PepperZip

By GoldSparrow in Adware

Threat Scorecard

Popularity Rank: 9,052
Threat Level: 10 % (Normal)
Infected Computers: 108,165
First Seen: August 25, 2014
Last Seen: October 24, 2025
OS(es) Affected: Windows

PepperZip is an adware platform that may offer services for loading targeted ads or other related offers through 3rd parties. The PepperZip program could be loaded on a computer automatically due to installing random freeware or bundled software. In such a case, PepperZip may then load at startup of Windows where it will display pop-up notifications or ads while you are surfing the internet. The PepperZip services may not prove to be useful for some computer users, who may also find PepperZip's actions annoying. In such a case, PepperZip should be removed or completely uninstalled. Due to PepperZip having other components or plugins that load up on a computer, it may be best to find all of those files and remove them one by one to fully eliminate PepperZip. Additionally, PepperZip could be completely removed through use of an antispyware application capable of removing adware from a PC.

Aliases

15 security vendors flagged this file as malicious.

Antivirus Vendor Detection
AVG Agent5.FTN
Kaspersky UDS:DangerousObject.Multi.Generic
McAfee Artemis!6290D79C5E91
Kaspersky Trojan.Win32.Agentb.bhbe
McAfee Artemis!353A2A82C174
Kaspersky Trojan.Win32.Agentb.bgux
Fortinet W32/Agentb.BGUS!tr
Kaspersky Trojan.Win32.Agentb.bgus
McAfee Artemis!45331B179B69
Kaspersky Trojan.Win32.Agentb.bgvq
McAfee Artemis!B465351883ED
Kaspersky Trojan.Win32.Agentb.bgwp
McAfee Artemis!915865ED8759
CAT-QuickHeal Trojan.Agen.g9
Kaspersky Trojan.Win32.Agentb.bguk

SpyHunter Detects & Remove PepperZip

File System Details

PepperZip may create the following file(s):
# File Name MD5 Detections
1. rcore.exe 063fa3188a36b02bf1e3015b6cb2d0e2 2,363
2. score.exe.vir 08675763b644244ce7cdc728f997583e 785
3. score.exe 353a2a82c174560b158651f1d5b1aed1 426
More files

Registry Details

PepperZip may create the following registry entry or registry entries:
CLSID
{00000000-BA82-4612-BE43-95B8B482C269}
File name without path
PepperZip.lnk
SOFTWARE\Classes\*\shellex\ContextMenuHandlers\{00000000-BA82-4612-BE43-95B8B482C269}
SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\{00000000-BA82-4612-BE43-95B8B482C269}
Software\Classes\PepperZip
SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\PepperZip.exe
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.zip\OpenWithProgids\PepperZip
Software\PepperZip
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\PepperZip.exe

Directories

PepperZip may create the following directory or directories:

%ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\PepperZip
%APPDATA%\Microsoft\Windows\Start Menu\Programs\PepperZip
%PROGRAMFILES%\PepperZip
%PROGRAMFILES(x86)%\PepperZip

Analysis Report

General information

Family Name: PUP.PepperZip
Signature status: No Signature

Known Samples

MD5: 293081c8d4f8f5353f8d0a1bc023a9e4
SHA1: 77a8f7bf18e699c98ac1e93bff492b4ffef9242b
SHA256: 20F75E29D8F5E4BBE4A5D3FE9BF9FA2A9AA82932CF59C7F1FE2B9C8B843EBCC4
File Size: 2.37 MB, 2368284 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Files Modified

File Attributes
c:\program files (x86)\pepperzip\pepperzip.dll Generic Write,Read Attributes
c:\program files (x86)\pepperzip\pepperzip.exe Generic Write,Read Attributes
c:\program files (x86)\pepperzip\pepperzip.url Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files (x86)\pepperzip\shell\ppzshellextension.dll Generic Write,Read Attributes
c:\program files (x86)\pepperzip\shell\ppzshellextension_x64.dll Generic Write,Read Attributes
c:\program files (x86)\pepperzip\shell\ppzshellextension_x64.dll Synchronize,Write Attributes
c:\program files (x86)\pepperzip\uninst.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsdfd2f.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\local\temp\nshf90a.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nshf90a.tmp\check.exe Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\nshf90a.tmp\check.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nshf90a.tmp\setup.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nshf90a.tmp\setup.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsrf8f9.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\local\temp\nszfee6.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nszfee6.tmp\system.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nszfee6.tmp\system.dll Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows\currentversion\app paths\pepperzip.exe:: C:\Program Files (x86)\PepperZip\PepperZip.exe RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\uninstall\pepperzip::displayname PepperZip 1.0 RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\uninstall\pepperzip::uninstallstring C:\Program Files (x86)\PepperZip\uninst.exe RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\uninstall\pepperzip::displayicon C:\Program Files (x86)\PepperZip\PepperZip.exe RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\uninstall\pepperzip::displayversion 1.0 RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\uninstall\pepperzip::urlinfoabout http://www.pepperware.net RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\uninstall\pepperzip::publisher PepperWare Co. RegNtPreCreateKey
HKCU\software\pepperzip:: C:\Program Files (x86)\PepperZip\PepperZip.exe RegNtPreCreateKey
HKLM\software\classes\clsid\{00000000-ba82-4612-be43-95b8b482c269}:: PPZShellExtContextMenu Class RegNtPreCreateKey
HKLM\software\classes\clsid\{00000000-ba82-4612-be43-95b8b482c269}\inprocserver32:: C:\Program Files (x86)\PepperZip\shell\PPZShellExtension_x64.dll RegNtPreCreateKey
Show More
HKLM\software\classes\clsid\{00000000-ba82-4612-be43-95b8b482c269}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\classes\*\shellex\contextmenuhandlers\{00000000-ba82-4612-be43-95b8b482c269}:: PPZShellExtContextMenu RegNtPreCreateKey
HKLM\software\classes\directory\shellex\contextmenuhandlers\{00000000-ba82-4612-be43-95b8b482c269}:: (NULL) RegNtPreCreateKey
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations \??\C:\Users\Rcdflkes\AppData\Local\Temp\nszFEE6.tmp\ RegNtPreCreateKey
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations \??\C:\Users\Rcdflkes\AppData\Local\Temp\nszFEE6.tmp\\??\C:\Users\Rcdflkes\AppData\Local\Temp\nshF90A.tmp\ RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Syscall Use
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryValueKey
Show More
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetValueKey
  • ntdll.dll!NtTerminateProcess
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
Other Suspicious
  • AdjustTokenPrivileges

Shell Command Execution

C:\Users\Rcdflkes\AppData\Local\Temp\nshF90A.tmp\setup.exe /S /T 15
"C:\WINDOWS\system32\regsvr32.exe" /s "C:\Program Files (x86)\PepperZip\shell\PPZShellExtension_x64.dll"
C:\Program Files (x86)\PepperZip\PepperZip.exe /A 00000 /T 15

Trending

Most Viewed

Loading...