Home Malware Programs Adware Eye Perform

Eye Perform

Posted: October 13, 2014

Threat Metric

Threat Level: 2/10
Infected PCs: 2,841
First Seen: October 13, 2014
Last Seen: July 13, 2023
OS(es) Affected: Windows


Eye Perform Ads is a program with a particularly negative reputation, created by SuperWeb LLC. It serves as adware and tries to improve the web traffic towards some third-party affiliate sites. Although the questionable application is promoted on myeyeperform.com, its distribution strategy relies on the help of other programs. When you perform the installation of different free software products, you may be asked to load Eye Perform as well. The problem is that these adware add-ons are often marked in advance, so they will enter unless you manually uncheck them. If this unreliable tool enters your system, it will cause visible changes in the functionality of Google Chrome, Mozilla Firefox and Internet Explorer. You may be disturbed by frequently appearing pop-ups, banners, hyperlinked words and interstitial ads. They may be displayed on various pages because they are integrated directly into your Internet clients. This commercial content may offer you discounts, gift cards and seemingly cheap products, but very often this strategy is just a trick to make you click on the ads. If you do, you may be redirected to unknown e-commerce platforms, which may try to sell you stuff. Since it is possible for you to be scammed, you should not purchase products from sites you have never heard of. The pop-ups may also lure you into suspicious surveys, which ask you about your e-mail address to start sending you spam. The ads may even pose a security risk as they may lead to compromised pages. Since Eye Perform is not there to help, you should seriously consider deleting it.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Program Files\eye perform\eyeperformuninstall.exe File name: C:\Program Files\eye perform\eyeperformuninstall.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
eyeperformbho.dll File name: eyeperformbho.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
updateeyeperform.exe File name: updateeyeperform.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

CLSID{7768ecae-6b40-4398-bef1-db0a206f0009}HKEY..\..\..\..{RegistryKeys}SOFTWARE\Eye PerformSoftware\Microsoft\Internet Explorer\Approved Extensions\{7768ecae-6b40-4398-bef1-db0a206f0009}SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{7768ecae-6b40-4398-bef1-db0a206f0009}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7768ecae-6b40-4398-bef1-db0a206f0009}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7768ecae-6b40-4398-bef1-db0a206f0009}SOFTWARE\Wow6432Node\Eye PerformSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{7768ecae-6b40-4398-bef1-db0a206f0009}SYSTEM\ControlSet001\services\eventlog\Application\Update Eye PerformSYSTEM\ControlSet001\services\eventlog\Application\Util Eye PerformSYSTEM\ControlSet001\services\Update Eye PerformSYSTEM\ControlSet001\services\Util Eye PerformSYSTEM\CurrentControlSet\services\eventlog\Application\Update Eye PerformSYSTEM\CurrentControlSet\services\eventlog\Application\Util Eye PerformSYSTEM\CurrentControlSet\services\Update Eye PerformSYSTEM\CurrentControlSet\services\Util Eye PerformHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Eye Perform

Additional Information

The following directories were created:
%PROGRAMFILES%\Eye Perform%PROGRAMFILES(x86)%\Eye Perform%Temp%\Eye Perform
The following URL's were detected:
myeyeperform.com/support
Loading...