Malware

AdWare.Win32.MegaSearch.am malicious file

Malware Removal

The AdWare.Win32.MegaSearch.am is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.MegaSearch.am virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to create or modify a Browser Helper Object
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine AdWare.Win32.MegaSearch.am?


File Info:

name: DF8CE86656549EAEFE6E.mlw
path: /opt/CAPEv2/storage/binaries/83f7bae4fc54306db713cdef4d859b8e28e902bf4b86d6665a7b6b8213322c28
crc32: 867A039E
md5: df8ce86656549eaefe6e57b900273080
sha1: e6b3c04e5c85231b9a3ba8a1eb63a2988e73926b
sha256: 83f7bae4fc54306db713cdef4d859b8e28e902bf4b86d6665a7b6b8213322c28
sha512: e0699fd815fbaec4a601cdcfa2296d22345a2fd97ebaad855da91fb9aaef75f78bd5e73158db0ea8ad3873c484e748c98365f93a4d49844dba218b989889f060
ssdeep: 6144:h1OgDPdkBAFZWjadD4s56kgOB0zEIbQXC5WmVvxxJR:h1OgLdaO9d2SS5WmVvxHR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11A44D0213EE1C5F6D2420432CAA47FD5F1F9D7250F3048A777D84A2D2E7DA85C136A6A
sha3_384: 003a2ccdb7bc6b4730591e73e50e135cb447dd0b311b80911a4c451dc800fc852efcc102516852b5396552d5f0af7587
ep_bytes: 558bec6aff68e0b94100682c4a410064
timestamp: 2010-11-18 16:27:35

Version Info:

CompanyName: Igor Pavlov
FileDescription: 7z Setup SFX
FileVersion: 9.20
InternalName: 7zS.sfx
LegalCopyright: Copyright (c) 1999-2010 Igor Pavlov
OriginalFilename: 7zS.sfx.exe
ProductName: 7-Zip
ProductVersion: 9.20
Translation: 0x0409 0x04b0

AdWare.Win32.MegaSearch.am also known as:

BkavW32.AIDetectMalware
LionicAdware.Win32.MultiPlug.2!c
AVGJS:Browsermodifier-B [Trj]
Elasticmalicious (high confidence)
MicroWorld-eScanDropped:Adware.JS.MultiPlug.A
FireEyeDropped:Adware.JS.MultiPlug.A
CAT-QuickHealDiplugem.JS.A
SkyhighBehavesLike.Win32.Suspicious.dc
McAfeeDownloader-FLN
Cylanceunsafe
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/grayware_confidence_100% (W)
AlibabaAdWare:Script/MegaSearch.27727bff
VirITTrojan.Win32.Zyx.SP
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
CynetMalicious (score: 100)
APEXMalicious
ClamAVJs.Adware.Multiplug-2
Kasperskynot-a-virus:AdWare.Win32.MegaSearch.am
BitDefenderDropped:Adware.JS.MultiPlug.A
NANO-AntivirusRiskware.Script.Plugin.cjvvyt
AvastJS:Browsermodifier-B [Trj]
TencentWin32.Script.Agent.Hajl
EmsisoftDropped:Adware.JS.MultiPlug.A (B)
F-SecureMalware.JS/MPlug.PR
DrWebJS.Plugin.13
VIPREDropped:Adware.JS.MultiPlug.A
TrendMicroADW_CONSAVE
Trapminemalicious.high.ml.score
SophosGeneric Reputation PUA (PUA)
IkarusPUA.Monetizer.Gen7
JiangminAdWare.Script.q
WebrootW32.Adware.Multplug
VaristJS/MPlug.A
AviraADWARE/Adware.Gen7
Antiy-AVLRiskWare/Win32.Application
KingsoftWin32.Troj.MegaSearch.am
MicrosoftBrowserModifier:Win32/Diplugem
XcitiumApplication.Win32.Multiplug.D@4rev5n
ArcabitAdware.JS.MultiPlug.A
ZoneAlarmnot-a-virus:HEUR:AdWare.Script.Generic
GDataWin32.Trojan.Multiplug.E
GoogleDetected
VBA32Adware.MultiPlug
ALYacDropped:Adware.JS.MultiPlug.A
MAXmalware (ai score=100)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/CI.A
TrendMicro-HouseCallADW_CONSAVE
RisingAdware.ScrInject!1.CF70 (CLASSIC)
YandexPUA.Agent!oLP4FA1o/W4
MaxSecureAdware.JS.MultiPlug.P
FortinetAdware/MultiPlug
Cybereasonmalicious.656549
DeepInstinctMALICIOUS

How to remove AdWare.Win32.MegaSearch.am?

AdWare.Win32.MegaSearch.am removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment