PehPai

PehPai is an adware that is bundled with adware components that shaw advertisement on the infected system. PehPai is an adware that is bundled with adware components that shaw advertisement on the infected system.0

General information:

Malware Name: PehPai
Malware Type: Adware
Company Name: ZapSpot, Inc
Company URL: http://www.zapspot.com/
Threat Level: Elevated Risk
Operating System: WIN XP
Installation Type: Installed through EXE
Operation: Time of After Installation

Company Description:

ZapSpot, Inc provides you the software PehPai that has been a popular pastime for centuries thanks to its simplicity and elegance. The goal in the game is to clear the screen from cards by removing them in ascending or descending order.

Spyware Description:

PehPai is an adware that is bundled with adware components that shaw advertisement on the infected system. PehPai is an adware that is bundled with adware components that shaw advertisement on the infected system.0

Characteristics/Symptoms:

    -> This free program contains some adware components. -> The adware components installed display ads on the infected system.

Additional information might be found here:

google Search at Google for PehPai
bing Search at Bing for PehPai
yahoo Search at Yahoo for PehPai

Processes Running:

ZapSpot.exe

File information Created after Installation:

File Location Size (Bytes) Type
C:\Documents and Settings\priya\Application Data\ZapSpot\Games\{681FDB0B-DF7A-4E91-9445-0D7CF22687E7}\{681FDB0B-DF7A-4E91-9445-0D7CF22687E7}.gam 192589 GAM File
C:\Documents and Settings\priya\Application Data\ZapSpot\System\Skins\asl-zs-resume-52x52x2.gif 2473 GIF Image
C:\Documents and Settings\priya\Application Data\ZapSpot\System\Skins\default.skn 7599 SKN File

Folder information Created after Installation:

Folder Location
C:\Documents and Settings\priya\Application Data\ZapSpot
C:\Documents and Settings\priya\Application Data\ZapSpot\Games

Registry information Created after Installation:

Main Registry Key Sub Registry Key Key Value Name
HKEY_CLASSES_ROOT \.ZML [NULL]0
HKEY_CLASSES_ROOT \ZapSpot.ZML.1 [NULL]0
HKEY_CURRENT_USER \Software\P3 [NULL]0