Adware

About “Adware.MediaSave” infection

Malware Removal

The Adware.MediaSave is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.MediaSave virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Korean
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.filenolja.com

How to determine Adware.MediaSave?


File Info:

crc32: 4CBA28E6
md5: 56ab8a8ee68a421de7c7041a89d4ec94
name: 56AB8A8EE68A421DE7C7041A89D4EC94.mlw
sha1: e1bf2a9e90bf69694a7a078013828f6b9d904851
sha256: 6017388630c20a1a0a257ec574e40f74d424f41f7a3ca45b9f718b4145aa3eac
sha512: ddf14f1ddaf40b64a8de3708bd972001c7994f68df71828ef43adc14f23ce2fd747e77f4b8893b917de1f4f2df3386470a2ebc86b2c36b70641bcd3c548c7afc
ssdeep: 12288:7ZTHuBb23YYnjVzD25pn4w9U77VgNqyK/r1c6RdFst7veBoOS3KNoNclY20Bl:7Bu8jVzIp39SGNqyW1c6RdF0W+HGi
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName:
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: Download Launcher
ProductVersion: 1.0.0.0
FileDescription: Free Downloader (Mini webhard)
OriginalFilename:
Translation: 0x0412 0x03b5

Adware.MediaSave also known as:

K7AntiVirusTrojan ( 7000000f1 )
LionicRiskware.Win32.Filenolja.1!c
DrWebTrojan.PWS.Tibia.2231
CynetMalicious (score: 100)
ALYacGen:Variant.Ulise.198585
CylanceUnsafe
ZillyaTrojan.Delf.Win32.48832
SangforTrojan.Win32.Save.a
AlibabaDownloader:Win32/Filenolja.c1a482d0
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.e90bf6
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.Filenolja.A
APEXMalicious
AvastWin32:Adware-gen [Adw]
Kasperskynot-a-virus:Downloader.Win32.Filenolja.m
BitDefenderGen:Variant.Ulise.198585
NANO-AntivirusTrojan.Win32.Agent.cnepmv
MicroWorld-eScanGen:Variant.Ulise.198585
TencentMalware.Win32.Gencirc.10c2a26a
Ad-AwareGen:Variant.Ulise.198585
SophosGeneric ML PUA (PUA)
ComodoApplicUnwnt@#2lj50b7jyav4p
VIPRETrojan.Win32.Generic!BT
FireEyeGeneric.mg.56ab8a8ee68a421d
EmsisoftGen:Variant.Ulise.198585 (B)
SentinelOneStatic AI – Suspicious PE
AviraTR/Taranis.4023
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Occamy.C
ZoneAlarmnot-a-virus:Downloader.Win32.Filenolja.m
GDataGen:Variant.Ulise.198585
AhnLab-V3PUP/Win32.MulDown.R25854
McAfeeGenericRXAA-AA!56AB8A8EE68A
MAXmalware (ai score=100)
VBA32TScope.Trojan.Delf
MalwarebytesAdware.MediaSave
RisingAdware.Filenolja!1.C074 (CLASSIC)
YandexTrojan.GenAsa!d8WZ5VGsoRA
IkarusTrojan-GameThief.Win32.Tibia
FortinetW32/Delf.AOU!tr.dldr
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml

How to remove Adware.MediaSave?

Adware.MediaSave removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment