PUP.Complitly.A

PUP.Complitly.A is a detection name that EnigmaSoft's SpyHunter and other security products assign to a potentially unwanted program (PUP) belonging to the long-running Complitly adware family. Programs flagged as PUP.Complitly.A present themselves as helpful "search autocomplete" or "search suggestion" browser add-ons, but in practice they inject advertising, harvest browsing data, and degrade the browsing experience across Chrome, Firefox, Edge, and legacy Internet Explorer.

The analyzed sample is a 32-bit Windows executable of roughly 4.64 MB (4,869,336 bytes). It is unsigned, carries high-entropy sections, and exhibits anti-analysis and data-access behavior in the sandbox. This report explains what PUP.Complitly.A is, how it reaches systems, what the real sandbox telemetry shows, how to hunt for it, and how to remove it completely.

What Is PUP.Complitly.A?

PUP.Complitly.A is the classification for members of the Complitly adware family, a category of "potentially unwanted program" rather than a destructive trojan or ransomware. Complitly first became widely known as a browser plugin (often branded as a "Complitly Helper" or search-completion component) that promised to auto-complete search queries and surface related suggestions. In reality, the add-on monetizes users by intercepting search activity, redirecting queries through affiliate search providers, and displaying additional advertising.

Complitly is publicly documented across mainstream security vendors, which classify it under names such as PUA:Win32/Complitly. It is historically tied to the broader family of monetization toolbars and "search settings" products (the SweetIM / SweetPacks bundling ecosystem is a frequently cited neighbor in this space). The common thread is that the software is technically functional and often installs with nominal consent buried in an installer, which is why it is categorized as "potentially unwanted" — the user rarely wants it, and its real purpose is to benefit its distributors through ad revenue and data collection. Because Complitly is a real, well-established PUP family, this detection is enrichable with attributed public context, while the specific indicators below come only from the analyzed sample.

How It Spreads / Distribution

The dominant distribution method for Complitly-class PUPs is software bundling. The add-on rides along inside the installers of free utilities, media players, download managers, PDF tools, and similar freeware offered on third-party download portals. During installation, the bundled component is frequently pre-selected or hidden behind a "Recommended"/"Express" installation path, so users who click through quickly end up installing the search add-on without realizing it.

Secondary vectors reported for this class of adware include misleading advertisements and fake "update" prompts (for example, prompts to update a media player or browser plugin), and download links seeded on file-sharing and cracked-software sites. Once present, the program is engineered to be sticky: resetting the browser or removing the visible extension alone is often insufficient because a companion Windows component reinstates the behavior.

Technical Analysis & Behavior

The examined sample is a Windows PE executable targeting the x86 (32-bit) architecture. Static traits flagged during analysis include high entropy (consistent with compressed or obfuscated content, even though no named packer was identified), no version information in the file's resources, and the absence of a valid digital signature. A total of 12 PE characteristic flags were recorded for the binary. The lack of version metadata and a code signature is typical of bundled monetization components that are rebuilt and rotated frequently to evade reputation-based blocking.

Dynamic sandbox execution surfaced three behavior categories. First, anti-debugging behavior, indicating the sample checks for analysis or debugging conditions — a hardening technique that also slows manual reverse engineering. Second, user-data access, consistent with the family's well-documented habit of reading browsing-related data and system identifiers. Third, network activity via WinINet, the Windows HTTP/HTTPS API commonly used by browser-integrated software to contact remote servers for configuration, suggestions, or ad content. Notably, in this particular run the sandbox recorded zero registry modifications and zero file modifications, and it did not attribute the sample to any similar-family cluster. That is consistent with a component that defers its persistence and browser-integration steps until later stages, user interaction, or a full installer context that the isolated run did not trigger.

Indicators of Compromise

The following indicators identify the specific analyzed sample of PUP.Complitly.A:

  • MD5: cad486fd2cea0dff24017a9214243618
  • SHA-1: a4683bb64d900b49382481757ba71c7f9bc9a6cd
  • SHA-256: BCDC8A23BD3A03CA4C8A16A42F89CEE81771D6D6FC7737FFD2A59B22CA946C23
  • File size: 4,869,336 bytes (~4.64 MB)
  • Architecture: x86 (32-bit) Windows PE
  • Signature: unsigned (no valid Authenticode signer)
  • Notable static traits: high entropy, no version info

Representative-sample disclaimer: these values reflect one analyzed sample. Specific indicators such as hashes, file size, and embedded strings rotate frequently across builds of this PUP family, so hash-based blocking should be combined with behavioral and heuristic detection.

Detection Heuristics

Security engines flag PUP.Complitly.A through a combination of reputation, static, and behavioral signals rather than a single hash. Static heuristics that contribute to a positive verdict include an unsigned x86 PE with missing version information and high section entropy — a profile common to obfuscated, freshly rebuilt bundleware. Behavioral heuristics escalate the score when the process exhibits anti-debugging checks, reads user/browsing data, and initiates outbound WinINet network calls from a component that markets itself as a passive "search helper." Reputation heuristics — low prevalence, no signer, and delivery from bundled installers — push the classification firmly into the potentially-unwanted category. Because the family rebuilds often, generic and machine-learning models keyed on these structural and behavioral traits detect new variants that pure signature matching would miss.

Digital Forensics

When triaging a suspected Complitly infection, investigators should hunt across several artifact classes. On disk, look for a large (multi-megabyte) unsigned x86 executable and any "Complitly," search-helper, or unfamiliar toolbar/add-on directories under user and program-data locations. In the browsers, enumerate installed extensions and add-ons across Chrome, Firefox, Edge, and Internet Explorer, and inspect the configured default search provider, home page, and new-tab settings for unauthorized changes. In process memory, watch for a running helper process making WinINet HTTP/HTTPS connections and performing anti-debug checks.

For persistence and configuration, review the usual autostart locations (Run keys, scheduled tasks, services, and browser-managed policies) even though this particular sandbox run recorded zero registry and zero file modifications — a real-world installation performed through the full bundled installer typically adds browser integration and startup entries that an isolated executable run does not. Because the analyzed sample's registry/file modification counts and behavior categories reflect one run, treat them as a starting point and corroborate with live-host telemetry.

Symptoms of Infection

  • New search suggestions, toolbars, or a "search helper" add-on you did not intentionally install.
  • Search queries redirected through an unfamiliar search provider or affiliate results.
  • Increased advertisements, pop-ups, and in-text ads while browsing.
  • Browser slowdowns, stalls, or unexpected redirects.
  • Changed default search engine, home page, or new-tab page that reverts after you fix it.
  • Browsing habits and basic system identifiers being collected without clear consent.

How to Remove PUP.Complitly.A

1. Run a full system scan with SpyHunter. Because Complitly-class PUPs pair a visible browser add-on with a companion Windows component, an automated full scan is the most reliable way to find and remove every related file. Install or update SpyHunter, run a complete system scan, and quarantine or remove all detected PUP.Complitly.A items, then reboot.

2. Uninstall suspicious programs (Windows). Open Settings > Apps (or Control Panel > Programs and Features), sort by install date, and remove any "Complitly," search-helper, toolbar, or unfamiliar program installed around the time symptoms began.

3. Clean each browser.

  • Google Chrome: Menu > Extensions > remove unknown add-ons; Settings > Search engine and On startup > restore your preferred defaults; then Settings > Reset settings > Restore settings to their original defaults.
  • Mozilla Firefox: Menu > Add-ons and themes > Extensions > remove unknown items; Settings > Search > restore your default engine; then Help > More troubleshooting information > Refresh Firefox.
  • Microsoft Edge: Menu > Extensions > remove unknown add-ons; Settings > Privacy, search, and services and Settings > Start, home, and new tabs > restore defaults; then Settings > Reset settings > Restore settings to their default values.
  • Android: Uninstall recently installed or unknown apps from Settings > Apps; in Chrome for Android clear the site settings/notifications for any unfamiliar sites, and if problems persist clear the browser app's cache/data.

4. Manual and Safe Mode cleanup. If the add-on reappears after removal, reboot into Safe Mode with Networking, re-run the SpyHunter full scan, and remove any leftover unsigned executable, scheduled task, or autostart entry associated with the program. Reset the browsers again after the component is gone so hijacked search and startup settings do not restore themselves.

Conclusion

PUP.Complitly.A is a potentially unwanted program from the established Complitly adware family — a "search helper" that trades convenience for advertising injection and browsing-data collection. The analyzed sample is an unsigned, high-entropy 32-bit executable that exhibits anti-debugging, user-data access, and WinINet network behavior. While Complitly is not a destructive threat like ransomware, it undermines privacy, slows browsing, and resists casual removal by pairing a browser add-on with a persistent Windows component. Removing every related file — ideally with a full SpyHunter scan followed by per-browser cleanup and, if needed, Safe Mode — restores your search settings, stops the unwanted advertising, and closes the data-collection channel.

Analysis Report

General information

Family Name: PUP.Complitly.A
Signature status: No Signature

Known Samples

MD5: cad486fd2cea0dff24017a9214243618
SHA1: a4683bb64d900b49382481757ba71c7f9bc9a6cd
SHA256: BCDC8A23BD3A03CA4C8A16A42F89CEE81771D6D6FC7737FFD2A59B22CA946C23
File Size: 4.87 MB, 4869336 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
File Version 1.0
Legal Copyright Copyright © Zwinky

File Traits

  • HighEntropy
  • No Version Info
  • x86

Block Information

Total Blocks: 1,536
Potentially Malicious Blocks: 112
Whitelisted Blocks: 1,282
Unknown Blocks: 142

Visual Map

? 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 x 0 0 0 x 0 x 0 0 ? ? x 0 0 x 0 0 0 0 0 0 0 ? ? 0 0 0 0 x 0 0 0 x 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x ? 0 x 0 x 0 0 ? 0 x 0 ? ? 0 0 0 ? ? ? x 0 x 0 x x 0 0 0 0 0 0 ? x x x ? 0 x x ? x 0 0 0 0 0 0 0 0 ? x ? ? 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 x ? 0 ? 0 0 0 0 0 0 0 x 0 x 0 ? 0 0 0 0 0 0 0 0 0 x 0 0 x x 0 ? ? x x 0 0 0 0 0 0 0 0 ? ? ? 0 0 x 0 x 0 0 0 x x 0 x x x x x ? x x x x x 0 0 0 0 0 ? ? 0 0 0 0 0 0 x ? 0 0 0 0 0 0 0 x x x x 0 0 ? 0 0 x x 0 0 0 0 0 0 0 0 x ? ? ? ? x x x x x x x 0 ? ? x x x x x x ? 0 0 x x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x ? 0 0 0 0 0 ? 0 0 0 0 0 x 0 0 0 0 x x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 ? 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 ? ? ? 0 ? 0 0 ? ? ? 0 0 ? ? ? ? ? ? ? ? ? 0 x ? ? ? ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? ? 0 0 0 ? ? 0 0 ? ? 0 ? 0 ? ? 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x 0 0 ? ? 0 ? 0 0 ? 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x 0 0 ? 0 ? ? ? 0 ? ? ? 0 x x x 0 0 x x 0 x x 0 ? ? ? 0 ? ? ? 0 0 ? ? 0 0 0 0 0 0 ? 0 ? 0 0 ? 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 ? ? 0 0 0 0 0 ? ? ? ? 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? 0 0 0 0 x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 ? x x 0 0 x 0 0 ? 0 0 ? 0 0 x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 0 0 0 1 0 0 0 0 1 0 0 0 0 0 1 0 0 1 1 0 1 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 1 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 2 2 2 3 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 0 0 1 0 0 1 0 0 1 0 0 0 0 1 0 0 0 0 1 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Network Wininet
  • InternetOpen
  • InternetOpenUrl
  • InternetQueryOption
  • InternetSetOption

Related Posts

Trending

Most Viewed

Loading...