Shop-wit

Shop-wit

Known Toolbar

by shopwit

What is Shop-wit?

Shop-wit is software application developed by shopwit. It is most commonly found on computers running Windows 7 with nearly 57.89% of installations running this operating system. Shop-wit's installer is typically 811.00 KB in size and installs around 51 files.

Shop-wit is most popular in the United States with 40.13% of installations residing in this country.

Shop-wit adds 2 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times.

About Shop-wit?

Shopwit is a browser extension designed to display banner and text-context link advertisements. These advertisements are intended to promote the installation of additional software, including web browser toolbars, optimization utilities, and other products. Additionally, Shopwit may convert random web page text into hyperlinks. It is important to note that the installation of Shopwit may lead to the inadvertent installation of other unwanted adware programs without the user's knowledge.

Multiple virus scanners have detected malware in Shop-wit.

shopup.exe (MD5: 8b227a63d115d18328a909522ef7e72a) has been flagged by 29 scanners:
Scanner Software Result
Lavasoft Ad-Aware Adware.PayByAds.A
ALYac Adware.PayByAds.A
Antiy-AVL RiskWare[Downloader:not-a-virus]/Win32.Montiera
AVG Paybyads.893
AVware Montiera (fs)
Baidu-International Hacktool.Win32.Montiera.aPCE
Bitdefender Adware.PayByAds.A
Bkav FE W32.HfsAdware.BDBE
Emsisoft Anti-Malware Adware.PayByAds.A (B)
ESET-NOD32 a variant of Win32/Toolbar.Montiera.R
Fortinet FortiGate Riskware/Montiera
F-Secure Adware.PayByAds.A
G Data Adware.PayByAds.A
IKARUS anti.virus not-a-virus:Downloader.Montiera
K7 AntiVirus Unwanted-Program ( 004b1ff21 )
K7GW Unwanted-Program ( 004b1ff21 )
Kaspersky not-a-virus:Downloader.Win32.Montiera.b
Malwarebytes PUP.Optional.ShopWit.A
McAfee Artemis!8B227A63D115
McAfee-GW-Edition BehavesLike.Win32.BadFile.gh
MicroWorld-eScan Adware.PayByAds.A
nProtect Adware.PayByAds.A
Panda Antivirus Trj/CI.A
Sophos PayByAds
Symantec Trojan.Zbot
Trend Micro TROJ_GEN.R0C1C0OLO14
TrendMicro-HouseCall TROJ_GEN.R0C1C0OLO14
VIPRE Antivirus Montiera (fs)
Zillya Downloader.Montiera.Win32.30
shopwit.exe (MD5: a1100ce92720ff0387d92afc5ff1b194) has been flagged by 32 scanners:
Scanner Software Result
Antiy-AVL Trojan/Win32.TGeneric
avast! Win32:Dropper-gen [Drp]
Baidu-International Adware.Win32.ShopWit.81
ByteHero BDV Virus.Win32.Heur.n
ESET-NOD32 a variant of Win32/Toolbar.Montiera.K
G Data Win32.Trojan.Agent.SZWJSL
McAfee Artemis!A1100CE92720
McAfee-GW-Edition Artemis!A1100CE92720
Qihoo-360 Win32/Trojan.Dropper.c9f
Trend Micro ADW_MONTIERA
TrendMicro-HouseCall ADW_MONTIERA
Lavasoft Ad-Aware Adware.PayByAds.A
ALYac Adware.PayByAds.A
AVG Paybyads.893
AVware Montiera (fs)
Bitdefender Adware.PayByAds.A
Bkav FE W32.HfsAdware.BDBE
Emsisoft Anti-Malware Adware.PayByAds.A (B)
Fortinet FortiGate Riskware/Montiera
F-Secure Adware.PayByAds.A
IKARUS anti.virus not-a-virus:Downloader.Montiera
K7 AntiVirus Unwanted-Program ( 004b1ff21 )
K7GW Unwanted-Program ( 004b1ff21 )
Kaspersky not-a-virus:Downloader.Win32.Montiera.b
Malwarebytes PUP.Optional.ShopWit.A
MicroWorld-eScan Adware.PayByAds.A
nProtect Adware.PayByAds.A
Panda Antivirus Trj/CI.A
Sophos PayByAds
Symantec Trojan.Zbot
VIPRE Antivirus Montiera (fs)
Zillya Downloader.Montiera.Win32.30

Software Behaviors

Scheduled tasks:
  • shopwit.exe is scheduled as a task named '$crrUnisntlDsply$' (Next runs on 2015-04-17 at 16:45).
  • shopup.exe is scheduled as a task named '$crrUnisntlDsply$ Udpater' (Next runs on 2015-04-17 at 16:45).

Startup Entries

Registry entries:
  • shopwit.exe is loaded in the current user (HKCU) registry as an auto-starting executable named 'Shop-wit' and executes as C:\Program Files\shopwit\shopwit\1.4.0.5\shopwit.exe.

Software Details

URL:
Support:
Installation path:
C:\users\user\appdata\local\shopwit\shopwit\1.3.6.10
Uninstaller:
"C:\users\user\appdata\Local\shopwit\shopwit\1.3.6.10\shopwit.exe" /uninstl
Size:
811.00 KB
Language:
English

Shop-wit Executable Details

Primary executable:
shopwit.exe
Name:
Shop-wit
Path:
C:\users\user\appdata\local\shopwit\shopwit\1.3.6.10\shopwit.exe
MD5:
a1100ce92720ff0387d92afc5ff1b194
SHA-1:
SHA-256:
Files installed by Shop-wit
File Type Filename MD5
DLL
1792fc44f20490a60ffe878c8b0a8939
EXE
fe4ef99eb36aa2c57787f52a01e08fef
DLL
3c647473458c4ae33b66b8a9dd9c840f
DLL
4cfa2e5ac5ee637ccc5c0279690cf780
DLL
e423814eb67063d69a4c3cdfe6e83020
DLL
2541ecfad024b74e4dde98b000abd1ea
DLL
8047cd3bf593be872abb74e7f817dfef
EXE
shopup.exe
Malware
8b227a63d115d18328a909522ef7e72a
DLL
a0411bd5d69243d96314f36cf20328e5
DLL
b8b1be7e50ac66b7093d5bc3acfccea5