Malware

AdWare.Win32.MultiPlug.sjdq (file analysis)

Malware Removal

The AdWare.Win32.MultiPlug.sjdq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.MultiPlug.sjdq virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Transacted Hollowing
  • CAPE detected the embedded win api malware family
  • Created a service that was not started
  • Yara detections observed in process dumps, payloads or dropped files

How to determine AdWare.Win32.MultiPlug.sjdq?


File Info:

name: B1F3D3256C3150005C37.mlw
path: /opt/CAPEv2/storage/binaries/e9103fe95d1a87001e86b898df8203026549816fd489eac8fac17ebc8d0ea965
crc32: 0D2786B3
md5: b1f3d3256c3150005c37ed1cf074755b
sha1: 1381100e3d65397f3bd073fca97678b81fade37b
sha256: e9103fe95d1a87001e86b898df8203026549816fd489eac8fac17ebc8d0ea965
sha512: 4894bc902f37a451ef33a2a443bf282bbe68ef353f0e6a409b85ee95e333fd4c53220b2add3edc534a845f920089648043021d48d1b9ff88d7f55282f465bf1b
ssdeep: 98304:NcsRYD7uzeNvENXqhKJVcCVp+d+Ij5TcNSMreXQN8d8jKd358:SGYXxvQaWGIp2+qpMreAO8Wk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FF163314A759A43AF062FDB4AD17F9120F397DD80D3804621A5E8E3FAD221F5B6CB163
sha3_384: 966e06cc71753f2d2a37d8789eb19863638366664a12af66b54a8c1c8f3a57dcf295e2a777060b336527e617b9994253
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: EU Audio Converter Setup
FileVersion:
LegalCopyright:
ProductName: EU Audio Converter
ProductVersion: 0.1.1.8
Translation: 0x0000 0x04b0

AdWare.Win32.MultiPlug.sjdq also known as:

LionicAdware.Win32.MultiPlug.2!c
SkyhighBehavesLike.Win32.ObfuscatedPoly.wc
Cylanceunsafe
SangforAdware.Win32.MultiPlug.Vi6q
K7AntiVirusTrojan ( 005722f11 )
AlibabaAdWare:Win32/MultiPlug.a9b8097e
K7GWTrojan ( 005722f11 )
SymantecPUA.Gen.2
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
Kasperskynot-a-virus:AdWare.Win32.MultiPlug.sjdq
NANO-AntivirusRiskware.Win32.MultiPlug.khksju
AvastWin32:Malware-gen
TencentWin32.AdWare.Multiplug.Vsmw
F-SecureTrojan.TR/Drop.Agent.fpxve
DrWebTrojan.Siggen24.17727
SophosGeneric Reputation PUA (PUA)
IkarusTrojan.Win32.Crypt
GDataWin32.Trojan.Kryptik.9V3OCT
AviraTR/Drop.Agent.fpxve
VaristW32/Agent.RJGR-3706
KingsoftWin32.Troj.Unknown.a
ZoneAlarmnot-a-virus:AdWare.Win32.MultiPlug.sjdq
MicrosoftTrojan:Win32/ICLoader.JL!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R631969
McAfeeArtemis!B1F3D3256C31
MalwarebytesGeneric.Malware/Suspicious
TrendMicro-HouseCallTROJ_GEN.R002H0DAI24
FortinetW32/Agent.SLC!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove AdWare.Win32.MultiPlug.sjdq?

AdWare.Win32.MultiPlug.sjdq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment