Forum Home
Press F1
 
Thread ID: 74799 2006-12-05 16:24:00 AOL.EXE."-b Found By Spybot, But Not In Regedit or HJT? SurferJoe46 (51) Press F1
Post ID Timestamp Content User
504470 2006-12-05 16:24:00 Spybot found AOL . EXE in startups, but in the drill-down thru the regedit, after I get to microsoft, current version does not exist . . . . . and this is the flow of the registry entry that Spybot reports .

Hidden files (if that made a difference, but I don't see how) are showing . . . . .

truncated version of the drill down is as follows:

HKEY_CURRENT_USER\
software\
Microsoft\
Windows\
Current Version\ (this is where it ends)
Run\
AOL Faststart ="C:\
Program Files\
AMERICA ONLINE 9 . 0\
AOL . EXE . "-b

I have searched all my hdds (all 9), and even disconnected the network and shared files/folders with the other puters . . even disconnected all the printers and scanners too (some have mem cards) .

I used Windows search, Google Desktop and HJT . . . but it doesn't show in HJT at all either .

And . . what's with this part AOL . EXE . "-b what's that "-b all about?

Any ideas?

I hate AOL and haven't used it for years . . . and this report is after a complete burn-down and reinstall of XP on my 40gig .

Did AOL make some sort of deal with Uncle Bill? :mad:
SurferJoe46 (51)
504471 2006-12-05 19:06:00 Were they any bits of it on the PC at all? Could be a false positive.... pctek (84)
504472 2006-12-05 22:25:00 According to this site ( . emsisoft . com/Default . aspx?g=profile&u=1108722" target="_blank">forum . emsisoft . com) the -b is an indication that this is not the password stealing AOL . EXE .

Or the -b means its running in the background .

So, that entry is most probably safe . And here ( . bleepingcomputer . com/startups/AOL . EXE_b-7469 . html" target="_blank">www . bleepingcomputer . com)
Speedy Gonzales (78)
504473 2006-12-05 23:15:00 Look in M$ Favorites perhaps? ? R2x1 (4628)
504474 2006-12-06 00:59:00 I'm home after wandering out all day....now on to finding and killing that AOL stuff...hah!

Thanks for the info...will go get it outta my system now....
SurferJoe46 (51)
1