PUP.Verti

By GoldSparrow in Potentially Unwanted Programs

Threat Scorecard

Popularity Rank: 12,709
Threat Level: 10 % (Normal)
Infected Computers: 752
First Seen: October 22, 2013
Last Seen: August 13, 2025
OS(es) Affected: Windows

PUP.Verti is a potentially unwanted program that may hijack the PC user's online searches for receiving search results on numerous search provider websites. PUP.Verti may also replace search results in any genuine search engine related to the computer user's queries with links taking web users to dubious advertising websites. PUP.Verti may insert an unwanted add-on, plug-in or extension in Mozilla Firefox, Google Chrome, and Internet Explorer while PC users download and install other freeware and shareware applications from the Internet. When computer users install these free software products, they may also install PUP.Verti on their computer systems. Once installed, PUP.Verti may hijack an online search form in any legal website and replace it with its own. Computer users may have the possibility to carry out an online search via a particular doubtful search provider, getting sponsored links from which the creators of the specific commercial website may earn money. PC users should always pay attention when installing shareware and freeware programs because often, a certain program installer may contain optional installs, such as PUP.Verti. Web users should be careful what free programs they agree to install. They should always select for the custom install on their PCs.

Analysis Report

General information

Family Name: PUP.Verti
Signature status: Root Not Trusted

Known Samples

MD5: f766d9dbc691651252b863f964d99fa3
SHA1: ce89f0fba0ba30f0c110d67254d54e231354a2a0
SHA256: 0462512BABF82E92D8EA39B87AAE8BC5AF0D38A15C7F39B5C6C01AFBD75B8D3C
File Size: 442.36 KB, 442360 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
File Version 1.0.102.0
Product Version 1.0.102.0

Digital Signatures

Signer Root Status
Verti Technology Group, Inc. VeriSign Class 3 Public Primary Certification Authority - G5 Root Not Trusted

Block Information

Total Blocks: 1,017
Potentially Malicious Blocks: 21
Whitelisted Blocks: 860
Unknown Blocks: 136

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? ? 0 0 0 0 0 0 ? ? ? ? ? 0 ? ? 0 1 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? ? ? ? ? ? 0 0 0 ? 0 ? 0 ? 0 ? ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 0 ? ? 0 0 0 0 0 0 0 0 ? ? x x 0 0 ? ? 0 ? 0 0 ? ? ? 0 0 0 0 0 ? ? x x x x x x x x x ? ? ? ? ? 0 ? ? ? ? x x 0 0 0 x 0 ? ? 0 0 0 0 0 x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? ? ? ? 0 ? ? 0 0 0 ? ? ? ? 0 ? ? 0 0 1 0 ? x 0 0 0 0 0 0 0 0 0 0 0 ? x x ? ? 0 0 0 0 0 0 0 0 ? x 0 0 0 0 x 0 0 0 0 0 0 0 ? 0 ? ? 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 0 0 ? 0 ? 0 0 0 0 ? ? ? ? ? ? ? 0 ? ? 0 0 0 1 0 0 1 0 0 x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 1 1 0 0 0 1 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 2 2 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 1 1 0 1 0 1 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 1 1 0 1 1 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 1 0 0 0 1 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 3 0 1 0 0 0 0 1 0 1 0 0 0 0 1 1 0 0 1 0 0 2 2 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 ? ? ? 0 ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Anti Debug
  • NtQuerySystemInformation
Network Wininet
  • HttpOpenRequest
  • HttpSendRequest
  • InternetConnect
  • InternetOpen
  • InternetReadFile
Encryption Used
  • BCryptOpenAlgorithmProvider
Network Winhttp
  • WinHttpOpen

Trending

Most Viewed

Loading...