Re: 8oeucz.exe file malicious & can't delete, help!

From: Steven L Umbach (n9rou_at_n0-spam-for-me-comcast.net)
Date: 07/15/04


Date: Thu, 15 Jul 2004 00:39:52 GMT

There is a lot of junk that is very hard to get rid of these days. I would however
try downloading AdAware also being sure to update it right away which is an option
when you start the program. They are doing almost daily updates. Try it once and if
it finds anything try again. If it continues to keep finding problems you will need
to try more advanced techniques as explained in the link below. It would also be
worth trying to run AdAware in safe mode if it does not work otherwise. If need be
you could try loading safe mode on networking to download and install software if
regular mode will not allow it. Note that booting into safe mode with networking will
disable a software firewall.

Configure AdAware to use custom options after you select start. Then enable all
possible options by selecting customize that would normally be red in color.While in
customize select tweaks and then cleaning engine and enable try to unregister objects
prior to deletion. Delete all of your temporary internet files and cookies before
scanning. if you continue to have problems you might try to disable BHO capability in
Internet Explorer by going into tools/advanced options and disable third party
browser extensions that will require a reboot. You may have to reinstall any
applications using BHO's when done. BHODemon can help find and eliminate unwanted
BHO's.

The Process Explorer tool from SysInternals may help you in tracking down rogue
processes and Autoruns may help also with startup programs list that will be a lot
more extensive than msconfig. --- Steve

http://www.lavasoftusa.com/
http://www.definitivesolutions.com/bhodemon.htm
http://www.aumha.org/a/quickfix.htm -- more advanced procedures including Hijack
this.
http://www.sysinternals.com/ntw2k/freeware/procexp.shtml

"Edward29" <anonymous@discussions.microsoft.com> wrote in message
news:2d41d01c469fa$f9416710$a501280a@phx.gbl...
> I have a crazy acting Win 2K Pro(sp4), it has a file
> named '8oeucz.exe' listed & jumping all over the Processes
> list, consuming all kinds of processor, and preventing the
> PC from starting beyond the desktop background(no icons).
> I can get the task manager open & then Run, command line.
> Worse when connected to the internet. I can kill all the
> startups in MSconfig and get it started at times.
> All MS security & updates are in place. Spybot & F-Prot
> don't find it. Other suspect applications I can't un-
> install include:
> The other suspect applications I can't uninstall are:
> 'Context Display'
> 'Internet Optimizer'
> 'LookSmart Search'
> 'Lycos Search'
> 'Remove MyApp'
> 'RON Display'
> 'URL Display'
> 'WSEM Update'
>
> Help!!
> Any suggestions appreciated.
>



Relevant Pages

  • Re: Slow start up?
    ... However, I'd perform some checks for malware, using a combo of Adaware SE ... and Spybot Search and Destroy - with updated definitions - in safe mode. ... Internet files". ...
    (microsoft.public.windowsxp.general)
  • Re: Nasty Virus
    ... Have Adaware remove the parasites in Safe Mode and delete the hosts file. ... | Restore and re-apply any ...
    (microsoft.public.security.virus)
  • Re: Control Panel wont open
    ... I used Adaware 6, Spybot S&D, and SwatIt. ... I also have Norton Internet Security which is along with the previous ... I did as you suggested by running them in Safe mode along with Normal mode ... > download it and install it. ...
    (microsoft.public.windows.file_system)
  • Re: ie 6 dies on internet connection
    ... The problem is when Internet Explorer tries ... I can open any HTM page on my hard drive with IE6, ... >>typing in a URL, windows media, real player, norton antivirus, adaware, ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: Please Help! Hijacked Network!
    ... that AdAware misses, and visa-versa. ... There's a free tool called AutoRuns on ... >> I suspect it's just a key left over from one of the old ... >> The good news is that Safe Mode prevents the queues from ...
    (microsoft.public.windows.server.sbs)