The original version of this page can be found at : http://forum.bullguard.com/forum/10/Googlecom-not-working_96150.html
Posted By : beasty513 - 11/2/2013 9:04 AM
 
 
Hello.
 
 
Google is not working.
 
 
Won't show on any of the browsers.
 
 
 
=========================================
 
 
 
Here is my ComboFix log:
 
ComboFix 13-11-01.03 - User 11/02/2013   2:21.2.1 - x86
Microsoft Windows 7 Ultimate   6.1.7600.0.1252.1.1033.18.2038.1315 [GMT -4:00]
Running from: c:\users\User\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
 
(((((((((((((((((((((((((   Files Created from 2013-10-02 to 2013-11-02  )))))))))))))))))))))))))))))))
.
.
2073-10-27 15:55 . 2004-08-24 19:27 375808 ----a-w- c:\program files\Microsoft Games\Halo Custom Edition\binkw32.dll
2013-11-02 06:46 . 2013-11-02 06:47 -------- d-----w- c:\users\User\AppData\Local\temp
2013-11-02 06:46 . 2013-11-02 06:46 -------- d-----w- c:\users\User2\AppData\Local\temp
2013-11-02 06:46 . 2013-11-02 06:46 -------- d-----w- c:\users\Public\AppData\Local\temp
2013-11-02 06:46 . 2013-11-02 06:46 -------- d-----w- c:\users\Guest\AppData\Local\temp
2013-11-02 06:46 . 2013-11-02 06:46 -------- d-----w- c:\users\Guest.User-PC\AppData\Local\temp
2013-11-02 06:46 . 2013-11-02 06:46 -------- d-----w- c:\users\Fix\AppData\Local\temp
2013-11-02 06:46 . 2013-11-02 06:46 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-11-02 06:46 . 2013-11-02 06:46 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\temp
2013-11-01 19:29 . 2004-09-09 02:17 58880 ----a-w- c:\windows\system32\dbrename7.exe
2013-11-01 19:28 . 2001-09-05 09:18 225280 ------w- c:\program files\Common Files\InstallShield\IScript\IScript.dll
2013-11-01 19:28 . 2001-09-05 09:14 176128 ------w- c:\program files\Common Files\InstallShield\engine\6\Intel 32\iuser.dll
2013-11-01 19:28 . 2001-09-05 09:13 32768 ------w- c:\program files\Common Files\InstallShield\engine\6\Intel 32\objectps.dll
2013-11-01 19:28 . 2001-09-05 09:18 77824 ----a-w- c:\program files\Common Files\InstallShield\engine\6\Intel 32\ctor.dll
2013-11-01 19:28 . 2000-01-04 10:39 212992 ----a-w- c:\program files\Common Files\InstallShield\engine\6\Intel 32\ILog.dll
2013-11-01 19:28 . 2002-07-25 20:07 614532 ----a-w- c:\program files\Common Files\InstallShield\engine\6\Intel 32\IKernel.exe
2013-11-01 19:11 . 2013-11-01 19:11 846864 ----a-w- c:\program files\Internet Explorer\IE10-Windows6.1-en-us.exe
2013-11-01 08:19 . 2013-11-01 08:19 -------- d-----w- c:\users\User2\AppData\Local\avgchrome
2013-10-31 17:39 . 2013-10-31 17:39 -------- d-----w- c:\users\User\AppData\Roaming\MaskMyIP
2013-10-31 17:39 . 2013-10-31 17:39 -------- d-----w- c:\programdata\MaskMyIP
2013-10-14 21:19 . 2013-10-14 21:19 -------- d-----w- c:\windows\system32\Extensions
2013-10-14 21:19 . 2013-10-14 21:19 -------- d-----w- c:\windows\system32\searchplugins
2013-10-14 21:01 . 2013-10-14 21:01 -------- d-----w- c:\users\User\AppData\Local\avgchrome
2013-10-14 09:10 . 2013-10-28 14:01 -------- d-----w- c:\programdata\BitGuard
2013-10-14 09:10 . 2013-10-14 09:10 -------- d-----w- c:\program files\Delta
2013-10-14 09:10 . 2013-10-14 09:10 -------- d-----w- c:\users\User\AppData\Roaming\Delta
2013-10-14 09:10 . 2013-10-14 09:10 -------- d-----w- c:\users\User\AppData\Roaming\BabSolution
2013-10-14 09:08 . 2013-10-14 09:08 -------- d-----w- c:\programdata\Babylon
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-09-30 20:04 . 2013-09-30 20:03 728960 ----a-w- C:\SpyHunter-Installer_exe
2013-09-30 19:45 . 2013-09-30 19:44 728960 ----a-w- c:\program files\SpyHunter-Installer_exe
2013-03-07 14:31 . 2013-03-08 04:15 263064 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{b920380d-fbe7-45c7-96ab-37e9870a566c}]
2013-07-17 08:13 226592 ----a-w- c:\program files\InternetHelper3\prxtbInt2.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{b920380d-fbe7-45c7-96ab-37e9870a566c}"= "c:\program files\InternetHelper3\prxtbInt2.dll" [2013-07-17 226592]
.
[HKEY_CLASSES_ROOT\clsid\{b920380d-fbe7-45c7-96ab-37e9870a566c}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{B920380D-FBE7-45C7-96AB-37E9870A566C}"= "c:\program files\InternetHelper3\prxtbInt2.dll" [2013-07-17 226592]
.
[HKEY_CLASSES_ROOT\clsid\{b920380d-fbe7-45c7-96ab-37e9870a566c}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2012-12-28 22:19 2042528 ----a-w- c:\program files\Microsoft Office 15\root\office15\grooveex.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2012-12-28 22:19 2042528 ----a-w- c:\program files\Microsoft Office 15\root\office15\grooveex.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2012-12-28 22:19 2042528 ----a-w- c:\program files\Microsoft Office 15\root\office15\grooveex.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2013-10-02 20472992]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-23 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-23 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-23 150552]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-06-20 1316136]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
"XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2009-09-30 718688]
"SearchProtectAll"="c:\program files\SearchProtect\bin\cltmng.exe" [2013-09-22 3470624]
"DivXMediaServer"="c:\program files\DivX\DivX Media Server\DivXMediaServer.exe" [2013-01-30 450560]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2013-02-13 1263952]
"pcreg"="c:\program files\wrapper_inst\service.exe" [2013-09-26 346720]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.8.130\SSScheduler.exe [2013-9-6 273296]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 0 (0x0)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableVirtualization"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~2\BitGuard\271769~1.27\{C16C1~1\BitGuard.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
R2 pcregservice;pcregservice Service;c:\program files\wrapper_inst\file_to_run.exe [2013-09-26 25088]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2013-09-05 171680]
R3 BTCFilterService;USB Networking Driver Filter Service;c:\windows\system32\DRIVERS\motfilt.sys [2009-01-29 6016]
R3 esgiguard;esgiguard;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [x]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\3.8.130\McCHSvc.exe [2013-09-06 235216]
R3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\DRIVERS\motccgp.sys [2009-06-19 19712]
R3 motccgpfl;MotCcgpFlService;c:\windows\system32\DRIVERS\motccgpfl.sys [2009-01-29 8320]
R3 Motousbnet;Motorola USB Networking Driver Service;c:\windows\system32\DRIVERS\Motousbnet.sys [2010-04-01 23424]
R3 motusbdevice;Motorola USB Dev Driver;c:\windows\system32\DRIVERS\motusbdevice.sys [2010-01-25 9472]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-09-01 1343400]
S2 BitGuard;BitGuard;c:\programdata\BitGuard\2.7.1769.27\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe [2013-10-22 2864096]
S2 CltMngSvc;Search Protect by Conduit Updater;c:\program files\SearchProtect\bin\CltMngSvc.exe [2013-02-20 93984]
S2 OfficeSvc;Microsoft Office Service;c:\program files\Microsoft Office 15\ClientX86\integratedoffice.exe [2012-09-11 1034880]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-03-02 139776]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-10-17 12:03 1185744 ----a-w- c:\program files\Google\Chrome\Application\30.0.1599.101\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-11-02 c:\windows\Tasks\dsmonitor.job
- c:\program files\Uniblue\DriverScanner\dsmonitor.exe [2013-03-19 18:47]
.
2013-11-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-09-01 18:19]
.
2013-11-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-09-01 18:19]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://bing.com/
LSP: c:\windows\system32\Sendori.dll
TCP: DhcpNameServer = 65.32.5.74 65.32.5.75
TCP: Interfaces\{D04157B8-85C4-4BB4-8DE7-EC3AE689CEB0}: NameServer = 216.146.35.240,216.146.36.240,65.32.1.65,65.43.1.70
TCP: Interfaces\{D04157B8-85C4-4BB4-8DE7-EC3AE689CEB0}\2456C6B696E6E243246433: NameServer = 216.146.35.240,216.146.36.240,65.32.1.65,65.43.1.70
TCP: Interfaces\{D04157B8-85C4-4BB4-8DE7-EC3AE689CEB0}\25F646567716970223: NameServer = 216.146.35.240,216.146.36.240,65.32.1.65,65.43.1.70
TCP: Interfaces\{D04157B8-85C4-4BB4-8DE7-EC3AE689CEB0}\25F646567716971303: NameServer = 216.146.35.240,216.146.36.240,65.32.1.65,65.43.1.70
TCP: Interfaces\{D04157B8-85C4-4BB4-8DE7-EC3AE689CEB0}\27F6465677169733: NameServer = 216.146.35.240,216.146.36.240,65.32.1.65,65.43.1.70
TCP: Interfaces\{D04157B8-85C4-4BB4-8DE7-EC3AE689CEB0}\341626C65675966496: NameServer = 216.146.35.240,216.146.36.240,65.32.1.65,65.43.1.70
TCP: Interfaces\{D04157B8-85C4-4BB4-8DE7-EC3AE689CEB0}\66363677962756C6563737E65647: NameServer = 216.146.35.240,216.146.36.240,65.32.1.65,65.43.1.70
TCP: Interfaces\{D04157B8-85C4-4BB4-8DE7-EC3AE689CEB0}\C696E6B6379737: NameServer = 216.146.35.240,216.146.36.240,65.32.1.65,65.43.1.70
FF - ProfilePath - c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\yavvfdvw.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3007394&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - WhiteSmoke Bar Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://www.delta-search.com/?babsrc=HP_ss&mntrId=3041001B9E4BA541&affID=125361&tsp=5035
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3007394&SearchSource=2&q=
FF - prefs.js: network.proxy.type - 0
FF - ExtSQL: 2013-10-14 05:10; ffxtlbr@delta.com; c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\yavvfdvw.default\extensions\ffxtlbr@delta.com
FF - ExtSQL: !HIDDEN! 2011-10-29 11:03; textlinks@epicplay.com; c:\users\User\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\textlinks@epicplay.com
FF - ExtSQL: !HIDDEN! 2013-03-04 22:45; infoatoms@infoatoms.com; c:\program files\Mozilla FireFox\extensions\infoatoms@infoatoms.com
FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false
FF - user.js: extensions.delta.tlbrSrchUrl -
FF - user.js: extensions.delta.id - 30410dce000000000000001b9e4ba541
FF - user.js: extensions.delta_i.babTrack - affID=125361&tsp=5035
FF - user.js: extensions.delta_i.babExt -
FF - user.js: extensions.delta_i.srcExt - ss
FF - user.js: extensions.delta.autoRvrt - false
FF - user.js: extensions.delta.rvrt - false
FF - user.js: extensions.delta.newTab - false
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
HKCU-Run-SearchProtect - c:\users\User\AppData\Roaming\SearchProtect\bin\cltmng.exe
HKLM-Run-Sendori Tray - c:\program files\Sendori\SendoriTray.exe
HKLM-Run-AS2014 - c:\programdata\9npDn373\9npDn373.exe
AddRemove-ZDaemon - c:\users\User\Doom\uninstall.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2013-11-02  02:52:59
ComboFix-quarantined-files.txt  2013-11-02 06:52
ComboFix2.txt  2013-04-09 19:02
.
Pre-Run: 28,946,227,200 bytes free
Post-Run: 29,276,557,312 bytes free
.
- - End Of File - - A187F421959D94D3D998289D96A04721
A36C5E4F47E84449FF07ED3517B43A31
 
==================================================
 
I don't know what the root cause is.
 
 
Thanks in advance.... :-)
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Posted By : Andreea-Luciana Ostache - 11/2/2013 12:42 PM
Here is a guide that you can follow to remove any toolbars, add-ons, extensions, from your browser and computer:
www.bullguard.com/support/tech-guides/how-to-remove-browser-toolbars.aspx
Note: You should remove anything that you did not install yourself (Babylon, Delta Search, WhiteSmoke Bar Customized Web Search)

Also, I recommend that you reset Internet Options as seen in this guide: support.microsoft.com/kb/923737


Andreea-Luciana Ostache
Senior Support Technician EN
support@bullguard.com
www.bullguard.com

Download the Free Trial version of BullGuard Internet Security 14

You have a BullGuard related problem? Post your question on these forums, contact Support or contact me on Twitter!


Posted By : rozermartin - 12/16/2013 1:16 PM
Well that also worked. Thanks Andreea....
And Beasty, if that issue is going on with Google only then you may try loading the encrypted page for Google by addressing encrypted.google.com in the browser bar.
-->