Be sure to run both.
SpyBot and Ad-Aware, as what one does not detect the other
may. It is important that you follow all directions carefully:
SpyBot Search & Destroy: Free
http://download.com.com/3000-8022-10289035.html?tag=lst-0-2
or
http://majorgeeks.com/download2471.html
AdAware: Free
http://www.lavasoftusa.com/support/download/
or
http://www.majorgeeks.com/downloads31.html
AdAware Free:
Manual updates: Scroll down to Updates Available -
http://lavasoft.element5.com/support/download
(Check for Product Updates http://tinyurl.com/23lv4 )
CWShredder: Free
http://tinyurl.com/2l9kl
or
http://www.majorgeeks.com/download4086.html
SuperAntiSpyware
http://www.superantispyware.com/superantispywarefreevspro.html
Update all software before using them to scan your system. ALSO, and this is important, do all your scans in SAFE MODE.
I also suggest downloading, installing and updating BHODemon for any Browser Helper Objects that may be on the PC.
* BHODemon
http://www.majorgeeks.com/downloadget.php?id=3550&file=11&evp=245a87539eea8ed6904332b4b8b8442d
For viral malware...
* Download MULTI_AV.EXE from the URL --
http://www.ik-cs.com/programs/virtools/Multi_AV.exe
To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close
Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }
NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through your FireWall to allow it to download the needed AV vendor related files.
C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal Mode.
This way all the components can be downloaded from each AV vendor's web site.
The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the PC.
You can choose to go to each menu item and just download the needed files or you can download the files and perform a scan in Normal Mode. Once you have downloaded the files needed for each scanner you want to use, you should reboot the PC into Safe Mode [F8 key during boot] and re-run the menu again and choose which scanner you want to run in Safe Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.
When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive PDF help file.
http://www.ik-cs.com/multi-av.htm
Additional Instructions:
http://pcdid.com/Multi_AV.htm
If you don't have a firewall, Zone Alarm Free or Sygate Personal Firewall (free also) works very well. Close the following ports:
135, 137, 138, 139, 445
Zone Alarm - Free
http://tinyurl.com/iwhb
or
http://tinyurl.com/kzq
If you install this program it will help keep parasites and such from getting a firm grip on your system.
SpywareBlaster: Free
http://www.javacoolsoftware.com/spywareblaster.html
This is a must install.
Another thing, if you have not already done so, try to uninstall anything related to Zango using the "Add/Remove Programs" in the Control Panel. Also, there may be a re-install program builtin the windows "Startup" folder. If you have not already checked, take a look at the "Startup" tab and uncheck any strange programs running there when you bootup. Go to the Start button and choose "Run", type in MSCONFIG and say OK, then click Startup tab and check the list to see if anything there looks like it is for the Zango. If so, uncheck it.
Go through these malware removal steps systematically, doing all the preparatory work first:
http://www.elephantboycomputers.com/page2.html#Removing_Malware
When all else fails, read the information about using HijackThis at the link above and post to one of the specialty forums listed there.
Some forums that interpret HijackThis logs:
http://www.spywareinfo.com/forums/
http://forum.aumha.org/viewforum.php?f=30
http://forums.tomcoyote.org/
http://www.wilderssecurity.com/
If you are using any version of Sun Java that is prior to JRE Version 5.0, then you are strongly urged to remove any/all versions that are prior to JRE Version 5.0. There are vulnerabilities in them and they are actively being exploited.
It is possible that is how you got infected with malware.
Therefore, it is highly suggested that if there are any prior versions of Sun Java to Version 5 on the PC that they be removed and Sun Java JRE Version 5.0 Update 6 be installed ASAP. Unlike MS patching, Sun's are too dumb to remove old JREs when installing new ones, and the old ones can remain an exploitable risk. So remove the old ones first before installing the latest version. Not all malware infects through Java, though it is a favorite tactic for some.
Simple check, look under...
C:\Program Files\Java
The only folder under that folder should be the latest version...
C:\Program Files\Java\jre1.5.0_06
http://www.java.com/en/download/manual.jsp
ALSO....
In the Task Manager, stop running these programs:
180sainstalleradperform.exe
zanu.exe
Execute:
Click Start>Run> type the following then hit Enter:
regsvr32 /u zanuhook.dll
Remove registry entries:
Click Start>Run>type regedit>hit Enter.
Be careful when you do this becoz if you make a mistake you will have to reinstall Windows.
Delete the following entries:
HKEY_CLASSES_ROOT\typelib\{68bf4626-d66b-4383-a6af-62e57e9b6cd4}\1.0
HKEY_CURRENT_USER\software\zanu
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\zanu
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\zanu
HKEY_LOCAL_MACHINE\software\zanu
Find and delete files:
Using Windows' Search, find these...
180sainstalleradperform.exe
uninstall zango instructions.lnk
zango.com.url
zanu.exe
zanu_kyf.dat
zanuau.dat
zanuhook.dll
Remove Folders that are named something to the effect of:
C:\Program Files\Common Files\*zango*
C:\Program Files\*zango*
More information and assistance is available at these sites:
Blocking Ads, Parasites, and Hijackers with a Hosts File
http://www.mvps.org/winhelp2002/hosts.htm
The Parasite Fight
http://www.aumha.org/a/parasite.htm
For further assistance, go to:
My Computer Headaches YahooGroup:
http://groups.yahoo.com/group/mycomputerheadaches/
My Computer Headaches Forums
http://mycomputerheadaches.tz4.com
Guidelines on how to use SpywareBlaster, Ad-Aware, Spybot, and other anti-spyware are available in a restricted forum here. It requires a special password to access. You also must register. It is free membership.
2006-06-15 18:15:34
·
answer #1
·
answered by Reston 4
·
1⤊
0⤋
Somebody downloaded an adware infested game or software....I guess people will never learn, nothing is free on the internet! Keep in mind, you cant remove zango without removing the associated software! Tell whoever is using your system not to download so called, free music, internet games, porn, etc or you will be plagued forever. Limewire, bearshare, all this crap is at the very least infested with spyware! Sometimes the files also contain trojans, viruses, and page hijackers! Anyway, this is the only way to remove zango so get your typing finger limbered up.
http://www.spyany.com/program/article_adw_rm_Zango.html
2006-06-16 00:14:41
·
answer #2
·
answered by Anonymous
·
0⤊
0⤋
Zango is this site where you go to get "free" stuff but in the EULA which most people don't read, it expilicitly states "in return for free software we'll show you a few ads a day"
It can be easily removed with a proper spyware removal program. Your anti-virus simply would tell you where it is for manual removal, but tha damned places files all over your registry, so this is not practical.
One thing that people neglect to do before running a virus scan on already infected system is to switch off their "system restore" or else the virus or spyware/adware file remains continuously in back up.
You right click on "My Computer" click properties. click on the stytem restotre tab then check "Turn off System Restore on all drives and apply. Then run your virus scan again.
First of all, one of the easiest wey to stop online attacks is, STOP USING INTERNET EXPLORER. Ever noticed that add ons can be attached to that particular browser only. As well it uses ActiveX controls, whether you need it not. which allows your computer to be identified. Both Netscape and the latest versin of Firefox gives you the option to use ActiveX when it's actually needed.
The recommendation to use Spybot, I totally agree with, it is the only Spyware/Adware program that identifies and removes Trojans.: http://www.safer-networking.org/en/download/index.html
Also if you are running Window Defender it would have blocked the download in the first place, with a warning of the contents of the files:
http://www.microsoft.com/downloads/details.aspx?FamilyId=435BFCE7-DA2B-4A6A-AFA4-F7F14E605A0D&displaylang=en
Of course you need to be running a genuine version of Windows to download this.
2006-06-21 17:01:00
·
answer #3
·
answered by TrueTrueWest_Indian 2
·
0⤊
0⤋
Zango is extremely easy to remove...so I wouldn't worry about all the work involved in the previous answer.
Go to Control Panel - Add/Remove Programs.
Scroll down to Zango and click Remove.
Grab CCleaner from here:
http://www.ccleaner.com/
Clean your temp files and your registry with it and Zango is gone.
2006-06-16 03:00:32
·
answer #4
·
answered by Anonymous
·
0⤊
0⤋
Zango is an adware on your computer. Go here and hopefully it will remove it for you.
http://www.microsoft.com/windows/IE/community/columns/bugbusting.mspx
Now I recommend you get Site Advisor. It will alert you to bad sites. Read about and get it here: Its Free.
http://www.siteadvisor.com/
2006-06-16 00:13:24
·
answer #5
·
answered by Anonymous
·
0⤊
0⤋
it is a pain in the but spywar and adware, for a game site, you boobooed getting it, it is hard to get rid of,.here is the instructions
scroll down the page for the instructions
http://www.geekstogo.com/forum/index.php?showtopic=100018
2006-06-16 00:09:53
·
answer #6
·
answered by butchell 6
·
0⤊
0⤋
i got the same thing 3 months ago i had to reinstall my windows its the only way
2006-06-16 00:17:59
·
answer #7
·
answered by carriage64 2
·
0⤊
0⤋
they got you -- crap! -- time to re-load windows! STOP CLICKING ON **** YOU DON'T KNOW WHAT IT IS!!
2006-06-16 00:10:23
·
answer #8
·
answered by MaLLoDoG 1
·
0⤊
0⤋
It's adware
it's the devil.
2006-06-16 00:08:36
·
answer #9
·
answered by Hippie 6
·
0⤊
0⤋