PUP.Complitly.A
PUP.Complitly.A is a detection name that EnigmaSoft's SpyHunter and other security products assign to a potentially unwanted program (PUP) belonging to the long-running Complitly adware family. Programs flagged as PUP.Complitly.A present themselves as helpful "search autocomplete" or "search suggestion" browser add-ons, but in practice they inject advertising, harvest browsing data, and degrade the browsing experience across Chrome, Firefox, Edge, and legacy Internet Explorer.
The analyzed sample is a 32-bit Windows executable of roughly 4.64 MB (4,869,336 bytes). It is unsigned, carries high-entropy sections, and exhibits anti-analysis and data-access behavior in the sandbox. This report explains what PUP.Complitly.A is, how it reaches systems, what the real sandbox telemetry shows, how to hunt for it, and how to remove it completely.
Table of Contents
What Is PUP.Complitly.A?
PUP.Complitly.A is the classification for members of the Complitly adware family, a category of "potentially unwanted program" rather than a destructive trojan or ransomware. Complitly first became widely known as a browser plugin (often branded as a "Complitly Helper" or search-completion component) that promised to auto-complete search queries and surface related suggestions. In reality, the add-on monetizes users by intercepting search activity, redirecting queries through affiliate search providers, and displaying additional advertising.
Complitly is publicly documented across mainstream security vendors, which classify it under names such as PUA:Win32/Complitly. It is historically tied to the broader family of monetization toolbars and "search settings" products (the SweetIM / SweetPacks bundling ecosystem is a frequently cited neighbor in this space). The common thread is that the software is technically functional and often installs with nominal consent buried in an installer, which is why it is categorized as "potentially unwanted" — the user rarely wants it, and its real purpose is to benefit its distributors through ad revenue and data collection. Because Complitly is a real, well-established PUP family, this detection is enrichable with attributed public context, while the specific indicators below come only from the analyzed sample.
How It Spreads / Distribution
The dominant distribution method for Complitly-class PUPs is software bundling. The add-on rides along inside the installers of free utilities, media players, download managers, PDF tools, and similar freeware offered on third-party download portals. During installation, the bundled component is frequently pre-selected or hidden behind a "Recommended"/"Express" installation path, so users who click through quickly end up installing the search add-on without realizing it.
Secondary vectors reported for this class of adware include misleading advertisements and fake "update" prompts (for example, prompts to update a media player or browser plugin), and download links seeded on file-sharing and cracked-software sites. Once present, the program is engineered to be sticky: resetting the browser or removing the visible extension alone is often insufficient because a companion Windows component reinstates the behavior.
Technical Analysis & Behavior
The examined sample is a Windows PE executable targeting the x86 (32-bit) architecture. Static traits flagged during analysis include high entropy (consistent with compressed or obfuscated content, even though no named packer was identified), no version information in the file's resources, and the absence of a valid digital signature. A total of 12 PE characteristic flags were recorded for the binary. The lack of version metadata and a code signature is typical of bundled monetization components that are rebuilt and rotated frequently to evade reputation-based blocking.
Dynamic sandbox execution surfaced three behavior categories. First, anti-debugging behavior, indicating the sample checks for analysis or debugging conditions — a hardening technique that also slows manual reverse engineering. Second, user-data access, consistent with the family's well-documented habit of reading browsing-related data and system identifiers. Third, network activity via WinINet, the Windows HTTP/HTTPS API commonly used by browser-integrated software to contact remote servers for configuration, suggestions, or ad content. Notably, in this particular run the sandbox recorded zero registry modifications and zero file modifications, and it did not attribute the sample to any similar-family cluster. That is consistent with a component that defers its persistence and browser-integration steps until later stages, user interaction, or a full installer context that the isolated run did not trigger.
Indicators of Compromise
The following indicators identify the specific analyzed sample of PUP.Complitly.A:
- MD5: cad486fd2cea0dff24017a9214243618
- SHA-1: a4683bb64d900b49382481757ba71c7f9bc9a6cd
- SHA-256: BCDC8A23BD3A03CA4C8A16A42F89CEE81771D6D6FC7737FFD2A59B22CA946C23
- File size: 4,869,336 bytes (~4.64 MB)
- Architecture: x86 (32-bit) Windows PE
- Signature: unsigned (no valid Authenticode signer)
- Notable static traits: high entropy, no version info
Representative-sample disclaimer: these values reflect one analyzed sample. Specific indicators such as hashes, file size, and embedded strings rotate frequently across builds of this PUP family, so hash-based blocking should be combined with behavioral and heuristic detection.
Detection Heuristics
Security engines flag PUP.Complitly.A through a combination of reputation, static, and behavioral signals rather than a single hash. Static heuristics that contribute to a positive verdict include an unsigned x86 PE with missing version information and high section entropy — a profile common to obfuscated, freshly rebuilt bundleware. Behavioral heuristics escalate the score when the process exhibits anti-debugging checks, reads user/browsing data, and initiates outbound WinINet network calls from a component that markets itself as a passive "search helper." Reputation heuristics — low prevalence, no signer, and delivery from bundled installers — push the classification firmly into the potentially-unwanted category. Because the family rebuilds often, generic and machine-learning models keyed on these structural and behavioral traits detect new variants that pure signature matching would miss.
Digital Forensics
When triaging a suspected Complitly infection, investigators should hunt across several artifact classes. On disk, look for a large (multi-megabyte) unsigned x86 executable and any "Complitly," search-helper, or unfamiliar toolbar/add-on directories under user and program-data locations. In the browsers, enumerate installed extensions and add-ons across Chrome, Firefox, Edge, and Internet Explorer, and inspect the configured default search provider, home page, and new-tab settings for unauthorized changes. In process memory, watch for a running helper process making WinINet HTTP/HTTPS connections and performing anti-debug checks.
For persistence and configuration, review the usual autostart locations (Run keys, scheduled tasks, services, and browser-managed policies) even though this particular sandbox run recorded zero registry and zero file modifications — a real-world installation performed through the full bundled installer typically adds browser integration and startup entries that an isolated executable run does not. Because the analyzed sample's registry/file modification counts and behavior categories reflect one run, treat them as a starting point and corroborate with live-host telemetry.
Symptoms of Infection
- New search suggestions, toolbars, or a "search helper" add-on you did not intentionally install.
- Search queries redirected through an unfamiliar search provider or affiliate results.
- Increased advertisements, pop-ups, and in-text ads while browsing.
- Browser slowdowns, stalls, or unexpected redirects.
- Changed default search engine, home page, or new-tab page that reverts after you fix it.
- Browsing habits and basic system identifiers being collected without clear consent.
How to Remove PUP.Complitly.A
1. Run a full system scan with SpyHunter. Because Complitly-class PUPs pair a visible browser add-on with a companion Windows component, an automated full scan is the most reliable way to find and remove every related file. Install or update SpyHunter, run a complete system scan, and quarantine or remove all detected PUP.Complitly.A items, then reboot.
2. Uninstall suspicious programs (Windows). Open Settings > Apps (or Control Panel > Programs and Features), sort by install date, and remove any "Complitly," search-helper, toolbar, or unfamiliar program installed around the time symptoms began.
3. Clean each browser.
- Google Chrome: Menu > Extensions > remove unknown add-ons; Settings > Search engine and On startup > restore your preferred defaults; then Settings > Reset settings > Restore settings to their original defaults.
- Mozilla Firefox: Menu > Add-ons and themes > Extensions > remove unknown items; Settings > Search > restore your default engine; then Help > More troubleshooting information > Refresh Firefox.
- Microsoft Edge: Menu > Extensions > remove unknown add-ons; Settings > Privacy, search, and services and Settings > Start, home, and new tabs > restore defaults; then Settings > Reset settings > Restore settings to their default values.
- Android: Uninstall recently installed or unknown apps from Settings > Apps; in Chrome for Android clear the site settings/notifications for any unfamiliar sites, and if problems persist clear the browser app's cache/data.
4. Manual and Safe Mode cleanup. If the add-on reappears after removal, reboot into Safe Mode with Networking, re-run the SpyHunter full scan, and remove any leftover unsigned executable, scheduled task, or autostart entry associated with the program. Reset the browsers again after the component is gone so hijacked search and startup settings do not restore themselves.
Conclusion
PUP.Complitly.A is a potentially unwanted program from the established Complitly adware family — a "search helper" that trades convenience for advertising injection and browsing-data collection. The analyzed sample is an unsigned, high-entropy 32-bit executable that exhibits anti-debugging, user-data access, and WinINet network behavior. While Complitly is not a destructive threat like ransomware, it undermines privacy, slows browsing, and resists casual removal by pairing a browser add-on with a persistent Windows component. Removing every related file — ideally with a full SpyHunter scan followed by per-browser cleanup and, if needed, Safe Mode — restores your search settings, stops the unwanted advertising, and closes the data-collection channel.
Analysis Report
General information
| Family Name: | PUP.Complitly.A |
|---|---|
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
cad486fd2cea0dff24017a9214243618
SHA1:
a4683bb64d900b49382481757ba71c7f9bc9a6cd
SHA256:
BCDC8A23BD3A03CA4C8A16A42F89CEE81771D6D6FC7737FFD2A59B22CA946C23
File Size:
4.87 MB, 4869336 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have debug information
- File doesn't have exports table
- File doesn't have relocations information
- File doesn't have security information
- File is 32-bit executable
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
- File is not packed
Show More
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Icons
File Icons
This section displays icon resources found within family samples. Malware often replicates icons commonly associated with legitimate software to mislead users into believing the malware is safe.Windows PE Version Information
Windows PE Version Information
This section displays values and attributes that have been set in the Windows file version information data structure for samples within this family. To mislead users, malware actors often add fake version information mimicking legitimate software.| Name | Value |
|---|---|
| File Version | 1.0 |
| Legal Copyright | Copyright © Zwinky |
File Traits
- HighEntropy
- No Version Info
- x86
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 1,536 |
|---|---|
| Potentially Malicious Blocks: | 112 |
| Whitelisted Blocks: | 1,282 |
| Unknown Blocks: | 142 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| Anti Debug |
|
| User Data Access |
|
| Network Wininet |
|