We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Trojan Horse Pakes.CBE please help

1234689

Comments

  • Dustykitten
    Dustykitten Posts: 16,507 Forumite
    Part of the Furniture 10,000 Posts Combo Breaker
    Shield back on - stopzilla looked fun and was much less scary, shame it's rubbish.
    The birds of sadness may fly overhead but don't let them nest in your hair
  • Dustykitten
    Dustykitten Posts: 16,507 Forumite
    Part of the Furniture 10,000 Posts Combo Breaker
    I think it was after I had installed it but before I ran it. Is Zango a virus?

    ETA: OK I've just googled it and now wish I hadn't! OH has just walked throught the door; returned from an overseas trip and when I told him he screamed at me don't delete registry keys - I'm sticking with you guys.
    The birds of sadness may fly overhead but don't let them nest in your hair
  • Certainly undesirable.
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    If you feel upto it Kitty ~ these instructions 'should' completely remove it (Dependent on if ZANGO has gotten worse since)

    http://www.411-spyware.com/remove-zango-toolbar#deletefiles
    :idea:
  • Dustykitten
    Dustykitten Posts: 16,507 Forumite
    Part of the Furniture 10,000 Posts Combo Breaker
    Thanks RIK that is the website I saw last night. I think the procedure is way above my ability (you saw what happened yesterday) so I need to do it this evening when OH is about as I don't even know how to backup my registry (OK I don't even know what my registry is).
    The birds of sadness may fly overhead but don't let them nest in your hair
  • Dustykitten
    Dustykitten Posts: 16,507 Forumite
    Part of the Furniture 10,000 Posts Combo Breaker
    I ran spybot again to see if anything had changed.

    Updated
    Immunized and today there are 49 unprotected files (plugins) yesterday they were all protected.
    Scan picked up just the same toolbar problem but again it cannot fix it.

    ETA: I've now run AVG aswell and worryingly it does not find any infections or warnings
    The birds of sadness may fly overhead but don't let them nest in your hair
  • Combofix has a built in programme that backs up your registry - so all is good on that front.

    If all is ok at the moment I am loathed to start fiddling with the registry.

    It's up to you but if all is good at the moment I would be inclined to give it a day or two and see if you get any more warnings.

    Your call.
  • Dustykitten
    Dustykitten Posts: 16,507 Forumite
    Part of the Furniture 10,000 Posts Combo Breaker
    I've just started getting messages from zone alarm saying 'google toolbar' is trying to access a ......... zone' could that be Zango pretending to be google?
    The birds of sadness may fly overhead but don't let them nest in your hair
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Just block it for now if your not sure

    May as well try a scan with DR WEB ~
    http://www.freedrweb.com/
    :idea:
  • I would go with the above suggestion at the moment - I need to research more about the locked reg key;

    Before we start fixing anything you should print out these instructions or copy them to a NotePad file so they will be accessible. Some steps will require you to disconnect from the Internet or use Safe Mode and you will not have access to this page.

    Please download DrWeb-CureIt and save it to your desktop. DO NOT perform a scan yet.

    Reboot your computer in "Safe Mode" using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

    Scan with Dr.Web CureIt as follows:
    • Double-click on launch.exe to start the program.
    • Cancel any prompts to download the latest CureIt version and click Start.
    • At the prompt to "Start scan now", click Ok. Allow the setup.exe/driver to load if asked by any of your security programs.
    • The Express scan will automatically begin.
      (This is a short scan of files currently running in memory, boot sectors, and targeted folders).
    • If an infected object is found, you will be prompted to move anything that cannot be cured. Click Yes to All.
    • When complete, click Select All, then choose Cure > Move incurable.
      (This will move any detected files to the C:\Documents and Settings\userprofile\DoctorWeb\Quarantine folder if they can't be cured)
    • Now put a check next to Complete scan to scan all local disks and removable media.
    • In the top menu, click Settings > Change settings, and UNcheck "Heuristic analysis" under the "Scanning" tab, then click Ok.
    • Back at the main window, click the green arrow "Start Scanning" button on the right under the Dr.Web logo.
    • When the scan is complete, a message will be displayed at the bottom indicating if any viruses were found.
    • Click "Yes to all" if asked to cure or move the file(s) and select "Move incurable".
    • In the top menu, click file and choose save report list.
    • Save the DrWeb.csv report to your desktop.
    • Exit Dr.Web Cureit when done.
    • Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
    • After reboot, post the contents of the log from Dr.Web in your next reply. (You can use Notepad to open the DrWeb.cvs report)
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 352.1K Banking & Borrowing
  • 253.6K Reduce Debt & Boost Income
  • 454.3K Spending & Discounts
  • 245.2K Work, Benefits & Business
  • 600.8K Mortgages, Homes & Bills
  • 177.5K Life & Family
  • 259K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.