Malware

AdWare.Win32.MegaSearch.am (file analysis)

Malware Removal

The AdWare.Win32.MegaSearch.am is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.MegaSearch.am virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to create or modify a Browser Helper Object
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine AdWare.Win32.MegaSearch.am?


File Info:

name: D1B448D3F0B56B0E1D0E.mlw
path: /opt/CAPEv2/storage/binaries/1270946a253c20b0e3fef08ce39905fccb08fee0eb05239f47eae43b383e9516
crc32: 7B155C7E
md5: d1b448d3f0b56b0e1d0e02052aa04302
sha1: 6fea1dad15ab96e3faa9bdb9504978b2341902f8
sha256: 1270946a253c20b0e3fef08ce39905fccb08fee0eb05239f47eae43b383e9516
sha512: 83ff221a3169f96c5b147573f45cbed9dc0bf06207b9c07e97131f0aad56a357858d1f429b10af7a61e5b568841ddb01382b16321d7047071e9b04b00f6d9831
ssdeep: 6144:h1OgDPdkBAFZWjadD4s5f5WpaXlU26dDdfOx:h1OgLdaOowuBDhOx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18944D02139E1C8FAD2520032CEB87FD5E2FAD6550F31887733D94A2D2F3D595C22AA59
sha3_384: 6cc80acfa72b6b541f0ced771dd4f7e67d018e76bc4730cbd875022bfb167c1a0fd8b0ba87bc4b28ee1d004a0b900c47
ep_bytes: 558bec6aff68e0b94100682c4a410064
timestamp: 2010-11-18 16:27:35

Version Info:

CompanyName: Igor Pavlov
FileDescription: 7z Setup SFX
FileVersion: 9.20
InternalName: 7zS.sfx
LegalCopyright: Copyright (c) 1999-2010 Igor Pavlov
OriginalFilename: 7zS.sfx.exe
ProductName: 7-Zip
ProductVersion: 9.20
Translation: 0x0409 0x04b0

AdWare.Win32.MegaSearch.am also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanDropped:Adware.JS.MultiPlug.A
ClamAVLegacy.Trojan.Trojan-1039
FireEyeDropped:Adware.JS.MultiPlug.A
CAT-QuickHealDiplugem.JS.A
SkyhighBehavesLike.Win32.Downloader.dc
ALYacDropped:Adware.JS.MultiPlug.A
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.ins
AlibabaAdWare:Script/MegaSearch.575bdfe4
CrowdStrikewin/grayware_confidence_100% (D)
VirITTrojan.Win32.Zyx.SP
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
APEXMalicious
CynetMalicious (score: 100)
Kasperskynot-a-virus:AdWare.Win32.MegaSearch.am
BitDefenderDropped:Adware.JS.MultiPlug.A
NANO-AntivirusRiskware.Script.Plugin.cjvvyt
AvastJS:Browsermodifier-B [Trj]
TACHYONTrojan-Clicker/W32.MegaSearch.261654
EmsisoftDropped:Adware.JS.MultiPlug.A (B)
F-SecureMalware.JS/MPlug.PR
DrWebJS.Plugin.13
VIPREDropped:Adware.JS.MultiPlug.A
TrendMicroADW_MULTIPLUG
Trapminemalicious.high.ml.score
SophosGeneric ML PUA (PUA)
GDataWin32.Trojan.Multiplug.E
JiangminAdWare.Script.q
GoogleDetected
AviraADWARE/Adware.Gen7
Antiy-AVLTrojan/Win32.SGeneric
XcitiumApplication.Win32.Multiplug.D@4rev5n
ArcabitAdware.JS.MultiPlug.A
ZoneAlarmnot-a-virus:HEUR:AdWare.Script.Generic
MicrosoftProgram:Win32/Bitrepeyu.B
VaristJS/MPlug.A
McAfeeDownloader-FLN
MAXmalware (ai score=100)
VBA32Adware.MultiPlug
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallADW_MULTIPLUG
RisingAdware.ScrInject!1.CF70 (CLASSIC)
YandexPUA.Agent!oLP4FA1o/W4
IkarusPUA.Monetizer.Gen7
FortinetAdware/MultiPlug
AVGJS:Browsermodifier-B [Trj]
DeepInstinctMALICIOUS

How to remove AdWare.Win32.MegaSearch.am?

AdWare.Win32.MegaSearch.am removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment