Home Malware Programs Adware Adware.Adpeak

Adware.Adpeak

Posted: November 25, 2013

Threat Metric

Ranking: 5,027
Threat Level: 2/10
Infected PCs: 166,779
First Seen: November 25, 2013
Last Seen: October 15, 2023
OS(es) Affected: Windows

Adware.Adpeak is an advertising add-on for Internet Explorer that may be installed as part of the Scorpion Saver program. Since Adware.Adpeak makes changes to your browser, is installed in dubious ways and is unnecessary challenging to remove, malware researchers consider Adware.Adpeak a PUP or Potentially Unwanted Program that should be deleted to keep your Web browser optimized. With Adware.Adpeak's history of unwanted installation combined with a predilection for being installed along with other PUPs, using anti-adware or anti-malware utilities to conduct a thorough system scan should be the preferable way of handling Adware.Adpeak's uninstallation.

Hitting the Peak of Browser Advertising Problem

As an add-on specific to Internet Explorer, one might expect Adware.Adpeak to provide useful features similar to those of extensions and plugins for other browsers, but Adware.Adpeak's actual point is to deliver advertisements to your browser at no benefit to you. Adware.Adpeak may modify Web pages to display these advertisements automatically, occasionally even hosting JavaScript content that is detected as threatening. Whenever you're dealing with a browser lumbering under the weight of Adware.Adpeak's injected content, malware experts would recommend being alert to potential advertising network-based attacks.

Adware.Adpeak may be installed alone, but most cases of Adware.Adpeak installations also have involved the presence of Scorpion Saver, a related browser add-on. Malware experts also have seen other PUPs, adware programs and minor PC threats involved with Adware.Adpeak, including the ividi Toolbar (a browser hijacker for Search.Ividi.org) and a Metacrawler.com hijacker. Not all unwanted programs installed with Adware.Adpeak may show the expected components of a browser add-on, and some may not show any obvious symptoms. Another common factor in most of these cases is the typical presence of general browser error messages that may be caused by triggered security programs or improperly-loaded Adware.Adpeak content.

Climbing Down to Where You Can Control Your Own Web Browser

Since the lofty heights of Adware.Adpeak don't reveal anything more than a horizon full of advertisements and potential JavaScript errors, malware experts wouldn't consider Adware.Adpeak to be a good idea in almost any circumstance one could name. However, Adware.Adpeak does have a high chance of being installed with other PUPs and PC threats that should be uninstalled along with Adware.Adpeak. As the simplest way of addressing these scenarios of multiple unwanted programs, using anti-malware software to scan your entire system is a recommended solution.

Even that much of a solution shouldn't be needed, if you can avoid getting Adware.Adpeak on your PC at all. Adware.Adpeak previously has been seen being installed through fake codec updates, the likes of which often are distributed through unreliable sites and compromised advertisement networks. Updating your software from any source other than an official one always is a potential security issue, and malware experts would never recommend it, regardless of your feelings towards Adware.Adpeak or other advertisement purveyors.

Aliases

AdWare.Win32.Adpeak [Ikarus]Adware:Win32/Adpeak [Microsoft]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Windows\Temp\db444.exe File name: db444.exe
Size: 1.19 MB (1194496 bytes)
MD5: 5b49a6147f6239bf1c6b89440c3be9c2
Detection count: 2,225
File type: Executable File
Mime Type: unknown/exe
Path: C:\Windows\Temp\db444.exe
Group: Malware file
Last Updated: May 13, 2021
C:\WINDOWS\Temp\db29.exe File name: db29.exe
Size: 1.16 MB (1169920 bytes)
MD5: 9414753e3ead922290fcaa45116b6ff5
Detection count: 1,794
File type: Executable File
Mime Type: unknown/exe
Path: C:\WINDOWS\Temp\db29.exe
Group: Malware file
Last Updated: April 16, 2022
C:\WINDOWS\Temp\db444.exe File name: db444.exe
Size: 1.16 MB (1169920 bytes)
MD5: eceb6b00710320745c238060cab64337
Detection count: 1,209
File type: Executable File
Mime Type: unknown/exe
Path: C:\WINDOWS\Temp\db444.exe
Group: Malware file
Last Updated: January 25, 2023
C:\Windows\Temp\db101.exe File name: db101.exe
Size: 1.16 MB (1169920 bytes)
MD5: 5eb56a194e5424d101e662cafce9bb58
Detection count: 923
File type: Executable File
Mime Type: unknown/exe
Path: C:\Windows\Temp\db101.exe
Group: Malware file
Last Updated: January 25, 2023
%WINDIR%\temp\db444.exe File name: db444.exe
Size: 1.16 MB (1169920 bytes)
MD5: 0887744d0ff9e822446fa48e48ac9d47
Detection count: 796
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\temp
Group: Malware file
Last Updated: July 19, 2020
C:\Windows.old\Windows\Temp\db100.exe File name: db100.exe
Size: 1.16 MB (1169920 bytes)
MD5: 795be4bb3fbddc7dad4c426d0e6fe435
Detection count: 689
File type: Executable File
Mime Type: unknown/exe
Path: C:\Windows.old\Windows\Temp\db100.exe
Group: Malware file
Last Updated: July 22, 2021
C:\Windows\Temp\db1.exe File name: db1.exe
Size: 1.16 MB (1169920 bytes)
MD5: 46eae4fe2959ae4d70934587baf5b691
Detection count: 365
File type: Executable File
Mime Type: unknown/exe
Path: C:\Windows\Temp\db1.exe
Group: Malware file
Last Updated: November 20, 2022
C:\Windows\Temp\db27.exe File name: db27.exe
Size: 1.16 MB (1169920 bytes)
MD5: 2f75b6b5fa33f7af9d5eff0d5fcbf430
Detection count: 77
File type: Executable File
Mime Type: unknown/exe
Path: C:\Windows\Temp\db27.exe
Group: Malware file
Last Updated: August 16, 2021
C:\Windows.old\Windows\Temp\db14.exe File name: db14.exe
Size: 1.16 MB (1169920 bytes)
MD5: f4ebe5b12372ab0937fc8ed4d6d0894f
Detection count: 54
File type: Executable File
Mime Type: unknown/exe
Path: C:\Windows.old\Windows\Temp\db14.exe
Group: Malware file
Last Updated: July 22, 2021
%WINDIR%\temp\db5.exe File name: db5.exe
Size: 1.16 MB (1169920 bytes)
MD5: ad3477831fafa2c30723d6896469e4ea
Detection count: 33
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\temp
Group: Malware file
Last Updated: April 2, 2016
%WINDIR%\temp\db63.exe File name: db63.exe
Size: 1.16 MB (1169920 bytes)
MD5: a116cf445f4684310792bec2d62dc20b
Detection count: 33
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\temp
Group: Malware file
Last Updated: April 2, 2016
C:\Users\<username>\AppData\Local\Temp\8lsjIoVW.exe File name: 8lsjIoVW.exe
Size: 1.16 MB (1169920 bytes)
MD5: 836fe7319366bc87fe62b2afe3764378
Detection count: 28
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\8lsjIoVW.exe
Group: Malware file
Last Updated: August 16, 2021
%WINDIR%\temp\db25.exe File name: db25.exe
Size: 1.16 MB (1169920 bytes)
MD5: 4df56c8e447b30121de69a465e2cc0cc
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\temp
Group: Malware file
Last Updated: April 2, 2016
%WINDIR%\temp\db9.exe File name: db9.exe
Size: 1.16 MB (1169920 bytes)
MD5: 25adfdf58e14811e8be446bcbcc2c3ac
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\temp
Group: Malware file
Last Updated: April 2, 2016
%WINDIR%\temp\db11.exe File name: db11.exe
Size: 1.16 MB (1169920 bytes)
MD5: 9506e7ecb60d3939609b9982ee124a2c
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\temp
Group: Malware file
Last Updated: April 2, 2016
%WINDIR%\temp\db20.exe File name: db20.exe
Size: 1.16 MB (1169920 bytes)
MD5: 14ee6202a8d621ab958d73cec694ec15
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\temp
Group: Malware file
Last Updated: April 2, 2016
%WINDIR%\temp\db29.exe File name: db29.exe
Size: 1.16 MB (1169920 bytes)
MD5: d5dfd19d8942abf01490a63b24ba9087
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\temp
Group: Malware file
Last Updated: April 2, 2016
%WINDIR%\temp\db11.exe File name: db11.exe
Size: 1.16 MB (1169920 bytes)
MD5: 65c71fbda77b190fa8ef0d77a6dc05c4
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\temp
Group: Malware file
Last Updated: April 2, 2016
%WINDIR%\temp\db4.exe File name: db4.exe
Size: 1.16 MB (1169920 bytes)
MD5: 22ecc660de6743835dda75b272e10b69
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\temp
Group: Malware file
Last Updated: April 2, 2016
%WINDIR%\temp\db13.exe File name: db13.exe
Size: 1.16 MB (1169920 bytes)
MD5: ddca6f0f958af5036469b620b486f139
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\temp
Group: Malware file
Last Updated: April 2, 2016
%WINDIR%\temp\db24.exe File name: db24.exe
Size: 1.16 MB (1169920 bytes)
MD5: 5041ccc8e59ed2ec073792eea19af5cf
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\temp
Group: Malware file
Last Updated: April 2, 2016
%WINDIR%\temp\db90.exe File name: db90.exe
Size: 1.16 MB (1169920 bytes)
MD5: 5eef89e95d767bc791de1ec25412afa8
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\temp
Group: Malware file
Last Updated: April 2, 2016

More files

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%PROGRAMFILES%\004\rqpbhevlkc64.exe%WinDir%\System32\AdpeakProxy.ini%WinDir%\System32\AdpeakProxy64.dll%WinDir%\System32\AdpeakProxyOff.ini%WinDir%\SysWOW64\AdpeakProxy.dll%WinDir%\SysWOW64\AdpeakProxy.ini%WinDir%\SysWOW64\AdpeakProxyOff.iniHKEY..\..\..\..{RegistryKeys}Software\Adpeak, Inc.SYSTEM\ControlSet001\services\CouponDownloaderService64SYSTEM\ControlSet001\Services\rqpbhevlkc64SYSTEM\ControlSet001\services\vxlsnyaiet64SYSTEM\ControlSet002\services\CouponDownloaderService64SYSTEM\ControlSet002\Services\rqpbhevlkc64SYSTEM\ControlSet002\services\vxlsnyaiet64SYSTEM\CurrentControlSet\services\CouponDownloaderService64SYSTEM\CurrentControlSet\Services\rqpbhevlkc64SYSTEM\CurrentControlSet\services\vxlsnyaiet64

Additional Information

The following directories were created:
%PROGRAMFILES%\SI Service%PROGRAMFILES%\mediainformationaccess%PROGRAMFILES(x86)%\SI Service%PROGRAMFILES(x86)%\mediainformationaccess
Loading...