PUP.MediaGet

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 0
First Seen: April 24, 2012
OS(es) Affected: Windows

The detection of PUP.MediaGet on your system indicates the presence of a potentially unwanted program (PUP) that may be compromising your computer's security and performance. It's essential to understand the nature of this threat and take immediate action to remove it and prevent future infections.

What Is PUP.MediaGet?

PUP.MediaGet is a type of malware that is classified as a potentially unwanted program. This means that it is not necessarily malicious in nature, but it can still cause problems for your computer and compromise your personal data. PUPs are often bundled with other software or downloaded from the internet, and they can be difficult to remove without the right tools and expertise.

How PUP.MediaGet Operates

PUP.MediaGet operates by installing itself on your computer without your knowledge or consent. Once installed, it can start to display unwanted advertisements, collect your personal data, and even install additional malware on your system. It may also modify your browser settings and redirect you to suspicious websites. The goal of PUP.MediaGet is to generate revenue for its creators, often at the expense of your computer's performance and security.

Symptoms of Infection

If your computer is infected with PUP.MediaGet, you may notice a range of symptoms, including slow performance, unwanted advertisements, and suspicious browser behavior. You may also notice that your computer is crashing or freezing frequently, or that your personal data is being collected and transmitted to unknown parties. In some cases, PUP.MediaGet may even install additional malware on your system, which can lead to further problems and security risks.

  • Unwanted advertisements and pop-ups
  • Suspicious browser behavior and redirects
  • Slow computer performance and crashes
  • Collection and transmission of personal data
  • Installation of additional malware

How to Remove PUP.MediaGet

  1. Boot your computer in Safe Mode with Networking to prevent PUP.MediaGet from loading and to give you access to the internet.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and run a full scan of your system to detect and remove PUP.MediaGet and any other malware.
  3. Uninstall any suspicious programs that may be related to PUP.MediaGet, and be cautious when installing new software to avoid bundling with other PUPs.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions and settings.
  5. Reboot your computer and run another scan with your anti-malware tool to ensure that PUP.MediaGet has been completely removed.

Conclusion

Removing PUP.MediaGet from your computer requires a combination of technical expertise and the right tools. By following the steps outlined above, you can help to ensure that your computer is free from this potentially unwanted program and any other malware that may be present. It's essential to be vigilant when downloading software and to use reputable anti-malware tools to protect your computer and personal data from future threats. Remember to always prioritize your computer's security and take immediate action if you suspect that you have been infected with PUP.MediaGet or any other type of malware.

Analysis Report

General information

Family Name: PUP.MediaGet
Packers: UPX
Signature status: Self Signed

Known Samples

MD5: 743def049bb61665ebe4b03c3b625f1c
SHA1: 64a6a2700d20062be66f3f7491b681f923863748
SHA256: AB1C50EA8E22B46977540DDF4BCF32CCC7B6522A277ECE9C7D40B62A8BFF7D57
File Size: 7.37 MB, 7370984 bytes
MD5: 53f5e633ce66a614dd7ecf208807a24c
SHA1: 19ca10cc12f8152567781ef9eaa3c1a6cf7a60d2
SHA256: 9C0191ECABD85227E9D40D4455DE3D14C53C5AEC219E0073DE083D6720CB21B1
File Size: 686.59 KB, 686591 bytes
MD5: 5407d3e933ea702edd85c8143814998c
SHA1: b4e60529c7a45512216b5a0e88cbf653e6a1a7f7
SHA256: 59CFDB16C328D75E14E5D14A5F21A6F77B69EBDC8AA4A81299394BD450A51570
File Size: 632.67 KB, 632673 bytes
MD5: ede974c6d3ed331ed58f5b8360615c11
SHA1: 940c5628bc6f93e25cf0763a41b92f7ec1705cf1
SHA256: 59228CA30BCAD5389C265660A251C203F7A09D00E30B19863444AE24F4429A08
File Size: 1.01 MB, 1012376 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments
  • MediaGet installer
  • This installation was built with Inno Setup.
Company Name
  • MediaGet
  • MediaGet LLC
File Description
  • MediaGet installer
  • MediaGet Setup
File Version 1.0
Internal Name mediaget-installer
Legal Copyright Copyright (c) 2011 MediaGet LLC
Original Filename mediaget-installer.exe
Product Name
  • MediaGet
  • mediaget-installer Module
Product Version 1.0

Digital Signatures

Signer Root Status
Media Get LLC Media Get LLC Self Signed

Block Information

Similar Families

  • MediaGet.A

Files Modified

File Attributes
\device\namedpipe\dav rpc service Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\srvsvc Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\wkssvc Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\explorer\iconcache_16.db Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\explorer\iconcache_idx.db Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-4tv4j.tmp\64a6a2700d20062be66f3f7491b681f923863748_0007370984.tmp Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\explorer\mountpoints2\##10.200.31.10#amas::_labelfromdesktopini RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
User Data Access
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
Keyboard Access
  • GetKeyState

Shell Command Execution

"C:\Users\Ekfmquit\AppData\Local\Temp\is-4TV4J.tmp\64a6a2700d20062be66f3f7491b681f923863748_0007370984.tmp" /SL5="$10280,6975602,141312,c:\users\user\downloads\64a6a2700d20062be66f3f7491b681f923863748_0007370984"

Related Posts

Trending

Most Viewed

Loading...