PDA

View Full Version : Smitfraud-C and Zlob.Downloader



bandit1200
2008-01-07, 16:51
Hi!

I have already had a thread (http://forums.spybot.info/showthread.php?t=21605&highlight=bandit1200) but this was closed because too much time passed without any action of mine (sorry, but it was Christmas and our office was closed). So here is the new thread with a new HijackThis Log.

Spybot does not dectect malware anymore. A new virus scan by Kaspersky's has not been made, yet.

Thanks and my apologize for the inconvenience.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:41:50, on 07.01.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programme\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\a-squared Free\a2service.exe
C:\Programme\MSI\Bluetooth Software\bin\btwdins.exe
C:\Programme\F-Secure\Anti-Virus\fsgk32st.exe
C:\Programme\F-Secure\Common\FSMA32.EXE
C:\Programme\F-Secure\Anti-Virus\FSGK32.EXE
C:\WINDOWS\System32\GEARSec.exe
C:\Programme\F-Secure\Common\FSMB32.EXE
C:\Programme\F-Secure\Common\FCH32.EXE
C:\Programme\F-Secure\Common\FAMEH32.EXE
C:\Programme\F-Secure\Anti-Virus\fsqh.exe
C:\Programme\CDBurnerXP\NMSAccessU.exe
C:\WINDOWS\System32\svchost.exe
C:\Programme\PowerQuest\Drive Image 7.0\Agent\PQV2iSvc.exe
C:\Programme\F-Secure\Common\FNRB32.EXE
C:\Programme\F-Secure\Anti-Virus\fssm32.exe
C:\Programme\F-Secure\FSAUA\program\fsaua.exe
C:\Programme\F-Secure\FWES\Program\fsdfwd.exe
C:\Programme\F-Secure\Common\FIH32.EXE
C:\WINDOWS\Explorer.EXE
C:\Programme\F-Secure\Anti-Virus\fsav32.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Programme\CyberLink\PowerDVD\DVDLauncher.exe
C:\Programme\Java\jre1.6.0_03\bin\jusched.exe
C:\Programme\F-Secure\Common\FSM32.EXE
C:\Programme\SigmaTel\SigmaTel AC97 Audio-Treiber\stacmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programme\Spybot - Search & Destroy\TeaTimer.exe
C:\Programme\MSI\Bluetooth Software\BTTray.exe
C:\Programme\F-Secure\FSGUI\fsguidll.exe
C:\Programme\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Programme\ACT\act.exe
C:\Programme\Mozilla Firefox\firefox.exe
C:\Programme\Microsoft Office\OFFICE11\EXCEL.EXE
D:\Security Tools\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.de/firefox
O2 - BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Programme\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Copernic Desktop Search 2 - {968631B6-4729-440D-9BF4-251F5593EC9A} - C:\Programme\Copernic Desktop Search 2\DesktopSearchBand201013011.dll
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Programme\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programme\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Programme\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Programme\F-Secure\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Programme\F-Secure\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programme\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SigmaTel StacMon] C:\Programme\SigmaTel\SigmaTel AC97 Audio-Treiber\stacmon.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programme\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: BTTray.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Easy-WebPrint - Drucken - res://C:\Programme\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint - Schnelldruck - res://C:\Programme\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint - Vorschau - res://C:\Programme\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint - Zu Druckliste hinzufügen - res://C:\Programme\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {485D813E-EE26-4DF8-9FAF-DEDF2885306E} (NSHelp Class) - http://sbsserver1/connectcomputer/nshelp.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1098970218097
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file://C:\Programme\AutoCAD 2002\AcDcToday.ocx
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://C:\Programme\AutoCAD 2002\AcPreview.ocx
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = Telesis.local
O17 - HKLM\Software\..\Telephony: DomainName = Telesis.local
O17 - HKLM\System\CCS\Services\Tcpip\..\{E8992EDF-C2EE-4E95-B1F3-93B9150B0AEE}: NameServer = 192.168.120.252,192.168.120.253
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = Telesis.local
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Programme\a-squared Free\a2service.exe
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Programme\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Programme\MSI\Bluetooth Software\bin\btwdins.exe
O23 - Service: AVM FRITZ!web Routing Service (de_serv) - AVM Berlin - C:\Programme\Gemeinsame Dateien\AVM\de_serv.exe
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Programme\F-Secure\Anti-Virus\fsgk32st.exe
O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Programme\F-Secure\Common\FNRB32.EXE
O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Programme\F-Secure\FSAUA\program\fsaua.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Programme\F-Secure\FWES\Program\fsdfwd.exe
O23 - Service: FSMA - F-Secure Corporation - C:\Programme\F-Secure\Common\FSMA32.EXE
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Programme\CDBurnerXP\NMSAccessU.exe
O23 - Service: V2i Protector - PowerQuest Corporation - C:\Programme\PowerQuest\Drive Image 7.0\Agent\PQV2iSvc.exe

--
End of file - 8112 bytes

bandit1200
2008-01-08, 11:39
Hi!

Here is also the latest Kaspersky log file.

As it seems my PC should be clean :bigthumb:.

What do you think?

Thanks again.

Bandit

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Tuesday, January 08, 2008 11:33:43 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 8/01/2008
Kaspersky Anti-Virus database records: 504058
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - Folders:
C:\
D:\

Scan Statistics:
Total number of scanned objects: 51176
Number of viruses found: 0
Number of infected objects: 0
Number of suspicious objects: 0
Duration of the scan process: 01:09:57

Infected Object Name / Virus Name / Last Action
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\F-Secure\Logs\FSMA\fsma.log Object is locked skipped
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Cookies\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Verlauf\History.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\NTUSER.DAT Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\NTUSER.DAT Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\thohig.THOHIG-LAPTOP\Anwendungsdaten\Microsoft\Outlook\Standard.NK2 Object is locked skipped
C:\Dokumente und Einstellungen\thohig.THOHIG-LAPTOP\Anwendungsdaten\Microsoft\Outlook\Standard.srs Object is locked skipped
C:\Dokumente und Einstellungen\thohig.THOHIG-LAPTOP\Cookies\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\thohig.THOHIG-LAPTOP\Lokale Einstellungen\Anwendungsdaten\Microsoft\Outlook\archive.pst Object is locked skipped
C:\Dokumente und Einstellungen\thohig.THOHIG-LAPTOP\Lokale Einstellungen\Anwendungsdaten\Microsoft\Outlook\mailbox.PAB Object is locked skipped
C:\Dokumente und Einstellungen\thohig.THOHIG-LAPTOP\Lokale Einstellungen\Anwendungsdaten\Microsoft\Outlook\outlook.ost Object is locked skipped
C:\Dokumente und Einstellungen\thohig.THOHIG-LAPTOP\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Dokumente und Einstellungen\thohig.THOHIG-LAPTOP\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\thohig.THOHIG-LAPTOP\Lokale Einstellungen\Temp\ExchangePerflog_8484fa31adb63fd23925e066.dat Object is locked skipped
C:\Dokumente und Einstellungen\thohig.THOHIG-LAPTOP\Lokale Einstellungen\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\thohig.THOHIG-LAPTOP\Lokale Einstellungen\Verlauf\History.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\thohig.THOHIG-LAPTOP\Lokale Einstellungen\Verlauf\History.IE5\MSHist012008010820080109\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\thohig.THOHIG-LAPTOP\NTUSER.DAT Object is locked skipped
C:\Dokumente und Einstellungen\thohig.THOHIG-LAPTOP\ntuser.dat.LOG Object is locked skipped
C:\Programme\F-Secure\Anti-Virus\dbupdate.log Object is locked skipped
C:\Programme\F-Secure\Anti-Virus\deleteme_msg.log Object is locked skipped
C:\Programme\F-Secure\Anti-Virus\fsqh.exe.Qrt.log Object is locked skipped
C:\Programme\F-Secure\Anti-Virus\power.dat Object is locked skipped
C:\Programme\F-Secure\common\policy.bpf Object is locked skipped
C:\Programme\F-Secure\common\policy.ipf Object is locked skipped
C:\Programme\F-Secure\FSAUA\program\fsaua.dbg Object is locked skipped
C:\Programme\F-Secure\FSAUA\program\fsaua.log Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{EABF3E0D-85E8-4957-A3B9-F411E556CBEF}\RP2\change.log Object is locked skipped
C:\WINDOWS\CSC\00000001 Object is locked skipped
C:\WINDOWS\CSC\00000002 Object is locked skipped
C:\WINDOWS\CSC\00000003 Object is locked skipped
C:\WINDOWS\CSC\d1\80000058 Object is locked skipped
C:\WINDOWS\CSC\d1\80000188 Object is locked skipped
C:\WINDOWS\CSC\d1\80000470 Object is locked skipped
C:\WINDOWS\CSC\d1\80000478 Object is locked skipped
C:\WINDOWS\CSC\d1\80000480 Object is locked skipped
C:\WINDOWS\CSC\d1\800004C8 Object is locked skipped
C:\WINDOWS\CSC\d1\800004F8 Object is locked skipped
C:\WINDOWS\CSC\d2\00000019 Object is locked skipped
C:\WINDOWS\CSC\d2\00000601 Object is locked skipped
C:\WINDOWS\CSC\d2\80000129 Object is locked skipped
C:\WINDOWS\CSC\d2\800004C9 Object is locked skipped
C:\WINDOWS\CSC\d2\80000519 Object is locked skipped
C:\WINDOWS\CSC\d3\0000117A Object is locked skipped
C:\WINDOWS\CSC\d3\800000CA Object is locked skipped
C:\WINDOWS\CSC\d3\8000011A Object is locked skipped
C:\WINDOWS\CSC\d3\8000012A Object is locked skipped
C:\WINDOWS\CSC\d3\8000015A Object is locked skipped
C:\WINDOWS\CSC\d3\80000402 Object is locked skipped
C:\WINDOWS\CSC\d3\80000472 Object is locked skipped
C:\WINDOWS\CSC\d3\8000047A Object is locked skipped
C:\WINDOWS\CSC\d3\80000482 Object is locked skipped
C:\WINDOWS\CSC\d3\800004CA Object is locked skipped
C:\WINDOWS\CSC\d3\80000522 Object is locked skipped
C:\WINDOWS\CSC\d4\000005BB Object is locked skipped
C:\WINDOWS\CSC\d4\000010EB Object is locked skipped
C:\WINDOWS\CSC\d4\80000053 Object is locked skipped
C:\WINDOWS\CSC\d4\8000012B Object is locked skipped
C:\WINDOWS\CSC\d4\8000047B Object is locked skipped
C:\WINDOWS\CSC\d4\80000483 Object is locked skipped
C:\WINDOWS\CSC\d4\800004CB Object is locked skipped
C:\WINDOWS\CSC\d4\800004E3 Object is locked skipped
C:\WINDOWS\CSC\d4\80000503 Object is locked skipped
C:\WINDOWS\CSC\d5\80000054 Object is locked skipped
C:\WINDOWS\CSC\d5\8000012C Object is locked skipped
C:\WINDOWS\CSC\d5\8000047C Object is locked skipped
C:\WINDOWS\CSC\d5\80000504 Object is locked skipped
C:\WINDOWS\CSC\d6\00000215 Object is locked skipped
C:\WINDOWS\CSC\d6\80000055 Object is locked skipped
C:\WINDOWS\CSC\d6\8000012D Object is locked skipped
C:\WINDOWS\CSC\d6\80000465 Object is locked skipped
C:\WINDOWS\CSC\d6\80000485 Object is locked skipped
C:\WINDOWS\CSC\d6\8000051D Object is locked skipped
C:\WINDOWS\CSC\d7\00000216 Object is locked skipped
C:\WINDOWS\CSC\d7\000004C6 Object is locked skipped
C:\WINDOWS\CSC\d7\800003FE Object is locked skipped
C:\WINDOWS\CSC\d7\8000047E Object is locked skipped
C:\WINDOWS\CSC\d7\800004EE Object is locked skipped
C:\WINDOWS\CSC\d7\8000051E Object is locked skipped
C:\WINDOWS\CSC\d8\00000217 Object is locked skipped
C:\WINDOWS\CSC\d8\80000057 Object is locked skipped
C:\WINDOWS\CSC\d8\80000187 Object is locked skipped
C:\WINDOWS\CSC\d8\800003FF Object is locked skipped
C:\WINDOWS\CSC\d8\80000487 Object is locked skipped
C:\WINDOWS\CSC\d8\800004C7 Object is locked skipped
C:\WINDOWS\Debug\Netlogon.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{884CD4AC-54E7-4B49-A574-1EB5ACAB29D0}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\AVP8560.tmp Object is locked skipped
C:\WINDOWS\Temp\AVP8561.tmp Object is locked skipped
C:\WINDOWS\Temp\AVP8564.tmp Object is locked skipped
C:\WINDOWS\Temp\AVP8565.tmp Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\Postoffice\archive.pst Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

