Shop-wit
by shopwit
What is Shop-wit?
Shop-wit is software application developed by shopwit. It is most commonly found on computers running Windows 7 with nearly 57.89% of installations running this operating system. Shop-wit's installer is typically 811.00 KB in size and installs around 51 files.
Shop-wit is most popular in the United States with 40.13% of installations residing in this country.
Shop-wit adds 2 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times.
About Shop-wit?
Shopwit is a browser extension designed to display banner and text-context link advertisements. These advertisements are intended to promote the installation of additional software, including web browser toolbars, optimization utilities, and other products. Additionally, Shopwit may convert random web page text into hyperlinks. It is important to note that the installation of Shopwit may lead to the inadvertent installation of other unwanted adware programs without the user's knowledge.
Multiple virus scanners have detected malware in Shop-wit.
Scanner Software | Version | Result |
---|---|---|
Lavasoft Ad-Aware | 12.0.163.0 | Adware.PayByAds.A |
ALYac | 1.0.1.4 | Adware.PayByAds.A |
Antiy-AVL | 1.0.0.1 | RiskWare[Downloader:not-a-virus]/Win32.Montiera |
AVG | 15.0.0.4257 | Paybyads.893 |
AVware | 1.5.0.21 | Montiera (fs) |
Baidu-International | 3.5.1.41473 | Hacktool.Win32.Montiera.aPCE |
Bitdefender | 7.2 | Adware.PayByAds.A |
Bkav FE | 1.3.0.6267 | W32.HfsAdware.BDBE |
Emsisoft Anti-Malware | 3.0.0.600 | Adware.PayByAds.A (B) |
ESET-NOD32 | 10994 | a variant of Win32/Toolbar.Montiera.R |
Fortinet FortiGate | 5.0.999.0 | Riskware/Montiera |
F-Secure | 11.0.19100.45 | Adware.PayByAds.A |
G Data | 24 | Adware.PayByAds.A |
IKARUS anti.virus | T3.1.8.6.0 | not-a-virus:Downloader.Montiera |
K7 AntiVirus | 9.190.14602 | Unwanted-Program ( 004b1ff21 ) |
K7GW | 9.190.14602 | Unwanted-Program ( 004b1ff21 ) |
Kaspersky | 15.0.1.10 | not-a-virus:Downloader.Win32.Montiera.b |
Malwarebytes | 1.75.0.1 | PUP.Optional.ShopWit.A |
McAfee | 6.0.5.614 | Artemis!8B227A63D115 |
McAfee-GW-Edition | v2014.2 | BehavesLike.Win32.BadFile.gh |
MicroWorld-eScan | 12.0.250.0 | Adware.PayByAds.A |
nProtect | 2015-01-09.01 | Adware.PayByAds.A |
Panda Antivirus | 4.6.4.2 | Trj/CI.A |
Sophos | 4.98.0 | PayByAds |
Symantec | 20141.1.0.330 | Trojan.Zbot |
Trend Micro | 9.740.0.1012 | TROJ_GEN.R0C1C0OLO14 |
TrendMicro-HouseCall | 9.700.0.1001 | TROJ_GEN.R0C1C0OLO14 |
VIPRE Antivirus | 36544 | Montiera (fs) |
Zillya | 2.0.0.2031 | Downloader.Montiera.Win32.30 |
Scanner Software | Version | Result |
---|---|---|
Antiy-AVL | 1.0.0.1 | Trojan/Win32.TGeneric |
avast! | 2014.9-140620 | Win32:Dropper-gen [Drp] |
Baidu-International | 4.0.3.14620 | Adware.Win32.ShopWit.81 |
ByteHero BDV | 6.20.2014.10 | Virus.Win32.Heur.n |
ESET-NOD32 | 8.9972 | a variant of Win32/Toolbar.Montiera.K |
G Data | 14.6.24 | Win32.Trojan.Agent.SZWJSL |
McAfee | 5600.7094 | Artemis!A1100CE92720 |
McAfee-GW-Edition | 7.7094 | Artemis!A1100CE92720 |
Qihoo-360 | 1.0.0.1015 | Win32/Trojan.Dropper.c9f |
Trend Micro | 10.465.20 | ADW_MONTIERA |
TrendMicro-HouseCall | 7.2.171 | ADW_MONTIERA |
Lavasoft Ad-Aware | 12.0.163.0 | Adware.PayByAds.A |
ALYac | 1.0.1.4 | Adware.PayByAds.A |
AVG | 15.0.0.4257 | Paybyads.893 |
AVware | 1.5.0.21 | Montiera (fs) |
Bitdefender | 7.2 | Adware.PayByAds.A |
Bkav FE | 1.3.0.6267 | W32.HfsAdware.BDBE |
Emsisoft Anti-Malware | 3.0.0.600 | Adware.PayByAds.A (B) |
Fortinet FortiGate | 5.0.999.0 | Riskware/Montiera |
F-Secure | 11.0.19100.45 | Adware.PayByAds.A |
IKARUS anti.virus | T3.1.8.6.0 | not-a-virus:Downloader.Montiera |
K7 AntiVirus | 9.190.14602 | Unwanted-Program ( 004b1ff21 ) |
K7GW | 9.190.14602 | Unwanted-Program ( 004b1ff21 ) |
Kaspersky | 15.0.1.10 | not-a-virus:Downloader.Win32.Montiera.b |
Malwarebytes | 1.75.0.1 | PUP.Optional.ShopWit.A |
MicroWorld-eScan | 12.0.250.0 | Adware.PayByAds.A |
nProtect | 2015-01-09.01 | Adware.PayByAds.A |
Panda Antivirus | 4.6.4.2 | Trj/CI.A |
Sophos | 4.98.0 | PayByAds |
Symantec | 20141.1.0.330 | Trojan.Zbot |
VIPRE Antivirus | 36544 | Montiera (fs) |
Zillya | 2.0.0.2031 | Downloader.Montiera.Win32.30 |
Software Behaviors
- Scheduled tasks:
-
- shopwit.exe is scheduled as a task named '$crrUnisntlDsply$' (Next runs on 2015-04-17 at 16:45).
- shopup.exe is scheduled as a task named '$crrUnisntlDsply$ Udpater' (Next runs on 2015-04-17 at 16:45).
Startup Entries
- Registry entries:
-
- shopwit.exe is loaded in the current user (HKCU) registry as an auto-starting executable named 'Shop-wit' and executes as C:\Program Files\shopwit\shopwit\1.4.0.5\shopwit.exe.
Software Details
- URL:
- –
- Support:
- –
- Installation path:
- C:\users\user\appdata\local\shopwit\shopwit\1.3.6.10
- Uninstaller:
- "C:\users\user\appdata\Local\shopwit\shopwit\1.3.6.10\shopwit.exe" /uninstl
- Size:
- 811.00 KB
- Language:
- English
Shop-wit Executable Details
- Primary executable:
- shopwit.exe
- Name:
- Shop-wit
- Path:
- C:\users\user\appdata\local\shopwit\shopwit\1.3.6.10\shopwit.exe
- MD5:
- a1100ce92720ff0387d92afc5ff1b194
- SHA-1:
- –
- SHA-256:
- –
File Type | Filename | MD5 |
---|---|---|
DLL
|
1792fc44f20490a60ffe878c8b0a8939 | |
EXE
|
fe4ef99eb36aa2c57787f52a01e08fef | |
DLL
|
3c647473458c4ae33b66b8a9dd9c840f | |
DLL
|
4cfa2e5ac5ee637ccc5c0279690cf780 | |
DLL
|
e423814eb67063d69a4c3cdfe6e83020 | |
DLL
|
2541ecfad024b74e4dde98b000abd1ea | |
DLL
|
8047cd3bf593be872abb74e7f817dfef | |
EXE
|
shopup.exe
Malware
|
8b227a63d115d18328a909522ef7e72a |
DLL
|
a0411bd5d69243d96314f36cf20328e5 | |
DLL
|
b8b1be7e50ac66b7093d5bc3acfccea5 |