PUA

PUP.Optional.MultiPlug.BHO removal guide

Malware Removal

The PUP.Optional.MultiPlug.BHO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUP.Optional.MultiPlug.BHO virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to create or modify a Browser Helper Object
  • Creates a copy of itself
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine PUP.Optional.MultiPlug.BHO?


File Info:

name: D684B5346E1FC1362BDA.mlw
path: /opt/CAPEv2/storage/binaries/73f7d35f2be6bf385d72da9d087865fc6d6db1bb8cadd85fc1b22f8e22f6aab9
crc32: DAA9122F
md5: d684b5346e1fc1362bda4965469cdfc7
sha1: 054263320847d0da4995db53157f2b97f7f723d3
sha256: 73f7d35f2be6bf385d72da9d087865fc6d6db1bb8cadd85fc1b22f8e22f6aab9
sha512: 518f3a83620706c84149ae516e5590c800c38096e90fbb73c3a36c59e32810de3e3798a668b27fffb928dd16a17ceb69d832388831de40f6636c9008fe52bb62
ssdeep: 49152:THiV6GPddOkg8y30Y0ktsQubyFS9SFflpwklvWqFGLSQt1dBemiyxifi3PegV:THibOL8Md0kt3uvTklpGvt1di+i
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10FF549C1A41BF07ECF030B7522AD9D66F11A4AD426708CFB97E5FEB45B70A910462E72
sha3_384: 1b133453cd7c2cd0a6415faa77a82f564f2464a804a28abeac75961afa88dc155efe2121b3bc3874a25055eadc9f8c53
ep_bytes: e83f670000e9000000006a1468083354
timestamp: 2014-09-23 10:02:04

Version Info:

0: [No Data]

PUP.Optional.MultiPlug.BHO also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Adware.MPlug.7
CAT-QuickHealPua.Multiplug.33247
SkyhighMultiPlug-FQW
McAfeeMultiPlug-FQW
ZillyaAdware.MultiPlugGen.Win32.20
SangforTrojan.Win32.Save.a
K7AntiVirusUnwanted-Program ( 0040f9531 )
K7GWUnwanted-Program ( 0040f9531 )
ArcabitTrojan.Adware.MPlug.7
BitDefenderThetaGen:NN.ZexaF.36680.uxW@aaNxv7ki
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Adware.MultiPlug.CO
CynetMalicious (score: 100)
APEXMalicious
Kasperskynot-a-virus:HEUR:WebToolbar.Win32.Generic
BitDefenderGen:Variant.Adware.MPlug.7
NANO-AntivirusRiskware.Win32.MultiPlug.dfmjnh
AvastWin32:MultiPlug-NP [PUP]
TencentMalware.Win32.Gencirc.11bb3533
EmsisoftGen:Variant.Adware.MPlug.7 (B)
BaiduWin32.Adware.Generic.bc
F-SecureAdware.ADWARE/MultiPlug.Gen4
DrWebTrojan.Crossrider1.12877
VIPREGen:Variant.Adware.MPlug.7
SophosMultiPlug (PUA)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Adond.nc
WebrootW32.Adware.Multplug
VaristW32/A-6f1e42c2!Eldorado
AviraADWARE/MultiPlug.Gen4
Antiy-AVLGrayWare[AdWare]/Win32.MultiPlug.co
XcitiumApplication.Win32.Multiplug.DGA@6lb1up
MicrosoftProgram:Win32/Wacapew.C!ml
ZoneAlarmnot-a-virus:HEUR:WebToolbar.Win32.Generic
GDataGen:Variant.Adware.MPlug.7
GoogleDetected
AhnLab-V3Adware/Win32.Agent.R121723
VBA32Trojan.Adond
MalwarebytesPUP.Optional.MultiPlug.BHO
PandaTrj/Genetic.gen
RisingPUF.Bitrepeyu!8.132DA (TFE:5:UlfNZYSan0N)
YandexTrojan.GenAsa!6TKw469fvv8
IkarusAdWare.MPlug
MaxSecureTrojan.Malware.300983.susgen
FortinetAdware/MultiPlug
AVGWin32:MultiPlug-NP [PUP]
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_100% (D)

How to remove PUP.Optional.MultiPlug.BHO?

PUP.Optional.MultiPlug.BHO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment