Need some help to determine whether my pc security has been breached


My operating system is winsows 7


When I load up internet explorer 9 before getting the google homepage up as my default page, the explorer tab at the top of the screen says for a split second "london eng 14day weather" before changing the tab name to google and loading the google homepage.


I have run a full system scan using "malware bytes" anti-walware software and also run a full system scan using norton internet security.


Is this something sinister 7 how do i fix the problem? Has something been embedded in internet explorer software?


Appreciate your help

Hi Bazza,


Easiest way is for us to take a look at your IE settings.... and the rest of the system.


  • Download OTL to your desktop.
    right click on the link and select 'Save Link/Target As'.
    if you have problems, try this download link:
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check






Now copy the lines in bold below.






%systemroot%\*. /mp /s

%systemroot%\system32\*.dll /lockedfiles

%systemroot%\Tasks\*.job /lockedfiles

%systemroot%\system32\drivers\*.sys /lockedfiles

%systemroot%\system32\*.exe /lockedfiles



%USERPROFILE%\..|smtmp;true;true;true /FP


hklm\software\clients\startmenuinternet|command /rs

hklm\software\clients\startmenuinternet|command /64 /rs



  • right click in the Custom Scans/Fixes window (under the blue bar) and choose Paste.
  • Click the Run Scan button.
  • Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them with your next reply.




Member of:



Thanks for your speedy response.

Have run the OTL procedure as requested:

I have had to split the reply into two segments because it exceeds the character limit set.


Here are the otl text results:


OTL logfile created on: 1/22/2013 10:33:52 AM - Run 1

OTL by OldTimer - Version Folder = C:\Users\Barry\Pictures

64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation

Internet Explorer (Version = 9.0.8112.16421)

Locale: 00000409 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy


2.93 Gb Total Physical Memory | 1.76 Gb Available Physical Memory | 60.02% Memory free

5.86 Gb Paging File | 4.32 Gb Available in Paging File | 73.65% Paging File free

Paging file location(s): ?:\pagefile.sys [binary data]


%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)

Drive C: | 220.22 Gb Total Space | 167.82 Gb Free Space | 76.21% Space Free | Partition Type: NTFS

Drive D: | 12.47 Gb Total Space | 2.09 Gb Free Space | 16.72% Space Free | Partition Type: NTFS


Computer Name: BARRYSLAPTOP | User Name: Barry | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days


Restore point Set: OTL Restore Point


========== ZeroAccess Check ==========


========== Custom Scans ==========



[2009/07/14 04:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini


< %USERPROFILE%\..|smtmp;true;true;true /FP >


< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Win dows\WindowsUpdate\AU >


< hklm\software\clients\startmenuinternet|command /rs >

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2012/10/24 17:50:58 | 000,889,848 | ---- | M] (Mozilla Corporation)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2012/10/24 17:50:58 | 000,889,848 | ---- | M] (Mozilla Corporation)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2012/10/24 17:50:58 | 000,889,848 | ---- | M] (Mozilla Corporation)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\Program Files (x86)\Mozilla Firefox\firefox.exe [2012/10/24 17:50:37 | 000,917,984 | ---- | M] (Mozilla Corporation)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -preferences [2012/10/24 17:50:37 | 000,917,984 | ---- | M] (Mozilla Corporation)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -safe-mode [2012/10/24 17:50:37 | 000,917,984 | ---- | M] (Mozilla Corporation)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\Windows\System32\ie4uinit.exe" -show [2011/04/21 14:53:45 | 000,074,240 | ---- | M] (Microsoft Corporation)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\Windows\System32\ie4uinit.exe" -reinstall [2011/04/21 14:53:45 | 000,074,240 | ---- | M] (Microsoft Corporation)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\Windows\System32\ie4uinit.exe" -hide [2011/04/21 14:53:45 | 000,074,240 | ---- | M] (Microsoft Corporation)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -extoff [2012/11/14 02:56:04 | 000,757,296 | ---- | M] (Microsoft Corporation)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: C:\Program Files (x86)\Internet Explorer\iexplore.exe [2012/11/14 02:56:04 | 000,757,296 | ---- | M] (Microsoft Corporation)


< hklm\software\clients\startmenuinternet|command /64 /rs >

64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\UNINSTALL\HELPER.EXE" /HIDESHORTCUTS [2012/10/24 17:50:58 | 000,889,848 | ---- | M] (Mozilla Corporation)

64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\UNINSTALL\HELPER.EXE" /SHOWSHORTCUTS [2012/10/24 17:50:58 | 000,889,848 | ---- | M] (Mozilla Corporation)

64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\UNINSTALL\HELPER.EXE" /SETASDEFAULTAPPGLOBAL [2012/10/24 17:50:58 | 000,889,848 | ---- | M] (Mozilla Corporation)

64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\FIREFOX.EXE [2012/10/24 17:50:37 | 000,917,984 | ---- | M] (Mozilla Corporation)

64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\FIREFOX.EXE" -PREFERENCES [2012/10/24 17:50:37 | 000,917,984 | ---- | M] (Mozilla Corporation)

64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\FIREFOX.EXE" -SAFE-MODE [2012/10/24 17:50:37 | 000,917,984 | ---- | M] (Mozilla Corporation)

64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\WINDOWS\SYSTEM32\IE4UINIT.EXE" -SHOW [2011/04/21 14:53:44 | 000,089,088 | ---- | M] (Microsoft Corporation)

64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\WINDOWS\SYSTEM32\IE4UINIT.EXE" -REINSTALL [2011/04/21 14:53:44 | 000,089,088 | ---- | M] (Microsoft Corporation)

64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\WINDOWS\SYSTEM32\IE4UINIT.EXE" -HIDE [2011/04/21 14:53:44 | 000,089,088 | ---- | M] (Microsoft Corporation)

64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\PROGRAM FILES (X86)\INTERNET EXPLORER\IEXPLORE.EXE" -EXTOFF [2012/11/14 02:56:04 | 000,757,296 | ---- | M] (Microsoft Corporation)

64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: C:\PROGRAM FILES (X86)\INTERNET EXPLORER\IEXPLORE.EXE [2012/11/14 02:56:04 | 000,757,296 | ---- | M] (Microsoft Corporation)

< End of report >


Here is the Extras.txt report

OTL Extras logfile created on: 1/22/2013 10:33:52 AM - Run 1

OTL by OldTimer - Version Folder = C:\Users\Barry\Pictures

64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation

Internet Explorer (Version = 9.0.8112.16421)

Locale: 00000409 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy


2.93 Gb Total Physical Memory | 1.76 Gb Available Physical Memory | 60.02% Memory free

5.86 Gb Paging File | 4.32 Gb Available in Paging File | 73.65% Paging File free

Paging file location(s): ?:\pagefile.sys [binary data]


%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)

Drive C: | 220.22 Gb Total Space | 167.82 Gb Free Space | 76.21% Space Free | Partition Type: NTFS

Drive D: | 12.47 Gb Total Space | 2.09 Gb Free Space | 16.72% Space Free | Partition Type: NTFS


Computer Name: BARRYSLAPTOP | User Name: Barry | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days


========== Last 20 Event Log Errors ==========


Hi Bazza


There's nothing i can see in the reports to say what may be causing your problem.

There is a little tidying up to do though.


Step 1

You still have old Java items in your add/remove.

These should have been removed when a new Java update was installed.

Please remove these:

Java™ 6 Update 15 (64-bit)

Java™ SE Development Kit 6 Update 15 (64-bit)

Java™ 6 Update 20

Java™ 6 Update 37


Do not remove: Java 7 Update 11



Step 2

Let's tidy up the OTL report.

It has been found that Malwarebytes Antimalware can cause the fix to freeze.... so please uninstall MBAM.

You can reinstall it again after the fix has completed.


Double click on OTL to run it.

Copy the lines in the codebox below. (make sure that :Otl is on the first line )

O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKCU..\Run: [EPSON Stylus SX200 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIEFE. EXE /FU "C:\Windows\TEMP\E_SBF4A.tmp" /EF "HKCU" File not found
O8:64bit: - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6 FF0C6D236BF8.dll/cmsidewiki.html File not found
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6 FF0C6D236BF8.dll/cmsidewiki.html File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
[2013/01/18 14:52:52 | 000,000,000 | ---D | C] -- C:\Users\Barry\AppData\Local\{3FA0B81A-BB78-4706-AE66-8450E1CBF926}
[2013/01/17 10:15:18 | 000,000,000 | ---D | C] -- C:\Users\Barry\AppData\Local\{976CB183-4F70-4686-8AA1-CA6FC37A15AD}
[2013/01/12 09:51:38 | 000,000,000 | ---D | C] -- C:\Users\Barry\AppData\Local\{C4B90B67-3CF2-44EE-AE14-4A27E57690C9}
[2013/01/07 10:28:59 | 000,000,000 | ---D | C] -- C:\Users\Barry\AppData\Local\{360B9BF0-DA7F-4F64-9AEA-4F840556B62D}
[2013/01/03 16:07:12 | 000,000,000 | ---D | C] -- C:\Users\Barry\AppData\Local\{D3942E28-23A3-4618-B08B-1A6C059987BC}
[2012/12/31 09:50:19 | 000,000,000 | ---D | C] -- C:\Users\Barry\AppData\Local\{DC545490-B1FB-4530-91DD-4443F0739AAF}
[2011/07/07 16:25:00 | 000,000,000 | ---- | C] () -- C:\Users\Barry\AppData\Local\{6F97625D-B450-4668-B9F9-C2538AD005D5}

ipconfig /flushdns /c


  • Return to OTL,
  • right click in the Custom Scans/Fixes window (under the blue bar) and choose Paste.
  • Click the red Run Fix button.
  • OTL will reboot your system once the fix has completed.
  • After the reboot, you may need to double click OTL to launch the program and retrieve the log.


Copy and paste the contents of the OTL log that comes up after the fix in your next reply.


if you lose the report, there will be a copy here:




Step 3

You can try running Internet Explorer without any addons..... just to see if the problem is being caused by an addon.


Click Start >> All Programs >> Accessories >> System Tools >> Internet Explorer (no addons)


I have tried IE on my Win7 system but can't recreate the problem you experience.

Although i'm running IE 10 not 9



In your next reply, please submit:

Otl fix report

and let me know if you still get the problem when running without addons.




Member of:



Thanks for your reply.


Have removed the old versions of java and Malawarebytes


Ran otl fix as directed - results below:


Files\Folders moved on Reboot...

C:\Users\Barry\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...


ran ie without add-on had no problems


also ran ie with add-ons afterewards and it seemed to be working normally.


Has the issue now been resolved?


Hi Bazza,


Have been running ie for a few days now and everything seems to be working fine

That's good.

Otl will need to be removed now.


  • Please double-click OTL to run it.
  • You should see a CleanUp! button, press that button,
  • This will cleanup an assortment of tools used during malware removal, plus itself


You can reinstall MBAM now if you wish.


Safe surfing. http://fc08.deviantart.net/fs71/f/2010/033/b/3/Computer_addict__by_Sinister_Starfeesh.gif

Member of:


