Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
Ok, I being the ass that I am clicked on this little link in someones profile saying this Whoaaa....look at what I found, click here. Now when I sign on it says that in my profile and deletes my profile. I tried to uninstall and reinstall AIM and delete all the registry data. I think the file is in the AIM Data folder it is a folder called bartcache. Everytime I try to delete "bartcache" it just returns moments after and I cant get rid of it. If anyone has dealt with this before please let me know it is getting me very aggravated.

Hold Cntrl, Alt and tap Delete once. In Task Manager, look for any file that might be your virus, hilight it and click End Task. That will take it out of working memory and stop it from constantly rebooting.
Go into the Register, the RUN file in CURRENT USER and LOCAL MACHINE hives and look for a reference to bartcache, or another you don't recognize (possibly the same name as in Task Manager) and delete it. That will stop it from reloading when you boot. Go into AIM and remove the file.
Now go to Trend Micro's website and run their free online virus scan. If not, you will have to do it with normal boot. Hopefully that will get it.
If it still comes back, try doing the same thing in Safe Mode.

I had the same virus, so I went through the list of tasks using ctrl-alt-del and saw a new program running called "b" so I ended that one. Sure enough it worked and I don't get that annoying link on my AIM profile anymore. The program "b" is found in C:\Windows which you should delete. I also did numerous virus checks before that which may have helped.
Sam
PS- thanks ranchhand for ending my 5+ hours of searching for answers and doing multiple virus scans to get rid of that virus.

The only things u have to do are:
hit ctrl+alt+del on ur keyboard and click the process tab at the top. then look for a file in the process box that is named "b" or maybe its "b.exe" once you found it. click on it and then click end process. once you've done that go to My <nobr><a class="iAs" style="border-bottom:darkgreen 1px solid;text-decoration:underline;color:darkgreen;background-color:transparent;" href="http://itxt.vibrantmedia.com/al.asp?ipid=7&cc=us&cf=1&ai=3590232&di=73024&ts=20031115233900&redir=http://www5.overture.com/d/sr/?xargs=02u3hs9yoakU1vXSCDhhRNf1S9FD6C5VU01uvJrK2abeuBY2x1ToppsP3%2FLiiEc%2FOE85xzhh3gy%2BdamqULxs%2BqDoUPGmz9L42fExqm1hZfcptLgdNMgWzWyIZDGjMqOwof%2BUeHyravHBuPlROvKyo%2BHfYfiw6PTiOtHUi5PByAAHZ13i9vh1sL8zhheZreHitpjbXXbG4rIyI%2Bz8%2B6jXXbPmj%2ByXrdVXTEF8nBKGjlgdw3CO6eHO0eNfakVTDHxOwkIQYXBxUlhO%2Bl9AQ9%2BgSX4v28%2FWYnZwgZlk6AwZiz4IAwwrgKCGC7BLB6Dlqi7M5O2wahSuPqbbWjjm%2B53yGx67OxaXdSXhBIEYoxzuuBPMmN6ASENNIppQGkda%2B%2Fp%2FuZfohytGbwouMUAiGvJCEQKU1c%2F46mSXsWStX8BrKqJjVVRVXlN2BmPU6nAtzZswgxOMJhpP2SEQCiYUY%3D" target="_blank" oncontextmenu="return false;" onmouseover="kwE(event,73024);" onmouseout="kwL(event);" onmousemove="kwM(73024);">computer</nobr>, and then double click on the C:drive. then go to the windows folder in C:drive and double click it. once you've done that scroll down untill you've found a file name of b then click on it once so it highlights and delete it. then go to the recycling bin on ur desktop and delete the file name and thats all. no more hyperlink in ur profile.

I got the link off my instant messenger by deleting all "b" files, but the pop-up ads dont stop. I get about 25-30 a night. Is there a seperate file for that. Please help.

When I delete it and follow the directions that yall have given it goes away, but it comes back when I turn my computer on the next day. It's a real pain in the butt. Does anyone know what I might be doing wrong or know of something else that I can do?

For one thing, aren't you people running anti-virus programs? This would have never happened if u had one. I have norton and i clicked on it and it popped up saying that they were trying to send me a script and i stopped it. It tells me what it is, so maybe u people that have the virus, want me to do it again, so i can tell u what the script is and you can delete it from your computer? -Jon

yeah i found it but when i try to delet it .. it says ... cannot delet.. access denied and make sure the drive isnt full and blah blah.. can someone please help me?!?!

I was stupid enough to click the "woah look what i found here" hyperlink. I tried to download all of those programs and none of them work so this might help you too. go to cntrl anlt delete and scroll down until you find B. highlight it and click end task. look for it in C:/windows and look for B again. Delete it.Then also delete it from the recycle bin. go back yo your profile and delete it all. Sign off then get back on and see if it worked!;)

In c:\windows, I also found a program called bbb.exe next to b.exe. it had the same creation date so i assumed it was part of the virus so i deleted it as well. The hyperlink is no longer in my profile and i don't get those annoying pop ups anymore.

I FOUND OUT HOW TO CLEAR IT FOR GOOD!!!!!
everyone listen up!
follow my directions exactly!
1. press control+alt+delete. Find the application "B" or "b.exe" on your processes on ur task manager.
2. DELETE "B"/"b.exe"!!!
3. Go to C:\windows
4. Find "b" or "b.exe" and delete it
5. Go to your recycle bin AND DELETE IT!
6. Sign off of AIM if you are on it and sign back on. If its not on your profile congrats, if it still is follow the follow steps.
7. Go to your profile and edit it. UN-hyperlink the URL. Do this by hi-liting
the link and "remove link". Click ok and finish profile.8. Go BACK to your profile and delete the text. Finish it and sign off AIM.
9. SIGN BACK ON ARE YOU ARE DONE!
CONGRATS HOPE IT HELPED. AND THANKS TO EVERYONE ELSE TO TOLD ME HOW TO FIND B.EXE!
xoxoxoxooxox

Billy,
To end those damn pop ups, run services.msc from start->run. Then click on the Messenger entry in the list, click stop, and then disable. This should do it.

my problem here is I clicked that link but stopped the download in the middle, so I never had the link in my AIM profile. I do not have the b.exe or bbb.exe and my messenger entry in services.msc is already disabled and i keep getting the pop ups still i've run numerous anti-virus programs and went to the realphx.com website that was supposed to take it off and nothing is helping!!! it's slowing down my computer and i get about 20 pop ups per hour help me!!

i just wanted to thank all of u.... i have tried for sooooo long to get rid of it and u guys showed me how... thanks

well i clicked this too, and it downloaded porn things like some adult pass and adult entertainment and adult daily junk and an internet adult toolbar and some other tool bar, ive tried to get rid of it but its not working. Ive looked for them in remove programs on the control panel, ive deleted the folders off the desktop and the link folders out of my favorites and the shortcuts in my programs from start. but the toolbar is still there and when i check that toolbar all those links and everything pop right back up on my desktop and favorites! please help i dont want this stuff on my precious computer!!

for those of you getting pop ups, try spybot search for it in google. It might not just be the virus you got from aim, it might be caused by any website trying to force that on you. In this case run spy bot, delete all of the offer companions (ie gator) from your computer and hopefully that will try it. Also if all of the prior listings don't work and when you reboot the virus reappears, it is probably in your registry. This is stated in one of the earlier posts however you have to find out what key (local users, current) or whatever place, try googling this problem and it should tell you how to get to the key running regedit from the start>run. Good Luck, and before you ever click on a link in someone's profile place your mouses pointer over it to see what the link is, if you don't recognize it, why click it.

Easy Way to get rif of 'B.exe' - You should Dowload Ad-aware 6.0 if you don't already have it and then run it - it will delete everything that has to do with B.exe + get rid of a lot of other crap off your computer.

This virus downloads and installs over 500 files, about 15 different spyware programs. This is what causes the popups. Spybot finds approximately 300 of these files and will remove them. It also founds about 100 registry entries and removes those. The virus has not been classified by any virus scanner that I know of and thus they will not help. Just deleting b.exe will not remove the virus completely. There are also other files such as bbb.exe aaa.exe ccc.exe and mdbb.exe or something similar. There are also some files that appear to have randomly generated file names.

i delete the file from processes but it will not let me delete it from C:\windows. It says "make sure the disk is not full or write-protected and that the file is not currently in use". UHHHH driving me crazy! Anyone outt there that can help PLEASE?

