Threat Database Adware Adware.Vitruvian.A

Adware.Vitruvian.A

By CagedTech in Adware

Threat Scorecard

Threat Level: 20 % (Normal)
Infected Computers: 24
First Seen: January 12, 2023
Last Seen: January 22, 2026
OS(es) Affected: Windows

The detection of Adware.Vitruvian.A on your system indicates the presence of unwanted software that may be compromising your online experience and potentially exposing you to more severe security risks. Understanding what this detection means and how to address it is crucial for maintaining the health and security of your computer.

What Is Adware.Vitruvian.A?

Adware.Vitruvian.A refers to a type of adware, which is software designed to display unwanted advertisements on your computer, often in the form of pop-ups, banners, or sponsored content within websites. Adware can significantly degrade your browsing experience and may also collect data about your browsing habits without your consent, which can be used for targeted advertising or other malicious purposes.

How Adware.Vitruvian.A Operates

Adware like Adware.Vitruvian.A typically operates by infiltrating your system through various means, such as bundled software downloads, infected email attachments, or exploited vulnerabilities in software. Once installed, it can modify browser settings, install additional software without your knowledge, and monitor your browsing activities to deliver targeted advertisements. This behavior not only disrupts your use of the computer but also poses a risk to your personal data and can lead to further malware infections.

Symptoms of Infection

Symptoms of an Adware.Vitruvian.A infection can include an increase in unwanted advertisements, unexpected changes to your browser's homepage or search engine, the appearance of toolbars you didn't install, and overall slower performance of your computer or browser. You might also notice that your browser is being redirected to unwanted websites or that pop-ups appear even when you're not browsing the internet. These signs indicate that your system is compromised and that you should take immediate action to remove the adware.

How to Remove Adware.Vitruvian.A

  1. Boot your computer in Safe Mode with Networking to limit the adware's ability to interfere with the removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. This will help identify and remove all components of the adware.
  3. Uninstall any suspicious programs that you don't recognize or that were installed without your consent. Be cautious and only remove programs you are sure are not needed for your system's operation.
  4. Reset your browsers (Chrome, Firefox, Edge, etc.) to their default settings. This can often be done through the browser's settings or options menu and will remove any changes made by the adware.
  5. Reboot your computer and perform another scan with your anti-malware tool to ensure that all remnants of the adware have been removed.

Conclusion

Removing Adware.Vitruvian.A requires a thorough approach to ensure that all components of the malware are eliminated from your system. By following the steps outlined above and maintaining good computing practices, such as regularly updating your software and being cautious with downloads and email attachments, you can protect your computer from similar threats in the future. Remember, staying vigilant and proactive is key to maintaining the security and integrity of your digital environment.

Analysis Report

General information

Family Name: Adware.Vitruvian.A
Signature status: Self Signed

Known Samples

MD5: 565359c69eaf59feac843cca7ee6d82f
SHA1: bff6fce49082c4f2cef0a42ebe9b357b927ee66b
SHA256: 22018343EF827216FC87B4EA1ACC91ECB5DDB6EBB3FF12497ED87FDEAB79FE0A
File Size: 1.19 MB, 1188040 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name PhraseProfessor
File Description PP Setup
File Version 1.10.0.24
Internal Name PhraseProfessor-setup.exe
Legal Copyright (c) 2015 PhraseProfessor
Original Filename PhraseProfessor-setup.exe
Product Name PP
Product Version 1.10.0.24

Digital Signatures

Signer Root Status
Phrase Professor GlobalSign CodeSigning CA - G2 Self Signed

File Traits

  • x86

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsgbd7b.tmp\inetc.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsgbd7b.tmp\nsisplugin.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsgbd7b.tmp\system.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsgbd7b.tmp\uac.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsqbd6a.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\local\temp\vitruvian-installer-processes-v0002 Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\wow6432node\phraseprofessor_1.10.0.24::nid BFEB5820-9643-42AD-A79F-071DFF4D8E64 RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\content::cacheprefix RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\cookies::cacheprefix Cookie: RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\history::cacheprefix Visited: RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
Show More
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey

Windows API Usage

Category API
Network Wininet
  • HttpOpenRequest
  • HttpQueryInfo
  • HttpSendRequest
  • InternetConnect
  • InternetOpen
  • InternetQueryOption
  • InternetSetOption

Related Posts

Trending

Most Viewed

Loading...