Threat Database Adware ZangoSearch

ZangoSearch

By GoldSparrow in Adware

ZangoSearch is an adware application, which controls your web browsing experience, especially your browser windows. ZangoSearch opens partner websites when you type a certain keyword on Internet search or shopping browser windows. ZangoSearch installs files linked to 180Solutions as well. ZangoSearch creates files that a PC user didn't install, modifies the registry to launch every time you start Windows or Internet Explorer. ZangoSearch controls and fixes itself if needed or partially eliminated. Uninstall ZangoSearch immediately after detection.

File System Details

ZangoSearch may create the following file(s):
# File Name Detections
1. zanu.exe
2. zangotb.dll
3. %ProgramFiles%\Zango Applications\Zango TV Times\TvSkin.dll
4. %ProgramFiles%\Zango Games\Jade Shadow\JadeShadowInstall.exe
5. %ProgramFiles%\Zango Applications\Zango TV Times\TVTimesInstall.exe
6. %ProgramFiles%\Zango Applications\Zango TV Times\ZangoTVTimes.exe
7. zangoinstaller.exe
8. zangohook.dll
9. zanuhook.dll
10. %ProgramFiles%\Zango Games\Jade Shadow\UNWISE.EXE
11. %ProgramFiles%\Zango Games\Jade Shadow\JadeShadowSetup.exe
12. %ProgramFiles%\Zango Applications\Zango TV Times\UNWISE.EXE
13. installershell.exe
14. zango.exe
15. zangotbuninstaller.exe
16. %ProgramFiles%\Zango Applications\Zango TV Times\CryptoAPI.dll
17. %ProgramFiles%\Zango Games\Jade Shadow\JadeShadowInstaller.exe
18. %ProgramFiles%\Zango Applications\Zango TV Times\TVTimesInstaller.exe
19. %ProgramFiles%\Zango Applications\Zango TV Times\INSTALL.LOG
20. %ProgramFiles%\ZangoClient\zanuau.dat
21. %ProgramFiles%\Zango Games\Jade Shadow\jade.ico
22. %ProgramFiles%\Zango\Zango.com.url
23. %UserProfile%\Start Menu\Programs\Zango\Zango.com.url
24. %UserProfile%\Start Menu\Programs\Zango Games\Jade Shadow\Jade Shadow.lnk
25. %UserProfile%\Application Data\Zango TvTimes\My Preference\Startup.xml
26. %ProgramFiles%\Zango Applications\Zango TV Times\Loading
27. %ProgramFiles%\Zango Applications\Zango TV Times\log.txt
28. %ProgramFiles%\ZangoClient\zanu_kyf.dat
29. %ProgramFiles%\Zango Games\Jade Shadow\JSReadME.htm
30. %ProgramFiles%\Zango Applications\Zango TV Times\ZangoTVTimes.lnk
31. %UserProfile%\Start Menu\Programs\Zango\Uninstall Zango.lnk
32. %UserProfile%\Desktop\ZangoTVTimes.lnk
33. %ProgramFiles%\Zango Applications\Zango TV Times\Display
34. %ProgramFiles%\Zango Games\Jade Shadow\INSTALL.LOG
35. %ProgramFiles%\ZangoClient\zanu_gdf.dat
36. %ProgramFiles%\Zango Games\Jade Shadow\jade0.apk
37. %ProgramFiles%\Zango\Uninstall Zango Instructions.lnk
38. %UserProfile%\Start Menu\Programs\Zango Games\Jade Shadow\Jade Shadow Readme.lnk
39. %UserProfile%\Desktop\Jade Shadow.lnk
40. %UserProfile%\Application Data\Zango TvTimes\My Preference\TVTimesNotify.xml

Registry Details

ZangoSearch may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\RASAutodialControlLoginSessionDisable=1 21B4ACC4-8874-4AEC-AEAC-F567A249B4D4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\zanu
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall ango[applicationname]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ango[applicationname] E5B57AB3-15F8-43A2-ABAC-3E58A9C25818
HKEY_CURRENT_USER\Software\zanu
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\zanu
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall[gamename]
HKEY_LOCAL_MACHINE\SOFTWARE\zanu

Trending

Most Viewed

Loading...