Analysis by: Jaime Benigno Reyes


AdWare.Win32.MultiPlug.nbjr (Kaspersky)




  • Threat Type: Adware

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes


This adware may be manually installed by a user.


File Size:

866,672 bytes

File Type:


Memory Resident:


Initial Samples Received Date:

15 Nov 2014

Arrival Details

This adware may be manually installed by a user.


This adware adds the following folders:

  • %All Users Profile%\Application Data\Trusted Publisher (Versions lower than Windows Vista)
  • %All Users Profile%\Application Data\Trusted Publisher\SW-Booster (Versions lower than Windows Vista)
  • %All Users Profile%\Microsoft\Windows\Start Menu\Programs\EZDownloader (Windows Vista and higher versions)
  • %All Users Profile%\Microsoft\Windows\Start Menu\Programs\LiveSupport (Windows Vista and higher versions)
  • %All Users Profile%\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2 (Windows Vista and higher versions)
  • %All Users Profile%\Microsoft\Windows\Start Menu\Programs\SkypEmoticons (Windows Vista and higher versions)
  • %All Users Profile%\Start Menu\Programs\EZDownloader (Versions lower than Windows Vista)
  • %All Users Profile%\Start Menu\Programs\Optimizer Pro v3.2 (Versions lower than Windows Vista)
  • %All Users Profile%\Start Menu\Programs\LiveSupport (Versions lower than Windows Vista)
  • %All Users Profile%\Start Menu\Programs\SkypEmoticons (Versions lower than Windows Vista)
  • %All Users Profile%\Trusted Publisher (Windows Vista and higher versions)
  • %All Users Profile%\Trusted Publisher\SW-Booster (Windows Vista and higher versions)
  • %Application Data%\Mozilla\Firefox\Profiles\random alphanumeric characters.default\searchplugins
  • %Application Data%\SkypEmoticons
  • %Application Data%\SkypEmoticons\Temp
  • %Program Files%\EZDownloader
  • %Program Files%\LiveSupport
  • %Program Files%\Optimizer Pro
  • %System%\AMD64
  • %System%\X86
  • %User Temp%\7E82590C-48C6-48BD-9DBB-BDCC68C3CBB8[i]
  • %User Temp%\{random alphanumeric characters}
  • %User Temp%\{random alphanumeric characters}\images
  • %User Temp%\{random alphanumeric characters}\steps
  • %User Temp%\{random alphanumeric characters}\temp

(Note: %All Users Profile% is the All Users folder, where it usually is C:\Documents and Settings\All Users on Windows 2000, Windows Server 2003, and Windows XP (32- and 64-bit); C:\ProgramData on Windows Vista (32- and 64-bit), Windows 7 (32- and 64-bit), Windows 8 (32- and 64-bit), Windows 8.1 (32- and 64-bit), Windows Server 2008, and Windows Server 2012.. %Application Data% is the Application Data folder, where it usually is C:\Documents and Settings\{user name}\Application Data on Windows 2000, Windows Server 2003, and Windows XP (32- and 64-bit); C:\Users\{user name}\AppData\Roaming on Windows Vista (32- and 64-bit), Windows 7 (32- and 64-bit), Windows 8 (32- and 64-bit), Windows 8.1 (32- and 64-bit), Windows Server 2008, and Windows Server 2012.. %Program Files% is the Program Files folder, where it usually is C:\Program Files on all Windows operating system versions; C:\Program Files (x86) for 32-bit applications running on Windows 64-bit operating systems.. %System% is the Windows system folder, where it usually is C:\Windows\System32 on all Windows operating system versions.. %User Temp% is the user's temporary folder, where it usually is C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, Windows Server 2003, and Windows XP (32- and 64-bit); C:\Users\{user name}\AppData\Local\Temp on Windows Vista (32- and 64-bit), Windows 7 (32- and 64-bit), Windows 8 (32- and 64-bit), Windows 8.1 (32- and 64-bit), Windows Server 2008, and Windows Server 2012.)

It drops the following files:

  • %All Users Profile%\Application Data\Trusted Publisher\SW-Booster\SW-Booster.exe (Versions lower than Windows Vista)
  • %All Users Profile%\Application Data\Trusted Publisher\SW-Booster\{random number} (Versions lower than Windows Vista)
  • %All Users Profile%\Application Data\Trusted Publisher\SW-Booster\{random number}.ini (Versions lower than Windows Vista)
  • %All Users Profile%\Desktop\EZDownloader.lnk (Versions lower than Windows Vista)
  • %All Users Profile%\Microsoft\Windows\Start Menu\Programs\EZDownloader\EZDownloader.lnk (Windows Vista and higher versions)
  • %All Users Profile%\Microsoft\Windows\Start Menu\Programs\LiveSupport\LiveSupport.lnk (Windows Vista and higher versions)
  • %All Users Profile%\Microsoft\Windows\Start Menu\Programs\LiveSupport\Uninstall LiveSupport.lnk (Windows Vista and higher versions)
  • %All Users Profile%\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2\Check updates.lnk (Windows Vista and higher versions)
  • %All Users Profile%\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2\Help.lnk (Windows Vista and higher versions)
  • %All Users Profile%\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2\Optimizer Pro on the Web.lnk (Windows Vista and higher versions)
  • %All Users Profile%\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2\Optimizer Pro.lnk (Windows Vista and higher versions)
  • %All Users Profile%\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2\Uninstall Optimizer Pro.lnk (Windows Vista and higher versions)
  • %All Users Profile%\Microsoft\Windows\Start Menu\Programs\SkypEmoticons\SkypEmoticons.lnk (Windows Vista and higher versions)
  • %All Users Profile%\Start Menu\Programs\EZDownloader\EZDownloader.lnk (Versions lower than Windows Vista)
  • %All Users Profile%\Start Menu\Programs\LiveSupport\LiveSupport.lnk (Versions lower than Windows Vista)
  • %All Users Profile%\Start Menu\Programs\LiveSupport\Uninstall LiveSupport.lnk (Versions lower than Windows Vista)
  • %All Users Profile%\Start Menu\Programs\Optimizer Pro v3.2\Check updates.lnk (Versions lower than Windows Vista)
  • %All Users Profile%\Start Menu\Programs\Optimizer Pro v3.2\Help.lnk (Versions lower than Windows Vista)
  • %All Users Profile%\Start Menu\Programs\Optimizer Pro v3.2\Optimizer Pro on the Web.lnk (Versions lower than Windows Vista)
  • %All Users Profile%\Start Menu\Programs\Optimizer Pro v3.2\Optimizer Pro.lnk (Versions lower than Windows Vista)
  • %All Users Profile%\Start Menu\Programs\Optimizer Pro v3.2\Uninstall Optimizer Pro.lnk (Versions lower than Windows Vista)
  • %All Users Profile%\Start Menu\Programs\SkypEmoticons\SkypEmoticons.lnk (Versions lower than Windows Vista)
  • %All Users Profile%\Trusted Publisher\SW-Booster\SW-Booster.exe (Windows Vista and higher versions)
  • %All Users Profile%\Trusted Publisher\SW-Booster\{random number} (Windows Vista and higher versions)
  • %All Users Profile%\Trusted Publisher\SW-Booster\{random number}.ini (Windows Vista and higher versions)
  • %Application Data%\LiveSupport.exe_log.txt
  • %Application Data%\Mozilla\Firefox\Profiles\random alphanumeric characters.default\searchplugins\WebSearch.xml
  • %Application Data%\SkypEmoticons\Lng.s
  • %Application Data%\SkypEmoticons\Res.dll
  • %Application Data%\SkypEmoticons\SE.exe
  • %Application Data%\SkypEmoticons\SEDownloader.exe
  • %Application Data%\SkypEmoticons\
  • %Application Data%\SkypEmoticons\Temp\SE.exe
  • %Application Data%\SkypEmoticons\unins000.dat
  • %Application Data%\SkypEmoticons\unins000.exe
  • %Application Data%\regsvr32.exe_log.txt
  • %Desktop%\LiveSupport.lnk
  • %Desktop%\Optimizer Pro.lnk
  • %Program Files%\EZDownloader\EZDownloader.Core.dll
  • %Program Files%\EZDownloader\EZDownloader.Extension.dll
  • %Program Files%\EZDownloader\EZDownloader.Spider.dll
  • %Program Files%\EZDownloader\EZDownloader.exe
  • %Program Files%\EZDownloader\EZDownloader.exe.config
  • %Program Files%\EZDownloader\ICSharpCode.SharpZipLib.dll
  • %Program Files%\EZDownloader\Interop.SHDocVw.dll
  • %Program Files%\EZDownloader\TabStrip.dll
  • %Program Files%\EZDownloader\unins000.dat
  • %Program Files%\EZDownloader\unins000.exe
  • %Program Files%\LiveSupport\LiveSupport.exe
  • %Program Files%\LiveSupport\LiveSupport_deskband_x32.dll
  • %Program Files%\LiveSupport\LiveSupport_deskband_x64.dll
  • %Program Files%\LiveSupport\unins000.dat
  • %Program Files%\LiveSupport\unins000.exe
  • %Program Files%\LiveSupport\unins000.msg
  • %Program Files%\Optimizer Pro\CookiesException.txt
  • %Program Files%\Optimizer Pro\English.ini
  • %Program Files%\Optimizer Pro\English.iniAM
  • %Program Files%\Optimizer Pro\HomePage.url
  • %Program Files%\Optimizer Pro\OptProGuard.exe
  • %Program Files%\Optimizer Pro\OptProHelper.dll
  • %Program Files%\Optimizer Pro\OptProLauncher.exe
  • %Program Files%\Optimizer Pro\OptProReminder.exe
  • %Program Files%\Optimizer Pro\OptProSchedule.exe
  • %Program Files%\Optimizer Pro\OptProSmartScan.exe
  • %Program Files%\Optimizer Pro\OptProStart.exe
  • %Program Files%\Optimizer Pro\OptProUninstaller.exe
  • %Program Files%\Optimizer Pro\OptimizerPro.chm
  • %Program Files%\Optimizer Pro\OptimizerPro.exe
  • %Program Files%\Optimizer Pro\StartupList.txt
  • %Program Files%\Optimizer Pro\bg_new3.bmp
  • %Program Files%\Optimizer Pro\cancel.bmp
  • %Program Files%\Optimizer Pro\file_id.diz
  • %Program Files%\Optimizer Pro\itdownload.dll
  • %Program Files%\Optimizer Pro\scan.gif
  • %Program Files%\Optimizer Pro\sqlite3.dll
  • %Program Files%\Optimizer Pro\unins000.dat
  • %Program Files%\Optimizer Pro\unins000.exe
  • %Program Files%\Optimizer Pro\unins000.msg
  • %System Root%\Users\Public\Desktop\EZDownloader.lnk (Windows Vista and higher versions)
  • %System%\Tasks\SW-Booster-S-{random number}
  • %User Temp%\7E82590C-48C6-48BD-9DBB-BDCC68C3CBB8[i]\tmp
  • %User Temp%\LiveSupport_setup.exe
  • %User Temp%\optprosetup.exe
  • %User Temp%\sSetup-se.exe
  • %User Temp%\{random alphanumeric characters}\images\loader.gif
  • %User Temp%\{random alphanumeric characters}\images\progressbar.gif
  • %User Temp%\{random alphanumeric characters}\steps\1.ini
  • %User Temp%\{random alphanumeric characters}\steps\10.ini
  • %User Temp%\{random alphanumeric characters}\steps\11.ini
  • %User Temp%\{random alphanumeric characters}\steps\2.ini
  • %User Temp%\{random alphanumeric characters}\steps\4.ini
  • %User Temp%\{random alphanumeric characters}\steps\4_1.ini
  • %User Temp%\{random alphanumeric characters}\steps\4_2.ini
  • %User Temp%\{random alphanumeric characters}\steps\4_2_1.ini
  • %User Temp%\{random alphanumeric characters}\steps\5.ini
  • %User Temp%\{random alphanumeric characters}\steps\6.ini
  • %User Temp%\{random alphanumeric characters}\steps\6_1.ini
  • %User Temp%\{random alphanumeric characters}\steps\6_1_2.ini
  • %User Temp%\{random alphanumeric characters}\steps\6_1_2_1.ini
  • %User Temp%\{random alphanumeric characters}\steps\6_1_3.ini
  • %User Temp%\{random alphanumeric characters}\steps\6_1_4.ini
  • %User Temp%\{random alphanumeric characters}\steps\6_1_5.ini
  • %User Temp%\{random alphanumeric characters}\steps\6_1_6.ini
  • %User Temp%\{random alphanumeric characters}\steps\6_2.ini
  • %User Temp%\{random alphanumeric characters}\steps\6_2_1.ini
  • %User Temp%\{random alphanumeric characters}\steps\6_3.ini
  • %User Temp%\{random alphanumeric characters}\steps\7.ini
  • %User Temp%\{random alphanumeric characters}\steps\7_1.ini
  • %User Temp%\{random alphanumeric characters}\steps\7_2.ini
  • %User Temp%\{random alphanumeric characters}\steps\8.ini
  • %User Temp%\{random alphanumeric characters}\steps\8_1.ini
  • %User Temp%\{random alphanumeric characters}\steps\8_2.ini
  • %User Temp%\{random alphanumeric characters}\steps\8_2_1.ini
  • %User Temp%\{random alphanumeric characters}\steps\8_2_1.ini.txt
  • %User Temp%\{random alphanumeric characters}\steps\9.ini
  • %User Temp%\{random alphanumeric characters}\steps\9.ini.txt
  • %User Temp%\{random alphanumeric characters}\temp\EzDownloader_setup.exe
  • %User Temp%\{random alphanumeric characters}\temp\OpProSetup.exe
  • %User Temp%\{random alphanumeric characters}\temp\fs_sdhp.exe
  • %User Temp%\{random alphanumeric characters}\temp\putfu.exe
  • %User Temp%\{random alphanumeric characters}\temp\usetup.exe
  • %User Temp%\{random alphanumeric characters}\temp\wpc_mystartsearch.exe
  • %Windows%\Tasks\SW-Booster-S-{random number}.job

(Note: %All Users Profile% is the All Users folder, where it usually is C:\Documents and Settings\All Users on Windows 2000, Windows Server 2003, and Windows XP (32- and 64-bit); C:\ProgramData on Windows Vista (32- and 64-bit), Windows 7 (32- and 64-bit), Windows 8 (32- and 64-bit), Windows 8.1 (32- and 64-bit), Windows Server 2008, and Windows Server 2012.. %Application Data% is the Application Data folder, where it usually is C:\Documents and Settings\{user name}\Application Data on Windows 2000, Windows Server 2003, and Windows XP (32- and 64-bit); C:\Users\{user name}\AppData\Roaming on Windows Vista (32- and 64-bit), Windows 7 (32- and 64-bit), Windows 8 (32- and 64-bit), Windows 8.1 (32- and 64-bit), Windows Server 2008, and Windows Server 2012.. %Desktop% is the desktop folder, where it usually is C:\Documents and Settings\{user name}\Desktop in Windows 2000, Windows Server 2003, and Windows XP (32- and 64-bit); C:\Users\{user name}\Desktop in Windows Vista (32- and 64-bit), Windows 7 (32- and 64-bit), Windows 8 (32- and 64-bit), Windows 8.1 (32- and 64-bit), Windows Server 2008, and Windows Server 2012.. %Program Files% is the Program Files folder, where it usually is C:\Program Files on all Windows operating system versions; C:\Program Files (x86) for 32-bit applications running on Windows 64-bit operating systems.. %System Root% is the Windows root folder, where it usually is C:\ on all Windows operating system versions.. %System% is the Windows system folder, where it usually is C:\Windows\System32 on all Windows operating system versions.. %User Temp% is the user's temporary folder, where it usually is C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, Windows Server 2003, and Windows XP (32- and 64-bit); C:\Users\{user name}\AppData\Local\Temp on Windows Vista (32- and 64-bit), Windows 7 (32- and 64-bit), Windows 8 (32- and 64-bit), Windows 8.1 (32- and 64-bit), Windows Server 2008, and Windows Server 2012.. %Windows% is the Windows folder, where it usually is C:\Windows on all Windows operating system versions.)

Autostart Technique

This adware creates the following registry entries to enable automatic execution of dropped component at every system startup:

LiveSupport = ""%Program Files%\LiveSupport\LiveSupport.exe" /noshow /log"

Optimizer Pro = "%Program Files%\Optimizer Pro\OptProLauncher.exe"

se = ""%Application Data%\SkypEmoticons\SE.exe" /minimized "

Other System Modifications

This adware adds the following registry keys:





Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}

HKEY_CURRENT_USER\Software\Optimizer Pro



Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}


Optimizer Pro_is1

S-{random number}





It modifies the following registry entries:

Internet Explorer\Main
Start Page = "{number}&idate={installation date}"

(Note: The default value data of the said registry entry is "{user's start page}".)

Internet Explorer\Main
Start Page = "{number}&idate={installation date}"

(Note: The default value data of the said registry entry is "{user's start page}".)

Other Details

This adware connects to the following possibly malicious URL:

  • http://ad131m.{BLOCKED}
  • http://{BLOCKED}
  • http://bi.{BLOCKED}
  • http://c1.{BLOCKED}
  • http://creative.{BLOCKED}
  • http://dl.{BLOCKED}
  • http://dl.{BLOCKED}
  • http://i1.{BLOCKED}
  • http://i1.{BLOCKED}
  • http://i1.{BLOCKED}
  • http://i1.{BLOCKED}
  • http://i1.{BLOCKED}
  • http://i1.{BLOCKED}
  • http://i1.{BLOCKED}
  • http://i1.{BLOCKED}
  • http://i1.{BLOCKED}
  • http://i2.{BLOCKED}
  • http://i2.{BLOCKED}
  • http://{BLOCKED}
  • http://r1.{BLOCKED}
  • http://s.{BLOCKED}
  • http://{BLOCKED}
  • http://{BLOCKED}
  • http://{BLOCKED}
  • http://{BLOCKED}
  • http://websearch.{BLOCKED}
  • http://www.{BLOCKED}