Adware.Pirrit Description

Adware.macOS.Pirrit, Pirrit Mac Adware, or simply Pirrit, is a piece of Adware aimed at bombarding PC users with annoying pop-ups. Having bugged Windows-based machines, Pirrit has now set eyes on macOS systems, as well. Pirrit flags as a Potentially Unwanted Program (PUP) due to the intrusive nature of the ads that come with it.

A Nerve-Wracking Experience

Imagine being flooded with miscellaneous ads, banners, pop-ups, coupons, and surveys, which keep popping up while you are browsing the web. They disrupt your activity and lead you straight to a variety of suspicious websites you’ve never seen before. That’s what Pirrit does, and that’s when you should raise a red flag signifying that your Mac has come under an adware attack. Albeit a low-level threat, adware tools like Pirrit may bring you to malware-infested sites anytime. Moreover, those sites may turn out to contain much more severe pieces of malware hidden beneath the sea of pop-ups and banners generated by Pirrit itself. In the worst-case scenario, Pirrit may lead you to a Trojan capable of harvesting your banking details, login credentials, or other personal data. What is more, some victims have even complained about having had their microphones and cameras hijacked. That's why letting the Pirrit Adware reside in your Mac is a no-go.

Distribution Tactics and Operation

Adware.macOS.Pirrit typically comes as part of software bundles of popular programs users can get from the Internet. Besides the core tools, those bundles may often include lots of additional, often superfluous programs. Unless you uncheck them before installation, you will get them all, which increases the prospect of getting an adware infection like the Pirrit. Once installed, Pirrit may perform many actions such as:

  • Highlighting particular words during web browsing.
  • Placing hyperlinks within the viewed web content.
  • Loading pop-ups until they’ve covered your whole screen, etc.

You will easily recognize you have a Pirrit adware infection when you scroll over the embedded links. If you click on a Pirrit-generated ad, the crooks behind the Adware will earn a dime or two. That explains why they have been exploiting Pirrit to plague Windows-based machines for more than six years. Here are some of Pirrit's aliases over that time:

Adware.Win32.Tirrip.f, Generic5.AUTI [AVG], Riskware/Pirrit [Fortinet], Win32.Adware.Tirrip.Wrqs, Win32/AdWare.Pirrit.A, Trj/CI.A [Panda], AdWare.Tirrip, Win32.Troj.Tirrip.f.(kcloud), GrayWare[AdWare:not-a-virus]/Win32.Tirrip [Antiy-AVL], SPR/Tool.63488.4, AdWare/Tirrip.f, RDN/Generic PUP.x!c2y [McAfee-GW-Edition], Adware.Tirrip.Win32.6, Adware.Pirrit.2 [DrWeb] and ApplicUnwnt [Comodo].

Pirrit Removal

Like any other piece of Adware, you can either delete Pirrit manually or automatically. The latter method stands a much higher chance of cleaning up all the residual files, regardless of their destination folders. So, waste no time running a reputable AV solution to regain control of your Mac.

Aliases: Adware.Win32.Tirrip.f, Generic5.AUTI [AVG], Riskware/Pirrit [Fortinet], Win32.Adware.Tirrip.Wrqs, Win32/AdWare.Pirrit.A, Trj/CI.A [Panda], AdWare.Tirrip, Win32.Troj.Tirrip.f.(kcloud), GrayWare[AdWare:not-a-virus]/Win32.Tirrip [Antiy-AVL], SPR/Tool.63488.4, AdWare/Tirrip.f, RDN/Generic PUP.x!c2y [McAfee-GW-Edition], Adware.Tirrip.Win32.6, Adware.Pirrit.2 [DrWeb] and ApplicUnwnt [Comodo].

Technical Information

File System Details

Adware.Pirrit creates the following file(s):
# File Name Size MD5 Detection Count
1 %WINDIR%wauctla.exe 188,928 f2f28eaa6b0151e390d507749878cf13 3,993
2 %PROGRAMFILES%\WinSystem\Cleaner\WinSystemCleaner.exe 831,488 61e5aa1b041054d1f0f8d900e9320ade 320
3 %SystemDrive%\Users\JoanBrenda\AppData\Local\FileImportProgram\FileImportProgram.exe 98,341 9e9b754b9ca5081a4eca625567e1262d 191
4 %LOCALAPPDATA%\GUIRootSoftware\GUIRootSoftware.exe 98,341 152531bfef6e09defb06c29b0c6b0235 191
5 %WINDIR%\system32\commandremote32\commandremote32.exe 83,456 726790ac4efe16ff25705c76c299d02b 166
6 %PROGRAMFILES(x86)%\Windows Network Accelerater\v3\vxmclient.exe 4,586,400 3f6ddb4b5a066321544176c599b53a70 145
7 %USERPROFILE%\Local Settings\Application Data\DriverFreewareOS\DriverFreewareOS.exe 98,341 6af6c4cdf188f4e31a4d0f23224c4b79 138
8 %WINDIR%\SysWOW64\DatabaseFAT32Firmware\DatabaseFAT32Firmware.exe 68,096 8793f40f334723b0dc967c43d0413fd9 118
9 %SystemDrive%\Users\???\AppData\Local\CGICompilerIcon\CGICompilerIcon.exe 98,341 03dd7325372577b1f918f1dc43d4e8cd 107
10 %LOCALAPPDATA%\ExportFunctionGamma\ExportFunctionGamma.exe 98,341 72d0641e3b4f1e6523f58ca948f0771e 84
11 %LOCALAPPDATA%\CronDirect3dWinsock\CronDirect3dWinsock.exe 98,341 45d02e3c3e7c34539980b2cfdc0e739f 82
12 %LOCALAPPDATA%\ExportInterpreterODBC\ExportInterpreterODBC.exe 98,341 c5a19d1aba6f3fa39d9c8b229ffef6b3 76
13 %SystemDrive%\Users\Tammy\AppData\Local\CompileMinimalSnapshot\CompileMinimalSnapshot.exe 98,341 9db5393724c9795221e46bc262c6f765 73
14 %SystemDrive%\Users\Guest\AppData\Local\DashboardMacroMotion\DashboardMacroMotion.exe 98,341 cb54914a0ec158e62d341ef14f20111c 73
15 %LOCALAPPDATA%\DefaultGammaTooltip\DefaultGammaTooltip.exe 98,341 b64eb5d608203fb2fec787b7451ad7e2 73
16 %SystemDrive%\Users\Tammy\AppData\Local\AppOfficeRegister\AppOfficeRegister.exe 98,341 67b3efe0675d8787bced4027e43325f2 72
17 %LOCALAPPDATA%\FinderGUIOCR\FinderGUIOCR.exe 98,341 1bc29840497317001b6e2b46b8013dda 72
18 %USERPROFILE%\Local Settings\Application Data\Direct3dProcessSnapshot\Direct3dProcessSnapshot.exe 98,341 b32e9d254583d8050bf7621e09a9f4ba 70
19 %USERPROFILE%\Local Settings\Application Data\JAVAOpenScreenshot\JAVAOpenScreenshot.exe 98,341 c2c8c46de2752cd14c1485b51c18e079 70
20 %PROGRAMFILES%\WinSystem\Updater\WinSystemUpdater.exe 240,640 988b0aa8ed363cf2e31a6e0baf737b97 33
21 %WINDIR%\SysWOW64\DebuggerOCRSDK\DebuggerOCRSDK.exe 69,120 fabcb1eb1b0f2a204029837753694955 31
22 %LOCALAPPDATA%\ApplicationClipboardDock\ApplicationClipboardDock.exe 158,720 84c299db01efbd675ceecfe10b148c9a 10
23 %LOCALAPPDATA%\Helper\chrome32.exe 188,416 f53f8293448cc33a75b96f36e3c19705 10
24 %LOCALAPPDATA%\Helper\chrome64.exe 243,712 75407b350565593eb52d3f58b4d04584 7
25 %LOCALAPPDATA%\mswsocktspkgProvider\mswsocktspkgProvider.exe 209,408 b313522f02b459116dd6ec13f24712dd 5
26 %LOCALAPPDATA%\sharewaresdiagschdProt\sharewaresdiagschdProt.exe 209,408 16d2a7efcec5a4d3f63f3865aa79e150 2
More files

Registry Details

Adware.Pirrit creates the following registry entry or registry entries:
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\ammfplfdkakimnibcghcebgbiiphabgc
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Local Extension Settings\ammfplfdkakimnibcghcebgbiiphabgc
%LOCALAPPDATA%\Pirrit Suggestor
%PROGRAMFILES%\Windows Network Accelerater
%PROGRAMFILES(x86)%\Windows Network Accelerater
%USERPROFILE%\Local Settings\Application Data\PirritSuggestor
Regexp file mask
Registry key
Software\Microsoft\Internet Explorer\Approved Extensions\{D40C654D-7C51-4EB3-95B2-1E23905C2A2D}
SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{d40c654d-7c51-4eb3-95b2-1e23905c2a2d}
SOFTWARE\Pirrit Solutions
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{d40c654d-7c51-4eb3-95b2-1e23905c2a2d}
SOFTWARE\Wow6432Node\Pirrit Solutions

Site Disclaimer is not associated, affiliated, sponsored or owned by the malware creators or distributors mentioned on this article. This article should NOT be mistaken or confused in being associated in any way with the promotion or endorsement of malware. Our intent is to provide information that will educate computer users on how to detect, and ultimately remove, malware from their computer with the help of SpyHunter and/or manual removal instructions provided on this article.

This article is provided "as is" and to be used for educational information purposes only. By following any instructions on this article, you agree to be bound by the disclaimer. We make no guarantees that this article will help you completely remove the malware threats on your computer. Spyware changes regularly; therefore, it is difficult to fully clean an infected machine through manual means.

Leave a Reply

Please DO NOT use this comment system for support or billing questions. For SpyHunter technical support requests, please contact our technical support team directly by opening a customer support ticket via your SpyHunter. For billing issues, please refer to our "Billing Questions or Problems?" page. For general inquiries (complaints, legal, press, marketing, copyright), visit our "Inquiries and Feedback" page.