Zango |
Bedrohungslevel:
3
3
Wie man manuell Zango blocken und löschen kann
Mit der Infektion verbundene Dateien löschen (Zango):
ZangoSA.exe
zangosahook.dll
zangosahook.dll
Dynamische Link-Bibliotheken löschen (Zango):
zangohook.dll
zangotb.dll
zanuhook.dll
zangosahook.dll
zangotb.dll
zanuhook.dll
zangosahook.dll
Prozesse abbrechen (Zango):
nstallershell.exe
zangoinstaller.exe
zanu.exe
zango.exe
zangotbuninstaller.exe
ZangoSA.exe
zangoinstaller.exe
zanu.exe
zango.exe
zangotbuninstaller.exe
ZangoSA.exe
Registry-Schlüssel entfernen (Zango):
HKEY_CURRENT_USERSoftwareMicrosoftRASAutodialControlLoginSessionDisable=1
E5B57AB3-15F8-43A2-ABAC-3E58A9C25818
21B4ACC4-8874-4AEC-AEAC-F567A249B4D4
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunango[applicationname]
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunzanu
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstall[gamename]
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstallango[applicationname]
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstallzanu
HKEY_LOCAL_MACHINESOFTWAREzanuHKEY_CURRENT_USERSoftwarezanu
seekmosa
CoreSrv.CoreServices
CoreSrv.CoreServices.1
CoreSrv.LfgAx
CoreSrv.LfgAx.1
HostIE.Bho
HostIE.Bho.1
HostOL.MailAnim
HostOL.MailAnim.1
HostOL.WebmailSend
HostOL.WebmailSend.1
Srv.CoreServices
Srv.CoreServices.1
Toolbar.HtmlMenuUI
Toolbar.HtmlMenuUI.1
Toolbar.ToolbarCtl
Toolbar.ToolbarCtl.1
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{56F1D444-11BF-4879-A12B-79CF0177F038}
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ WeatherDPA
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\salm
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ ZangoOE
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ SeekmoSA
RUNNING PROGRAM\SBTV.exe
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ ZangoSA
RUNNING PROGRAM\explorer.exe
E5B57AB3-15F8-43A2-ABAC-3E58A9C25818
21B4ACC4-8874-4AEC-AEAC-F567A249B4D4
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunango[applicationname]
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunzanu
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstall[gamename]
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstallango[applicationname]
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstallzanu
HKEY_LOCAL_MACHINESOFTWAREzanuHKEY_CURRENT_USERSoftwarezanu
seekmosa
CoreSrv.CoreServices
CoreSrv.CoreServices.1
CoreSrv.LfgAx
CoreSrv.LfgAx.1
HostIE.Bho
HostIE.Bho.1
HostOL.MailAnim
HostOL.MailAnim.1
HostOL.WebmailSend
HostOL.WebmailSend.1
Srv.CoreServices
Srv.CoreServices.1
Toolbar.HtmlMenuUI
Toolbar.HtmlMenuUI.1
Toolbar.ToolbarCtl
Toolbar.ToolbarCtl.1
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{56F1D444-11BF-4879-A12B-79CF0177F038}
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ WeatherDPA
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\salm
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ ZangoOE
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ SeekmoSA
RUNNING PROGRAM\SBTV.exe
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ ZangoSA
RUNNING PROGRAM\explorer.exe






Beitrag verfassen — WIR BRAUCHEN IHRE MEINUNG!