing object access rights
3/22/2010 2:57:07 PM Run Once Wrapper Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/22/2010 2:57:06 PM Allowed: Changing object access rights swreg.exe Changing object access rights REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows Changing object access rights
3/22/2010 2:57:05 PM SWXCACLS.CFXXE Placed in group Trusted Known on the database of the known software
3/22/2010 2:57:05 PM swreg.exe Placed in group Trusted Known on the database of the known software
3/22/2010 2:57:04 PM Windows Setup API Placed in group Trusted Signed by the digital signature of entrusted manufacturers
3/22/2010 2:57:02 PM Allowed: Setting debug privileges iexplore.exe Setting debug privileges Setting debug privileges
3/22/2010 2:57:01 PM Allowed: Setting debug privileges n.pif Setting debug privileges Setting debug privileges
3/22/2010 2:57:01 PM pev.exe Placed in group Low Restricted High value of threat rating calculated heuristically
3/22/2010 2:57:01 PM n.pif Placed in group Trusted Known on the database of the known software
3/22/2010 2:57:00 PM iexplore.exe Placed in group Low Restricted High value of threat rating calculated heuristically
3/22/2010 2:56:59 PM HIDEC.EXE Placed in group Trusted Known on the database of the known software
3/22/2010 2:56:57 PM iexplore.exe Placed in group Trusted Known on the database of the known software
3/22/2010 2:56:54 PM Allowed: Setting debug privileges ComboFix.exe Setting debug privileges Setting debug privileges
3/22/2010 2:56:49 PM ComboFix.exe Placed in group Low Restricted High value of threat rating calculated heuristically
3/22/2010 2:03:26 PM Allowed: Start driver Absent Start driver C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS Start driver
3/22/2010 11:53:11 AM Task started Kaspersky Internet Security Application Control
Proactive Defense (events: 1)
3/22/2010 11:53:11 AM Task started Kaspersky Internet Security Proactive Defense
Firewall (events: 1)
3/22/2010 11:53:11 AM Task started Kaspersky Internet Security Firewall
IM Anti-Virus (events: 1)
3/22/2010 11:53:11 AM Task started Kaspersky Internet Security IM Anti-Virus
Objects Scan (events: 2)
3/22/2010 12:32:05 PM Task completed Kaspersky Internet Security Rootkit Scan
3/22/2010 12:23:21 PM Task started Kaspersky Internet Security Rootkit Scan
My Update Center (events: 4)
3/22/2010 2:55:02 PM Task completed Kaspersky Internet Security My Update Center
3/22/2010 2:52:43 PM Task started Kaspersky Internet Security My Update Center
3/22/2010 12:35:14 PM Task completed Kaspersky Internet Security My Update Center
3/22/2010 12:09:23 PM Task started Kaspersky Internet Security My Update Center







This is a random side question, but how are you able to print screen and copy on in this text field? I always have difficulty with it for some reason and never seems to work for me.
Hi,

That is only something that was accessed on that web page that Kaspersky detected as a suspicious script based on heuristics


it will be in your temporary internet files

Use the TFC program to clean temp files often.


Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean
It's normal after running TFC cleaner that the PC will be slower to boot the first time.


nothing to be too concerned about.
Phew! Thought it was something else serious to worry about. Seems the only thing that's stopping me from fully securing this computer is the fact that the operating system on this PC is not Microsoft Windows Genuine and I have the little star on the task bar that says Your system may be at risk….. Apparently this computer was bought from a computer flea market vendor in a town nearby by my mother. I had the same problem with my laptop. I'm not sure if Microsoft will help with authenticating this computer with a valid key. They helped me with this with my laptop and my primary PC that became infected with a serious virus and had to reformat with a windows xp recovery cd. It almost seems to me if your computer is infected badly enough beyond reformat, you have to spring for another operating system disc. I bring this up just out of curiosity of what you would suggest. I take it Microsoft would view my slight misfortune with this computer not being genuine and being sold from a random flea market as arbitrary and irrelevant. Your thoughts? By the way, if this is something I should be discussing on another section, I don't mind doing so Thank you!
My recommendation is to talk to Microsoft about the situation so that you may validate your Operating System, regardless of the fact you may have been duped by the seller of the computer, it is still your responsibility to make things right with Microsoft. We do not condone the use of non genuine Windows and strongly suggest you obtain a valid license from Microsoft.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI