PUP.MediaGet.B

The detection of PUP.MediaGet.B on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It is essential to understand the nature of this threat and take appropriate steps to remove it to prevent any potential harm.

What Is PUP.MediaGet.B?

PUP.MediaGet.B is a type of potentially unwanted program that may have been installed on your system without your knowledge or consent. PUPs are software applications that may not be malicious in nature but can still cause problems, such as displaying unwanted advertisements, collecting user data, or modifying system settings. The name PUP.MediaGet.B suggests that it may be related to a media-related application or service, but its exact purpose and behavior can vary.

How PUP.MediaGet.B Operates

PUPs like PUP.MediaGet.B can operate in various ways, including bundling with other software, exploiting vulnerabilities, or using social engineering tactics to trick users into installing them. Once installed, they may run in the background, consuming system resources, and potentially causing issues with system performance, stability, or security. PUPs can also collect user data, such as browsing habits or personal information, which can be used for targeted advertising or other malicious purposes.

Symptoms of Infection

Systems infected with PUP.MediaGet.B may exhibit various symptoms, including unwanted advertisements, pop-ups, or browser redirects. Users may also notice slower system performance, increased CPU usage, or unusual network activity. In some cases, PUPs can also cause issues with system stability, leading to crashes, freezes, or errors. If you suspect that your system is infected with PUP.MediaGet.B, it is crucial to take immediate action to remove it and prevent any further damage.

How to Remove PUP.MediaGet.B

  1. Boot your system in Safe Mode with Networking to prevent PUP.MediaGet.B from loading and to allow for a clean removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full system scan and detect any malicious components related to PUP.MediaGet.B.
  3. Uninstall any suspicious programs or applications that may be related to PUP.MediaGet.B from the Control Panel or Settings app.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform another full scan with your anti-malware tool to ensure that PUP.MediaGet.B has been completely removed.

Conclusion

Removing PUP.MediaGet.B from your system is essential to prevent any potential harm and restore your system's performance and security. By following the steps outlined above, you can effectively remove this potentially unwanted program and protect your system from similar threats in the future. It is also important to practice safe computing habits, such as regularly updating your operating system and software, using strong antivirus protection, and being cautious when installing new applications or clicking on links from unknown sources.

Analysis Report

General information

Family Name: PUP.MediaGet.B
Signature status: Root Not Trusted

Known Samples

MD5: 1cd47553cb6c7504f9804c9690c5b506
SHA1: b72e1ffc6ee5bdb53405848fb86711680e045d07
SHA256: 5C3C0CDBBFBEAEE6AD11D5187C91568A9AF24ED3DE351A6EB6746DE0C78D64E3
File Size: 4.81 MB, 4810240 bytes
MD5: 3c4328770b8dc1a0b6487c4cf46d9680
SHA1: b221fa9148c00e5c7ff514a24f0ae92701fa3138
SHA256: 79AC4DE1CBE4484D23D5B93CD269E7690076B29EC994E27ADF7ED73F6FFCFBDC
File Size: 4.65 MB, 4649423 bytes
MD5: c9fbc639435480a0be4a152e61c925ef
SHA1: 276d9879dc4d0fdedf684a0d23e621756c84ce3f
SHA256: 70D866CD89232D6753E5EDDA5E829678FBB6491D0FD485DC0862E0F971B4F1B8
File Size: 529.42 KB, 529416 bytes
MD5: ee0636a5d4268a5d1b2f618daa1c7535
SHA1: 877282c79f7c4c75924a8d144b6b5b8ad11edae3
SHA256: F2388417341CFAE06FA72F558D9FF870BCDFAC573D503B5A76C9657D63B925EA
File Size: 4.56 MB, 4557824 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments
  • PixelSee Player Installer
  • PixelSee Player Uninstaller
Company Name SIA Circle Solutions
File Description
  • PixelSee Player Installer
  • PixelSee Player Uninstaller
File Version
  • 14.0.0.0
  • 12.0.0.0
  • 1.0
Internal Name
  • pixelsee
  • pixelsee-uninstaller
Legal Copyright
  • Copyright � 2022-2023 SIA Circle Solutions
  • Copyright В© 2022-2023 SIA Circle Solutions
Original Filename
  • pixelsee
  • pixelsee-uninstaller
Private Build 0
Product Name PixelSee
Product Version
  • 14.0.0.0
  • 12.0.0.0
  • 1.0

Digital Signatures

Signer Root Status
SIA Circle Solutions Sectigo Public Code Signing Root R46 Root Not Trusted
SIA Circle Solutions Sectigo Public Code Signing Root R46 Hash Mismatch

File Traits

  • big overlay
  • HighEntropy
  • Installer Version
  • x86

Block Information

Total Blocks: 8,091
Potentially Malicious Blocks: 1,922
Whitelisted Blocks: 6,110
Unknown Blocks: 59

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x x x x x x x x x 0 0 x x x x 0 0 x x x 0 0 0 x 0 0 0 0 x 0 0 0 x 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x x x x x 0 x 0 0 x x 0 0 0 0 0 x x x x 0 x x x 0 0 0 0 x x 0 x x 0 0 0 x x 0 0 x 0 0 0 0 x x x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 x 0 x x 0 x x x 0 0 x x x x x x 0 x 0 0 x 0 x x x 0 0 x 0 0 0 x x 0 x 0 x x 0 0 x 0 x x 0 0 x x x x 0 x x 0 x 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 x x x 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 0 0 0 x 0 0 0 0 x 1 1 1 0 0 x 0 x 0 0 0 0 0 0 0 0 x x 0 x x x 0 x 0 0 0 0 x x x 0 0 0 x 0 0 x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 x 0 0 x x x x x x x x x x x 0 0 x x 0 0 x 0 x 0 0 0 0 x x 0 0 0 0 0 0 x x 0 0 x x 0 0 0 0 0 0 0 0 0 x x x x x 0 x x x 0 0 x 0 0 0 x x x 0 0 0 0 0 0 x x 1 1 1 1 1 1 0 x 0 0 x x 0 x x x x x x 0 0 0 0 0 x 0 0 0 x x 0 0 x x x 0 0 0 x 0 x 0 0 0 x 0 0 0 0 0 0 x x 0 0 0 0 x x 0 x x 0 x x x 0 0 x x x 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 x 0 0 0 x 0 0 x x 0 0 1 0 0 0 0 0 0 0 0 0 x x 0 x 0 x 0 0 0 0 x x x x x x 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 x x 0 x x 0 0 0 1 x x x x 0 0 x x x x 0 x x 0 0 0 x x x x 0 0 0 0 0 0 x 0 0 x x 0 0 0 0 0 0 0 0 0 x x x 0 0 x x x 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x x x 0 0 0 0 0 0 0 0 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 x 0 0 x x 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 x 0 x 0 0 0 0 x 0 0 x 0 0 x 0 x 0 0 0 x 0 0 x 0 x 0 0 x x 0 x 0 x x 0 x 0 x x 0 0 x 0 0 0 0 x 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 x x x x 0 0 0 0 0 x x 0 0 0 x 0 x x 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 x x x 0 x x x x 0 0 0 x 0 0 x 0 0 x 0 0 0 0 x 0 0 0 x x x x 0 0 0 0 x 0 0 0 0 0 0 x x x x x x x 0 0 0 0 0 x 0 0 x 0 x x 0 x 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 x 0 0 x 0 x x x 0 0 x 0 x 0 0 x 0 0 x x 0 x x x 0 x 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 x x x 0 0 0 x 0 x 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 0 0 0 0 0 0 0 0 x 0 0 x x x 0 0 0 x x 0 0 0 0 0 x x 0 0 x x x 0 0 0 0 x 0 x x x 0 0 0 0 x 0 0 x 0 0 0 x 0 0 x 0 x 0 0 0 0 0 x x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 x x 0 x 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 x 0 0 0 0 0 0 x x 0 0 0 x x 0 0 0 0 0 x x x x x 0 0 0 x x x 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 x x 0 x 0 0 x 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 x 0 0 0 0 x x x x 0 x 0 x x x 0 x 0 0 0 0 x x x x 0 x x x 0 x 0 0 x x 0 0 0 0 0 0 0 x 0 0 0 x x 0 0 0 0 0 0 0 0 0 x x x 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 1 x 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 1 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 x 0 x 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 x 0 0 0 0 0 0 0 0 x x x x 0 0 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x 0 0 x 0 0 x 0 0 0 0 0 0 0 x x x x x 0 0 0 0 0 x 0 x 0 0 x 0 0 x x 0 0 x x 0 0 0 0 0 0 0 x x 0 0 0 0 x 0 0 x 0 0 0 0 x x x 0 0 0 0 x x x 0 x x x 0 0 x 0 x 0 0 0 0 x x 0 0 x x x 0 x x 0 0 x x 0 x x x 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 x x x x x x 0 0 0 0 x x x x 0 0 0 x x 0 0 0 x x 0 0 x x x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x x 0 0 0 x 0 0 0 x 0 x x x x x x x x x x x 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MediaGet.B

Files Modified

File Attributes
c:\users\user\appdata\local\temp\pixelsee-uninstaller.exe Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\media get llc\mediaget2-systemscope\mediaget_info::hasdownloadedupdate false RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 � * �/��Y�d�� ��ރ�p��^�o�fVs} kP~ ��1��7 ���ﺃee����1��ie��r0�ve�� RegNtPreCreateKey
HKCU\software\pixelsee llc\pixelsee-systemscope\pixelsee_info::hasdownloadedupdate false RegNtPreCreateKey

Windows API Usage

Category API
Service Control
  • OpenSCManager
  • OpenService
Network Winsock2
  • WSAStartup
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • ShellExecute

Shell Command Execution

(NULL) C:\Users\Sgzwhjsf\AppData\Local\Temp\pixelsee-uninstaller.exe --uninstall

Related Posts

Trending

Most Viewed

Loading...