This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Goole Search on Firefox - Hijacked?

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,
Recently I have encountered problem while searching via Google, Firefox browser:
When I open browser, I navigate to www.google.com. Then I enter search word and click button. Nothing happens! The page stays unchanged and in the status bar it says "Done". If I go to e.g. image searching - it works, and when I come back to normal searching it works again.

I am suspicious if I have "guests" :( Can somebody help please? Here's my HijackThis log:

StartupList report, 8/19/2009, 10:00:19 AM
StartupList version: 1.52.2
Started from : C:\Documents and Settings\dxnikolic\Desktop\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
* Using default options
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
C:\Program Files\Fiberlink\G360\e360SysTray.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\SafeBoot Tray Manager\SbTrayManager.exe
C:\DB2\BIN\db2systray.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Java\jre6\bin\jusched.exe
C:\Program Files\Apoint\ApMsgFwd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\SafeBoot\SbClientManager.exe
C:\Program Files\Apoint\HidFind.exe
C:\java\fi\esi-ide\apache-2.0.55\Apache2\bin\ApacheMonitor.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Microsoft Office Communicator\communicator.exe
C:\java\fi\esi-ide\apache-2.0.55\Apache2\bin\Apache.exe
C:\Program Files\BigFix Enterprise\BES Client\BesClient.exe
C:\Program Files\ISS\Proventia Desktop\blackd.exe
C:\java\fi\esi-ide\apache-2.0.55\Apache2\bin\rotatelogs.exe
C:\java\fi\esi-ide\apache-2.0.55\Apache2\bin\Apache.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\java\fi\esi-ide\apache-2.0.55\Apache2\bin\rotatelogs.exe
C:\DB2\BIN\db2mgmtsvc.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Fiberlink\G360\FLUtilsSvc.exe
C:\Program Files\iPlus\Drivers\driver2k\GTMax\GtDetectSc.exe
C:\Program Files\iPlus\Drivers\driver2k\GTMax\GtFlashSwitch.exe
C:\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\msgserv.exe
C:\ISM\2.20\bin\nsrd.exe
C:\ISM\2.20\bin\nsrexecd.exe
C:\ISM\2.20\bin\portmap.exe
C:\Program Files\ISS\Proventia Desktop\RapApp.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\ISM\2.20\bin\nsrmmdbd.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Fiberlink\G360\ServiceMgr.exe
C:\ISM\2.20\bin\nsrindexd.exe
C:\ISM\2.20\bin\nsrmmd.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\StacSV.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\ISS\Proventia Desktop\vpatch.exe
C:\DB2\BIN\db2sec.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
C:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\dxnikolic\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\dxnikolic\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\dxnikolic\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\java\fi\esi-ide\eclipse-3.1.1\eclipse.exe
C:\java\fi\esi-ide\ibmjdk-1.4.2\bin\javaw.exe
C:\Documents and Settings\dxnikolic\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\dxnikolic\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\dxnikolic\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\dxnikolic\Desktop\HijackThis.exe

————————————————–

Listing of startup folders:

Shell folders Startup:
[C:\Documents and Settings\dxnikolic\Start Menu\Programs\Startup]
MS Communicator 2005.lnk = ?

Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
Monitor Apache Servers.lnk = C:\java\fi\esi-ide\apache-2.0.55\Apache2\bin\ApacheMonitor.exe
WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE

————————————————–

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

IgfxTray = C:\WINDOWS\system32\igfxtray.exe
HotKeysCmds = C:\WINDOWS\system32\hkcmd.exe
Persistence = C:\WINDOWS\system32\igfxpers.exe
SigmatelSysTrayApp = stsystra.exe
Apoint = C:\Program Files\Apoint\Apoint.exe
RoxioDragToDisc = "C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe"
e360SysTray = C:\Program Files\Fiberlink\G360\e360SysTray.exe
DVDLauncher = "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
ccApp = "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
vptray = C:\PROGRA~1\SYMANT~1\VPTray.exe
Adobe Reader Speed Launcher = "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
BluetoothAuthenticationAgent = rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
PCSuiteTrayApplication = C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
IntelWireless = "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
IntelZeroConfig = "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
SBPToy.ScriptRunner = "C:\Program Files\SafeBoot\ScriptRunner.exe"
SafeBootTrayManager = "C:\Program Files\SafeBoot Tray Manager\SbTrayManager.exe"
iPlusManager = C:\Program Files\iPlus\iPlusChecker.exe
DB2COPY1 - db2systray.exe DB2 = C:\DB2\BIN\db2systray.exe DB2
ISUSPM Startup = "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
ISUSScheduler = "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
SunJavaUpdateSched = "C:\Java\jre6\bin\jusched.exe"

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
Skype = "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
Google Update = "C:\Documents and Settings\dxnikolic\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

[OptionalComponents]
=

————————————————–

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\system32\logon.scr
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*

————————————————–


Enumerating Browser Helper Objects:

(no name) - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
(no name) - C:\Java\jre6\bin\ssv.dll - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
(no name) - C:\Java\jre6\bin\jp2ssv.dll - {DBC80044-A445-435b-BC74-9C25C1C588A9}
JQSIEStartDetectorImpl - C:\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll - {E7E6F031-17CE-4C07-BC86-EABFE594F69C}

————————————————–

Enumerating Task Scheduler jobs:

GoogleUpdateTaskUserS-1-5-21-1801674531-2052111302-2146921017-724518Core.job
GoogleUpdateTaskUserS-1-5-21-1801674531-2052111302-2146921017-724518UA.job

————————————————–

Enumerating Download Program Files:

[Macromedia Authorware Web Player Control]
InProcServer32 = C:\WINDOWS\system32\macromed\authorwa\awswax.ocx
CODEBASE = http://fpdownload.macromedia.com/get/shock…are/awswaxd.cab

[FileInterface Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\FSINT.dll
CODEBASE = https://rol.raiffeisenbank.rs/RaiffeisenDLL/FSINT.dll

[FileInterface Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\FSINT8.dll
CODEBASE = https://rol.raiffeisenbank.rs/RetailDLL/FSINT8.dll

[Archive Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\SAWZip.dll
CODEBASE = https://rol.raiffeisenbank.rs/RaiffeisenDLL/SAWZip.dll

[{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}]
CODEBASE = http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab

[Ebanking.Utility]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\EbankingWWW.dll
CODEBASE = https://rol.raiffeisenbank.rs/RaiffeisenDLL/EbankingWWW.dll

[SecAPI Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\EBCSCC2A.dll
CODEBASE = https://rol.raiffeisenbank.rs/RaiffeisenDLL/EBCSCC2A.dll

————————————————–

Enumerating Winsock LSP files:

NameSpace #4: C:\WINDOWS\system32\wshbth.dll
Protocol #1: C:\Program Files\ISS\Proventia Desktop\IBE\ICELSP_8.0.675.0.dll
Protocol #2: C:\Program Files\ISS\Proventia Desktop\IBE\ICELSP_8.0.675.0.dll
Protocol #3: C:\Program Files\ISS\Proventia Desktop\IBE\ICELSP_8.0.675.0.dll
Protocol #9: C:\Program Files\ISS\Proventia Desktop\IBE\ICELSP_8.0.675.0.dll

————————————————–

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\system32\webcheck.dll
SysTray: C:\WINDOWS\system32\stobject.dll

————————————————–
End of report, 11,143 bytes
Report generated in 0.219 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
Please do the following:

NEXT

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries





(note: please don't color code your log - hard to read)
I need to apology - due to given and other problems I had to reinstall windows, so your instructions do not make sense any longer. Anyway, thanks a lot for your effort!
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI