Threat Database Adware Adware.Multiplug.GB

Adware.Multiplug.GB

By CagedTech in Adware

Threat Scorecard

Threat Level: 20 % (Normal)
Infected Computers: 193
First Seen: January 19, 2011
Last Seen: February 10, 2026
OS(es) Affected: Windows

The detection of Adware.Multiplug.GB on your system indicates the presence of a potentially unwanted program that may be causing disruptions to your online experience. This type of software is designed to display unwanted advertisements, collect user data, and potentially lead to more severe security issues if left unchecked. It's essential to understand the nature of this threat and take immediate action to remove it from your system.

What Is Adware.Multiplug.GB?

Adware.Multiplug.GB is a type of adware program that is designed to generate revenue for its creators by displaying unwanted advertisements, often in the form of pop-ups, banners, or sponsored content. This software may have been installed on your system without your knowledge or consent, often through bundled downloads or exploited vulnerabilities. Adware programs like Adware.Multiplug.GB can be particularly problematic, as they may also collect user data, such as browsing history and personal information, which can be used for targeted advertising or sold to third-party companies.

How Adware.Multiplug.GB Operates

Adware.Multiplug.GB operates by infiltrating your system and integrating itself into your web browser or operating system. Once installed, it begins to display unwanted advertisements, which can be intrusive and disrupt your online activities. This software may also communicate with its creators or other servers to receive updates, report user data, or download additional malware. In some cases, adware programs like Adware.Multiplug.GB may also attempt to redirect your browser to suspicious websites or prompt you to download fake software updates or antivirus programs.

Symptoms of Infection

If your system is infected with Adware.Multiplug.GB, you may notice a range of symptoms, including an increase in unwanted advertisements, slow system performance, and suspicious browser behavior. You may also notice that your browser homepage or search engine has been changed without your consent, or that you are being redirected to suspicious websites. In some cases, you may also experience system crashes, freezes, or error messages, which can be indicative of a more severe infection.

  • Unwanted advertisements, such as pop-ups, banners, or sponsored content
  • Slow system performance or browser crashes
  • Suspicious browser behavior, such as redirects or changed homepage
  • System freezes or error messages
  • Unexplained changes to system settings or configuration

How to Remove Adware.Multiplug.GB

  1. Boot your system in Safe Mode with Networking to prevent the adware from loading
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all instances of Adware.Multiplug.GB
  3. Uninstall any suspicious programs or software that may be related to the adware infection
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons
  5. Reboot your system and perform a follow-up scan to ensure that all remnants of the adware have been removed

Conclusion

Removing Adware.Multiplug.GB from your system requires a combination of technical expertise and caution. By following the steps outlined above and using reputable anti-malware tools, you can effectively remove this unwanted program and restore your system to a safe and secure state. It's essential to remain vigilant and proactive in protecting your system from future infections by keeping your software up-to-date, avoiding suspicious downloads, and using robust security software to detect and prevent malware threats.

Analysis Report

General information

Family Name: Adware.Multiplug.GB
Signature status: Root Not Trusted

Known Samples

MD5: 49eaf418d6cf8ae5c59e436c434deeea
SHA1: 200488b4894536210d0f81d80daad98c298dd84b
SHA256: CE2E87EC64E528E17A2150D37FF46A8522C592408948A1862FADED20EDE25C37
File Size: 6.85 MB, 6851744 bytes
MD5: 6aaf3d3caeae3c32518ed171cde210a2
SHA1: 59312a5de510a59c70c0e277a4d1907b1ccccc2c
SHA256: 371BCA042DFD52A7D53E78F1761F8F29BDD550AE68379D1E305F931EFA4022B0
File Size: 9.24 MB, 9240592 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Super PC Tools Ltd
File Description
  • Fix PC problems and optimize performance
File Version
  • 3.2.0.0
Internal Name
  • Super Optimizer
Legal Copyright
  • Super PC Tools Ltd
Original Filename Super Optimizer
Product Name
  • Super Optimizer
  • Super Optimizer v3.2
Product Version
  • 3.2.0.0
  • 3.2

Digital Signatures

Signer Root Status
Super PC Tools Limited AddTrust External CA Root Root Not Trusted

File Traits

  • 2+ executable sections
  • dll
  • HighEntropy
  • x86

Block Information

Total Blocks: 2,970
Potentially Malicious Blocks: 20
Whitelisted Blocks: 2,950
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Gamehack.BSB
  • Qhost.MA

Files Modified

File Attributes
c:\users\user\appdata\local\temp\is-936s5.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-936s5.tmp\_isetup\_shfoldr.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-936s5.tmp\supopthelper.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-936s5.tmp\supoptstats.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-uuson.tmp\supoptsetup.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\{c8a51e09-4acf-4165-ad79-a34d9a91eb5c}\supoptsetup.exe Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\uninstall\abbc1e10897907bb:: bijlanCQH3xmzY4567VAtIN5iUzTLroTXg/PHZs3II1UcjdR7Jxy3CfL5HS/EIfNpyvLyK3o+k6OsrCcd RegNtPreCreateKey
HKCU\software\super optimizer::setupname c:\users\user\downloads\59312a5de510a59c70c0e277a4d1907b1ccccc2c_0009240592 RegNtPreCreateKey
HKCU\software\super optimizer::ir 1 RegNtPreCreateKey
HKCU\software\super optimizer::sessionid 19287837-4FBB-48EF-AE98-B81877A7DBF0 RegNtPreCreateKey

Windows API Usage

Category API
Network Info Queried
  • GetAdaptersInfo
Network Wininet
  • HttpOpenRequest
  • HttpQueryInfo
  • HttpSendRequest
  • InternetConnect
  • InternetOpen
  • InternetSetOption
Network Winhttp
  • WinHttpOpen
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess

Shell Command Execution

C:\Users\Osaonydy\AppData\Local\Temp\{C8A51E09-4ACF-4165-AD79-A34D9A91EB5C}\supoptsetup.exe /VERYSILENT
"C:\Users\Osaonydy\AppData\Local\Temp\is-UUSON.tmp\supoptsetup.tmp" /SL5="$2031C,7570068,221184,C:\Users\Osaonydy\AppData\Local\Temp\{C8A51E09-4ACF-4165-AD79-A34D9A91EB5C}\supoptsetup.exe" /VERYSILENT

Related Posts

Trending

Most Viewed

Loading...