Srpski | Македонски | العربية | Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español
Virus Total

Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...

File Setup_zango.exe received on 2009.01.20 17:07:16 (UTC)
Current status: finished
Result: 23/39 (58.97%)
Antivirus Version Last Update Result
a-squared 4.0.0.73 2009.01.20 Riskware.AdTool.Win32.Zango.r!IK
AhnLab-V3 5.0.0.2 2009.01.20 -
AntiVir 7.9.0.57 2009.01.20 ADSPY/AdSpy.Gen
Authentium 5.1.0.4 2009.01.19 -
Avast 4.8.1281.0 2009.01.20 -
AVG 8.0.0.229 2009.01.20 -
BitDefender 7.2 2009.01.20 Application.Generic.26735
CAT-QuickHeal 10.00 2009.01.20 -
ClamAV 0.94.1 2009.01.20 -
Comodo 939 2009.01.20 -
DrWeb 4.44.0.09170 2009.01.20 Adware.Zango
eSafe 7.0.17.0 2009.01.20 Suspicious File
eTrust-Vet 31.6.6317 2009.01.20 -
F-Prot 4.4.4.56 2009.01.19 -
F-Secure 8.0.14470.0 2009.01.20 -
Fortinet 3.117.0.0 2009.01.15 Adware/Hotbar
GData 19 2009.01.20 Application.Generic.26735
Ikarus T3.1.1.45.0 2009.01.20 not-a-virus:AdTool.Win32.Zango.r
K7AntiVirus 7.10.596 2009.01.20 -
Kaspersky 7.0.0.125 2009.01.20 not-a-virus:WebToolbar.Win32.Zango.bw
McAfee 5501 2009.01.20 potentially unwanted program Adware-ZangoSA
McAfee+Artemis 5500 2009.01.19 Generic!Artemis
Microsoft 1.4205 2009.01.20 Adware:Win32/ZangoSearchAssistant
NOD32 3781 2009.01.20 probably a variant of Win32/Genetik
Norman 5.93.01 2009.01.20 W32/180Solutions.ACX
nProtect 2009.1.8.0 2009.01.20 Application.Generic.26735
Panda 9.5.1.2 2009.01.20 Adware/Zango
PCTools 4.4.2.0 2009.01.20 -
Prevx1 V2 2009.01.20 Adware
Rising 21.13.11.00 2009.01.20 -
SecureWeb-Gateway 6.7.6 2009.01.20 Ad-Spyware.AdSpy.Gen
Sophos 4.37.0 2009.01.20 180solutions
Sunbelt 3.2.1835.2 2009.01.16 Zango.setup (v)
Symantec 10 2009.01.20 Adware.ZangoSearch
TheHacker 6.3.1.5.224 2009.01.20 -
TrendMicro 8.700.0.1004 2009.01.20 -
VBA32 3.12.8.10 2009.01.19 Signed-Adware.Win32.180Solutions
ViRobot 2009.1.20.1569 2009.01.20 Not_a_virus:WebToolbar.Zango.336136.C
VirusBuster 4.5.11.0 2009.01.20 -
Additional information
File size: 336136 bytes
MD5...: 1332621df4153d42ec4dcc15fa2c4451
SHA1..: 6408247896993937d1b9d93e34deea5965679450
SHA256: 6fe67242387519f6d11e9018955a526eb9c79e6f83ed9e99b9503eba6151540e
SHA512: 80b6bfef693e2faa81e40c26857af2f6bae8e655980bfa769e8cad6825efb72f
9cd295e893ed8e0a7faf42de09a86f993d2497b6dff75ed0be4ce03e3761806e
ssdeep: 6144:H6zpYyi8G4xz3emtxwByYwFcBDwybHt8rfFgGZaHHwRknE5rOxiPeRhWe0r
jKL2:kx+gbemAfwpivGZaHHwRkEtdPeYrjKL2
PEiD..: UPX 2.90 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser
TrID..: File type identification
UPX compressed Win32 Executable (39.5%)
Win32 EXE Yoda's Crypter (34.3%)
Win32 Executable Generic (11.0%)
Win32 Dynamic Link Library (generic) (9.8%)
Generic Win/DOS Executable (2.5%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x4a8060
timedatestamp.....: 0x49668d2e (Thu Jan 08 23:33:02 2009)
machinetype.......: 0x14c (I386)

( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
UPX0 0x1000 0x59000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
UPX1 0x5a000 0x4f000 0x4e200 7.89 db77448f72f3294b896e6b36e85bbb67
.rsrc 0xa9000 0x3000 0x2600 4.65 255398db10cf0294d443efca2d2af02a

( 9 imports )
> KERNEL32.DLL: LoadLibraryA, GetProcAddress, ExitProcess
> ADVAPI32.dll: RegCloseKey
> GDI32.dll: BitBlt
> ole32.dll: CoCreateGuid
> OLEAUT32.dll: -
> SHELL32.dll: ShellExecuteA
> SHLWAPI.dll: PathFileExistsA
> USER32.dll: GetDC
> VERSION.dll: VerQueryValueA

( 0 exports )
Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=09AA26DA08279EBE217C0529237C4800E382CD14
packers (Kaspersky): UPX
packers (F-Prot): UPX

ATENTION ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.

Scan another file