Home Malware Programs Adware Zapp

Zapp

Posted: March 24, 2014

Threat Metric

Ranking: 19,554
Threat Level: 2/10
Infected PCs: 3,333
First Seen: March 24, 2014
Last Seen: December 31, 2024
OS(es) Affected: Windows


Zapp is considered to be adware that was produced with the goal to possibly display non-stop pop-up advertisements on the PC most likely for commercial intentions. Upon installation on the computer system, Zapp may insert an unwanted Web browser plug-in which may be used for showing intrusive pop-up ads and notifications. Zapp may proliferate and install itself on the computer packaged with free programs that a PC user can download from unreliable download websites. If pop-up advertisements of Zapp are shown on the PC, this may specify that the computer has been contaminated with this adware. Zapp may double underline certain words on a website, and when the PC user hovers over them, 'Ads by Zapp' may be displayed. Zapp's advertisements may be random or related to the computer user's online surfing routine and, if clicked, may divert PC users to questionable websites.

Aliases

Onefloorap [AVG]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Program Files (x86)\HomeTab\IE\wdapimng.exe File name: wdapimng.exe
Size: 182.85 KB (182856 bytes)
MD5: 84ff9f6dfcdcee101ec389839859e927
Detection count: 1,323
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\HomeTab\IE\wdapimng.exe
Group: Malware file
Last Updated: November 9, 2023
%PROGRAMFILES(x86)%\Zapp\SystemSockets.exe File name: SystemSockets.exe
Size: 34.37 KB (34376 bytes)
MD5: be790e73b8b4e399b6ee3a0ac15ea2c8
Detection count: 145
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Zapp
Group: Malware file
Last Updated: May 30, 2014
C:\Program Files (x86)\ZappAddon\unins000.exe File name: unins000.exe
Size: 1.17 MB (1178949 bytes)
MD5: 1fceee06c0e10f4f2b6266f9731ea371
Detection count: 28
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\ZappAddon\unins000.exe
Group: Malware file
Last Updated: January 15, 2024
%TEMP%\DLG\exe\widdit-zapp-1.0-default\Zapp.exe File name: Zapp.exe
Size: 4.34 MB (4340096 bytes)
MD5: 00817a48fa54e6f0549e4efe934b0f2a
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\DLG\exe\widdit-zapp-1.0-default
Group: Malware file
Last Updated: February 2, 2020
%PROGRAMFILES%\Zapp\IE\Zapp.dll File name: Zapp.dll
Size: 1.1 MB (1103432 bytes)
MD5: 517adb833c9a15a507d22567b861fca7
Detection count: 5
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Zapp\IE
Group: Malware file
Last Updated: May 30, 2014

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{494bf343-9c44-4c0c-b0b0-fee3d2cb2ac8}{4c1c1ee1-5eb9-4a15-a461-fe9770c9550b}{851d170f-40f3-4779-8068-dd123e9f79c4}{93B3A696-A570-446B-AFB9-1442B2E20003}{CE808C4E-2415-4031-A4F4-05C6DB929432}{e2d02111-a8c1-4d36-b9f6-af7f15d6c789}{e6eeb20c-cf4a-4789-becf-64f78340708f}{f1abf166-ad38-4bcf-9844-c22b50874909}{f41b9858-c595-427c-a2d5-82ca2c8ba640}{f639cdd8-2177-4e3d-9b80-49bf8e7f4241}HKEY..\..\..\..{RegistryKeys}SOFTWARE\Classes\AppID\Zapp.DLLSOFTWARE\Classes\AppID\ZappAddon.DLLSOFTWARE\Classes\Wow6432Node\AppID\Zapp.DLLSOFTWARE\Classes\Wow6432Node\AppID\ZappAddon.DLLSoftware\Microsoft\Internet Explorer\ApprovedExtensionsMigration\{e6eeb20c-cf4a-4789-becf-64f78340708f}Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration\{f1abf166-ad38-4bcf-9844-c22b50874909}SOFTWARE\Microsoft\Tracing\Zapp_RASAPI32SOFTWARE\Microsoft\Tracing\Zapp_RASMANCSSOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e6eeb20c-cf4a-4789-becf-64f78340708f}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{e6eeb20c-cf4a-4789-becf-64f78340708f}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{f1abf166-ad38-4bcf-9844-c22b50874909}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E6EEB20C-CF4A-4789-BECF-64F78340708F}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F1ABF166-AD38-4BCF-9844-C22B50874909}Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{e6eeb20c-cf4a-4789-becf-64f78340708f}SOFTWARE\Wow6432Node\Classes\AppID\Zapp.DLLSOFTWARE\Wow6432Node\Classes\AppID\ZappAddon.DLLSOFTWARE\Wow6432Node\Microsoft\Tracing\Zapp_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\Zapp_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{e6eeb20c-cf4a-4789-becf-64f78340708f}Software\ZappSoftware\ZappAddonHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{447f77b7-9433-4a8b-b657-79e1c71898f6}_is1{7dd964ce-bd82-4752-80e4-5ab17ee135bf}_is1

Additional Information

The following directories were created:
%APPDATA%\Zapp%APPDATA%\ZappAddon%PROGRAMFILES%\Zapp%PROGRAMFILES%\ZappAddon%PROGRAMFILES(x86)%\Zapp%PROGRAMFILES(x86)%\ZappAddon%USERPROFILE%\AppData\LocalLow\Zapp%USERPROFILE%\AppData\LocalLow\ZappAddon

Related Posts

Loading...