I would not doubt their figures though I would question what they consider to be malware.
For example, most key generators I've come across will be picked up as a virus or malware by many scanners but aren't. As to purchasing a PC with a pirated OS...It's more than reasonable to expect something else loaded on the PC as well. Even if nothing was maliciously added you'd have to consider that pirated OS's usually do not offer the same level of security as their legit and updated cousins so are more easily exploited by previously published attack vectors.
That said, I do use pirated software but take precautions in doing so. I'll never use a pirated OS on my main computer but will do so on a less vital system.