Threat Database Adware Adware.Multiplug.I

Adware.Multiplug.I

By CagedTech in Adware

Threat Scorecard

Popularity Rank: 22,246
Threat Level: 20 % (Normal)
Infected Computers: 212
First Seen: August 16, 2021
Last Seen: May 31, 2026
OS(es) Affected: Windows

The detection of Adware.Multiplug.I on your system indicates the presence of unwanted software that may be displaying advertisements, collecting data, or performing other potentially malicious activities. It is essential to take immediate action to remove this threat and prevent further damage to your computer and personal data.

What Is Adware.Multiplug.I?

Adware.Multiplug.I is a type of malicious software that is designed to display unwanted advertisements, collect user data, or perform other actions without the user's consent. The name "Adware.Multiplug.I" suggests that it is a form of adware, which is a type of malware that is intended to generate revenue for its creators by displaying advertisements or promoting certain products or services.

How Adware.Multiplug.I Operates

Adware.Multiplug.I, like other forms of adware, operates by infiltrating a user's system and then displaying unwanted advertisements, collecting user data, or performing other malicious activities. It may do this by exploiting vulnerabilities in software or by tricking users into installing it voluntarily. Once installed, it can be challenging to remove, and it may continue to display advertisements, collect data, or perform other actions without the user's knowledge or consent.

Adware.Multiplug.I may also have the ability to track user behavior, collect personal data, or install additional malware on the affected system. It is crucial to remove this threat as soon as possible to prevent further damage and protect your personal data.

Symptoms of Infection

Systems infected with Adware.Multiplug.I may exhibit a range of symptoms, including unwanted advertisements, pop-ups, or browser redirects. Users may also notice that their system is running slowly, or that their browser is crashing frequently. In some cases, users may notice that their search results are being redirected to unfamiliar websites or that their personal data is being collected without their consent.

  • Unwanted advertisements or pop-ups
  • Browser redirects or unfamiliar search results
  • Slow system performance or frequent crashes
  • Unexplained changes to browser settings or system configuration

How to Remove Adware.Multiplug.I

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for easier removal.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malware or other threats.
  3. Uninstall any suspicious programs or applications that may be related to the Adware.Multiplug.I infection.
  4. Reset your browser settings to their default values, including Chrome, Firefox, and Edge, to remove any malicious extensions or add-ons.
  5. Reboot your system and perform a follow-up scan to ensure that the threat has been fully removed.

Conclusion

Removing Adware.Multiplug.I from your system is crucial to preventing further damage and protecting your personal data. By following the steps outlined above, you can help to ensure that your system is safe and secure. It is also essential to practice good computer hygiene, including regularly updating your operating system and software, using strong passwords, and being cautious when installing new programs or applications. By taking these steps, you can help to protect your system from future malware infections and keep your personal data safe.

Analysis Report

General information

Family Name: Adware.Multiplug.I
Signature status: No Signature

Known Samples

MD5: 0b555238bb9d0de1e3ca0858ada69cdf
SHA1: daff834a9221d72ab721946a571bcfbab1868a6c
SHA256: 41A1F63D9057E3B71A231ACF93E5A916755776FFE748DCCB95DA75CA8C3B0D1D
File Size: 419.33 KB, 419328 bytes
MD5: f53a2e8659ac091bf80e379708c60140
SHA1: df56bf03df055ff05969adcd257cde074fa5fa78
SHA256: A2EB6E463A71D58C95EB147EAA85816E75CB3379FAE3434CC9E199E9D423D846
File Size: 423.42 KB, 423424 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have relocations information
  • File doesn't have security information
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name TODO: <Company name>
File Description TODO: <File description>
File Version 1.0.0.1
Internal Name runtime.dll
Legal Copyright TODO: (c) <Company name>. All rights reserved.
Original Filename runtime.dll
Product Name TODO: <Product name>
Product Version 1.0.0.1

File Traits

  • Default Version Info
  • dll
  • x86

Block Information

Total Blocks: 1,344
Potentially Malicious Blocks: 179
Whitelisted Blocks: 1,013
Unknown Blocks: 152

Visual Map

0 0 0 0 0 0 0 0 ? ? ? ? x x ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 ? ? 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x 0 x 0 0 x 0 0 x 0 x x 0 x x x x x x x x x x 0 ? 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 x x 0 0 ? ? 0 0 0 0 0 0 0 x 0 0 0 ? 0 0 0 x 0 x x x 0 x x 0 0 0 0 0 x x 0 ? ? 0 ? 0 x x x 0 0 0 0 x 0 0 0 0 x 0 ? 0 x x x x 0 ? x ? ? 0 ? ? x 0 ? 0 0 0 0 x x x 0 x 0 0 x x x x x x x x x x x x 0 0 0 x x x x x x x x x x x x 0 x x ? 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x x x x x 0 0 0 0 0 0 ? x x ? ? 0 ? 0 0 0 ? ? ? x 0 0 x x 0 x 0 0 0 0 0 0 0 0 x ? 0 0 ? x 0 0 ? ? ? ? ? ? ? ? ? 0 x ? ? ? ? ? ? x 0 x x x x x 0 0 ? 0 0 x x x x x 0 0 0 0 0 x x x x x ? 0 0 0 ? 0 0 ? 0 ? 0 x x x 0 x ? 0 x x 0 x x 0 0 0 0 0 x 0 0 ? 0 x ? 0 0 0 0 ? 0 x ? ? ? ? ? 0 0 x 0 ? ? ? 0 0 0 ? ? 0 ? ? x 0 x ? 0 0 0 x ? 0 ? 0 ? 0 ? 0 ? x ? ? 0 0 0 ? ? 0 ? 0 ? ? 0 ? 0 0 ? 0 x 0 0 x x 0 0 0 0 0 0 1 1 0 0 0 0 0 ? ? x ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? 0 ? ? 0 ? ? ? 0 ? 0 ? ? x x ? ? 0 ? ? ? x 0 0 ? ? ? x ? 0 ? x ? 0 ? 0 ? 0 ? 0 x ? ? x ? ? x ? ? ? ? ? ? ? ? ? ? ? ? x x x ? 0 ? x ? ? x x x ? x ? x x x x ? x ? ? 0 x x 0 x x x 0 0 x x x x 0 0 0 0 0 0 0 1 1 0 0 1 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 2 0 0 0 0 0 0 0 0 0 0 0 0 1 2 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 3 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 3 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 1 0 0 0 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 2 2 1 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtProtectVirtualMemory
Show More
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\daff834a9221d72ab721946a571bcfbab1868a6c_0000419328.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\df56bf03df055ff05969adcd257cde074fa5fa78_0000423424.,LiQMAxHB

Related Posts

Trending

Most Viewed

Loading...