Threat Database Adware Adware.Complitly

Adware.Complitly

By CagedTech in Adware
Published:
Last updated:

Threat Scorecard

Popularity Rank: 11,181
Threat Level: 20 % (Normal)
Infected Computers: 10,506
First Seen: May 4, 2013
Last Seen: September 30, 2026
OS(es) Affected: Windows

The detection of Adware.Complitly on your system indicates the presence of a potentially unwanted program that could be compromising your computer's security and performance. Adware programs like Adware.Complitly are designed to display unwanted advertisements, collect user data, and sometimes even install additional malicious software. Understanding what Adware.Complitly is, how it operates, and the symptoms it causes is crucial for effective removal and prevention of future infections.

What Is Adware.Complitly?

Adware, short for advertising-supported software, is a type of software that displays advertisements on your computer. While not all adware is malicious, Adware.Complitly falls into a category that can pose significant risks to your privacy and system security. It may collect personal data, track your browsing habits, and expose your system to other threats by downloading additional malware.

How Adware.Complitly Operates

Adware.Complitly operates by infiltrating your system, often through bundled software downloads or deceptive links. Once installed, it can alter your browser settings, add toolbars, and change your homepage without your consent. It may also communicate with its command and control servers to report your browsing activities and receive instructions for displaying targeted advertisements. This operation can significantly slow down your computer and internet connection, making your online experience frustrating.

Symptoms of Infection

Symptoms of an Adware.Complitly infection can vary but commonly include an increase in unwanted pop-ups, banners, and advertisements on web pages and even on your desktop. You might also notice unfamiliar programs or toolbars in your browser that you did not install. Furthermore, your browser may redirect you to unwanted websites, or you might experience a general slowdown in your computer's performance. These symptoms indicate that your system is compromised and requires immediate attention.

How to Remove Adware.Complitly

  1. Boot your computer in Safe Mode with Networking to prevent Adware.Complitly from loading and to give you a clean environment to work in.
  2. Perform a full scan of your computer using a reputable anti-malware tool, such as SpyHunter, to detect and remove all traces of Adware.Complitly and other potential threats.
  3. Uninstall any suspicious programs that you do not recognize or that were installed around the time your issues began. This can help remove any additional malware or unwanted software that Adware.Complitly might have installed.
  4. Reset your browsers (Google Chrome, Mozilla Firefox, Microsoft Edge, etc.) to their default settings. This step will remove any changes made by Adware.Complitly, including unwanted extensions and home page alterations.
  5. Reboot your computer and perform another scan with your anti-malware tool to ensure that all remnants of Adware.Complitly have been removed and that your system is clean.

Conclusion

Removing Adware.Complitly from your system requires careful steps to ensure all components are eliminated. By following the removal guide and maintaining good computer hygiene, such as regularly updating your software, avoiding suspicious downloads, and using strong antivirus protection, you can protect your system from future infections. Remember, vigilance and proactive measures are key to keeping your computer secure and your personal data safe from threats like Adware.Complitly.

SpyHunter Detects & Remove Adware.Complitly

File System Details

Adware.Complitly may create the following file(s):
# File Name MD5 Detections
1. Complitly.dll d729490c3ef7e4a1b67e38bfff00ab8e 131
2. Complitly64.dll 1d1d8b81144cff8e67c81f10fd132588 120
3. ComplitlyEngine.dll f68402d3530ffa384c1eadaf8d9675a8 13
4. ComplitlyEngine64.dll d0de5fe3d424572552a27be6a47b5d4b 2
More files

Registry Details

Adware.Complitly may create the following registry entry or registry entries:
SOFTWARE\Classes\AppID\Complitly.DLL
Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
SOFTWARE\Wow6432Node\Classes\AppID\Complitly.DLL
Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0FB6A909-6086-458F-BD92-1F8EE10042A0}

Directories

Adware.Complitly may create the following directory or directories:

%APPDATA%\Complitly
%APPDATA%\ComplitlyEngine
%PROGRAMFILES%\Complitly
%PROGRAMFILES(x86)%\Complitly

Analysis Report

General information

Family Name: Adware.Complitly
Signature status: No Signature

Known Samples

MD5: 7fe8aae525239120e61062ea79548f39
SHA1: ec8f527f0ae15c589eaa1f33da08ce63d541aa78
SHA256: 7F883F00E192C3606C3A5623F1E1C5DA2D9E6494A0AD7058DC254102CE57AA4B
File Size: 3.08 MB, 3077108 bytes
MD5: ab3de0060863baf019988d582045d416
SHA1: fdbb1c38e6219a2a30c903ef1a6b759f608c7194
SHA256: 43E7B1542ED079DA4553827C951C60BD952B896C2E0984331D23FDFF450901F7
File Size: 92.89 KB, 92888 bytes
MD5: 3a8df8210640033fed2e368a67142add
SHA1: 5e530ed3ed2ca4bf7e3cd75812e8a19ea238e7a4
SHA256: F794D5650BC99A1B914B818B5118561C211C1A1BADB1DE038799339AEEA86D0F
File Size: 5.83 MB, 5825439 bytes
MD5: 4d279538307799a7477ece236b3e5c4e
SHA1: 74abd98588e4f831d395be1862ff808da0d6a9bc
SHA256: 455DD8E68EB306E1BEB4F9AFD87852F8EDCE83B72109D4B456F2BEF12B4560F5
File Size: 887.83 KB, 887832 bytes
MD5: a18fbf98d031af2eba6614a9c390c460
SHA1: 4a4b58a1fdde320c31f14627809e594fad7ec2c7
SHA256: 12E53105F28E1B62785B42918D738B66754645BD4E852F19DB7336C8BA53866F
File Size: 2.51 MB, 2506374 bytes
Show More
MD5: 74e32a22f4dc9f05db5cfca9e77da5cb
SHA1: 268244a2ce55c17f576e908789189a212f664d86
SHA256: 8B23A831A93684008E12BFC3499D731CEEF995676B51BAC2679AB6BE6B4BCC7A
File Size: 3.31 MB, 3313664 bytes
MD5: ddb14294b87bb03de2cdb68678c2b00d
SHA1: ee9cdd1a6aad24d568784be1f85941599bef5019
SHA256: A91AFF2D7F0AC4204B10212EA415A26D16971A3046CCD9046B9AFC5CC8306AD6
File Size: 9.86 MB, 9861358 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments This installation was built with Inno Setup.
Company Name
  • 7art-screensavers.com
  • Chris P.C. srl
  • Complitly
  • EasyHideIP.com
  • Moo0
  • y-mule.com
File Description
  • ChrisPC Free Anonymous Proxy Setup
  • Complitly Setup
  • EasyHideIP.com Easy Hide Your IP and Surf Anonymously Setup
  • Installer
  • yMule Youtube Downloader Setup
File Version
  • 2.1
  • 1.0.0.0
Internal Name Installer.exe
Legal Copyright
  • (c) Moo0. All rights reserved.
  • Copyright (c) 2010, y-mule.com
  • Copyright © 7art-screensavers.com
  • Copyright © 2011 Chris P.C. srl
Original Filename Installer.exe
Product Name
  • ChrisPC Free Anonymous Proxy
  • Complitly
  • EasyHideIP.com Easy Hide Your IP and Surf Anonymously
  • Installer
  • yMule Youtube Downloader
Product Version
  • 2.1
  • 1.0.0.0

Digital Signatures

Signer Root Status
SimplyGen SimplyGen Self Signed

Block Information

Similar Families

  • Kryptik.CAB

Files Modified

File Attributes
c:\users\user\appdata\local\temp\bhoupdater.restart Generic Read,Generic Execute,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 786496
c:\users\user\appdata\local\temp\is-4bde0.tmp\ee9cdd1a6aad24d568784be1f85941599bef5019_0009861358.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-bvk84.tmp\4a4b58a1fdde320c31f14627809e594fad7ec2c7_0002506374.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-e0m0p.tmp\5e530ed3ed2ca4bf7e3cd75812e8a19ea238e7a4_0005825439.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-irt1u.tmp\_isetup\_regdll.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-irt1u.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-irt1u.tmp\_isetup\_shfoldr.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-irt1u.tmp\favicon.ico Generic Read,Write Attributes
c:\users\user\appdata\local\temp\is-irt1u.tmp\favicon.ico Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-jfis7.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
Show More
c:\users\user\appdata\local\temp\is-jfis7.tmp\_isetup\_shfoldr.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-jfis7.tmp\certifiedtoolbar7art.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-jfis7.tmp\icon7.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-jfis7.tmp\itdownload.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-jfis7.tmp\screensaverskytoolbaracpro.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-rdfgv.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-rdfgv.tmp\_isetup\_shfoldr.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-rdfgv.tmp\itdownload.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-rdfgv.tmp\toolbar_preview.bmp Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 炜挪ǜ RegNtPreCreateKey

Windows API Usage

Category API
Network Wininet
  • HttpQueryInfo
  • InternetOpen
  • InternetOpenUrl
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
  • ShellExecuteEx
  • WriteConsole
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
Show More
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Other Suspicious
  • AdjustTokenPrivileges
  • SetWindowsHookEx
Process Terminate
  • TerminateProcess
Keyboard Access
  • GetKeyState

Shell Command Execution

"C:\Users\Jxsqlcpx\AppData\Local\Temp\is-E0M0P.tmp\5e530ed3ed2ca4bf7e3cd75812e8a19ea238e7a4_0005825439.tmp" /SL5="$E005C,5403605,140288,c:\users\user\downloads\5e530ed3ed2ca4bf7e3cd75812e8a19ea238e7a4_0005825439"
open taskkill.exe /f /im yMule.exe
WriteConsole: ERROR: The proce
"C:\Users\Gcewxbsx\AppData\Local\Temp\is-BVK84.tmp\4a4b58a1fdde320c31f14627809e594fad7ec2c7_0002506374.tmp" /SL5="$300EA,2260558,54272,c:\users\user\downloads\4a4b58a1fdde320c31f14627809e594fad7ec2c7_0002506374"
"C:\Users\Kubonshh\AppData\Local\Temp\is-4BDE0.tmp\ee9cdd1a6aad24d568784be1f85941599bef5019_0009861358.tmp" /SL5="$B034A,9365778,114176,c:\users\user\downloads\ee9cdd1a6aad24d568784be1f85941599bef5019_0009861358"