Home Malware Programs Adware Adware.Pirrit

Adware.Pirrit

Posted: January 23, 2014

Threat Metric

Ranking: 12,292
Threat Level: 2/10
Infected PCs: 300,531
First Seen: January 23, 2014
Last Seen: January 31, 2025
OS(es) Affected: Windows


Adware.Pirrit is adware that may display random pop-up advertisements or advertisements linked to the PC user's surfing habits in a web browser when a computer user is visiting various questionable websites. The Adware.Pirrit ads may indicate that a PC is corrupted by adware or a potentially unwanted program. Adware.Pirrit may propagate and install itself onto the PC through packaged free software, which computer users can download and install from the Internet. Free applications may often carry various extra software, which may be not necessary for the PC user. Therefore, when the computer user installs any free tool, he should carefully look through what he is going to install together with the desired program that has been selected. When installed, the Adware.Pirrit browser extension may highlight words on the websites that are visited by computer users substituting them with hyperlinks. These Adware.Pirrit links may be added within the text, and may come with a double underline to separate them from normal links. When the PC user rolls the mouse over the link, the pop-up advertisements of Adware.Pirrit may emerge on the desktop. If the PC user clicks on the Adware.Pirrit pop-up links, the makers of the browser plug-in may make a profit from these ad clicks.

Aliases

Generic5.AUTI [AVG]Riskware/Pirrit [Fortinet]Trj/CI.A [Panda]GrayWare[AdWare:not-a-virus]/Win32.Tirrip [Antiy-AVL]RDN/Generic PUP.x!c2y [McAfee-GW-Edition]Adware.Pirrit.2 [DrWeb]ApplicUnwnt [Comodo]Generic PUA PC [Sophos]not-a-virus:AdWare.Win32.Tirrip.f [Kaspersky]Win32:PirritSuggestor-A [Adw] [Avast]Trojan.Gen.2 [Symantec]Adware ( 004a0c581 ) [K7AntiVirus]AdWare.Tirrip.r5 (Not a Virus) [CAT-QuickHeal]Win32.Backdoor.NGService.C [GData]WS.Reputation.1 [Symantec]
More aliases (34)

Use SpyHunter to Detect and Remove PC Threats

If you are concerned that malware or PC threats similar to Adware.Pirrit may have infected your computer, we recommend you start an in-depth system scan with SpyHunter. SpyHunter is an advanced malware protection and remediation application that offers subscribers a comprehensive method for protecting PCs from malware, in addition to providing one-on-one technical support service.

* See Free Trial offer below. EULA and Privacy/Cookie Policy.

Why can't I open any program including SpyHunter? You may have a malware file running in memory that kills any programs that you try to launch on your PC. Tip: Download SpyHunter from a clean computer, copy it to a USB thumb drive, DVD or CD, then install it on the infected PC and run SpyHunter's malware scanner.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Windows\wauctla.exe File name: wauctla.exe
Size: 1.04 MB (1044480 bytes)
MD5: 7d1e5892bb021fa20a03b7cd932a72da
Detection count: 8,895
File type: Executable File
Mime Type: unknown/exe
Path: C:\Windows\wauctla.exe
Group: Malware file
Last Updated: May 25, 2022
C:\Program Files (x86)\Windows Network Accelerater\v5\winvxm.exe File name: winvxm.exe
Size: 2.97 MB (2976880 bytes)
MD5: b34a08ba3041ae88e1953d22bec7ae38
Detection count: 5,801
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\Windows Network Accelerater\v5\winvxm.exe
Group: Malware file
Last Updated: October 14, 2021
C:\Windows\system32\openmemdiag_64\openmemdiag_64.exe File name: openmemdiag_64.exe
Size: 83.45 KB (83456 bytes)
MD5: 726790ac4efe16ff25705c76c299d02b
Detection count: 499
File type: Executable File
Mime Type: unknown/exe
Path: C:\Windows\system32\openmemdiag_64\openmemdiag_64.exe
Group: Malware file
Last Updated: January 1, 2024
%SystemDrive%\Users\<username>\AppData\Local\FileImportProgram\FileImportProgram.exe File name: FileImportProgram.exe
Size: 98.34 KB (98341 bytes)
MD5: 9e9b754b9ca5081a4eca625567e1262d
Detection count: 447
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Users\<username>\AppData\Local\FileImportProgram
Group: Malware file
Last Updated: September 24, 2016
%LOCALAPPDATA%\GUIRootSoftware\GUIRootSoftware.exe File name: GUIRootSoftware.exe
Size: 98.34 KB (98341 bytes)
MD5: 152531bfef6e09defb06c29b0c6b0235
Detection count: 447
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\GUIRootSoftware
Group: Malware file
Last Updated: September 24, 2016
%USERPROFILE%\Local Settings\Application Data\DriverFreewareOS\DriverFreewareOS.exe File name: DriverFreewareOS.exe
Size: 98.34 KB (98341 bytes)
MD5: 6af6c4cdf188f4e31a4d0f23224c4b79
Detection count: 323
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Local Settings\Application Data\DriverFreewareOS
Group: Malware file
Last Updated: September 24, 2016
%LOCALAPPDATA%\ExportFunctionGamma\ExportFunctionGamma.exe File name: ExportFunctionGamma.exe
Size: 98.34 KB (98341 bytes)
MD5: 72d0641e3b4f1e6523f58ca948f0771e
Detection count: 197
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\ExportFunctionGamma
Group: Malware file
Last Updated: September 24, 2016
%LOCALAPPDATA%\CronDirect3dWinsock\CronDirect3dWinsock.exe File name: CronDirect3dWinsock.exe
Size: 98.34 KB (98341 bytes)
MD5: 45d02e3c3e7c34539980b2cfdc0e739f
Detection count: 192
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\CronDirect3dWinsock
Group: Malware file
Last Updated: September 24, 2016
%LOCALAPPDATA%\ExportInterpreterODBC\ExportInterpreterODBC.exe File name: ExportInterpreterODBC.exe
Size: 98.34 KB (98341 bytes)
MD5: c5a19d1aba6f3fa39d9c8b229ffef6b3
Detection count: 178
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\ExportInterpreterODBC
Group: Malware file
Last Updated: September 24, 2016
%SystemDrive%\Users\<username>\AppData\Local\CompileMinimalSnapshot\CompileMinimalSnapshot.exe File name: CompileMinimalSnapshot.exe
Size: 98.34 KB (98341 bytes)
MD5: 9db5393724c9795221e46bc262c6f765
Detection count: 171
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Users\<username>\AppData\Local\CompileMinimalSnapshot
Group: Malware file
Last Updated: September 24, 2016
%SystemDrive%\Users\<username>\AppData\Local\DashboardMacroMotion\DashboardMacroMotion.exe File name: DashboardMacroMotion.exe
Size: 98.34 KB (98341 bytes)
MD5: cb54914a0ec158e62d341ef14f20111c
Detection count: 171
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Users\<username>\AppData\Local\DashboardMacroMotion
Group: Malware file
Last Updated: September 24, 2016
%LOCALAPPDATA%\DefaultGammaTooltip\DefaultGammaTooltip.exe File name: DefaultGammaTooltip.exe
Size: 98.34 KB (98341 bytes)
MD5: b64eb5d608203fb2fec787b7451ad7e2
Detection count: 171
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\DefaultGammaTooltip
Group: Malware file
Last Updated: September 24, 2016
%SystemDrive%\Users\<username>\AppData\Local\AppOfficeRegister\AppOfficeRegister.exe File name: AppOfficeRegister.exe
Size: 98.34 KB (98341 bytes)
MD5: 67b3efe0675d8787bced4027e43325f2
Detection count: 169
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Users\<username>\AppData\Local\AppOfficeRegister
Group: Malware file
Last Updated: September 24, 2016
%LOCALAPPDATA%\FinderGUIOCR\FinderGUIOCR.exe File name: FinderGUIOCR.exe
Size: 98.34 KB (98341 bytes)
MD5: 1bc29840497317001b6e2b46b8013dda
Detection count: 169
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\FinderGUIOCR
Group: Malware file
Last Updated: September 24, 2016
%USERPROFILE%\Local Settings\Application Data\JAVAOpenScreenshot\JAVAOpenScreenshot.exe File name: JAVAOpenScreenshot.exe
Size: 98.34 KB (98341 bytes)
MD5: c2c8c46de2752cd14c1485b51c18e079
Detection count: 164
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Local Settings\Application Data\JAVAOpenScreenshot
Group: Malware file
Last Updated: September 24, 2016
%PROGRAMFILES%\WinSystem\Cleaner\WinSystemCleaner.exe File name: WinSystemCleaner.exe
Size: 1.06 MB (1062912 bytes)
MD5: 2843a01b05c92f7b2bb3bd56c0a3886a
Detection count: 119
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\WinSystem\Cleaner
Group: Malware file
Last Updated: January 13, 2017
%WINDIR%\SysWOW64\DebuggerOCRSDK\DebuggerOCRSDK.exe File name: DebuggerOCRSDK.exe
Size: 69.12 KB (69120 bytes)
MD5: fabcb1eb1b0f2a204029837753694955
Detection count: 73
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\SysWOW64\DebuggerOCRSDK
Group: Malware file
Last Updated: May 19, 2020
C:\Users\<username>\AppData\Local\Helper\chrome32.exe File name: chrome32.exe
Size: 188.41 KB (188416 bytes)
MD5: f53f8293448cc33a75b96f36e3c19705
Detection count: 47
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Helper\chrome32.exe
Group: Malware file
Last Updated: May 29, 2023
%PROGRAMFILES%\WinSystem\Updater\WinSystemUpdater.exe File name: WinSystemUpdater.exe
Size: 240.64 KB (240640 bytes)
MD5: 8d0107719204715e22affdbcaa734c93
Detection count: 28
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\WinSystem\Updater
Group: Malware file
Last Updated: January 13, 2017
%LOCALAPPDATA%\mswsocktspkgProvider\mswsocktspkgProvider.exe File name: mswsocktspkgProvider.exe
Size: 209.4 KB (209408 bytes)
MD5: b313522f02b459116dd6ec13f24712dd
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\mswsocktspkgProvider
Group: Malware file
Last Updated: January 27, 2015
%LOCALAPPDATA%\sharewaresdiagschdProt\sharewaresdiagschdProt.exe File name: sharewaresdiagschdProt.exe
Size: 209.4 KB (209408 bytes)
MD5: 16d2a7efcec5a4d3f63f3865aa79e150
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\sharewaresdiagschdProt
Group: Malware file
Last Updated: January 27, 2015

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{D40C654D-7C51-4EB3-95B2-1E23905C2A2D}Regexp file mask%PROGRAMFILES%\WinSystem\Cleaner\WinSystemCleaner.exe%PROGRAMFILES%\WinSystem\Services\WinSystemServices.exe%PROGRAMFILES%\WinSystem\Updater\WinSystemUpdater.exeHKEY..\..\..\..{RegistryKeys}SOFTWARE\Classes\Pirrit.PirritHelperSoftware\Microsoft\Internet Explorer\Approved Extensions\{D40C654D-7C51-4EB3-95B2-1E23905C2A2D}SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{d40c654d-7c51-4eb3-95b2-1e23905c2a2d}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D40C654D-7C51-4EB3-95B2-1E23905C2A2D}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D40C654D-7C51-4EB3-95B2-1E23905C2A2D}Software\PirritSOFTWARE\Pirrit SolutionsSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{d40c654d-7c51-4eb3-95b2-1e23905c2a2d}SOFTWARE\Wow6432Node\PirritSOFTWARE\Wow6432Node\Pirrit SolutionsSYSTEM\ControlSet001\services\PirritDesktopSYSTEM\ControlSet001\services\PirritUpdaterSYSTEM\CurrentControlSet\services\PirritDesktopSYSTEM\CurrentControlSet\services\PirritUpdater

Additional Information

The following directories were created:
%AppData%\Pirrit%LOCALAPPDATA%\Pirrit Suggestor%LOCALAPPDATA%\PirritSuggestor%PROGRAMFILES%\Pirrit%PROGRAMFILES%\Windows Network Accelerater%PROGRAMFILES(x86)%\Pirrit%PROGRAMFILES(x86)%\Windows Network Accelerater%USERPROFILE%\Local Settings\Application Data\PirritSuggestor

One Comment

  • Kaja says:

    Clean also c:\windows\system32\drivers\etc\hosts file records pointing google domains to some Pirrit server.

Loading...
Spywareremove.com uses cookies to provide you with a better browsing experience and analyze how users navigate and utilize the Site. By using this Site or clicking on "OK", you consent to the use of cookies. Learn more.