Threat Database Adware Adware.Elex.IC

Adware.Elex.IC

By CagedTech in Adware
Published:
Last updated:

Threat Scorecard

Popularity Rank: 22,681
Threat Level: 20 % (Normal)
Infected Computers: 2
First Seen: March 25, 2023
Last Seen: September 24, 2026
OS(es) Affected: Windows

Adware.Elex.IC is a detection name used to identify a family of adware programs designed to run on Windows computers. Rather than being a single application, it represents a group of related adware variants that share common behaviors, such as injecting advertisements, modifying browser settings, and collecting information about a user's online activity. Although adware like this is generally considered a lower-level threat compared to viruses or ransomware, it can still be disruptive, invasive, and a sign that unwanted software has found its way onto a system.

What Adware.Elex.IC Does

Once active on a computer, Adware.Elex.IC typically behaves like other programs in the adware category. It may insert extra advertisements into web pages, open new browser tabs or windows displaying promotional content, or redirect search queries through sponsored pages before reaching the intended destination. Many adware programs of this type also monitor browsing habits, including visited websites and search terms, so that advertisers can serve more targeted ads. In some cases, this tracked data may include technical details about the device or, less commonly, personal information such as email addresses, which can later be used for marketing or spam purposes. The primary motivation behind this type of software is typically financial: generating revenue for its creators through forced ad impressions, click-throughs, or data collection deals with advertising networks.

How It Usually Gets Onto Computers

Adware such as Adware.Elex.IC commonly spreads through bundled software installers. Users who download free programs, media tools, or utilities from unofficial or third-party websites may unknowingly agree to install additional adware components during a rushed setup process. This frequently happens when installation wizards are not reviewed carefully, allowing pre-checked boxes authorizing extra software installs to go unnoticed. Adware can also arrive through deceptive advertisements, fake update prompts, or links in spam emails that lead to compromised or misleading download pages.

Risks for the User

While adware infections are not typically as damaging as more severe forms of malware, they still pose real risks. Constant advertising can slow down browsing, clutter the user interface, and make it harder to navigate the web safely, since some ads may lead to scam sites or further unwanted downloads. The data-tracking aspect of adware is also a privacy concern, as users often have little visibility into what information is being collected or how it is shared with third parties. Additionally, the presence of adware may indicate weaker overall system security, since the same installation habits that allow adware in can also expose a computer to more dangerous threats.

Signs of Infection

Common indicators that Adware.Elex.IC or similar adware may be present include a noticeable increase in pop-up ads, unexpected browser redirects, new toolbars or extensions that were not intentionally installed, and a general slowdown in browser or system performance. Users might also notice their default search engine or homepage has changed without permission.

How to Stay Protected

To reduce the risk of adware infections, it is advisable to download software only from official or trusted sources, carefully review installation steps instead of clicking through them quickly, and decline optional bundled offers. Keeping the operating system and browsers updated, along with routinely checking installed programs and browser extensions, can also help users spot and remove unwanted software before it causes further issues.

Analysis Report

General information

Family Name: Adware.Elex.IC
Signature status: No Signature

Known Samples

MD5: 1ec84274a449827b2875b3312afac303
SHA1: 1cb62fc7682bdd08a28d2d7b79e0918f64983ada
SHA256: F66459D11E7F38D8D5DEBD10237B4A52890CD65990F345B2B06D1827EB434893
File Size: 118.27 KB, 118272 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have security information
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • dll
  • x86

Block Information

Total Blocks: 420
Potentially Malicious Blocks: 21
Whitelisted Blocks: 394
Unknown Blocks: 5

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x 0 0 x x x 0 ? 0 0 0 0 0 0 0 x x x x 0 x x 0 x x x 0 0 0 0 ? ? 0 0 0 x ? ? 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 1 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 1 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 2 3 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 2 2 1 0 1 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\1cb62fc7682bdd08a28d2d7b79e0918f64983ada_0000118272.,LiQMAxHB