Unzip HJT into it's own permanent folder before doing anything in order for it to create backups. (Not a temporary folder or directly on the desktop & not directly on your hard drive). Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' :
R0 - HKLM\Software\Micros oft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\bl ank.htm
O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-DD56626C6C42} - C:\WINDOWS\twaintec.dll
O2 - BHO: MyWay Search Assistant BHO - {04079851-5845-4dea-848C-3ECD647AA554} - (no file)
O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-00E04C60FAF2} - C:\WINDOWS\2_0_1brow serhelper2.dll
O2 - BHO: (no name) - {9C691A33-7DDA-4C2F-BE4C-C176083F35CF} - (no file)
O4 - HKLM\..\Run: [stcloader] C:\WINDOWS\System32\ stcloader.exe
O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\Downloade d Program Files\bridge.dll",Load
04 - HKLM\..\Run: [gryxat] C:\WINDOWS\gryxat.exe
O16 - DPF: {9C691A33-7DDA-4C2F-BE4C-C176083F35CF} - http://static.flingstone.com/cab/20...TInc/bridge.cab
Reboot into safe mode following the instructions here & navigate to & delete the following if found:
C:\WINDOWS\System32\ stcloader.exe< file
C:\WINDOWS\gryxat.exe< file
Reboot normally.
Download & instal Adaware from here
& update it B4 scanning.
In settings under 'scanning,' have it set to
'scan within archives,'
'scan active processes,'
'scan registry,'
'deepscan registry'
'scan my IE Favourites for banned URL's,'
'scan my host's file.'
In 'tweaks' under 'scanning engine' set it to 'unload recognised processes during scanning.'
Also in 'tweaks' under 'cleaning engine' set it to 'Automatically try to unregister objects prior to deletion' & 'let Windows remove files in use at next reboot.'
Select 'activate in-depth scan' before starting scan.
When the scan is finished select 'next.'
Remove what it finds by placing a check in the box to the left of the object. Reboot
Download & instal Spybot S&D from here Update it B4 scanning. Go into settings & have it check for Beta releases also & download if available.
After the scan is complete, have spybot fix everything marked RED.
On the page that first opens when you start Spybot there is an option to immunise, you should do this. In the immunise section there is also a link to download Spywareblaster. This program will prevent the install of bad activex controls that it has knowledge of. Download that & you can keep it updated by selecting the same link that you use to download it. Reboot
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
See if you can rename the stcloader file to oldstcloader.exe & reboot. Then go to that file & delete it.
Please post back with a fresh HJT log after.
Concerning the other file, where did you locate the GRYXAT.EXE-3659D145.pf ??
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
Download a tool called Moveonboot from http://www.webattack.com/get/moveonboot.html It will add extra context into the right click menu allowing you to delete an unwanted file at reboot. Go to stcloader.exe & right click on it & select delete on next boot. Then post that fresh log.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
I would say that HJT has removed what was left of that file. It no longer shows in your log. However, you still have a couple more things to fix. If you do not want backups all over your desktop, you should create a new folder there & drag the hijackthis.exe into it & run it from there.
Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' :
R0 - HKLM\Software\Micros oft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
O4 - HKLM\..\Run: [msbb] c:\windows\msbb.exe
Reboot into safe mode following the instructions here & navigate to & delete the following if found:
c:\windows\msbb.exe< file
Reboot normally.
Launch Notepad, and copy/paste the bold below into a new text file. Save it as URLRepair.reg (Change the 'Save As Type' to 'All Files'). Save it in C:\
REGEDIT4
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"=""
Locate it (in C:\) and double-click on it (launch it). You'll recieve a prompt similar to: "Do you wish to merge the information into the registry?". Answer yes and wait for a message to appear similar to "Merged Successfully".
Post a new log after plz & that should be clean :) .
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
Yep. Been at work. That's my other life. What you were meant to do was fix the R3 entry with the _ underscore. It is still present in your log so something went wrong, or you never completed the task. The file is legitimate. Try doing the fix again.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
It is an added registry entry where only one should exist. Try this.
Download Registrar Lite from here:
http://www.resplendence.com/download/reglite.exe
Put it in its own folder. You may want to keep this program. It is an excellent free, registry editor.
Copy and paste the follow text into the address bar, then hit 'Go':
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks
In the pane on the right are the values associated with that key.
We want to remove this one>
_{CFBFAE00-17A6-11D0-99CB-00C04FD64497}
Notice the underscore at the end.
Right click on it and select delete.
If you get a confirmation question, respond OK then close out of the program.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
It is probably no longer showing up in the HJT log either now. Don't ask me why 'cos I don't know, but this happens occasionally. A self healing Windows :)
It was not a problem either way, just a minor cleanup in your system.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
No problems there. You can download a registry cleaner if you wish to clean out leftovers etc.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985