PUP.MediaGet.AA

The detection of PUP.MediaGet.AA on your system indicates the presence of a potentially unwanted program (PUP) that may be compromising your computer's security and performance. It is essential to understand the nature of this threat and take immediate action to remove it and prevent further damage.

What Is PUP.MediaGet.AA?

PUP.MediaGet.AA is a type of malware that is classified as a potentially unwanted program. This category of threats includes software that may not be malicious in the classical sense but can still cause significant disruptions to your system's functionality and pose risks to your personal data. PUPs often find their way onto computers through bundled software downloads, deceptive installation prompts, or exploits in software vulnerabilities.

How PUP.MediaGet.AA Operates

Once installed, PUP.MediaGet.AA may operate in various ways to achieve its goals, which could include displaying unwanted advertisements, collecting user data without consent, or modifying system settings to facilitate further malware infections. It may also consume system resources, leading to decreased performance and increased instability. The exact operational methods can vary, but the common denominator is the potential to cause harm or inconvenience to the user.

Symptoms of Infection

Symptoms of a PUP.MediaGet.AA infection can be subtle at first but may escalate over time. Common indicators include an unusual increase in pop-up advertisements, unfamiliar programs or toolbars installed on your browser, unexpected changes in your browser's homepage or search engine, and overall system slowdown. If you've noticed any of these symptoms, it's crucial to take action to remove the PUP and restore your system's health.

How to Remove PUP.MediaGet.AA

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for a clean environment to perform removal steps.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, which is capable of detecting and removing PUPs like PUP.MediaGet.AA. Perform a full scan of your system to identify all components of the malware.
  3. Uninstall any suspicious programs that were installed around the time the symptoms began. Be cautious and only remove programs you are certain are not necessary for your system's operation.
  4. Reset your web browsers (Chrome, Firefox, Edge, etc.) to their default settings to remove any malicious extensions or settings changes made by the PUP.
  5. Reboot your computer and perform another scan with your anti-malware tool to ensure that all components of PUP.MediaGet.AA have been removed.

Conclusion

Removing PUP.MediaGet.AA requires a combination of understanding the threat, using the right tools, and taking methodical steps to cleanse your system. It's also important to adopt preventive measures to avoid future infections, such as being cautious with downloads, keeping your software up to date, and regularly scanning your system for malware. By taking these steps, you can protect your computer, your data, and your online activities from the potential harm caused by PUPs like PUP.MediaGet.AA.

Analysis Report

General information

Family Name: PUP.MediaGet.AA
Packers: UPX
Signature status: No Signature

Known Samples

MD5: ca0b0d8bacc4c52207bbf3ba0bc10725
SHA1: ae2cbfc1a47e29858667eb980b0ae5ae6c5e4897
SHA256: 952C93A9AA1CE840782428FB654FD4497AD5C576B729E9F30D77AA0DB02CBBDC
File Size: 154.55 KB, 154546 bytes
MD5: e3974972e338105de6c8cb48f6a51a61
SHA1: 01d13df70903dbe96b90cf5a1f339caca83fc4bc
SHA256: A89D7F44A7073AB14B5E71E2EC7F595B33BA7501B94D89133457A885FB7718A2
File Size: 153.43 KB, 153434 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name MediaGet LLC
File Description MediaGet downloader module
File Version 1, 0, 0, 1
Internal Name mediaget_downloader
Legal Copyright Copyright 2010
Original Filename mediaget_downloader.exe
Product Name MediaGet downloader
Product Version 1, 0, 0, 1

File Traits

  • packed
  • x86

Block Information

Total Blocks: 1,011
Potentially Malicious Blocks: 84
Whitelisted Blocks: 922
Unknown Blocks: 5

Visual Map

0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 x x x ? 0 x ? x x x ? x 0 0 0 ? x 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 0 x 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x x x x x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 x x 0 0 0 0 0 x x 0 0 x x 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 x 0 0 0 x x 0 0 0 0 x x x x x 0 0 x x x x 0 x 0 0 x x x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 x x 0 0 0 x 0 0 0 x 0 x x x 0 0 x 0 0 x x 0 x 0 0 0 x 0 0 0 0 0 0 0 x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 1 1 0 0 0 0 2 0 0 1 0 0 2 0 0 0 0 1 0 0 1 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 1 1 0 1 0 0 0 0 0 1 1 0 2 3 0 1 0 0 1 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 1 1 0 0 1 0 0 2 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 1 0 0 0 1 1 0 0 0 0 1 1 3 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 1 0 0 1 0 0 0 0 1 0 1 0 1 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\appdata\local\temp\mediaget_installer.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\newdownload.torrent Generic Write,Read Attributes

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Network Wininet
  • HttpOpenRequest
  • HttpQueryInfo
  • HttpSendRequest
  • InternetConnect
  • InternetOpen
  • InternetReadFile
  • InternetSetOption
Network Winhttp
  • WinHttpOpen

Related Posts

Trending

Most Viewed

Loading...