Zango

Publisher Information

Zango is a software developer located in Bellevue, Washington in the United States*. The company is a primary distributor of unwanted software. Zango, also known as 180solutions, Hotbar and ePIPO, is a adware publisher that now operates as Pinball Corporation. The software mostly consists of browser plugins that are difficult to remove. Thre are 4 additional code signing certificates issued to this publisher.
Remove Zango Malware - Powered by Reason Core Security
Authority:
VeriSign, Inc.

Valid from:
2/13/2008 4:00:00 PM

Valid to:
5/12/2010 4:59:59 PM

Subject:
CN=Zango, OU=Zango, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Zango, L=Bellevue, S=Washington, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1ca00caea054614d44d3119b6db48ad8

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.ChromePlugin.Zango.Q, PUP.Zango.G, PUP.Installer.Zango.H, PUP.Zango.K, PUP.Zango.I, PUP.Zango.Installer, PUP.Zango (M), PUP.Zango.Installer (M)
100.00%

Bitdefender
Gen:Adware.Heur.eu9@Re61Tjmi, Gen:Adware.Heur.Au9@RqMn4Kmi, Gen:Adware.Heur.pu9@ROnSwIhi, Adware.Zango.AU, Gen:Adware.Heur.qu9@Ra9JTOni
60.00%

Comodo Security
ApplicUnsaf.Win32.AdWare.Hotbar.a1, Application.Win32.Adware.HotBar, Application.Win32.Adware.180Solutions, UnclassifiedMalware
60.00%

Avira AntiVirus
ADSPY/AdSpy.Gen
60.00%

G Data
Gen:Adware.Heur.eu9@Re61Tjmi, Gen:Adware.Heur.Au9@RqMn4Kmi, Gen:Adware.Heur.pu9@ROnSwIhi, Adware.Zango.AU, Gen:Adware.Heur.qu9@Ra9JTOni
60.00%

Vba32 AntiVirus
AdWare.HotBar, Win32.Adware.HotBar, AdWare.Win32.Shopper.ar, Win32.Adware.Toolbar.ZangoBar, Signed-Adware.Win32.180Solutions
60.00%

IKARUS anti.virus
Gen.AdWare.Heur, Win32.AdWare.HotBar, Application.Win32.AdWare.Hotbar, AdWare.AdSpy, not-a-virus:AdWare.Win32.180Solutions
60.00%

Fortinet FortiGate
Adware/Hotbar, Adware/Zango
60.00%

McAfee
Adware-ZangoSA, Artemis!5359A44A20A8, Artemis!13016674FA2B, potentially unwanted program Generic PUP, Adware-180SA, Artemis!058B4ACCE5E8, potentially unwanted program Adware-HotBar, potentially unwanted program Artemis!6DB56E245F92, potentially unwanted program Adware-ZangoSA, potentially unwanted program Artemis!23B2B86E0F9A, Artemis!9F4BFD1AB5A1, Artemis!AD67BCCB92EF, potentially unwanted program Adware-180SA!a
57.78%

Sophos
ClickPotato Installer, 180solutions, PUA '180solutions' (of type Adware), Hotbar, Mal/Generic-A, Generic 180solutions Application
57.78%

1 / 68      (Adware)
zangosa.exe (Zango by Zango)  (c3cc0c0b94f69ed3a88352cc0d3818d1)

1 / 68      (Adware)
vuzesetup.exe (Setup by Zango)  (beb14af878a92c55c99b3a8868064d3c)

1 / 68      (Adware)
WeSkin.DLL (Weather by Zango)  (f1175ba59afab3edfdfe081436de0ac1)

1 / 68      (Adware)
Weather.EXE (Weather by Zango)  (29cf6a5c2c1055f8811505aad1f559c3)

1 / 68      (Adware)
Setup.exe (Setup by Zango)  (13d81a68d5d6c40078f463c73e8d7ab8)

1 / 68      (Adware)
Weather.EXE (Weather by Zango)  (3bd3e739669ccb4596abf22bd01cabfa)

1 / 68      (Adware)
zangosa.exe (Zango Search Assistant by Zango)  (a09cba5fcf44ebdf90a92d94d5eb03f9)

1 / 68      (Adware)
oeaddon.exe (Zango by Zango)  (6bacd0ccbe9cb8fdffcbe9974a6c8d0c)

1 / 68      (Adware)
npclntax_zangosa.dll (Zango Firefox Plugin by Zango)  (de950f2868ee3fd88a55d4ca89fffebb)

1 / 68      (Adware)
zangouninstaller.exe (Zango by Zango)  (135adef311dee3d8e24ac8175615b2ca)

1 / 68      (Adware)
zangosadf.exe (Zango Flash App by Zango)  (41615ae6f31e6f0501daea8eb0657420)

1 / 68      (Adware)
zangosaax.dll (Zango ActiveX Control by Zango)  (0b8073ca99c727b8e12ecb98214a5456)

1 / 68      (Adware)
WeSkin.DLL (Weather by Zango)  (f34491f8a1f0f6da0ea108aba6204f78)

1 / 68      (Adware)
wallpaper.dll (Zango by Zango)  (359e31dbd4d7891f1f8c22b1982900f0)

1 / 68      (Adware)
toolbar.dll (Zango by Zango)  (133decbf1a0c397bc3da553af5272e38)

1 / 68      (Adware)
hostol.dll (Zango by Zango)  (8add5388449c7ca29b6b399cbc567e84)

1 / 68      (Adware)
cntntcntr.dll (Zango by Zango)  (a871dabbea25b6ddb4d62fd13d243f85)

41 / 68    (Adware)
coresrv.dll (Zango by Zango)  (1dc55e857b992ba03ac9c4365b1d96dd)

32 / 68    (Adware)
hostie.dll (Zango by Zango)  (067fcfab472ad15db19d7cad2d2e950f)

36 / 68    (Adware)
npclntax_zangosa.dll (Zango Firefox Plugin by Zango)  (08c678de74609e8120a6273701d8282a)

28 / 68    (Adware)
zangouninstaller.exe (Zango by Zango)  (05f66ff082aa68630bbdb037cfdcd312)

16 / 68    (Adware)
ZangoSAHook.dll (Zango by Zango)  (8a1c44ce239613f8a03d60df8372b14e)

16 / 68    (Adware)
zangosadf.exe (Zango Flash App by Zango)  (ad67bccb92efb1cdf0afeab644f8b8fa)

21 / 68    (Adware)
zangosaax.dll (Zango ActiveX Control by Zango)  (9f4bfd1ab5a15273299303c78f869895)

25 / 68    (Adware)
zangosa.exe (Zango Search Assistant by Zango)  (23b2b86e0f9a8cf3d5f7b22c4bbce246)

28 / 68    (Adware)
WeSkin.DLL (Weather by Zango)  (f7dcaf96feba543b8fd23a7ce092188f)

33 / 68    (Adware)
Weather.EXE (Weather by Zango)  (386f2b7416c8e642d5d65f5df204373f)

30 / 68    (Adware)
wallpaper.dll (Zango by Zango)  (47a48035a7a3b18cdd56b10cde42de5e)

24 / 68    (Adware)
toolbar.dll (Zango by Zango)  (d13086464410f3a4fd4a127879bc8b39)

23 / 68    (Adware)
srv.exe (Zango by Zango)  (d16db56e245f924010085a356ec44bd6)

 
Latest 30 of 45 files

The certificates below are also signed by Zango.

1BFD2BADE8D6BA77BAB6FA3C75F46631  (Mar 20, 2007 to May 13, 2008)

7A9E3D20F0540AA46412FA66C233F5B8  (Mar 16, 2006 to May 10, 2007)

7F7BA710B2DE94E64618988A4FC1BDBD  (Apr 26, 2005 to Apr 27, 2006)

02A6ED914A18FFBC5CDE777EFF702F6A  (May 20, 2004 to May 21, 2005)

Remove Zango Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to Zango by VeriSign, Inc. on February 13, 2008 with the serial number '1ca00caea054614d44d3119b6db48ad8'.