LaptopWrecked
Posts: 39 +0
Hi.
I have been infected by this malware. Had to create a new user account to access my programs. Most desktop icons gone. Program list missing. Documents missing access to them, but still there if I go to the new adminstrator account.
Have begun 7 steps of fixing to create damage logs from the other help thread.
Ran RKILL and MBAM.EXE to clean malware from running, but system still damaged.
GMER log below:
GMER 1.0.15.15640 - http://www.gmer.net
Rootkit scan 2011-06-10 03:24:20
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 HTS721060G9AT00 rev.MC3OA40M
Running: 0mnpk6mt.exe; Driver: C:\DOCUME~1\FIXASU~1.000\LOCALS~1\Temp\kxtdykoc.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\system32\drivers\sbaphd.sys (Sunbelt ActiveProtection hook driver/Sunbelt Software) ZwCreateKey [0xF79BD4D0]
SSDT \SystemRoot\system32\drivers\sbaphd.sys (Sunbelt ActiveProtection hook driver/Sunbelt Software) ZwSetValueKey [0xF79BD520]
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe[552] USER32.dll!SetScrollInfo 7E419056 5 Bytes JMP 00688BF0 C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe (VZAccess Manager/Smith Micro Software, Inc.)
.text C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe[552] USER32.dll!GetScrollInfo 7E42DFE2 5 Bytes JMP 00688B40 C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe (VZAccess Manager/Smith Micro Software, Inc.)
.text C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe[552] USER32.dll!ShowScrollBar 7E42F2F2 5 Bytes JMP 00688CC0 C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe (VZAccess Manager/Smith Micro Software, Inc.)
.text C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe[552] USER32.dll!GetScrollPos 7E42F704 5 Bytes JMP 00688B80 C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe (VZAccess Manager/Smith Micro Software, Inc.)
.text C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe[552] USER32.dll!SetScrollPos 7E42F750 5 Bytes JMP 00688C30 C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe (VZAccess Manager/Smith Micro Software, Inc.)
.text C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe[552] USER32.dll!GetScrollRange 7E42F787 5 Bytes JMP 00688BB0 C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe (VZAccess Manager/Smith Micro Software, Inc.)
.text C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe[552] USER32.dll!SetScrollRange 7E42F99B 5 Bytes JMP 00688C70 C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe (VZAccess Manager/Smith Micro Software, Inc.)
.text C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe[552] USER32.dll!EnableScrollBar 7E468005 5 Bytes JMP 00688B00 C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe (VZAccess Manager/Smith Micro Software, Inc.)
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\Tcpip \Device\Ip sbtis.sys (Sunbelt TDI Inspection System/Sunbelt Software)
AttachedDevice \Driver\Tcpip \Device\Ip TFilter.sys (TFilter Kernel Module/Avanquest North America, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 mouclass.sys (Mouse Class Driver/Microsoft Corporation)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp sbtis.sys (Sunbelt TDI Inspection System/Sunbelt Software)
AttachedDevice \Driver\Tcpip \Device\Tcp TFilter.sys (TFilter Kernel Module/Avanquest North America, Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp sbtis.sys (Sunbelt TDI Inspection System/Sunbelt Software)
AttachedDevice \Driver\Tcpip \Device\Udp TFilter.sys (TFilter Kernel Module/Avanquest North America, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp sbtis.sys (Sunbelt TDI Inspection System/Sunbelt Software)
AttachedDevice \Driver\Tcpip \Device\RawIp TFilter.sys (TFilter Kernel Module/Avanquest North America, Inc.)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SOFTWARE\Classes\CLSID\{9F9FDD4A-11DE-0279-B037-7668911670D9}\InprocServer32@ C:\WINDOWS\system32\ole32.dll
Reg HKLM\SOFTWARE\Classes\CLSID\{9F9FDD4A-11DE-0279-B037-7668911670D9}\InprocServer32@ThreadingModel Both
---- Files - GMER 1.0.15 ----
File C:\Documents and Settings\XXXXXXXXXX\Application Data\Macromedia\Flash Player\#SharedObjects\HN5V2ALN\www.acousticguitar.com.\flowplayer.commercial-3.1.5.swf 0 bytes
File C:\Documents and Settings\XXXXXXXXXX\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.acousticguitar.com.\settings.sol 93 bytes
---- EOF - GMER 1.0.15 ----
THANKS!
I have been infected by this malware. Had to create a new user account to access my programs. Most desktop icons gone. Program list missing. Documents missing access to them, but still there if I go to the new adminstrator account.
Have begun 7 steps of fixing to create damage logs from the other help thread.
Ran RKILL and MBAM.EXE to clean malware from running, but system still damaged.
GMER log below:
GMER 1.0.15.15640 - http://www.gmer.net
Rootkit scan 2011-06-10 03:24:20
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 HTS721060G9AT00 rev.MC3OA40M
Running: 0mnpk6mt.exe; Driver: C:\DOCUME~1\FIXASU~1.000\LOCALS~1\Temp\kxtdykoc.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\system32\drivers\sbaphd.sys (Sunbelt ActiveProtection hook driver/Sunbelt Software) ZwCreateKey [0xF79BD4D0]
SSDT \SystemRoot\system32\drivers\sbaphd.sys (Sunbelt ActiveProtection hook driver/Sunbelt Software) ZwSetValueKey [0xF79BD520]
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe[552] USER32.dll!SetScrollInfo 7E419056 5 Bytes JMP 00688BF0 C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe (VZAccess Manager/Smith Micro Software, Inc.)
.text C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe[552] USER32.dll!GetScrollInfo 7E42DFE2 5 Bytes JMP 00688B40 C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe (VZAccess Manager/Smith Micro Software, Inc.)
.text C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe[552] USER32.dll!ShowScrollBar 7E42F2F2 5 Bytes JMP 00688CC0 C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe (VZAccess Manager/Smith Micro Software, Inc.)
.text C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe[552] USER32.dll!GetScrollPos 7E42F704 5 Bytes JMP 00688B80 C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe (VZAccess Manager/Smith Micro Software, Inc.)
.text C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe[552] USER32.dll!SetScrollPos 7E42F750 5 Bytes JMP 00688C30 C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe (VZAccess Manager/Smith Micro Software, Inc.)
.text C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe[552] USER32.dll!GetScrollRange 7E42F787 5 Bytes JMP 00688BB0 C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe (VZAccess Manager/Smith Micro Software, Inc.)
.text C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe[552] USER32.dll!SetScrollRange 7E42F99B 5 Bytes JMP 00688C70 C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe (VZAccess Manager/Smith Micro Software, Inc.)
.text C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe[552] USER32.dll!EnableScrollBar 7E468005 5 Bytes JMP 00688B00 C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe (VZAccess Manager/Smith Micro Software, Inc.)
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\Tcpip \Device\Ip sbtis.sys (Sunbelt TDI Inspection System/Sunbelt Software)
AttachedDevice \Driver\Tcpip \Device\Ip TFilter.sys (TFilter Kernel Module/Avanquest North America, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 mouclass.sys (Mouse Class Driver/Microsoft Corporation)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp sbtis.sys (Sunbelt TDI Inspection System/Sunbelt Software)
AttachedDevice \Driver\Tcpip \Device\Tcp TFilter.sys (TFilter Kernel Module/Avanquest North America, Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp sbtis.sys (Sunbelt TDI Inspection System/Sunbelt Software)
AttachedDevice \Driver\Tcpip \Device\Udp TFilter.sys (TFilter Kernel Module/Avanquest North America, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp sbtis.sys (Sunbelt TDI Inspection System/Sunbelt Software)
AttachedDevice \Driver\Tcpip \Device\RawIp TFilter.sys (TFilter Kernel Module/Avanquest North America, Inc.)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SOFTWARE\Classes\CLSID\{9F9FDD4A-11DE-0279-B037-7668911670D9}\InprocServer32@ C:\WINDOWS\system32\ole32.dll
Reg HKLM\SOFTWARE\Classes\CLSID\{9F9FDD4A-11DE-0279-B037-7668911670D9}\InprocServer32@ThreadingModel Both
---- Files - GMER 1.0.15 ----
File C:\Documents and Settings\XXXXXXXXXX\Application Data\Macromedia\Flash Player\#SharedObjects\HN5V2ALN\www.acousticguitar.com.\flowplayer.commercial-3.1.5.swf 0 bytes
File C:\Documents and Settings\XXXXXXXXXX\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.acousticguitar.com.\settings.sol 93 bytes
---- EOF - GMER 1.0.15 ----
THANKS!