PUA

Win32:Zango-M [PUP] removal guide

Malware Removal

The Win32:Zango-M [PUP] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Zango-M [PUP] virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the embedded pe malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32:Zango-M [PUP]?


File Info:

name: 29044C49FA2B285BB51B.mlw
path: /opt/CAPEv2/storage/binaries/d4cf04b5a2d9ac7e6caf09695abdde5802b6bdc3ea5f65751f7f4b78cdd92f6e
crc32: 4089A72B
md5: 29044c49fa2b285bb51bf37ada37d41c
sha1: f7e0fd9406c830f9f37abca228686ddeac28e171
sha256: d4cf04b5a2d9ac7e6caf09695abdde5802b6bdc3ea5f65751f7f4b78cdd92f6e
sha512: 99458ec5581510e241cecd96ea6f45df8100b195895acf7ceb93ec4355af0301ea75b5c77f4c0c2cf378052d19791c9b5b714d46c103d43afa9fc9401d073f8f
ssdeep: 98304:+D3cQYoH5//fMSMtVj3tY6jcHCzGDDy/EE+seb7I7MRC:63VYoH5//kSY+qFzGDDqvte3I7MM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1630633C3DC8744BBDBF08EB54244C32B6336BE339E94C85123E75439A69B09D97589C6
sha3_384: 8f263433d95e4226a973ae53cb564173133931b7f151a3ae6f216f7bc211861a167f1560f1bf667c77ec7517cebe0748
ep_bytes: 558bec83c4b853565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Win32:Zango-M [PUP] also known as:

BkavW32.Common.0581380B
LionicAdware.Win32.180Solutions.2!c
AVGWin32:Zango-M [PUP]
DrWebAdware.nCase
SkyhighArtemis!PUP
MalwarebytesGeneric.Malware/Suspicious
AlibabaAdWare:Win32/180Solutions.51925e6c
SymantecAdware.Clkpotato!gen3
ESET-NOD32Win32/Adware.180Solutions
CynetMalicious (score: 100)
AvastWin32:Zango-M [PUP]
Kasperskynot-a-virus:AdWare.Win32.180Solutions
NANO-AntivirusRiskware.Win32.180Solutions.synwb
TencentWin32.AdWare.180solutions.Uimw
F-SecureAdware.ADWARE/180Solutions.xdjbi
SophosGeneric Reputation PUA (PUA)
Ikarusnot-a-virus:AdWare.Win32.180Solutions
VaristW32/Adware.RVGK-0796
AviraADWARE/180Solutions.xdjbi
MAXmalware (ai score=98)
XcitiumMalware@#3c4ypgyirpazu
MicrosoftProgram:Win32/Wacapew.C!ml
ZoneAlarmnot-a-virus:AdWare.Win32.180Solutions
GoogleDetected
McAfeeArtemis!29044C49FA2B
VBA32Adware.180Solutions
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H0CAU24
FortinetAdware/180Solutions
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_100% (W)

How to remove Win32:Zango-M [PUP]?

Win32:Zango-M [PUP] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment