Adware

How to remove “Adware.Zango.1”?

Malware Removal

The Adware.Zango.1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Zango.1 virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Enumerates physical drives
  • Attempted to write directly to a physical drive
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Adware.Zango.1?


File Info:

name: A1F904ABD689FFF2B13C.mlw
path: /opt/CAPEv2/storage/binaries/63ae685216c549645f087af830be34e779ed580c1ee9c6303beb63358a71fd0b
crc32: F5964A60
md5: a1f904abd689fff2b13c3981411eb085
sha1: 7ad72bd127e61953214cfd9f4edade572ac6886d
sha256: 63ae685216c549645f087af830be34e779ed580c1ee9c6303beb63358a71fd0b
sha512: 2c94c3ebd835e0b48daad1b2f1284f7e111fec8f4305936222a9f52c10d0be0361d7baeb98000eaa84865bb999695c0504515eb31120f5823ba8bf1f27e025ce
ssdeep: 6144:feXA47CURW+eirtnIwE0XzBTjrBLt4smgZt0nduextCDLLqM2TR:feXv7tRWwnIKBTjx6smgonLtqL32TR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T106641292E6007554F1A00EBC927784E61609F1BBECAC6B1BCE9D8DA32DF5BD30757206
sha3_384: 2904b86d5587d56604c425d81b6a312c15e2ee3afd46b77331db20e90f37ff1d1d1f100070698366dfbbb380e2010cba
ep_bytes: 60be00b046008dbe0060f9ff57eb0b90
timestamp: 2012-10-29 15:33:03

Version Info:

FileDescription: Setup
FileVersion: 3.0.110.1
ProductVersion: 3.0.110.1
Translation: 0x0409 0x04b0

Adware.Zango.1 also known as:

BkavW32.AIDetectMalware
LionicAdware.Win32.ScreenSaver.lr65
Elasticmalicious (moderate confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.a1f904abd689fff2
CAT-QuickHealPUA.Appbundler.Gen
SkyhighAdware-HotBar.d
McAfeeAdware-HotBar.d
Cylanceunsafe
SangforPUA.Win32.Sign.a
K7AntiVirusAdware ( 00314f2c1 )
AlibabaAdWare:Win32/ScreenSaver.c4dae630
K7GWAdware ( 00314f2c1 )
CrowdStrikewin/grayware_confidence_100% (W)
VirITPUP.Win32.AppBundler.A
SymantecPUA.Gen.2
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Adware.HotBar.L
APEXMalicious
ClamAVWin.Adware.Screensaver-1
Kasperskynot-a-virus:AdWare.Win32.ScreenSaver.e
BitDefenderGen:Variant.Adware.Zango.1
NANO-AntivirusTrojan.Win32.cwpj.dvtojy
MicroWorld-eScanGen:Variant.Adware.Zango.1
AvastWin32:Zango-AQ [PUP]
TencentAdware.Win32.Hotbar.16000527
EmsisoftGen:Variant.Adware.Zango.1 (B)
BaiduWin32.Adware.Agent.b
F-SecureTrojan.TR/Banach.A
DrWebAdware.Hotbar.700
TrendMicroPossible_HOTBAR.UNP
Trapminemalicious.moderate.ml.score
SophosHotbar (PUA)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Adware.Zango.1
JiangminAdWare/ScreenSaver.qi
WebrootAdware.Hotbar
GoogleDetected
AviraTR/Banach.A
Antiy-AVLGrayWare[AdWare]/Win32.HotBar
Kingsoftmalware.kb.b.973
XcitiumApplicUnwnt.Win32.AdWare.ScreenSaver.DI@4t0hrx
ArcabitTrojan.Adware.Zango.1
ZoneAlarmnot-a-virus:AdWare.Win32.ScreenSaver.e
MicrosoftAdware:Win32/Hotbar
VaristW32/A-1bf7d2ed!Eldorado
AhnLab-V3Adware/Win32.ScreenSaver.R22944
Acronissuspicious
VBA32BScope.Adware.ScreenSaver
ALYacGen:Variant.Adware.Zango.1
MAXmalware (ai score=99)
MalwarebytesGeneric.Malware.AI.DDS
TrendMicro-HouseCallPossible_HOTBAR.UNP
RisingTrojan.Win32.Generic.14570C1A (C64:YzY0OriBSg+S9h1a)
YandexTrojan.GenAsa!ZoRco6P4FCQ
IkarusTrojan.SuspectCRC
MaxSecureAdware.AdWare.WIN32.ScreenSaver.e_214905
FortinetAdware/Hotbar
AVGWin32:Zango-AQ [PUP]
Cybereasonmalicious.127e61
DeepInstinctMALICIOUS

How to remove Adware.Zango.1?

Adware.Zango.1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment