ZANGO and my PC - PC is not looking so good.....

G

Guest

this past weekend I got infected by ZANGO. I was running EZ Armor virus,
pest partol, and the firewall. I also had WINDOWS DEFENDER in the back ground
set to get auto updates, and winpartol. A sign showed up on my screen asking
if "I wanted to run this program" along with the winpartol showing up saying
with the warning "unsafe program" and then all of a sudden, ZANGO was in. I
didnt even have time to click no. Nothing was clicked, but it was there. I
unplugged the computer. It disabled my firewall along with the other
programs running. .
Here is my problem, and I would appricate ALL the help I can get, I am at my
wits end. Zango hit my system and hit it hard. It destroyed all of my auth.
codes, I no longer have access to my Office XP and it did the save for
Windows XP Home. I have been able to get windows going again, but when when
I try to install the new anti virus program, I get " WINDOWS INSTALLER IS NOT
ACCESSIABLE, THIS EITHER HAPPENS WHEN YOU ARE IN SAFE MODE OR INSTALLER IS
NOT INSTALLED CORRECTLY". from the looks of it as i dig deeper, my I386
files have been corrupted, when I try to get system info, it tells me that
the data is not able to be located. Basically in a matter of SECONDS, this
virus destroyed many of my system files. I do not have my system disks but I
do have all the system info printed up. ( I try to keep a paper copy for
back-up) I am in desporate need of assistance. If I could just wipe it all
clean and redo the computer, that would be great....BUT I have important docs
on here that I am needing for a court case, and I am unable get them off. So
as of right now, re-formatting is NOT A OPTION. PLEASE, IF ANYONE CAN HELP
....... I have all types of logs that i have saved, BEFORE AND AFTER THE
ATTACK. I need someone who will be willing to see what i see. I called TECH
support.....and when I spoke with them today, they had not heard of ZANGO .
They said that Windows Defender does not recognize Zango as a threat, because
it is a actual site. Then I was told that what i was saying is happening
- can not be happening. I have done the MS online PC scan and it didn't
detect anything, but I did a online scan from another site and it picked up
alot. I need someone that is willing to set aside all of their knowledge
and take a look at what I have with a open mind, I would greatly appricate
it. ZANGO is nothing nice. It did ALOT of DAMAGE in a small amount of
time. Here are a couple of links that tells a little about it. These links
are safe..they are just for information.

http://www.bleepingcomputer.com/startups/zango.exe-7041.html

http://research.sunbelt-software.com/threat_display.cfm?name=Zango.SearchAssistant&threatid=14904
 
M

Malke

what said:
this past weekend I got infected by ZANGO. I was running EZ Armor
virus, pest partol, and the firewall. I also had WINDOWS DEFENDER in
the back ground
set to get auto updates, and winpartol. A sign showed up on my screen
asking if "I wanted to run this program" along with the winpartol
showing up saying
with the warning "unsafe program" and then all of a sudden, ZANGO was
in. I
didnt even have time to click no. Nothing was clicked, but it was
there. I
unplugged the computer. It disabled my firewall along with the other
programs running. .
Here is my problem, and I would appricate ALL the help I can get, I am
at my
wits end. Zango hit my system and hit it hard. It destroyed all of my
auth.
codes, I no longer have access to my Office XP and it did the save
for
Windows XP Home. I have been able to get windows going again, but
when when I try to install the new anti virus program, I get " WINDOWS
INSTALLER IS NOT ACCESSIABLE, THIS EITHER HAPPENS WHEN YOU ARE IN SAFE
MODE OR INSTALLER IS
NOT INSTALLED CORRECTLY". from the looks of it as i dig deeper, my
I386 files have been corrupted, when I try to get system info, it
tells me that
the data is not able to be located. Basically in a matter of SECONDS,
this
virus destroyed many of my system files. I do not have my system
disks but I do have all the system info printed up. ( I try to keep a
paper copy for
back-up) I am in desporate need of assistance. If I could just wipe
it all clean and redo the computer, that would be great....BUT I have
important docs on here that I am needing for a court case, and I am
unable get them off. So
as of right now, re-formatting is NOT A OPTION. PLEASE, IF ANYONE CAN
HELP ...... I have all types of logs that i have saved, BEFORE AND
AFTER THE
ATTACK. I need someone who will be willing to see what i see. I
called TECH support.....and when I spoke with them today, they had not
heard of ZANGO . They said that Windows Defender does not recognize
Zango as a threat, because
it is a actual site. Then I was told that what i was saying is
happening
- can not be happening. I have done the MS online PC scan and it
didn't detect anything, but I did a online scan from another site and
it picked up
alot. I need someone that is willing to set aside all of their
knowledge and take a look at what I have with a open mind, I would
greatly appricate
it. ZANGO is nothing nice. It did ALOT of DAMAGE in a small amount
of
time. Here are a couple of links that tells a little about it. These
links are safe..they are just for information.

http://www.bleepingcomputer.com/startups/zango.exe-7041.html
http://research.sunbelt-software.com/threat_display.cfm?name=Zango.SearchAssistant&threatid=14904

I would first get the data off by using Knoppix. I'll give you
instructions, but if it sounds like more than you can do (and there is
no shame in admitting that), take the machine to a professional
computer repair shop. Call first to make sure they have data recovery
skills. This will not be your local version of BigStoreUSA.

After you've gotten the data off, safely backed up, then run HijackThis
and post your log at one of the HJT forums below (not here, please).

Knoppix:

An easy way to retrieve Windows files is to boot with Knoppix, a Linux
distro on a live cd. You will need a computer with two cd drives, one
of which is a cd/dvd-rw OR a usb thumb drive with enough capacity to
hold your data OR an external hard drive formatted FAT32 (not NTFS). To
get Knoppix, you need a computer with a fast Internet connection and
third-party burning software. Download the Knoppix .iso from
www.knoppix.net and create your bootable cd. Then boot with it and it
will be able to see the Windows files. If you are using the usb thumb
drive or external hard drive, right-click on its icon (on the Desktop)
to get its properties and uncheck the box that says "Read Only". Then
click on it to open it. Note that the default mouse action in the
window manager used by Knoppix (KDE) is a single click to open instead
of the traditional MS Windows' double-click. Otherwise, use the K3b
burning program to burn the files to cd/dvd-r's.

HijackThis:

http://www.aumha.org/a/hjttutor.htm - HijackThis tutorial by Merijn
http://www.bleepingcomputer.com/forums/index.php?showtutorial=42 -
another tutorial
http://aumha.net/viewforum.php?f=30
http://castlecops.com/forum67.html
http://spywarewarrior.com/viewforum.php?f=5 - Spyware Warrior HijackThis
forum
http://www.wilderssecurity.com/
http://forums.tomcoyote.org/

Malke
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads


Top