Scan process completed.

pskelley
2008-01-08, 13:21
Welcome to Safer Networking, I wish to be sure you have viewed and understand this information.
"BEFORE you POST" (READ this Procedure before Requesting Assistance)
http://forums.spybot.info/showthread.php?t=288
All advice given is taken at your own risk.
Please make sure you have read this information so we are on the same page.

You said:

but this was closed because too much time passed without any action of mine (sorry, but it was Christmas and our office was closed).
For your information:

Note: When the infected computer in question is a company machine in the workplace, and you are an employee.
Your organization must give their permission for assistance to be received in the removal of malware. The intention of this forum is not to replace a company's IT department.
More than one machine could be at stake, possibly even the server. If sensitive material has been compromised by an infection, the company could be held liable.
Please inform your IT department or Supervisor when a workplace computer has been infected, immediately.
Thank you for your understanding.
Having said that, I can say your HJT log looks clean as well as your Kaspersky scan.

Some good information for you:
http://users.telenet.be/bluepatchy/miekiemoes/slowcomputer.html

Here is some great information from experts in this field that will help you stay clean and safe online.
http://users.telenet.be/bluepatchy/miekiemoes/prevention.html
http://forums.spybot.info/showthread.php?t=279
http://russelltexas.com/malware/allclear.htm
http://forum.malwareremoval.com/viewtopic.php?t=14
http://www.bleepingcomputer.com/forums/topict2520.html
http://cybercoyote.org/security/not-admin.shtml

Thanks...pskelley
Safer Networking Forums
http://www.spybot.info/en/donate/index.html
If you are reading this information...thank a teacher,
If you are reading it in English...thank a soldier.