zangosadf.exe

Zango Flash App

Zango

The application zangosadf.exe by Zango has been detected as adware by 13 anti-malware scanners.
Publisher:
Zango, Inc.  (signed by Zango)

Product:
Zango Flash App

Version:
10.3.79.0

MD5:
ad67bccb92efb1cdf0afeab644f8b8fa

SHA-1:
1c644e0aaaa47847ec830aa26787042785a8cd8a

SHA-256:
b75eb858544e248c56efd58c32018888a36c2a28aba24038a57ead08838ab220

Scanner detections:
13 / 68

Status:
Adware

Analysis date:
4/23/2024 11:41:56 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Avira AntiVirus
ADSPY/AdSpy.Gen
7.9.0.168

Bitdefender
Gen:Adware.Heur.7124DBDBDB
1.0.20.1650

Comodo Security
Unclassified Malware
1157

Fortinet FortiGate
Adware/Hotbar
11/26/2015

F-Secure
Adware:W32/Zango.S
11.2015-26-11_5

G Data
Gen:Adware.Heur.7124DBDBDB
15.11.19

IKARUS anti.virus
AdWare.AdSpy
t3scan.1.2.09.0

McAfee
Artemis!AD67BCCB92EF
5600.6570

Prevx
Low Risk Adware
3.0

Quick Heal
Trojan.Agent.ATV
11.15.10.00

Reason Heuristics
PUP.Zango (M)
15.11.26.11

Sophos
Generic 180solutions Application
4.41

Vba32 AntiVirus
Signed-Adware.Win32.180Solutions
3.12.10.5

File size:
377.3 KB (386,312 bytes)

Product version:
10.3.79.0

Copyright:
Copyright © 2006-2008 Zango, Inc. All rights reserved.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\zango\bin\10.3.79.0\zangosadf.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
2/13/2008 4:00:00 PM

Valid to:
5/12/2010 4:59:59 PM

Subject:
CN=Zango, OU=Zango, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Zango, L=Bellevue, S=Washington, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1CA00CAEA054614D44D3119B6DB48AD8

File PE Metadata
Compilation timestamp:
3/16/2009 4:13:32 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
3072:hjIHrBRftGYTnLiplFN/GxOtERwoM6Gh+v8PlNkq2AqgLkMWwVfdihFS35z:+V4FFGUuRmb+QlG82MWUihg

Entry address:
0x16DA6

Entry point:
E8, B2, 7C, 00, 00, E9, 16, FE, FF, FF, 8D, 42, FF, 5B, C3, 8D, A4, 24, 00, 00, 00, 00, 8D, 64, 24, 00, 33, C0, 8A, 44, 24, 08, 53, 8B, D8, C1, E0, 08, 8B, 54, 24, 08, F7, C2, 03, 00, 00, 00, 74, 15, 8A, 0A, 83, C2, 01, 3A, CB, 74, CF, 84, C9, 74, 51, F7, C2, 03, 00, 00, 00, 75, EB, 0B, D8, 57, 8B, C3, C1, E3, 10, 56, 0B, D8, 8B, 0A, BF, FF, FE, FE, 7E, 8B, C1, 8B, F7, 33, CB, 03, F0, 03, F9, 83, F1, FF, 83, F0, FF, 33, CF, 33, C6, 83, C2, 04, 81, E1, 00, 01, 01, 81, 75, 1C, 25, 00, 01, 01, 81, 74, D3, 25...
 
[+]

Entropy:
5.7692

Code size:
292 KB (299,008 bytes)

Remove zangosadf.exe - Powered by Reason Core Security