Adware.Pirrit
Posted: January 23, 2014
Threat Metric
The following fields listed on the Threat Meter containing a specific value, are explained in detail below:
Threat Level: The threat level scale goes from 1 to 10 where 10 is the highest level of severity and 1 is the lowest level of severity. Each specific level is relative to the threat's consistent assessed behaviors collected from SpyHunter's risk assessment model.
Detection Count: The collective number of confirmed and suspected cases of a particular malware threat. The detection count is calculated from infected PCs retrieved from diagnostic and scan log reports generated by SpyHunter.
Volume Count: Similar to the detection count, the Volume Count is specifically based on the number of confirmed and suspected threats infecting systems on a daily basis. High volume counts usually represent a popular threat but may or may not have infected a large number of systems. High detection count threats could lay dormant and have a low volume count. Criteria for Volume Count is relative to a daily detection count.
Trend Path: The Trend Path, utilizing an up arrow, down arrow or equal symbol, represents the level of recent movement of a particular threat. Up arrows represent an increase, down arrows represent a decline and the equal symbol represent no change to a threat's recent movement.
% Impact (Last 7 Days): This demonstrates a 7-day period change in the frequency of a malware threat infecting PCs. The percentage impact correlates directly to the current Trend Path to determine a rise or decline in the percentage.
Ranking: | 12,292 |
---|---|
Threat Level: | 2/10 |
Infected PCs: | 300,531 |
First Seen: | January 23, 2014 |
---|---|
Last Seen: | January 31, 2025 |
OS(es) Affected: | Windows |
Adware.Pirrit is adware that may display random pop-up advertisements or advertisements linked to the PC user's surfing habits in a web browser when a computer user is visiting various questionable websites. The Adware.Pirrit ads may indicate that a PC is corrupted by adware or a potentially unwanted program. Adware.Pirrit may propagate and install itself onto the PC through packaged free software, which computer users can download and install from the Internet. Free applications may often carry various extra software, which may be not necessary for the PC user. Therefore, when the computer user installs any free tool, he should carefully look through what he is going to install together with the desired program that has been selected. When installed, the Adware.Pirrit browser extension may highlight words on the websites that are visited by computer users substituting them with hyperlinks. These Adware.Pirrit links may be added within the text, and may come with a double underline to separate them from normal links. When the PC user rolls the mouse over the link, the pop-up advertisements of Adware.Pirrit may emerge on the desktop. If the PC user clicks on the Adware.Pirrit pop-up links, the makers of the browser plug-in may make a profit from these ad clicks.
Aliases
More aliases (34)
Use SpyHunter to Detect and Remove PC Threats
If you are concerned that malware or PC threats similar to Adware.Pirrit may have infected your computer, we recommend you start an in-depth system scan with SpyHunter. SpyHunter is an advanced malware protection and remediation application that offers subscribers a comprehensive method for protecting PCs from malware, in addition to providing one-on-one technical support service.
* See Free Trial offer below. EULA and Privacy/Cookie Policy.
Why can't I open any program including SpyHunter? You may have a malware file running in memory that kills any programs that you try to launch on your PC. Tip: Download SpyHunter from a clean computer, copy it to a USB thumb drive, DVD or CD, then install it on the infected PC and run SpyHunter's malware scanner.
Technical Details
File System Modifications
Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.
The following files were created in the system:C:\Windows\wauctla.exe
File name: wauctla.exeSize: 1.04 MB (1044480 bytes)
MD5: 7d1e5892bb021fa20a03b7cd932a72da
Detection count: 8,895
File type: Executable File
Mime Type: unknown/exe
Path: C:\Windows\wauctla.exe
Group: Malware file
Last Updated: May 25, 2022
C:\Program Files (x86)\Windows Network Accelerater\v5\winvxm.exe
File name: winvxm.exeSize: 2.97 MB (2976880 bytes)
MD5: b34a08ba3041ae88e1953d22bec7ae38
Detection count: 5,801
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\Windows Network Accelerater\v5\winvxm.exe
Group: Malware file
Last Updated: October 14, 2021
C:\Windows\system32\openmemdiag_64\openmemdiag_64.exe
File name: openmemdiag_64.exeSize: 83.45 KB (83456 bytes)
MD5: 726790ac4efe16ff25705c76c299d02b
Detection count: 499
File type: Executable File
Mime Type: unknown/exe
Path: C:\Windows\system32\openmemdiag_64\openmemdiag_64.exe
Group: Malware file
Last Updated: January 1, 2024
%SystemDrive%\Users\<username>\AppData\Local\FileImportProgram\FileImportProgram.exe
File name: FileImportProgram.exeSize: 98.34 KB (98341 bytes)
MD5: 9e9b754b9ca5081a4eca625567e1262d
Detection count: 447
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Users\<username>\AppData\Local\FileImportProgram
Group: Malware file
Last Updated: September 24, 2016
%LOCALAPPDATA%\GUIRootSoftware\GUIRootSoftware.exe
File name: GUIRootSoftware.exeSize: 98.34 KB (98341 bytes)
MD5: 152531bfef6e09defb06c29b0c6b0235
Detection count: 447
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\GUIRootSoftware
Group: Malware file
Last Updated: September 24, 2016
%USERPROFILE%\Local Settings\Application Data\DriverFreewareOS\DriverFreewareOS.exe
File name: DriverFreewareOS.exeSize: 98.34 KB (98341 bytes)
MD5: 6af6c4cdf188f4e31a4d0f23224c4b79
Detection count: 323
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Local Settings\Application Data\DriverFreewareOS
Group: Malware file
Last Updated: September 24, 2016
%LOCALAPPDATA%\ExportFunctionGamma\ExportFunctionGamma.exe
File name: ExportFunctionGamma.exeSize: 98.34 KB (98341 bytes)
MD5: 72d0641e3b4f1e6523f58ca948f0771e
Detection count: 197
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\ExportFunctionGamma
Group: Malware file
Last Updated: September 24, 2016
%LOCALAPPDATA%\CronDirect3dWinsock\CronDirect3dWinsock.exe
File name: CronDirect3dWinsock.exeSize: 98.34 KB (98341 bytes)
MD5: 45d02e3c3e7c34539980b2cfdc0e739f
Detection count: 192
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\CronDirect3dWinsock
Group: Malware file
Last Updated: September 24, 2016
%LOCALAPPDATA%\ExportInterpreterODBC\ExportInterpreterODBC.exe
File name: ExportInterpreterODBC.exeSize: 98.34 KB (98341 bytes)
MD5: c5a19d1aba6f3fa39d9c8b229ffef6b3
Detection count: 178
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\ExportInterpreterODBC
Group: Malware file
Last Updated: September 24, 2016
%SystemDrive%\Users\<username>\AppData\Local\CompileMinimalSnapshot\CompileMinimalSnapshot.exe
File name: CompileMinimalSnapshot.exeSize: 98.34 KB (98341 bytes)
MD5: 9db5393724c9795221e46bc262c6f765
Detection count: 171
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Users\<username>\AppData\Local\CompileMinimalSnapshot
Group: Malware file
Last Updated: September 24, 2016
%SystemDrive%\Users\<username>\AppData\Local\DashboardMacroMotion\DashboardMacroMotion.exe
File name: DashboardMacroMotion.exeSize: 98.34 KB (98341 bytes)
MD5: cb54914a0ec158e62d341ef14f20111c
Detection count: 171
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Users\<username>\AppData\Local\DashboardMacroMotion
Group: Malware file
Last Updated: September 24, 2016
%LOCALAPPDATA%\DefaultGammaTooltip\DefaultGammaTooltip.exe
File name: DefaultGammaTooltip.exeSize: 98.34 KB (98341 bytes)
MD5: b64eb5d608203fb2fec787b7451ad7e2
Detection count: 171
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\DefaultGammaTooltip
Group: Malware file
Last Updated: September 24, 2016
%SystemDrive%\Users\<username>\AppData\Local\AppOfficeRegister\AppOfficeRegister.exe
File name: AppOfficeRegister.exeSize: 98.34 KB (98341 bytes)
MD5: 67b3efe0675d8787bced4027e43325f2
Detection count: 169
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Users\<username>\AppData\Local\AppOfficeRegister
Group: Malware file
Last Updated: September 24, 2016
%LOCALAPPDATA%\FinderGUIOCR\FinderGUIOCR.exe
File name: FinderGUIOCR.exeSize: 98.34 KB (98341 bytes)
MD5: 1bc29840497317001b6e2b46b8013dda
Detection count: 169
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\FinderGUIOCR
Group: Malware file
Last Updated: September 24, 2016
%USERPROFILE%\Local Settings\Application Data\JAVAOpenScreenshot\JAVAOpenScreenshot.exe
File name: JAVAOpenScreenshot.exeSize: 98.34 KB (98341 bytes)
MD5: c2c8c46de2752cd14c1485b51c18e079
Detection count: 164
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Local Settings\Application Data\JAVAOpenScreenshot
Group: Malware file
Last Updated: September 24, 2016
%PROGRAMFILES%\WinSystem\Cleaner\WinSystemCleaner.exe
File name: WinSystemCleaner.exeSize: 1.06 MB (1062912 bytes)
MD5: 2843a01b05c92f7b2bb3bd56c0a3886a
Detection count: 119
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\WinSystem\Cleaner
Group: Malware file
Last Updated: January 13, 2017
%WINDIR%\SysWOW64\DebuggerOCRSDK\DebuggerOCRSDK.exe
File name: DebuggerOCRSDK.exeSize: 69.12 KB (69120 bytes)
MD5: fabcb1eb1b0f2a204029837753694955
Detection count: 73
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\SysWOW64\DebuggerOCRSDK
Group: Malware file
Last Updated: May 19, 2020
C:\Users\<username>\AppData\Local\Helper\chrome32.exe
File name: chrome32.exeSize: 188.41 KB (188416 bytes)
MD5: f53f8293448cc33a75b96f36e3c19705
Detection count: 47
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Helper\chrome32.exe
Group: Malware file
Last Updated: May 29, 2023
%PROGRAMFILES%\WinSystem\Updater\WinSystemUpdater.exe
File name: WinSystemUpdater.exeSize: 240.64 KB (240640 bytes)
MD5: 8d0107719204715e22affdbcaa734c93
Detection count: 28
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\WinSystem\Updater
Group: Malware file
Last Updated: January 13, 2017
%LOCALAPPDATA%\mswsocktspkgProvider\mswsocktspkgProvider.exe
File name: mswsocktspkgProvider.exeSize: 209.4 KB (209408 bytes)
MD5: b313522f02b459116dd6ec13f24712dd
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\mswsocktspkgProvider
Group: Malware file
Last Updated: January 27, 2015
%LOCALAPPDATA%\sharewaresdiagschdProt\sharewaresdiagschdProt.exe
File name: sharewaresdiagschdProt.exeSize: 209.4 KB (209408 bytes)
MD5: 16d2a7efcec5a4d3f63f3865aa79e150
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\sharewaresdiagschdProt
Group: Malware file
Last Updated: January 27, 2015
More files
Registry Modifications
CLSID{D40C654D-7C51-4EB3-95B2-1E23905C2A2D}Regexp file mask%PROGRAMFILES%\WinSystem\Cleaner\WinSystemCleaner.exe%PROGRAMFILES%\WinSystem\Services\WinSystemServices.exe%PROGRAMFILES%\WinSystem\Updater\WinSystemUpdater.exeHKEY..\..\..\..{RegistryKeys}SOFTWARE\Classes\Pirrit.PirritHelperSoftware\Microsoft\Internet Explorer\Approved Extensions\{D40C654D-7C51-4EB3-95B2-1E23905C2A2D}SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{d40c654d-7c51-4eb3-95b2-1e23905c2a2d}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D40C654D-7C51-4EB3-95B2-1E23905C2A2D}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D40C654D-7C51-4EB3-95B2-1E23905C2A2D}Software\PirritSOFTWARE\Pirrit SolutionsSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{d40c654d-7c51-4eb3-95b2-1e23905c2a2d}SOFTWARE\Wow6432Node\PirritSOFTWARE\Wow6432Node\Pirrit SolutionsSYSTEM\ControlSet001\services\PirritDesktopSYSTEM\ControlSet001\services\PirritUpdaterSYSTEM\CurrentControlSet\services\PirritDesktopSYSTEM\CurrentControlSet\services\PirritUpdater
Clean also c:\windows\system32\drivers\etc\hosts file records pointing google domains to some Pirrit server.