I, like everyone else here, clicked on that Godforsaken whoaaa...look at link and although it did not get put into my AIM profile it did result in adult icons on my desktop, an adult toolbar, and a ton of pop-ups. I deleted everything and then downloaded Spybot and everything seemed to be okay, but now I can no longer download powerpoint slides from the Internet(I need these for my classes). Every time I try it a message pops up from Microsoft Explorer telling me there was a problem and it must close the program. This is very frustrating and I would greatly appreciate it if someone could tell me what is causing this -the virus or Spybot? - and what can I do to fix the problem???? Please help....

Supposedly the talkstocks AIM profile link is not a virus or anything, just annoying adware. Go to this website and click remove: http://www.talkstocks.net/disclaimer.htm

4get that weird stuf about opening ur c drive it was confusing and wasnt on my puter
just go to http://www.rsaisp.com/software.asp and click binary and download it its SO easy it LITERALLY takes 5 minutes to get rid of that dumb aim link
it worked really well for meand u ppl who have the pop up problems, i also had that same problem 2..its probably ad-ware/spy-ware messing up ur puter
http://download.com.com/3000-2144-10186632.html
download it and run it and itll get rida the ass-ware 4 ya! ;-) glad 2 be of service
AliKat91190 (7:48:24 PM): 4get that weird stuf about opening ur c drive it was confusing and wasnt on my puter
just go to http://www.rsaisp.com/software.asp and click binary and download it its SO easy it LITERALLY takes 5 minutes to get rid of that dumb aim link
it worked really well for meand u ppl who have the pop up problems, i also had that same problem 2..its probably ad-ware/spy-ware messing up ur puter
http://download.com.com/3000-2144-10186632.html
download it and run it and itll get rida the ass-ware 4 ya! ;-) glad 2 be of service

If anyone didn't post this yet, I'd like to mention that there is also the html file that contains the link to talkstocks on there.
Go to u'r windows explorer:
Expand the C:\ drive
Expand "WINDOWS"
Expand "aim95"
click on the folder w/ u'r s/n on it...u'll see an html file called "info"--which contains the link. that is also another thing u will need to delete.

Dowload Ad-aware 6.0 if you don't already have it and then run it - it will delete everything that has to do with B.exe + get rid of a lot of other crap off your computer.

click this link and i promise it works because i tried the whole scanning for viruses, control alt delete, and couldnt get n e of it to work but my bf told me to click this link and i promise it works!! all u have to do is what it says at the very bottom. u can read the top but dont get confused, JUST DO THE BOTTOM cause the link looks like the site that u clicked on to get the damn thing in the first place. click and do the botton http://www.talkstocks.net/disclaimer.htm

I deleted AIM off my system, and now I'm trying to reinstall it. But when I try this, I get 2 messages...one saying that miscui.ocm failed to load, and the other saying that the instruction at "XXXX" referenced memory at "XXXX". The memory could not be read.
Does anyone know how to fix this so I can download AIM again?? I've been using AIM express and getting sick of it...

for those of you with the popup problem, download a stopper at popupstopper.com...it helps get rid of all those AIM popups that require you to click ok to get rid of...for internet popups, download a full version of popupstopper deluxe of kazaa or something. I also strongly agree with the guy up there that said to download Ad-Aware...it's a great program, got rid of a lot of spyware and junk.

I also have a file named ccc.exe in my windows folder....it was created last night when i was trying to get rid of another program i found while trying to get rid of the realphx thing...i dunno where it came from...but i found a site that will get rid of a lot of parasites in ur comp...i got rid of at least 5 and my comp is runnin a lot better now..http://www.doxdesk.com

I have deleted everything as instructed above, and I installed a spybot and everything, but everytime I restart, I still get the adult toolbar and adult links shortcut. I've deleted this several times and it keeps coming back. What else can I do?

go to http://www.doxdesk.com/parasite/AdultLinks.html that will give u instructions to get rid of the adult links for good........

To get rid of the WHOAAA... LOOK WHAT I FOUND, CLICK HERE! adware go ................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................
..........................................................................................HERE:
http://www.realphx.com/remove.htm (this is simple-step instructions on how to get it off your profile, out of your favorites, and off your computer for good.)

do NOT go to realphx.com!!!
here is a quote from " http://www.rsaisp.com/software.asp "
*DO NOT download the realphx fix provided by realphx.com. All it does it removes the current worm, and installs an updated version that does more damage to your computer.is that enough?

Okay... here's how you do it, im sure of it:
1) Press CTRL+ALT+DELETE at the same time and then run through the tasks and look for "b" or "b.exe". Then END THE TASK.
2) Then do a search for either "b" or "b.exe". When you find it DELETE IT.
3) Go to RECYCLE BIN and EMPTY IT
4) Then download Ad-aware 6.0 from download.com, or just do a google search. RUN IT and then make sure all the little boxes are clicked before you hit FINISH.
5) SIGN ON AND OFF OF AIM. It should be gone, if not you did something wrong.

sirously I JUST NOW deleted this stuff
press ctrl+alt+delete at the same time and a screen should pop up...make sure ur in the process tab... now look for files saying "b.exe" or "bb.exe" or anything that is remotely close to that like "belt.exe" or whatever.
and after you find those files select them and press END PROCESS at the bottom.
now go to c/:windows
look for the same thing "b.exe" etc... delete them too...
go to the RECYCLE BIN and EMPTY IT
then go to ur aim profile and delete the link content
SIGN OFF
SIGN BACK ON
and CHECK to see if its OFF congrats!!!!!
you dont have to download ad-aware..its godo to clear a whole bunch of files that the link may have downloaded which u prolly should do....hope this helped !!!!!

everytime i try to delete it from my windos, i get the "you cant cuz the disk is full or in use" thing... how do i get around it?!! HELP!!

it says its in use becus u havent ended the prcocess prolly.
so do these steps over:
press ctrl+alt+delete at the same time and a screen should pop up...make sure ur in the process tab... now look for files saying "b.exe" or "bb.exe" or anything that is remotely close to that like "belt.exe" or whatever.
and after you find those files select them and press END PROCESS at the bottom.

Ok, none of you have given a good explanation.
First, one may not have even needed to accept or Ok the download in the first place if they haven't updated their microsoft internet explorer since October. There are several backdoors that can be taken advantage of. AIM runs off of some IE which is where the trojan sends itself.
Like any good/annoying trojan or virus, you can't simply delete one file. By the time you restart your computer, it'll be back again. Here is a program that we, RCC staff members at Bowling Green State University, have that will remove the troubles.
Unfortunately, this will only work to remove Realphx and Aplore. We're having problems with removing the tallstocks.net version.
By going to the following site, which you'll see is official by being .edu, the download will initially start. Your web-browser should restart to it's default, msn.com, but you will need to manually change your AIM profile afterwards.
http://rcc.bgsu.edu/faq/Tools/FixMessageTrojans.exe
You're welcome.
Magnus Unus

yea ok well for me it didnt and so for everyone has been saying it worked...so maybe its just you, or you havent done it yourself buddy.

HELP!***
Whenever I bring up the Task Manager bar (you know, the box that comes up when one presses Ctr+Alt+del.?) there are NO TABS at the top where i can FIND the "b.exe" or "b". There is also NO "X" or "minimize" buttons at the top. Somehow they are GONE and if anyone knows how TO GET THEM BACK, PLEEEEEASEEEEEE tell me!!!!!!!!!!!!!!!!!!!!!!!

I'm not sure why there are no tabs, maybe you would want to try doing system restore and then a windows update to try and fix the problem.
Remove b.exe - Go to Start, Run, type in msconfig, go to the startup tab and uncheck b.exe -- Go to Start/My Computer, C: - WINDOWS Folder & then to regedit icon (green blocks) Once you open up your Registry Editor go to Edit - Find and type in b.exe - delete the folder. Download Ad-aware 6.0, run it. It will remove the b.exe - I had it and I know a lot of other that have had it. That should remove it. Also, make sure you go to the WINDOWS Folder once more and delete the b.exe installer as well.

PivX has released a FREE tool called Qwik-Fix that protects against future infections of AIM/AOL Instant Messanger profile and message viruses. Once you have removed the virus(s) [http://rcc.bgsu.edu/faq/FixMessageTrojans.htm]
...then you can go to the PivX website and Install Qwik-Fix: http://www.pivx.com/qwikfix/

hey i too got he same "whoa.." virus, and it put a link into my profile. But then, it went away on its own. does that mean the virus is gone for good?

hmm.. i have another problem somewhat similar to this megdbest... i was being really stupid and decided to click something on one of my friend's profiles.. it said something like, " look at this picture of *insert screename* HAHAHAHA" or something like that, its not exact.. but once i clicked it, i was stupid (yet again) and installed/downloaded something, and wondered where it was..later i realized that phrase was in MY profile, and whenever i put my away message on, the phrase came back to my profile.. i tried things but it didnt go away.. and then all of a sudden it just.. disappeared.. this was all in a matter of 30 minutes btw.. i dont know what happened, and worried this will come back.. what should i do? thanks..(i hope i made sense, sorry if i didnt)..

go to that site listed above... the same way to get rid of the wooooh look at this site!!! thing...

hey, wow. it came back. When i did a check, it said that i didn't have any of the bb.exe files. and i went to [http://rcc.bgsu.edu/faq/FixMessageTrojans.htm] site and it didn't help. I also don't have the realphx one i have the toolstocks virus. grrr. could someone give me directions in lamen's terms cuz i'm not very computer savvy.

ok with the picture link virus, under windows what about the ones called bi whatever, i have belt too... should i delete those? and what about ending any processes? i dont have one called belt so im not sure.

which adware thingi do i download? I know its 6.0 and i clicked the fere copy, but then in the free copy there are like 6 options. do i get all siX?

ok ok. i got how you do this. Do NOT go to realphx.com. go to "http://www.rsaisp.com/software.asp " Once i did that, I said open, and then it scanned my computer. then i just went and changed my profile and it changed for good!! YEY :). so if u have a problem like mie where the only thing affected is u're profile, then just follow the directions on the above website :). YEY. good luck :)

Dee, I also had the same virus you had. I had to do the ctr. alt delete thing and delete the process b.exe AND a process called av.exe. This was recommended by McAfee Virus Scan. After you do that you need to do a search for both b.exe and av.exe and delete anything that looks close to that. Thanks!

In my AIM profile I keep getting a link that says Look at what I found IImeow22's pic. HAHAHAHA. I have tried everything to get rid of it. I finally got it to get out of my profile but now everytime I try making a profile it will delete it and become blank. And does anyone know if "bartcache" is supposed to be a folder on your computer? Can someone please tell me what to do. Thanks.

hey guys!
ive been having the same problem, and i couldnt find a b.exe or anything. i found an AV.exe though, and i think it serves the same purpose. just thought you should know. try ctrl alt delete, and end task on av.exe, and then delet all the junk you need to delete.

OK, im adding something else to this.
I just fixed it on my computer. I think there has been a recent update to the file, and that's why it's such a bitch to delete. end task on av.exe, delete it from the windows file, delete the info.html file in your aim95 folder, and delete the system registry key "antivirus" in HKEY_LOCAL_MACHINE/software/microsoft/windows/currentversion
there ya go, worked for me

Hey all, i had the talkstocks.net virus too, i tried to remove it but didnt(not enough time), had to restore my comp for a different reason because my computer wouldn't boot so i had to restore, if all else fails for you guys, save the files u want on a disk and restore your computer.

The best way to just get rid of the virus... is get a copy of the latest norton anti virus, makes sure you have the lastest virus definitions and it will clean the infected files and protect you from further occurences

is bartcache supposed to be a folder, or is it related to the virus?
i manually deleted the virus, so av.exe and the registry key are gone, but that bartcache folder keeps coming back.
please reply and tell me if this is a viral folder. if so, how can i remove and prevent it.

first of all the file is called av.exe i had the file and the same thing all of u have..no wonder b or b.exe isn't in there!!
ok go into taskmanager look for a thing called av.exe then press end process
go to your profile highlight the link and right click press delete not backspace then sign off and get back on!! and if it is not gone do this again

I've fixed this virus on a couple of people's computers…just as a clarification, the virus can have up to three files associated with it: b.exe, bbb.exe, and av.exe. I haven't had to deal with the porn stuff yet, although I wouldn't be surprised if I have to, eventually.
I don't know anything about a bartcache folder related to this virus. I don't think it's related to the virus…on the other hand, I don't think it's a normal AIM folder, so…

u guys dont noe the answer at all. there is no b.exe thats spyware from the virus, u dont have to delete it. damn i figured it out and im only 13 years old. go here http://www.angelfire.com/scary/neopunk/ there ur answers r solved

![]() |
![]() |
![]() |

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |