Adware.Elex.IC
Threat Scorecard
EnigmaSoft Threat Scorecard
EnigmaSoft Threat Scorecards are assessment reports for different malware threats which have been collected and analyzed by our research team. EnigmaSoft Threat Scorecards evaluate and rank threats using several metrics including real-world and potential risk factors, trends, frequency, prevalence, and persistence. EnigmaSoft Threat Scorecards are updated regularly based on our research data and metrics and are useful for a wide range of computer users, from end users seeking solutions to remove malware from their systems to security experts analyzing threats.
EnigmaSoft Threat Scorecards display a variety of useful information, including:
Popularity Rank: The ranking of a particular threat in EnigmaSoft’s Threat Database.
Severity Level: The determined severity level of an object, represented numerically, based on our risk modeling process and research, as explained in our Threat Assessment Criteria.
Infected Computers: The number of confirmed and suspected cases of a particular threat detected on infected computers as reported by SpyHunter.
See also Threat Assessment Criteria.
| Popularity Rank: | 22,681 |
| Threat Level: | 20 % (Normal) |
| Infected Computers: | 2 |
| First Seen: | March 25, 2023 |
| Last Seen: | September 24, 2026 |
| OS(es) Affected: | Windows |
Adware.Elex.IC is a detection name used to identify a family of adware programs designed to run on Windows computers. Rather than being a single application, it represents a group of related adware variants that share common behaviors, such as injecting advertisements, modifying browser settings, and collecting information about a user's online activity. Although adware like this is generally considered a lower-level threat compared to viruses or ransomware, it can still be disruptive, invasive, and a sign that unwanted software has found its way onto a system.
Table of Contents
What Adware.Elex.IC Does
Once active on a computer, Adware.Elex.IC typically behaves like other programs in the adware category. It may insert extra advertisements into web pages, open new browser tabs or windows displaying promotional content, or redirect search queries through sponsored pages before reaching the intended destination. Many adware programs of this type also monitor browsing habits, including visited websites and search terms, so that advertisers can serve more targeted ads. In some cases, this tracked data may include technical details about the device or, less commonly, personal information such as email addresses, which can later be used for marketing or spam purposes. The primary motivation behind this type of software is typically financial: generating revenue for its creators through forced ad impressions, click-throughs, or data collection deals with advertising networks.
How It Usually Gets Onto Computers
Adware such as Adware.Elex.IC commonly spreads through bundled software installers. Users who download free programs, media tools, or utilities from unofficial or third-party websites may unknowingly agree to install additional adware components during a rushed setup process. This frequently happens when installation wizards are not reviewed carefully, allowing pre-checked boxes authorizing extra software installs to go unnoticed. Adware can also arrive through deceptive advertisements, fake update prompts, or links in spam emails that lead to compromised or misleading download pages.
Risks for the User
While adware infections are not typically as damaging as more severe forms of malware, they still pose real risks. Constant advertising can slow down browsing, clutter the user interface, and make it harder to navigate the web safely, since some ads may lead to scam sites or further unwanted downloads. The data-tracking aspect of adware is also a privacy concern, as users often have little visibility into what information is being collected or how it is shared with third parties. Additionally, the presence of adware may indicate weaker overall system security, since the same installation habits that allow adware in can also expose a computer to more dangerous threats.
Signs of Infection
Common indicators that Adware.Elex.IC or similar adware may be present include a noticeable increase in pop-up ads, unexpected browser redirects, new toolbars or extensions that were not intentionally installed, and a general slowdown in browser or system performance. Users might also notice their default search engine or homepage has changed without permission.
How to Stay Protected
To reduce the risk of adware infections, it is advisable to download software only from official or trusted sources, carefully review installation steps instead of clicking through them quickly, and decline optional bundled offers. Keeping the operating system and browsers updated, along with routinely checking installed programs and browser extensions, can also help users spot and remove unwanted software before it causes further issues.
Analysis Report
General information
| Family Name: | Adware.Elex.IC |
|---|---|
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
1ec84274a449827b2875b3312afac303
SHA1:
1cb62fc7682bdd08a28d2d7b79e0918f64983ada
SHA256:
F66459D11E7F38D8D5DEBD10237B4A52890CD65990F345B2B06D1827EB434893
File Size:
118.27 KB, 118272 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have security information
- File has exports table
- File is 32-bit executable
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
- File is not packed
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Traits
- dll
- x86
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 420 |
|---|---|
| Potentially Malicious Blocks: | 21 |
| Whitelisted Blocks: | 394 |
| Unknown Blocks: | 5 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| Syscall Use |
Show More
|
| Process Manipulation Evasion |
|
| Process Shell Execute |
|
| Anti Debug |
|
Shell Command Execution
Shell Command Execution
This section lists Windows shell commands that are run by the samples in this family. Windows Shell commands are often leveraged by malware for nefarious purposes and can be used to elevate security privileges, download and launch other malware, exploit vulnerabilities, collect and exfiltrate data, and hide malicious activity.
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\1cb62fc7682bdd08a28d2d7b79e0918f64983ada_0000118272.,LiQMAxHB
|