Threat Database Adware Adware.Multiplug.G

Adware.Multiplug.G

By CagedTech in Adware

Threat Scorecard

Popularity Rank: 15,564
Threat Level: 20 % (Normal)
Infected Computers: 791
First Seen: January 19, 2011
Last Seen: May 26, 2026
OS(es) Affected: Windows

The detection of Adware.Multiplug.G on your system indicates the presence of a potentially unwanted program that may be causing unwanted advertisements and potentially collecting your personal data. It is essential to understand the nature of this threat and take immediate action to remove it and protect your system and personal information.

What Is Adware.Multiplug.G?

Adware.Multiplug.G is a type of adware that is designed to display unwanted advertisements on your system, often in the form of pop-ups, banners, or sponsored content. The primary goal of adware is to generate revenue for its creators by displaying advertisements and collecting user data. Adware can be installed on your system through various means, including freeware or shareware downloads, infected software bundles, or exploits in vulnerable applications.

How Adware.Multiplug.G Operates

Once installed, Adware.Multiplug.G can operate in various ways to achieve its goals. It may monitor your browsing habits, collect your personal data, and use this information to display targeted advertisements. Adware can also modify your system settings, such as changing your default homepage or search engine, to further increase its revenue. In some cases, adware can also download and install additional malware or unwanted programs on your system, leading to further complications and security risks.

Symptoms of Infection

The symptoms of Adware.Multiplug.G infection can vary, but common indicators include an increase in unwanted advertisements, slow system performance, and unexpected changes to your system settings. You may also notice that your browser is being redirected to unwanted websites or that your search results are being hijacked. In some cases, adware can also cause system crashes, freezes, or errors, making it essential to remove the infection as soon as possible.

  • Unwanted advertisements, including pop-ups, banners, and sponsored content
  • Slow system performance and responsiveness
  • Unexpected changes to system settings, such as default homepage or search engine
  • Browser redirects and hijacked search results
  • System crashes, freezes, or errors

How to Remove Adware.Multiplug.G

  1. Boot your system in Safe Mode with Networking to prevent the adware from loading and to allow for a more effective removal process
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all instances of Adware.Multiplug.G
  3. Uninstall any suspicious programs or applications that may be related to the adware infection
  4. Reset your browser settings, including Chrome, Firefox, and Edge, to their default values to remove any unwanted changes
  5. Reboot your system and perform a follow-up scan to ensure that the adware has been completely removed

Conclusion

Removing Adware.Multiplug.G from your system requires a combination of technical knowledge and the right tools. By following the steps outlined above and using a reputable anti-malware tool, you can effectively remove the infection and protect your system and personal data. It is essential to remain vigilant and take proactive measures to prevent future infections, such as keeping your operating system and software up-to-date, avoiding suspicious downloads, and using strong antivirus software. By taking these steps, you can help ensure the security and integrity of your system and prevent the risks associated with adware and other types of malware.

Analysis Report

General information

Family Name: Adware.Multiplug.G
Signature status: No Signature

Known Samples

MD5: 497a4dd86c9ac22ad3b6c04a7fd9bdba
SHA1: eb6dee57dc78d7eaf4846635ea3262724d474758
SHA256: 84F0F28AD0113D2595F6441B5BBDFC7224E5139428D39107592519E25C539380
File Size: 970.75 KB, 970752 bytes
MD5: 09b272010194da5a1c27987b992dd6c5
SHA1: d378730d4c81f1d95565ed347fdb8a3c62d05744
SHA256: 9CA3D682FD5D28A5A3AC56D03603FBC7DFD93ACA1234B6B7ACC240D10A9A6818
File Size: 2.46 MB, 2464768 bytes
MD5: 422ea28e187b13d2b761b9dad8e91862
SHA1: e6c60154494c556450399b0f49911805170d7395
SHA256: 2F7865F5848904EE68FF8550F886E71C1C90DF9B8F58CA859FD3FA52288E3431
File Size: 1.66 MB, 1659904 bytes
MD5: b279dfbf0ff27885cb6acc094cc76296
SHA1: eaec95d71f383dc3543b683bac1d2bef77c26a9c
SHA256: 01D3C9C57A2E318C05D5979A2AE4509DC9A114369B7066ADC88CB1E4C9BE203E
File Size: 916.48 KB, 916480 bytes
MD5: de6f9d4959fd2b95154a5f2e0904524c
SHA1: 8c440e8bd6026c260856383ab50006d0831ecda3
SHA256: E29022A4E8DC56EA1264ABC798F65360A3BF10C27581651FB073E8184CEDF17F
File Size: 833.54 KB, 833536 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have resources
  • File doesn't have security information
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • dll
  • HighEntropy
  • No Version Info
  • x86

Block Information

Total Blocks: 3,743
Potentially Malicious Blocks: 1,966
Whitelisted Blocks: 1,527
Unknown Blocks: 250

Visual Map

x x x x x x x x x x x x x x x x ? 0 x x x x ? ? x 0 0 x x x 0 x x 0 x 0 0 x 0 x x 0 0 0 0 0 x x ? x x x x x x ? x x 0 0 0 x x 0 ? x x 0 0 x x x x x x x x x x 0 x 0 x x x 0 0 x x x 0 0 x 0 x 0 x x x x 0 ? x x 0 ? 0 x 0 0 x 0 x x 0 0 x x 0 x x 0 x x x x x 0 x 0 0 0 0 x 0 0 0 x x x x 0 x 0 x 0 x x x 0 x x x x 0 x x x x x 0 ? x x x 0 x x x 0 x 0 x 0 x x 0 x x x x 0 0 1 1 x 0 x x x x x x x x 0 x x 0 0 x 0 x x 0 x x 0 x x x x x 0 x 0 x x x 0 x 0 ? x x x x x 0 x x x 0 x x x x ? x 0 x 0 ? x x 0 0 0 ? 0 0 x 0 x 0 x x x x x x 0 x 0 x x x x x x 0 0 x ? x x 0 x 0 x x x x 0 x 0 0 x x x 0 x x x 0 x x 0 x 0 x x 0 0 0 x 0 x 0 x x x ? 0 x x 0 x 0 0 x 0 x x 0 x x x 0 x x 0 x x x 0 0 ? x x 0 x x 0 ? ? 0 0 ? 0 x 0 ? ? x 0 0 x x x 0 0 x x 0 x 0 x 0 0 x x x 0 x 0 x x x x 0 x 0 0 0 0 x 0 ? 0 ? x x x x x ? ? x ? x x ? ? ? ? 0 0 0 ? 0 x 0 0 x x 0 0 x x 0 x x x x 0 0 0 x x x 0 x x 0 x x 0 x 0 x 0 x x x x x 0 x x x x x x 0 x 0 x x 0 x ? 0 0 0 x 0 x ? 0 0 0 x 0 x 0 0 x x x x x x x 0 0 0 x 0 x 0 x 0 ? x 0 0 x 0 0 x x x x x x x x x 0 x ? 0 x 0 0 0 x 0 0 0 x x x x x x x x 0 0 x x x x x 0 x 0 x x x x x x x x x x 0 x 0 x 0 x x x x x x x x x x 0 0 0 0 2 0 0 0 1 0 0 1 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 2 3 0 0 0 0 0 1 0 0 1 0 1 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 2 2 1 0 0 0 0 0 1 0 0 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 3 1 1 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 x x x x ? 0 x x x 0 x x x 0 0 x x x x x x x x x x x x x x x x 0 0 x 0 0 x x x x x 0 ? x x x x ? 0 ? x x x 0 x x 0 x x 0 x x 0 x x x 0 0 0 0 x 0 0 ? x x x x x 0 0 x x x 0 x x x x 0 x 0 x x x x x x 0 x x 0 x x x x x 0 x x 0 x 0 x 0 x x x x x x 0 0 x 0 0 0 x x 0 0 x x 0 x x x x x x 0 x ? x x x x x x ? x x x x x x 0 0 x 0 x x 0 0 0 0 0 0 x x x 0 ? x 0 ? x 0 x x x ? ? x x x x x x x x 0 x x x ? x x x x x x x x x x x ? 0 0 x x 0 0 0 0 0 x 0 x 0 0 0 1 1 0 1 x x x x 0 x x 0 ? x x 0 x x 0 x x x 0 x x 0 x 0 0 0 x 0 0 0 x x 0 0 0 0 x x x 0 x x x ? 0 x 0 x ? x x ? x ? ? x x x ? x ? 0 ? 0 0 x 0 ? x 0 ? 0 ? 0 x 0 ? 0 0 0 0 0 x ? 0 0 0 0 0 ? 0 0 0 0 ? ? ? ? 0 x 0 x 0 x x x 0 x x x x ? x 0 x x x x 0 x x x x 0 x x 0 0 ? x x x x x 0 x 0 x 0 x 0 x x 0 x x x 0 ? 0 x 0 x x x x 0 x x x 0 0 0 x 0 x x 0 x ? x x x 0 ? x 0 0 ? 0 0 x 0 x 0 ? x ? x x ? 0 x x 0 0 x 0 x x ? x x x ? x x x 0 0 x x x x x x ? x 0 x x x x x 0 0 x 0 x x x 0 0 x x x 0 x 0 0 x x x 0 0 0 x x x x x 0 x x x x 0 0 x x x x x x 0 x x x x x x x ? x 0 0 x 0 x 0 0 x x x x ? x x 0 x x x x 0 0 x x x x x x x x x x x x x x x x x x x 0 x x x x x 0 0 x x x x x 0 x 0 0 0 x x x x 0 0 x x 0 x x ? 0 x 0 x x x 0 x 0 x x 0 0 x x 0 x 0 ? x 0 x x x x x x x x x x 0 x 0 x x x 0 0 ? x ? ? 0 x x 0 ? 0 x x 0 x ? x 0 x x x ? ? ? x x x x x x x x x x 0 x x x x 0 x x x x x 0 x 0 x x x x 0 0 x 0 x 0 0 x x x x 0 0 x 0 x x x x ? x x 0 x x 0 x x x x 0 x x x x 0 x x x x x 0 0 ? x x x 0 0 x x 0 0 0 x x x x x 0 x 1 x 0 x x 0 0 0 x 0 0 x 0 x x x 0 x x x x x x x 0 0 0 0 x x x x x x x x x x x x x 0 x 0 x x x 0 x 0 0 0 x x x x x 0 0 x 0 x 0 x x x x x x x x x ? 0 x 0 x 0 x 0 x x x x x 0 x x 0 0 x 0 0 x 0 ? 0 0 x 0 0 x x 0 x x 0 x x 0 x x x x 0 0 x x 0 x x x x x x x x x 0 0 x 0 x x x x x x 0 x x 0 0 0 x x x x x 0 x x x x x x x x x x x x ? ? x 0 x 0 0 0 x x 0 0 x x x 0 0 x 0 x x 0 x x x 0 0 x x x x x x x 0 x 0 0 x x x 0 x x 0 ? x x x x 0 ? 0 0 x 0 x 0 0 x x 0 x x 0 0 0 x x x 0 0 x x x 0 0 x ? 0 x 0 ? 0 0 x 0 0 ? ? ? x x x 0 0 x x x x x x x x 0 0 x x 0 x 0 x x x x x 0 x x 0 x 0 x 0 x 0 x x x 0 0 x x x 0 0 x x x 0 0 x x x x x 0 x 0 x
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Multiplug.G
  • Multiplug.GA

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.1.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.2.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtProtectVirtualMemory
Show More
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\eb6dee57dc78d7eaf4846635ea3262724d474758_0000970752.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\e6c60154494c556450399b0f49911805170d7395_0001659904.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\eaec95d71f383dc3543b683bac1d2bef77c26a9c_0000916480.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\8c440e8bd6026c260856383ab50006d0831ecda3_0000833536.,LiQMAxHB

Related Posts

Trending

Most Viewed

Loading...