Threat Database Adware Adware.Pirrit

Adware.Pirrit

By JubileeX in Adware, Mac Malware

Threat Scorecard

Ranking: 8,065
Threat Level: 20 % (Normal)
Infected Computers: 128,290
First Seen: January 23, 2014
Last Seen: April 15, 2024
OS(es) Affected: Windows

Adware.macOS.Pirrit, Pirrit Mac Adware, or simply Pirrit, is a piece of Adware aimed at bombarding PC users with annoying pop-ups. Having bugged Windows-based machines, Pirrit has now set eyes on macOS systems, as well. Pirrit flags as a Potentially Unwanted Program (PUP) due to the intrusive nature of the ads that come with it.

A Nerve-Wracking Experience

Imagine being flooded with miscellaneous ads, banners, pop-ups, coupons, and surveys, which keep popping up while you are browsing the web. They disrupt your activity and lead you straight to a variety of suspicious websites you’ve never seen before. That’s what Pirrit does, and that’s when you should raise a red flag signifying that your Mac has come under an adware attack. Albeit a low-level threat, adware tools like Pirrit may bring you to malware-infested sites anytime. Moreover, those sites may turn out to contain much more severe pieces of malware hidden beneath the sea of pop-ups and banners generated by Pirrit itself. In the worst-case scenario, Pirrit may lead you to a Trojan capable of harvesting your banking details, login credentials, or other personal data. What is more, some victims have even complained about having had their microphones and cameras hijacked. That's why letting the Pirrit Adware reside in your Mac is a no-go.

Distribution Tactics and Operation

Adware.macOS.Pirrit typically comes as part of software bundles of popular programs users can get from the Internet. Besides the core tools, those bundles may often include lots of additional, often superfluous programs. Unless you uncheck them before installation, you will get them all, which increases the prospect of getting an adware infection like the Pirrit. Once installed, Pirrit may perform many actions such as:

  • Highlighting particular words during web browsing.
  • Placing hyperlinks within the viewed web content.
  • Loading pop-ups until they’ve covered your whole screen, etc.

You will easily recognize you have a Pirrit adware infection when you scroll over the embedded links. If you click on a Pirrit-generated ad, the crooks behind the Adware will earn a dime or two. That explains why they have been exploiting Pirrit to plague Windows-based machines for more than six years. Here are some of Pirrit's aliases over that time:

Adware.Win32.Tirrip.f, Generic5.AUTI [AVG], Riskware/Pirrit [Fortinet], Win32.Adware.Tirrip.Wrqs, Win32/AdWare.Pirrit.A, Trj/CI.A [Panda], AdWare.Tirrip, Win32.Troj.Tirrip.f.(kcloud), GrayWare[AdWare:not-a-virus]/Win32.Tirrip [Antiy-AVL], SPR/Tool.63488.4, AdWare/Tirrip.f, RDN/Generic PUP.x!c2y [McAfee-GW-Edition], Adware.Tirrip.Win32.6, Adware.Pirrit.2 [DrWeb] and ApplicUnwnt [Comodo].

Pirrit Removal

Like any other piece of Adware, you can either delete Pirrit manually or automatically. The latter method stands a much higher chance of cleaning up all the residual files, regardless of their destination folders. So, waste no time running a reputable AV solution to regain control of your Mac.

Aliases

15 security vendors flagged this file as malicious.

Anti-Virus Software Detection
AVG Generic5.AUTI
Fortinet Riskware/Pirrit
Panda Trj/CI.A
Antiy-AVL GrayWare[AdWare:not-a-virus]/Win32.Tirrip
McAfee-GW-Edition RDN/Generic PUP.x!c2y
DrWeb Adware.Pirrit.2
Comodo ApplicUnwnt
Sophos Generic PUA PC
Kaspersky not-a-virus:AdWare.Win32.Tirrip.f
Avast Win32:PirritSuggestor-A [Adw]
Symantec Trojan.Gen.2
K7AntiVirus Adware ( 004a0c581 )
CAT-QuickHeal AdWare.Tirrip.r5 (Not a Virus)
GData Win32.Backdoor.NGService.C
Symantec WS.Reputation.1

SpyHunter Detects & Remove Adware.Pirrit

File System Details

Adware.Pirrit may create the following file(s):
# File Name MD5 Detections
1. WinSystemUpdater.exe f84f55d365a414e52d3d0821a60855e5 155
2. WinSystemCleaner.exe ee8bda935c173d53fa6b8da4585e88bc 139
3. WinSystemCleaner.exe 80485cc586df371dcc9c86c1a33cd170 75
4. WinSystemCleaner.exe 2843a01b05c92f7b2bb3bd56c0a3886a 51
5. WinSystemUpdater.exe e4fb25d368c4b69ebd24d67d1f899040 50
6. WinSystemCleaner.exe b34ed12013e0dfd2df37996b077e15b1 50
7. WinSystemCleaner.exe 9a9538431b6252400a381b3b172ef639 37
8. WinSystemCleaner.exe b9de551766ec5d6524c1d6c3966c8fb0 37
9. WinSystemCleaner.exe e12a76cca3c59c6f2f41dca30d7fc06f 27
10. WinSystemCleaner.exe f89ed6e2bf840b0681b43adc4fbe2109 27
11. WinSystemUpdater.exe e88dbc43777253493f24806e7aab409f 21
12. WinSystemUpdater.exe 9cb50c1dc0734aa571b562605f5a11cb 21
13. WinSystemCleaner.exe 0a68e284f7db0068d6f1c60691d8ac6a 17
14. WinSystemUpdater.exe 5e1aae8a944fdf133cfc376573989b93 17
15. WinSystemUpdater.exe e7ffa68f4a9e8a25c33b8514021fbb37 16
16. WinSystemCleaner.exe 2f7a6667fbca9e3d6cc08c99e190d029 16
17. WinSystemUpdater.exe 968d4f1863413bc72c88892a58aa146d 16
18. WinSystemUpdater.exe 163e236b2de9240d630c5f406e04c2fd 16
19. WinSystemUpdater.exe a969ee001d1e5f85d9807cf673e11781 13
20. WinSystemCleaner.exe 5cea07af29b9b37480a26990030bf7dd 12
21. WinSystemUpdater.exe 8d0107719204715e22affdbcaa734c93 12
22. WinSystemUpdater.exe d1f4a56bc4ee7c94a5e3e912f8143302 11
23. WinSystemCleaner.exe da59d183903745419fae611bff855792 11
24. WinSystemUpdater.exe a0abc4e6390524e578d171ccb10bcfc0 11
25. WinSystemCleaner.exe 2436edf5e7fa69b03f590f178f7e3b5f 11
26. WinSystemCleaner.exe dd2219ddf44d5319d3fd0a5aafbec6df 11
27. WinSystemUpdater.exe a30bea5db94bb8feb9f6b7cdfc34c99a 11
28. WinSystemUpdater.exe 93170b03f6655d0c99c9a20880c6aa29 10
29. WinSystemUpdater.exe 09f8718526460a801f9756608cc33630 10
More files

Registry Details

Adware.Pirrit may create the following registry entry or registry entries:
CLSID
{D40C654D-7C51-4EB3-95B2-1E23905C2A2D}
Regexp file mask
%PROGRAMFILES%\WinSystem\Cleaner\WinSystemCleaner.exe
%PROGRAMFILES%\WinSystem\Services\WinSystemServices.exe
%PROGRAMFILES%\WinSystem\Updater\WinSystemUpdater.exe
SOFTWARE\Classes\Pirrit.PirritHelper
Software\Microsoft\Internet Explorer\Approved Extensions\{D40C654D-7C51-4EB3-95B2-1E23905C2A2D}
SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{d40c654d-7c51-4eb3-95b2-1e23905c2a2d}
Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D40C654D-7C51-4EB3-95B2-1E23905C2A2D}
Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D40C654D-7C51-4EB3-95B2-1E23905C2A2D}
Software\Pirrit
SOFTWARE\Pirrit Solutions
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{d40c654d-7c51-4eb3-95b2-1e23905c2a2d}
SOFTWARE\Wow6432Node\Pirrit
SOFTWARE\Wow6432Node\Pirrit Solutions
SYSTEM\ControlSet001\services\PirritDesktop
SYSTEM\ControlSet001\services\PirritUpdater
SYSTEM\CurrentControlSet\services\PirritDesktop
SYSTEM\CurrentControlSet\services\PirritUpdater

Directories

Adware.Pirrit may create the following directory or directories:

%AppData%\Pirrit
%LOCALAPPDATA%\Pirrit Suggestor
%LOCALAPPDATA%\PirritSuggestor
%PROGRAMFILES%\Pirrit
%PROGRAMFILES%\Windows Network Accelerater
%PROGRAMFILES(x86)%\Pirrit
%PROGRAMFILES(x86)%\Windows Network Accelerater
%USERPROFILE%\Local Settings\Application Data\PirritSuggestor

Trending

Most Viewed

Loading...