PUP.Zap PDF

Threat Scorecard

Popularity Rank: 8,112
Threat Level: 10 % (Normal)
Infected Computers: 88
First Seen: March 10, 2026
Last Seen: July 2, 2026
OS(es) Affected: Windows

The detection of PUP.Zap PDF on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It's essential to understand what this detection means and how to properly remove it to prevent any potential harm.

What Is PUP.Zap PDF?

PUP.Zap PDF is a type of potentially unwanted program that may have been installed on your system without your knowledge or consent. PUPs are software applications that are not necessarily malicious but can still cause problems, such as displaying unwanted advertisements, collecting user data, or slowing down system performance. The "PUP" designation indicates that the program is not considered malware in the classical sense but can still be a nuisance and potentially pose security risks.

How PUP.Zap PDF Operates

PUPs like PUP.Zap PDF often operate by installing themselves on a system through bundled software downloads or by exploiting vulnerabilities in existing applications. Once installed, they may start displaying unwanted ads, collecting user data, or running background processes that consume system resources. In some cases, PUPs can also install additional software or modify system settings without user consent, leading to further problems.

Symptoms of Infection

If your system is infected with PUP.Zap PDF, you may notice several symptoms, including unwanted pop-ups or advertisements, slow system performance, or unfamiliar programs running in the background. You may also notice that your browser settings have been modified or that new toolbars or extensions have been installed without your consent. In some cases, PUPs can also cause system crashes or freezes, especially if they are consuming excessive system resources.

How to Remove PUP.Zap PDF

  1. Boot your system in Safe Mode with Networking to prevent the PUP from loading and to ensure a stable environment for removal.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any associated files or registry entries.
  3. Uninstall any suspicious programs or applications that may be related to the PUP, using the "Add/Remove Programs" or "Programs and Features" control panel.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any modified settings or installed extensions.
  5. Reboot your system and perform a follow-up scan with your anti-malware tool to ensure that all associated files and registry entries have been removed.

Conclusion

Removing PUP.Zap PDF from your system requires careful attention to detail and a thorough understanding of the removal process. By following the steps outlined above, you can help ensure that your system is free from this potentially unwanted program and any associated risks. Remember to always use reputable anti-malware tools and to stay vigilant when downloading software or clicking on links from unknown sources to prevent future infections.

SpyHunter Detects & Remove PUP.Zap PDF

File System Details

PUP.Zap PDF may create the following file(s):
# File Name MD5 Detections
1. zappdf.exe 735dc0470cb55040b5610cde35f4831e 37
2. zapdf.exe 038556979e7af268c9337e7526074f70 30

Analysis Report

General information

Family Name: PUP.Zap PDF
Signature status: No Signature

Known Samples

MD5: 1146d03d6eacbaedf50a67e7d57bdedc
SHA1: 490dd220f7dcf8f01c6d963cdeea57f8d0ea3d4c
SHA256: 0053AAE53EB57E7253FFCE01516F4DD5F175E4FEDF7AF5FEBAA5346AEC4A3A4D
File Size: 618.50 KB, 618496 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is .NET application
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.0.6
Comments Convert, compress and merge your files into one PDF
File Description Zapdf
File Version 1.0.0.6
Internal Name Zapdf.exe
Legal Copyright Zapdf © 2025
Original Filename Zapdf.exe
Product Name Zapdf
Product Version 1.0.0.6

File Traits

  • .NET
  • x86

Block Information

Total Blocks: 68
Potentially Malicious Blocks: 1
Whitelisted Blocks: 36
Unknown Blocks: 31

Visual Map

0 0 0 x 0 0 ? ? ? 0 ? 0 0 ? 0 0 ? ? ? 0 0 0 0 ? 0 0 ? 0 0 0 0 0 ? 0 0 0 ? ? ? ? 0 0 ? ? ? ? ? 0 0 ? ? ? 0 0 ? ? 0 ? 0 ? 0 ? ? 0 ? 0 ? 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\appdata\local\zapdf\zapdf_txt.txt Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\tracing\rasapi32::enablefiletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::enableautofiletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::enableconsoletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::maxfilesize  RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::filedirectory %windir%\tracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::enablefiletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::enableautofiletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::enableconsoletracing RegNtPreCreateKey
Show More
HKLM\software\microsoft\tracing\rasmancs::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::maxfilesize  RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::filedirectory %windir%\tracing RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreatePortSection
  • ntdll.dll!NtAlpcCreateSectionView
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcDeleteSecurityContext
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcQueryInformationMessage
  • ntdll.dll!NtAlpcSendWaitReceivePort
Show More
  • ntdll.dll!NtAlpcSetInformation
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtGetCompleteWnfStateSubscription
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtPowerInformation
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryEvent
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtQueueApcThread
  • ntdll.dll!NtQueueApcThreadEx2
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRemoveIoCompletion
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSetTimerEx
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtUnsubscribeWnfStateChange
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair

4 additional items are not displayed above.

User Data Access
  • GetComputerName
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
Anti Debug
  • IsDebuggerPresent
Network Info Queried
  • GetAdaptersAddresses
  • GetNetworkParams
Other Suspicious
  • AdjustTokenPrivileges
Network Winsock2
  • WSASend
  • WSASocket
  • WSAStartup
  • WSAttemptAutodialName
Network Winsock
  • bind
  • closesocket
  • freeaddrinfo
  • getaddrinfo
  • setsockopt
Network Winhttp
  • WinHttpOpen

Related Posts

Trending

Most Viewed

Loading...