In the view drop down menu: Toolbars; I have one that will not go away. the title, in lower case, is "stchchbjxcr". It automatically inserts it self in IE, but has now changed and opens in the Google toolbar instead and Google opens in stchchbjxcr. I have search as far as my knowledge goes but have been unable to find the source. Is there anyone who can help me. I isn't picked up when I run my antivirus program, just would like to remove it. :evil:

Dani AI

Generated

The toolbar name you see (stchchbjxcr) is almost certainly an Internet Explorer add-on — usually implemented as a COM add-on or a Browser Helper Object (BHO). Those load by registry registration rather than by a single executable, which is why a standard antivirus scan can miss them. The steps below take a surgical approach: identify the add-on, disable it, find the registered COM/CLSID and its DLL, then remove the leftover registry entries and files. (learn.microsoft.com)

First, try the browser UI and a trusted autorun inspector. Use Internet Explorer: Tools > Manage Add-ons > Show: All add-ons and disable the suspicious entry. If it returns or Manage Add-ons won’t let you remove it, download and run Autoruns (Sysinternals) as administrator, open the Internet Explorer tab, and uncheck the BHO/toolbar — Autoruns shows the exact file path and publisher so you can see what to remove. Disable first; delete only after you know the file and registry keys. (support.microsoft.com)

If that still fails, locate and examine the registry entries for the toolbar and BHO, export them, then remove them safely. Useful keys to inspect are:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbars
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
HKEY_CLASSES_ROOT\CLSID\{CLSID}\InprocServer32

Copy the CLSID from the Toolbars or BHO key, open the CLSID entry to see the DLL path, export those keys (File > Export) and create a System Restore point before deleting anything. If a DLL is in use, boot to Safe Mode to remove it. (support.microsoft.com)

This follows and expands on earlier tips from and : scanning with a current on-demand anti-malware tool after disabling/removing the BHO is a good cleanup step. If unsure, save and post an Autoruns (or HijackThis) log — it shows the exact CLSID and file path so someone can point to the precise keys/files to remove.

Recommended Answers

All 4 Replies

If the program is not in your add/remove programs list then try searching for any file named stchchbjxcr. You could then delete any file named such, making sure to back the files up in case they affect the system. If that didn't work, I would uninstall IE and install Netscape :) just kidding.

I would uninstall IE and install Netscape :) just kidding.

Why say that you're kidding?

Most of the spyware/hijack/etc. programs exploit vulnerabilities that exist in IE; using another browser is actually a very good way to protect yourself from the stuff.

I would totally go with Mozilla man. www.mozilla.org That is what I would recommand.

In the view drop down menu: Toolbars; I have one that will not go away. the title, in lower case, is "stchchbjxcr". It automatically inserts it self in IE, but has now changed and opens in the Google toolbar instead and Google opens in stchchbjxcr. I have search as far as my knowledge goes but have been unable to find the source. Is there anyone who can help me. I isn't picked up when I run my antivirus program, just would like to remove it. :evil:

Download & instal Adaware from
& update it B4 scanning.
In settings under 'scanning,' have it set to
'scan within archives,'
'scan active processes,'
'scan registry,'
'deepscan registry'
'scan my IE Favourites for banned URL's,'
'scan my host's file.'
In 'tweaks' under 'scanning engine' set it to 'unload recognised processes during scanning.'
Also in 'tweaks' under 'cleaning engine' set it to 'Automatically try to unregister objects prior to deletion' & 'let Windows remove files in use at next reboot.'
Select 'activate in-depth scan' before starting scan.
When the scan is finished select 'next.'
Remove what it finds by placing a check in the box to the left of the object. Reboot

Download & instal Spybot S&D from Update it B4 scanning. Go into settings & have it check for Beta releases also & download if available.
After the scan is complete, have spybot fix everything marked RED.
On the page that first opens when you start Spybot there is an option to immunise, you should do this. In the immunise section there is also a link to download Spywareblaster. Download that & you can keep it updated by selecting the same link that you use to download it. Reboot

If that doesn't fix it Download HijackThis from & unzip it into it's own, permanent folder, (not a temporary folder & not on the desktop). Start HJT & press the scan button. When the scan is finished the scan button will change to save. Save the log to a text file, copy the entire contents of the text file & paste it into the body of your post. DO NOT FIX ANYTHING YET. Most of what is there is harmless & even necessary to the running of your system.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.