PehPai
PehPai is an adware that is bundled with adware components that shaw advertisement on the infected system. PehPai is an adware that is bundled with adware components that shaw advertisement on the infected system.0
General information:
Malware Name: |
PehPai |
Malware Type: |
Adware |
Company Name: |
ZapSpot, Inc |
Company URL: |
http://www.zapspot.com/
|
Threat Level: |
Elevated Risk |
Operating System: |
WIN XP |
Installation Type: |
Installed through EXE |
Operation: |
Time of After Installation |
Company Description:
ZapSpot, Inc provides you the software PehPai that has been a popular pastime for centuries thanks to its simplicity and elegance. The goal in the game is to clear the screen from cards by removing them in ascending or descending order.
Spyware Description:
PehPai is an adware that is bundled with adware components that shaw advertisement on the infected system. PehPai is an adware that is bundled with adware components that shaw advertisement on the infected system.0
Characteristics/Symptoms:
-> This free program contains some adware components. -> The adware components installed display ads on the infected system.
Additional information might be found here:
Processes Running:
ZapSpot.exe
File information Created after Installation:
File Location |
Size (Bytes) |
Type |
C:\Documents and Settings\priya\Application Data\ZapSpot\Games\{681FDB0B-DF7A-4E91-9445-0D7CF22687E7}\{681FDB0B-DF7A-4E91-9445-0D7CF22687E7}.gam |
192589 |
GAM File |
C:\Documents and Settings\priya\Application Data\ZapSpot\System\Skins\asl-zs-resume-52x52x2.gif |
2473 |
GIF Image |
C:\Documents and Settings\priya\Application Data\ZapSpot\System\Skins\default.skn |
7599 |
SKN File |
Folder information Created after Installation:
Folder Location |
C:\Documents and Settings\priya\Application Data\ZapSpot |
C:\Documents and Settings\priya\Application Data\ZapSpot\Games |
Registry information Created after Installation:
Main Registry Key |
Sub Registry Key |
Key Value Name |
HKEY_CLASSES_ROOT |
\.ZML |
[NULL]0 |
HKEY_CLASSES_ROOT |
\ZapSpot.ZML.1 |
[NULL]0 |
HKEY_CURRENT_USER |
\Software\P3 |
[NULL]0 |