Threat Database Adware Adware.Elex.OA

Adware.Elex.OA

By CagedTech in Adware

Threat Scorecard

Threat Level: 20 % (Normal)
Infected Computers: 66
First Seen: September 1, 2022
Last Seen: April 4, 2026
OS(es) Affected: Windows

The detection of Adware.Elex.OA on your system indicates the presence of a potentially unwanted program that may be causing disruptions to your browsing experience and system performance. It is essential to understand the nature of this threat and take immediate action to remove it and prevent further damage.

What Is Adware.Elex.OA?

Adware.Elex.OA is a type of adware program designed to display unwanted advertisements on infected systems. Adware programs like this one can be bundled with free software or downloaded from compromised websites, often without the user's knowledge or consent. Once installed, adware can collect user data, track browsing habits, and display targeted advertisements, which can be annoying and potentially malicious.

How Adware.Elex.OA Operates

Adware.Elex.OA operates by infiltrating a system through various means, such as exploited vulnerabilities, drive-by downloads, or social engineering tactics. Once inside, it can modify system settings, create new registry entries, and install additional malware components. The primary goal of adware is to generate revenue for its creators by displaying advertisements, which can be in the form of pop-ups, banners, or sponsored search results. Adware can also collect sensitive user data, such as browsing history, search queries, and personal information, which can be used for targeted advertising or sold to third-party companies.

Symptoms of Infection

Systems infected with Adware.Elex.OA may exhibit various symptoms, including an increase in unwanted advertisements, slow system performance, and unexpected browser behavior. Users may notice that their browser homepage or search engine has been changed, or that new toolbars or extensions have been installed without their consent. Additionally, adware can cause system crashes, freezes, and errors, making it essential to remove the infection as soon as possible.

  • Unwanted advertisements and pop-ups
  • Slow system performance and responsiveness
  • Unexpected browser behavior and changes to settings
  • System crashes, freezes, and errors

How to Remove Adware.Elex.OA

  1. Boot your system in Safe Mode with Networking to prevent the adware from loading and to allow for a more effective removal process.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all components of the adware.
  3. Uninstall any suspicious programs or applications that may be related to the adware infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any changes made by the adware.
  5. Reboot your system and perform another full scan to ensure that all components of the adware have been removed.

Conclusion

Removing Adware.Elex.OA from your system is crucial to prevent further damage and protect your personal data. By following the steps outlined above, you can effectively remove the infection and restore your system to its normal state. It is essential to remain vigilant and take proactive measures to prevent future infections, such as keeping your operating system and software up-to-date, using reputable anti-malware tools, and being cautious when downloading software or clicking on links from unknown sources.

Analysis Report

General information

Family Name: Adware.Elex.OA
Signature status: No Signature

Known Samples

MD5: cc7d7b54eee8d6539a25b28db55f958b
SHA1: 7d3f9dc20ef60c6668bf160003416610c1d9b0a6
SHA256: 27BDD3377083513AAA2FB7B4F1681DC7C1162D05FD20F9E75E88336B416E1291
File Size: 2.84 MB, 2835223 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name iBank
File Description iBank
File Version 6.6.0.22
Internal Name iBank.exe
Legal Copyright Copyright (C) iBank.com 2010
Original Filename iBank.exe
Product Name iBank
Product Version 6.6.0.22

File Traits

  • big overlay
  • x86

Block Information

Total Blocks: 1,653
Potentially Malicious Blocks: 48
Whitelisted Blocks: 1,595
Unknown Blocks: 10

Visual Map

0 x x 0 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? x x 0 0 0 0 x x x 0 ? 0 ? x 0 0 0 0 x 0 ? x 0 x x x x x x x 0 0 0 0 0 0 0 0 x x ? ? 0 ? 0 0 ? ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 2 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 1 0 0 0 0 0 1 0 0 0 0 1 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 2 3 0 1 1 0 0 1 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 2 2 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x x x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Elex.OA

Files Modified

File Attributes
c:\users\user\appdata\local\temp\ztmp02\39.json Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ztmp02\cf.ini Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ztmp02\default_newtabff#5.4.21.xpi Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ztmp02\everything.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ztmp02\ihpul.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ztmp02\picx.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ztmp02\qqbrowser.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ztmp02\qqbrowserframe.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ztmp02\uneverything.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ztmp02\winhlp.exe Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\ztmp02\xlxbqc Generic Write,Read Attributes

Windows API Usage

Category API
Network Lmaccess
  • NetUserEnum
Service Control
  • OpenSCManager
  • OpenService
Anti Debug
  • OutputDebugString

Related Posts

Trending

Most Viewed

Loading...