Adware

Adware.MPlug.1 removal guide

Malware Removal

The Adware.MPlug.1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.MPlug.1 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • A process created a hidden window
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Checks for the presence of known windows from debuggers and forensic tools
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics

Related domains:

download.costmin.info
www6.costmin.info

How to determine Adware.MPlug.1?


File Info:

crc32: 3290F383
md5: e981a0c46b86fac3f8c0edcba075ee91
name: E981A0C46B86FAC3F8C0EDCBA075EE91.mlw
sha1: b386cd716395fc51d2f035b85deaf1cd458b9da5
sha256: 1e1ca4a90fd3a6dabe84b52c929f89e00d571a73df668ebd4b2171348b23987b
sha512: 8b019dc3f9431ffb1d2243d203a3e655cccbb7950cd8d979c5cca70d958056513dcecfc8b19e733a25dd15df82109d3ae54608002bb38cf9567a404060afb6fc
ssdeep: 3072:e5WKPAfl8HG1XjNciUBzURTijM8jHvsgQBDPyIFqRgLte3CA7Zbr6EmErcIeTfJ:e5qsGljNfWzU4UBDFFeseCA7ZPuJf
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2014
InternalName:
FileVersion: 2.5.111.0
CompanyName:
LegalTrademarks1:
LegalTrademarks2:
ProductName:
ProductVersion: 2.5
FileDescription:
OriginalFilename:
Translation: 0x0409 0x04e4

Adware.MPlug.1 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Genome.a!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader11.27452
MicroWorld-eScanGen:Variant.Adware.MPlug.1
FireEyeGeneric.mg.e981a0c46b86fac3
ALYacGen:Variant.Adware.MPlug.1
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojanDownloader:Win32/Genome.01fa6294
CyrenW32/S-b59a379f!Eldorado
ESET-NOD32a variant of Win32/Adware.MultiPlug.BM.gen
APEXMalicious
AvastFileRepMalware
CynetMalicious (score: 100)
KasperskyTrojan-Downloader.Win32.Genome.uoth
BitDefenderGen:Variant.Adware.MPlug.1
NANO-AntivirusTrojan.Win32.Badur.dedeva
TencentWin32.Trojan.Generic.Alsb
Ad-AwareGen:Variant.Adware.MPlug.1
SophosGeneric PUA LD (PUA)
ComodoMalware@#1ucwb71tt5k38
BitDefenderThetaAI:Packer.3541EC8E1F
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_SPNR.38HR14
EmsisoftGen:Variant.Adware.MPlug.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminAdWare/MultiPlug.aajz
WebrootW32.Trojan.Gen
AviraADWARE/MultiPlug.Gen7
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Wacatac.A!ml
ArcabitTrojan.Adware.MPlug.1
SUPERAntiSpywareTrojan.Agent/Generic
GDataWin32.Trojan-Spy.Emotet.DR@gen
McAfeeGenericR-QXD!E981A0C46B86
MAXmalware (ai score=63)
VBA32BScope.Trojan.Joao
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_SPNR.38HR14
RisingTrojan.Generic@ML.100 (RDML:tQm++fndbLpGSRbuyxfrCw)
YandexTrojan.GenAsa!bRIppuM/tlE
IkarusTrojan.Win32.Badur
FortinetW32/Badur.BM!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Adware.MPlug.1?

Adware.MPlug.1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment