NativeDesktopMediaService

The NativeDesktopMediaService program that you may find in your 'Control Panel' on Windows is categorized as a Potentially Unwanted Program (PUP). The NativeDesktopMediaService software has no official site, and its primary distribution method is software bundling. The NativeDesktopMediaService may be found in the company of adware and trialware. The NativeDesktopMediaService program is known to drop an installer package to C:\WINDOWS\Installer\3a472.msi and run as 'CHECKER.EXE' once it is installed. Also, 'CHECKER.EXE' may be added to the startup programs list and boot with Windows. Computer security researchers have reported that NativeDesktopMediaService creates a scheduled task called 'Checker64' that runs on irregular intervals and exchanges data with remote servers at:

  • h[tt]p://efiwuniq[.]com
  • h[tt]p://xfieunst[.]com
  • h[tt]p://xfinucet[.]com
  • h[tt]p://xfinucte[.]com
  • h[tt]p://xfinuest[.]com
  • h[tt]p://zoruniq[.]com

NativeDesktopMediaService is observed to load C:\Program Files\Jetmedia\NativeDesktopMediaService\checker.exe and transmit information like Internet history records, information on your current software configuration and installed browser add-ons. It is believed that NativeDesktopMediaService is used to collect the Internet usage data from PC users and help marketers improve product positioning in online stores. The NativeDesktopMediaService program does not appear to offer useful utilities to users and serves as a data gathering instrument for third parties. NativeDesktopMediaService may be part of a monetization model for trialware and freeware developers. However, PC users may want to remove the NativeDesktopMediaService application as it does not deliver useful functionality. AV companies flag the files created by NativeDesktopMediaService as:

  • HW32.Packed.30F6
  • ML.Attribute.HighConfidence
  • MSIL/Packed.Confuser.J suspicious
  • Mal/VMProtBad-A
  • Trojan/Win32.Agent.R111742
  • TrojanDownloader:MSIL/Taily.A!bit
  • W32/S-6e1401f2!Eldorado
  • Win32/Expiro5.Gen

Trending

Most Viewed

Loading...