Malware

AdWare.Win32.MultiPlug.sjet removal tips

Malware Removal

The AdWare.Win32.MultiPlug.sjet is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.MultiPlug.sjet virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Transacted Hollowing
  • CAPE detected the embedded win api malware family
  • Created a service that was not started
  • Yara detections observed in process dumps, payloads or dropped files

How to determine AdWare.Win32.MultiPlug.sjet?


File Info:

name: 3676861C8FD1DA27FA6D.mlw
path: /opt/CAPEv2/storage/binaries/2ae3c25280a3aeea7234de8f6bedbe78f27eec6d44c260ba0fbefa7e401c6a1a
crc32: B3C464D5
md5: 3676861c8fd1da27fa6dcc9f3063f4e3
sha1: 5b0e23a14e0d6ec7f5ae7ef61e0bd0fc7f8ddc37
sha256: 2ae3c25280a3aeea7234de8f6bedbe78f27eec6d44c260ba0fbefa7e401c6a1a
sha512: 48cf5130750b2e4ddf278369db8eb47f65b6d36e42e4eb4200713aab8561e863c9edec82a94efde91dc6bd41306142c23b086fb63ab3fde7f0bbaf8a628518b3
ssdeep: 98304:NPvv/GieRfnhqGjNwNC8z8ZXBWqswSUY1OtKmv7KwZd358:xnGi8hvONCuxmCrCZk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DC06333534896179C1498EF11E5B903E86333A2E807536B7B38AC9CA7F13E554D8EB53
sha3_384: 41c4a7ee2f3bceab654b80b4f5b27838c9bf47ff443c8990a39d123f4eb5dc32e66555fb1a2327c4ae220f6e678f3a4b
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: EV Audio Center Setup
FileVersion:
LegalCopyright:
ProductName: EV Audio Center
ProductVersion: 0.1.1.8
Translation: 0x0000 0x04b0

AdWare.Win32.MultiPlug.sjet also known as:

BkavW32.Common.E05DB9AB
LionicAdware.Win32.MultiPlug.2!c
SkyhighBehavesLike.Win32.ObfuscatedPoly.wc
Cylanceunsafe
SangforAdware.Win32.MultiPlug.Vhns
K7AntiVirusTrojan ( 005722fe1 )
AlibabaAdWare:Win32/MultiPlug.96f8c520
K7GWTrojan ( 005722fe1 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecPUA.Gen.2
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
CynetMalicious (score: 100)
Kasperskynot-a-virus:AdWare.Win32.MultiPlug.sjet
AvastWin32:Malware-gen
TencentWin32.AdWare.Multiplug.Rwhl
F-SecureTrojan.TR/Drop.Agent.qhkbo
DrWebTrojan.Siggen24.19661
TrendMicroTROJ_FRS.0NA103B824
SophosGeneric Reputation PUA (PUA)
IkarusTrojan.Win32.Crypt
GDataWin32.Trojan.Kryptik.0HS80A
AviraTR/Drop.Agent.qhkbo
ZoneAlarmnot-a-virus:AdWare.Win32.MultiPlug.sjet
MicrosoftTrojan:Win32/ICLoader.JLK!MTB
VaristW32/Agent.MYWI-5961
AhnLab-V3Trojan/Win.Generic.R631969
McAfeeArtemis!3676861C8FD1
MalwarebytesGeneric.Malware/Suspicious
TrendMicro-HouseCallTROJ_FRS.0NA103B824
MaxSecureTrojan.Malware.3411146.susgen
FortinetRiskware/Agent
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove AdWare.Win32.MultiPlug.sjet?

AdWare.Win32.MultiPlug.sjet removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment