Home Malware Programs Adware Zapp

Zapp

Posted: March 24, 2014

Threat Metric

Ranking: 11,605
Threat Level: 2/10
Infected PCs: 3,284
First Seen: March 24, 2014
Last Seen: September 9, 2023
OS(es) Affected: Windows


Zapp is considered to be adware that was produced with the goal to possibly display non-stop pop-up advertisements on the PC most likely for commercial intentions. Upon installation on the computer system, Zapp may insert an unwanted Web browser plug-in which may be used for showing intrusive pop-up ads and notifications. Zapp may proliferate and install itself on the computer packaged with free programs that a PC user can download from unreliable download websites. If pop-up advertisements of Zapp are shown on the PC, this may specify that the computer has been contaminated with this adware. Zapp may double underline certain words on a website, and when the PC user hovers over them, 'Ads by Zapp' may be displayed. Zapp's advertisements may be random or related to the computer user's online surfing routine and, if clicked, may divert PC users to questionable websites.

Aliases

Onefloorap [AVG]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Program Files (x86)\HomeTab\IE\wdapimng.exe File name: wdapimng.exe
Size: 182.85 KB (182856 bytes)
MD5: 84ff9f6dfcdcee101ec389839859e927
Detection count: 1,316
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\HomeTab\IE\wdapimng.exe
Group: Malware file
Last Updated: May 22, 2021
%PROGRAMFILES(x86)%\Zapp\SystemSockets.exe File name: SystemSockets.exe
Size: 34.37 KB (34376 bytes)
MD5: be790e73b8b4e399b6ee3a0ac15ea2c8
Detection count: 145
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Zapp
Group: Malware file
Last Updated: May 30, 2014
%PROGRAMFILES%\Zapp\IE\Zapp.dll File name: Zapp.dll
Size: 1.43 MB (1431112 bytes)
MD5: f518ceecdec0e873c517f0e9b2b26435
Detection count: 70
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Zapp\IE
Group: Malware file
Last Updated: May 30, 2014
%PROGRAMFILES%\Zapp\IE\Zapp.dll File name: Zapp.dll
Size: 1.41 MB (1413704 bytes)
MD5: 7d72002e3741e8d25006a40d8e470af5
Detection count: 44
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Zapp\IE
Group: Malware file
Last Updated: May 30, 2014
%PROGRAMFILES%\Zapp\IE\Zapp.dll File name: Zapp.dll
Size: 1.1 MB (1103432 bytes)
MD5: 38d06a24090e73c792710fa6107ee6ae
Detection count: 31
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Zapp\IE
Group: Malware file
Last Updated: May 30, 2014
%TEMP%\DLG\exe\widdit-zapp-1.0-default\Zapp.exe File name: Zapp.exe
Size: 4.34 MB (4340096 bytes)
MD5: 00817a48fa54e6f0549e4efe934b0f2a
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\DLG\exe\widdit-zapp-1.0-default
Group: Malware file
Last Updated: February 2, 2020
%PROGRAMFILES%\Zapp\IE\Zapp.dll File name: Zapp.dll
Size: 1.1 MB (1103432 bytes)
MD5: 517adb833c9a15a507d22567b861fca7
Detection count: 5
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Zapp\IE
Group: Malware file
Last Updated: May 30, 2014

Registry Modifications

The following newly produced Registry Values are:

CLSID{494bf343-9c44-4c0c-b0b0-fee3d2cb2ac8}{4c1c1ee1-5eb9-4a15-a461-fe9770c9550b}{851d170f-40f3-4779-8068-dd123e9f79c4}{93B3A696-A570-446B-AFB9-1442B2E20003}{CE808C4E-2415-4031-A4F4-05C6DB929432}{e2d02111-a8c1-4d36-b9f6-af7f15d6c789}{e6eeb20c-cf4a-4789-becf-64f78340708f}{f1abf166-ad38-4bcf-9844-c22b50874909}{f41b9858-c595-427c-a2d5-82ca2c8ba640}{f639cdd8-2177-4e3d-9b80-49bf8e7f4241}HKEY..\..\..\..{RegistryKeys}SOFTWARE\Classes\AppID\Zapp.DLLSOFTWARE\Classes\AppID\ZappAddon.DLLSOFTWARE\Classes\Wow6432Node\AppID\Zapp.DLLSOFTWARE\Classes\Wow6432Node\AppID\ZappAddon.DLLSoftware\Microsoft\Internet Explorer\ApprovedExtensionsMigration\{e6eeb20c-cf4a-4789-becf-64f78340708f}Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration\{f1abf166-ad38-4bcf-9844-c22b50874909}SOFTWARE\Microsoft\Tracing\Zapp_RASAPI32SOFTWARE\Microsoft\Tracing\Zapp_RASMANCSSOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e6eeb20c-cf4a-4789-becf-64f78340708f}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{e6eeb20c-cf4a-4789-becf-64f78340708f}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{f1abf166-ad38-4bcf-9844-c22b50874909}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E6EEB20C-CF4A-4789-BECF-64F78340708F}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F1ABF166-AD38-4BCF-9844-C22B50874909}Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{e6eeb20c-cf4a-4789-becf-64f78340708f}SOFTWARE\Wow6432Node\Classes\AppID\Zapp.DLLSOFTWARE\Wow6432Node\Classes\AppID\ZappAddon.DLLSOFTWARE\Wow6432Node\Microsoft\Tracing\Zapp_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\Zapp_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{e6eeb20c-cf4a-4789-becf-64f78340708f}Software\ZappSoftware\ZappAddonHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{447f77b7-9433-4a8b-b657-79e1c71898f6}_is1{7dd964ce-bd82-4752-80e4-5ab17ee135bf}_is1

Additional Information

The following directories were created:
%APPDATA%\Zapp%APPDATA%\ZappAddon%PROGRAMFILES%\Zapp%PROGRAMFILES%\ZappAddon%PROGRAMFILES(x86)%\Zapp%PROGRAMFILES(x86)%\ZappAddon%USERPROFILE%\AppData\LocalLow\Zapp%USERPROFILE%\AppData\LocalLow\ZappAddon

Related Posts

Loading...