This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

AOL wants to start by itself

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

A couple of those files you listed don't look to good.


Go here and run at least one of the online scans, allow them to delete whatever they find:

TrendMicro HouseCall
eTrust AntiVirus Web Scanner
Panda ActiveScan
Note any thing that can't be fixed
Reboot when done.

Next:

Even if you've already run these, make SURE they're up-to-date and run per instructions.

Make sure you have the up-to-date versions of Spybot V 1.4 and Ad-aware SE Build 1.06 . All are free and available below.

Download Spybot, install and update. Then download Ad-aware, install, and update.

Spybot:

Install the program and launch it.

Go to Start > Programs >Spybot > Search & Destroy and choose Spybot S&D

Close ALL windows except Spybot S&D
Click the button to "Search for Updates" and download and install the Updates.
Next click the button "Check for Problems"
When Spybot is complete, it will be showing "RED" (RED) entries "BLACK" entries and "GREEN" (GREEN) entries in the window
Put a check mark beside the RED (RED) entries ONLY.
Choose "Fix Selected Problems" and allow Spybot to fix the RED (RED) entries.

Ad-Aware FULL SCAN:

Install the program and launch it.

First in the main window look in the bottom right corner and click on Check for updates now then click Connect and download the latest reference files.

From main window :Click Start then under Select a scan Mode check Perform full system scan.
Next deselect Search for negligible risk entries.
Now to scan just click the Next button.

When the scan is finished mark everything for removal and get rid of it.(Right-click the window and choose select all from the drop down menu and click Next)

Empty Recycle Bin

Reboot and "copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.
A quick question. I downloaded and ran HouseCall from TrendMicro. It found 6 files it did not like. If you like, I can list them. Five of them I had to delete because they were Non-Cleanable, but the sixth one is PE BUBE.A in C:\Windows\Explorer.Exe. It says it is cleanable but then it says it can't clean it because the file is in use. I know better than to delete Explorer. I have not proceeded any further iwith your last suggestions because I wanted to clear this up before I move on. Can I replace this file with a known good one using DOS, or is there some other trick I can use? Or should I not worry about this now and move on to your next step? Hal

Or should I not worry about this now and move on to your next step?

Just move on for now :thumbup:

Do you have your W98 CD?
LDTate,
All I can say is Thank you, Thank you, Thank you. With you help and guidance, I was finally able to clean up my computer. I have learned many things through this experience. I have learned patience. Even though it was five days after I had first posted my problems, and I think I dropped to page sixteen or lower, you still found my post and came to my aid. I have also learned that sometimes many things must be tried to resolve a problem. It now appears to me that no one program is the silver bullet to fix a computer. I have learned that sometimes many programs must be run, sometimes the same program may have to be run more than once, and the order in which the programs are run is important. And most importantly, I have learned that there are dedicated people out there that are willing to give their time to help total strangers. I cannot tell you how much this means to me, and I will gladly support this in the hope that you and your fellow helpers can continue to help other people. P.S. I have also learned to avoid some web sites.

I would like to list the results of the instructions you gave me. I ran HouseCall, and online scan of my computer, from TrendMicro. If memory serves me well, it found six problem files, only five of which I was able to delete. The sixth file was Explorer.exe, which was in use with Windows running so it could not repair it. Next I ran Spybot and it found 37 problems, 34 of them it fixed and 3 were deleted. Next I ran Ad-Aware and 137 problems were identified. These also were fixed or deleted. At this point, my AOL problems continued. I went back and took a look at Explorer.exe and noticed it was 4 kbs larger than Explorer on my other computer. Also noticed the date modified was very recent. I went into DOS mode and renamed Explorer to something else, then copied Explorer from my other computer to this one. Suddenly, all my AOL problems went away. I reran Spybot and it found 3 more problems, which it fixed. I have rerun both Spybot and Ad-Aware since, and both report no problems.

Just to wrap this up, I thought I would post a log of my clean computer.

Logfile of HijackThis v1.99.1
Scan saved at 4:14:40 PM, on 7/30/05
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\BRMFRSMG.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\WINWORD.EXE
C:\AOL DOWNLOADS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by America Online
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab

Note: I actually did all this yesterday, but I wanted to try things for a day before I pronounced my computer cured.

Thanks,
Hal
I knew your Explorer was infected by the scans we ran. That's why I asked if you have your 98 CD. I'm glad you have a second PC to copy from :D

Things are pretty bad now. It's not just the pop-up's anymore. The bad guys are trying to kill the PC's along with spyware and malware. But we'll keep up the fight :thumbup:

Good Job :thumbup:


Log looks good :D



1.Do one of the following:
In Windows 98/Me/2000, on the Windows desktop, double-click the My Computer icon.
In Windows XP, on the taskbar, click Start > My Computer.

2.Do one of the following:
In Windows 98, on the View menu, click Folder Options.
In Windows Me/2000/XP, on the Tools menu, click Folder Options.
On the View tab, check Hide file extensions for known file types.

3.Do one of the following:
In Windows 98, in the Advanced Settings box, under the "Hidden files" folder, unclick Show all files.
In Windows Me/2000/XP, check Hide protected operating system files. Then, under the "Hidden files" folder, unclick Show hidden files and folders.
If you see a warning message, click Yes.
Click Apply.
Click OK.



If you dont have these three programs I would recommend that you get them. Spywareblaster, Spywareguard and IESPY AD. They will add 1000's of sites to your resticted zone and block some hijacks from happening. I also have a FREE FIREWALL and FREE ANTI VIRUS if you need one.

It is critical to have both a firewall and anti virus to protect your system.

Keep your system up to date and run Adaware & Spybot, once a week works, and hopefully you will be ok from here on. Both are available below.

Safe Surfing. :D
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI