Home Malware Programs Adware Adware.melondrea

Adware.melondrea

Posted: May 29, 2014

Threat Metric

Ranking: 16,420
Threat Level: 2/10
Infected PCs: 9,235
First Seen: May 29, 2014
Last Seen: January 15, 2025
OS(es) Affected: Windows


Adware.Melondrea is adware that, after installation on a computer system, may embed a browser extension, plug-in or add-on into major Web browsers such as Google Chrome, Internet Explorer, and Mozilla Firefox. Adware.Melondrea may produce and show disturbing pop-up ads with the text 'Melondrea Ads' or 'Powered by Melondrea' and messages on the PC. The Adware.Melondrea pop-up advertisements including deals, offers, and discount coupons may emerge on the computer if Adware.Melondrea finds out that the PC user is surfing online shopping websites. Therefore, some PC users may think that advertisements of Adware.Melondrea are components of the website they visit. If the PC user clicks on any of the pop-up advertisements and messages sent by Adware.Melondrea, he may get repeatedly diverted to sponsored websites. The main goal of Adware.Melondrea may be gain benefit from raised web traffic of the sponsored website and clicks on intrusive advertisements.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES%\melondrea\updatemelondrea.exe File name: updatemelondrea.exe
Size: 348.44 KB (348448 bytes)
MD5: dbb62e22ba16b23b9cd1b8149dfedb0b
Detection count: 60
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\melondrea
Group: Malware file
Last Updated: May 29, 2014
%PROGRAMFILES%\melondrea\bin\melondrea.PurBrowse.exe File name: melondrea.PurBrowse.exe
Size: 239.39 KB (239392 bytes)
MD5: 9a92ff7dcc99e1f582e33541163e4420
Detection count: 42
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\melondrea\bin
Group: Malware file
Last Updated: May 29, 2014
%PROGRAMFILES%\melondrea\bin\utilmelondrea.exe File name: utilmelondrea.exe
Size: 317.72 KB (317728 bytes)
MD5: ab4993f52a5aa92b0a0a7c9ec40848f4
Detection count: 25
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\melondrea\bin
Group: Malware file
Last Updated: May 29, 2014
%TEMP%\melondrea\melondrea_Setup.exe File name: melondrea_Setup.exe
Size: 2.15 MB (2158088 bytes)
MD5: 04ad7aee770451d8642d1c9f724075e1
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\melondrea
Group: Malware file
Last Updated: May 29, 2014
%PROGRAMFILES%\melondrea\melondreabho.dll File name: melondreabho.dll
Size: 249.63 KB (249632 bytes)
MD5: 9c153621e8d652439e7f0a296fb785fe
Detection count: 5
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\melondrea
Group: Malware file
Last Updated: May 29, 2014
%PROGRAMFILES(x86)%\melondrea\melondreauninstall.exe File name: melondreauninstall.exe
Size: 240.03 KB (240031 bytes)
MD5: 56540b3fc93e99441d41034e651b84a2
Detection count: 1
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\melondrea
Group: Malware file
Last Updated: May 29, 2014

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{844daaf4-d158-49f0-a3c4-d6a343a0b8c0}HKEY..\..\..\..{RegistryKeys}SOFTWARE\melondreaSoftware\Microsoft\Internet Explorer\Approved Extensions\{844daaf4-d158-49f0-a3c4-d6a343a0b8c0}SOFTWARE\Microsoft\Tracing\melondrea_RASAPI32SOFTWARE\Microsoft\Tracing\melondrea_RASMANCSSOFTWARE\Microsoft\Tracing\updatemelondrea_RASAPI32SOFTWARE\Microsoft\Tracing\updatemelondrea_RASMANCSSOFTWARE\Microsoft\Tracing\utilmelondrea_RASAPI32SOFTWARE\Microsoft\Tracing\utilmelondrea_RASMANCSSoftware\Microsoft\Windows\CurrentVersion\Ext\Settings\{844daaf4-d158-49f0-a3c4-d6a343a0b8c0}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{844daaf4-d158-49f0-a3c4-d6a343a0b8c0}SOFTWARE\Wow6432Node\melondreaSOFTWARE\Wow6432Node\Microsoft\Tracing\melondrea_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\melondrea_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\updatemelondrea_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\updatemelondrea_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\utilmelondrea_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\utilmelondrea_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{844daaf4-d158-49f0-a3c4-d6a343a0b8c0}SYSTEM\ControlSet001\services\eventlog\Application\Update melondreaSYSTEM\ControlSet001\services\eventlog\Application\Util melondreaSYSTEM\ControlSet001\services\Update melondreaSYSTEM\ControlSet001\services\Util melondreaSYSTEM\ControlSet002\services\eventlog\Application\Util melondreaSYSTEM\ControlSet002\services\Util melondreaSYSTEM\CurrentControlSet\services\eventlog\Application\Update melondreaSYSTEM\CurrentControlSet\services\eventlog\Application\Util melondreaSYSTEM\CurrentControlSet\services\Update melondreaSYSTEM\CurrentControlSet\services\Util melondreaHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}melondrea

Additional Information

The following directories were created:
%PROGRAMFILES%\melondrea%PROGRAMFILES(x86)%\melondrea%TEMP%\melondrea
The following URL's were detected:
melondrea
Loading...