Multiplug
Threat Scorecard
EnigmaSoft Threat Scorecard
EnigmaSoft Threat Scorecards are assessment reports for different malware threats which have been collected and analyzed by our research team. EnigmaSoft Threat Scorecards evaluate and rank threats using several metrics including real-world and potential risk factors, trends, frequency, prevalence, and persistence. EnigmaSoft Threat Scorecards are updated regularly based on our research data and metrics and are useful for a wide range of computer users, from end users seeking solutions to remove malware from their systems to security experts analyzing threats.
EnigmaSoft Threat Scorecards display a variety of useful information, including:
Ranking: The ranking of a particular threat in EnigmaSoft’s Threat Database.
Severity Level: The determined severity level of an object, represented numerically, based on our risk modeling process and research, as explained in our Threat Assessment Criteria.
Infected Computers: The number of confirmed and suspected cases of a particular threat detected on infected computers as reported by SpyHunter.
See also Threat Assessment Criteria.
Ranking: | 302 |
Threat Level: | 20 % (Normal) |
Infected Computers: | 443,207 |
First Seen: | May 23, 2014 |
Last Seen: | September 21, 2023 |
OS(es) Affected: | Windows |
If your anti-virus software is detecting a Multiplug infection, this may mean that adware has been detected on your computer. These types of infections take the form of an extension or toolbar for your Web browser and are designed to generate revenue from advertising and affiliate marketing on the affected computer. The Multiplug infections are not particularly threatening and can be removed in a simpler manner than with other, more severe types of threats. However, despite that the Multiplug infection is categorized as adware, this does not mean that Multiplug is not severely disruptive. Many of the symptoms associated with Multiplug also may appear in cases of a more harmful threat like the Sirefef rootkit.
Multiplug may make the affected Web browser difficult to use and also may be difficult to remove completely because, if not removed entirely, Multiplug may come back to the affected computer. The Multiplug infections may cause the appearance of pop-up windows and error messages and cause alterations to your computer and Web browser preferences. In most cases, Multiplug also may make it difficult to use the affected Web browser because of its constant interruptions.
Table of Contents
The Advertisements Exhibited by Multiplug May Lead to Unsafe Websites
Symptoms associated with Multiplug may prevent computer users from using the infected computer effectively. The main purpose of Multiplug and similar infections is to profit at the expense of the computer user, mainly using advertisement revenue and affiliate marketing schemes. Because of this, the main purpose of Multiplug infections is to display advertisements on the infected Web browser or to force computer users to visit websites containing advertisements and affiliate marketing links repeatedly. Multiplug also may insert advertisements and links into online content that would normally not have these types of components. Many of these advertisements may be disruptive, and include video or audio content.
Multiplug may add banners, linked text, and similar advertisements to websites viewed on the affected Web browser. Many of the advertisements associated with Multiplug may be difficult to close, appear repeatedly, or open new Web browser windows or tabs when the computer user closes the advertisements. Some of the symptoms of the Multiplug infections that may be noticed easily include browser redirects to websites associated with Multiplug, the appearance of an unwanted toolbar on the infected Web browser, changes to the compromised Web browser's homepage and default search engine, browser redirects to websites associated with Multiplug, and poor system and Web browser's performance and Internet connection speed. Multiplug may change the affected Web browser's homepage and default search engine to websites associated with Multiplug and, in some cases, also may change the affected Web browser's security settings to make it easier for other unwanted components to be installed.
How Multiplug may Enter a Computer
The main way in which Multiplug is distributed is by bundling this adware with legitimate, free software. Shady marketers may hide Multiplug and the option to opt out of installing these types of components. Browser toolbars associated with Multiplug are very common when downloading free software from download websites with poorly regulated content. You can stay away from these types of tactics by paying attention to the installation process when installing new software on your computer. In many cases, computer users may be opted in automatically to begin the installation of Multiplug when installing other software. The option to drop out may be hidden, needing computer users to select 'custom' or 'advanced' installation. The language informing the computer user on how to opt out of installing Multiplug may be convoluted, using double negatives as well as multiple, confusing confirmation messages. This is all deliberate, ensuring that inexperienced computer users allow Multiplug to enter their computers, believing Multiplug to be a legitimate component.
Aliases
15 security vendors flagged this file as malicious.
Anti-Virus Software | Detection |
---|---|
AVG | Generic6.AXCM |
Fortinet | Riskware/MultiPlug |
Ikarus | PUA.Multiplug |
Panda | Generic Suspicious |
AhnLab-V3 | PUP/Win32.MultiPlug |
McAfee-GW-Edition | MultiPlug-FYT |
TrendMicro | TROJ_GEN.R021C0FF915 |
DrWeb | Trojan.Crossrider1.33816 |
F-Secure | Gen:Variant.Adware.Kazy |
Kaspersky | Trojan-Dropper.Win32.Agent.biqise |
ClamAV | Win.Trojan.Agent-880756 |
Avast | Win32:PUP-gen [PUP] |
Symantec | PUA.Gen.2 |
K7AntiVirus | Trojan ( 0040fa761 ) |
CAT-QuickHeal | TrojanDropper.Agent.g6 |
SpyHunter Detects & Remove Multiplug
Multiplug Screenshots
File System Details
# | File Name | MD5 |
Detections
Detections: The number of confirmed and suspected cases of a particular threat detected on
infected computers as reported by SpyHunter.
|
---|---|---|---|
1. | textenhance.dll | 218323b5638fa700b2eaa8d345fa9ecf | 36 |
2. | SystemAssister.dll | 419b9a3aa15b866aafd5ec08847d4a61 | 34 |
3. | textenhance.dll | 6a6ae312c51417690fd77a366dd11da5 | 22 |
4. | TextEnhance_26.0.1773.401.dll | 43eea0c9b47d493fa5cbb7f823f6b14f | 19 |
5. | TextEnhance.dll | 30d21c9739fcf4fb21c26ce396e54b10 | 12 |
6. | RelaySys.dll | d83d29c41d81dae61e6acd07110fada4 | 1 |
7. | textenhance.dll | 74e106dda60346920d51402cc4cb110c | 1 |
8. | WebLightSvc.dll | 064b43b6352cf6b31b56426a370ced15 | 1 |
9. | WebLightSvc.dll | 065e650c0638d298c3bca1d9b96e32ce | 1 |
10. | textenhance.dll | fdf88c80250d92e28287fc2c592cd6fb | 1 |
11. | WebLight_x64.dll | dc5f1558673fa0e166ffb4425d2e6588 | 1 |
12. | WebLight.dll | 48aaf386e8ed2a3ad54232f86d10837e | 1 |
13. | WebLight.dll | 0730e720ea26013a2914bda3f810a63d | 1 |
14. | WebLightSvc.dll | 51ae1f483243b1eaaaa875760852a7ee | 1 |
15. | WebLight.dll | 7f7352b7d3fe5d11f324a9929a160fa0 | 1 |
16. | WebLightSvc.dll | 3c27c5e9459b3a1b87e9649746b39f24 | 1 |
17. | WebLightSvc.dll | 4a853be6e00bc8c052568406bba3d934 | 1 |
18. | WebLightSvc.dll | e3267ce6cb60e8c178ef2b6662d27ecb | 1 |
19. | WebLight_x64.dll | 47a44bf5d37d9861617cebd74c63c6cf | 1 |
20. | WebLightSvc.dll | 3663308f4bdbf3d06dbd6ac2f638b807 | 1 |
21. | WebLight_x64.dll | c4772c50d54ae73eb8532c3d3022a4da | 1 |
22. | WebLight_x64.dll | 7925d228b173303d6988f00e2141e624 | 1 |
23. | WebLightSvc.dll | 225c58a2d9ed59719a7e27d070b0a846 | 1 |
24. | WebLight_x64.dll | 5ce8eb47df6a284281572ff9ef95012e | 1 |
25. | weblight.dll | b5c305c3b2ff2e35d4a270fad0675649 | 1 |
26. | WebLightSvc.dll | 737149b7aad0e1c03e941044323bdd4d | 1 |
27. | WebLightSvc.dll | 85cb067676c2b654a510566905956f43 | 1 |
28. | TextEnhance_6.2.2999.522.dll | 3b2697d63c404ce3eec49de4c4741c0f | 1 |
Registry Details
Directories
Multiplug may create the following directory or directories:
%ALLUSERSPROFILE%\5e6fb5de08469020 |
%ALLUSERSPROFILE%\Accelewin |
%ALLUSERSPROFILE%\Application Data\Accelewin |
%ALLUSERSPROFILE%\Application Data\Browser Enhancer |
%ALLUSERSPROFILE%\Application Data\Browser Stabilizer |
%ALLUSERSPROFILE%\Application Data\Content Accelerator |
%ALLUSERSPROFILE%\Application Data\FastSys |
%ALLUSERSPROFILE%\Application Data\Intelewin filter |
%ALLUSERSPROFILE%\Application Data\InteliWeb |
%ALLUSERSPROFILE%\Application Data\Interenet Optimizer |
%ALLUSERSPROFILE%\Application Data\Performance Optimizer |
%ALLUSERSPROFILE%\Application Data\Speed Streamer |
%ALLUSERSPROFILE%\Application Data\System Booster |
%ALLUSERSPROFILE%\Application Data\TurboNet |
%ALLUSERSPROFILE%\Application Data\WebGeniuos |
%ALLUSERSPROFILE%\Application Data\WebPlat |
%ALLUSERSPROFILE%\Application Data\Win sys filter |
%ALLUSERSPROFILE%\Application Data\WinSpeed |
%ALLUSERSPROFILE%\Application Data\WorldWideWebCoupon |
%ALLUSERSPROFILE%\Browser Enhancer |
%ALLUSERSPROFILE%\Browser Stabilizer |
%ALLUSERSPROFILE%\Codec-C |
%ALLUSERSPROFILE%\CodecC |
%ALLUSERSPROFILE%\Content Accelerator |
%ALLUSERSPROFILE%\Coolyou |
%ALLUSERSPROFILE%\FastSys |
%ALLUSERSPROFILE%\Intelewin filter |
%ALLUSERSPROFILE%\InteliWeb |
%ALLUSERSPROFILE%\Interenet Optimizer |
%ALLUSERSPROFILE%\Network Acceleration |
%ALLUSERSPROFILE%\Performance Optimizer |
%ALLUSERSPROFILE%\Speed Streamer |
%ALLUSERSPROFILE%\Surf Protect |
%ALLUSERSPROFILE%\System Booster |
%ALLUSERSPROFILE%\TurboNet |
%ALLUSERSPROFILE%\Web Light |
%ALLUSERSPROFILE%\WebGeniuos |
%ALLUSERSPROFILE%\WebPlat |
%ALLUSERSPROFILE%\WebTouch |
%ALLUSERSPROFILE%\Win sys filter |
%ALLUSERSPROFILE%\WinSpeed |
%ALLUSERSPROFILE%\WorldWideWebCoupon |
%PROGRAMFILES%\ Mail Checker |
%PROGRAMFILES%\ Similar Pages |
%PROGRAMFILES%\ Translate |
%PROGRAMFILES%\BocaEdit |
%PROGRAMFILES%\BocaFunc |
%PROGRAMFILES%\ChromeReload |
%PROGRAMFILES%\Clip to OneNote |
%PROGRAMFILES%\CutterMaker |
%PROGRAMFILES%\DiscountCouponPro |
%PROGRAMFILES%\Godzilla Shopper |
%PROGRAMFILES%\IncludeMaker |
%PROGRAMFILES%\IncludeRunner |
%PROGRAMFILES%\IndepthEdit |
%PROGRAMFILES%\IndepthRunner |
%PROGRAMFILES%\PragmaEngine |
%PROGRAMFILES%\SoftwareHelp |
%PROGRAMFILES%\TerminusSys |
%PROGRAMFILES%\TotalComicBooks |
%PROGRAMFILES%\TrimModule |
%PROGRAMFILES%\UpgradeLeader |
%PROGRAMFILES%\Weather Aware |
%PROGRAMFILES%\coPuunk |
%PROGRAMFILES%\myselfcoupon |
%PROGRAMFILES%\reactorrise |
%PROGRAMFILES%\toolextender |
%PROGRAMFILES(X86)%\ Mail Checker |
%PROGRAMFILES(X86)%\ Translate |
%PROGRAMFILES(X86)%\TotalComicBooks |
%PROGRAMFILES(x86)%\ Similar Pages |
%PROGRAMFILES(x86)%\BocaEdit |
%PROGRAMFILES(x86)%\BocaFunc |
%PROGRAMFILES(x86)%\ChromeReload |
%PROGRAMFILES(x86)%\Clip to OneNote |
%PROGRAMFILES(x86)%\CutterMaker |
%PROGRAMFILES(x86)%\DiscountCouponPro |
%PROGRAMFILES(x86)%\Godzilla Shopper |
%PROGRAMFILES(x86)%\IncludeMaker |
%PROGRAMFILES(x86)%\IncludeRunner |
%PROGRAMFILES(x86)%\IndepthEdit |
%PROGRAMFILES(x86)%\IndepthRunner |
%PROGRAMFILES(x86)%\PragmaEngine |
%PROGRAMFILES(x86)%\SoftwareHelp |
%PROGRAMFILES(x86)%\TerminusSys |
%PROGRAMFILES(x86)%\TrimModule |
%PROGRAMFILES(x86)%\UpgradeLeader |
%PROGRAMFILES(x86)%\Weather Aware |
%PROGRAMFILES(x86)%\coPuunk |
%PROGRAMFILES(x86)%\myselfcoupon |
%PROGRAMFILES(x86)%\reactorrise |
%PROGRAMFILES(x86)%\toolextender |
%ProgramFiles%\DeltaFix |
%ProgramFiles(x86)%\DeltaFix |
URLs
Multiplug may call the following URLs:
"Azm9CdOLv |
epicunitscan.info |
mynamedomain.koko |
Submit Comment
Please DO NOT use this comment system for support or billing questions. For SpyHunter technical support requests, please contact our technical support team directly by opening a customer support ticket via your SpyHunter. For billing issues, please refer to our "Billing Questions or Problems?" page. For general inquiries (complaints, legal, press, marketing, copyright), visit our "Inquiries and Feedback" page.