Categories: Adware

About “Adware.MediaSave” infection

The Adware.MediaSave is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.MediaSave virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Korean
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.filenolja.com

How to determine Adware.MediaSave?


File Info:

crc32: 4CBA28E6md5: 56ab8a8ee68a421de7c7041a89d4ec94name: 56AB8A8EE68A421DE7C7041A89D4EC94.mlwsha1: e1bf2a9e90bf69694a7a078013828f6b9d904851sha256: 6017388630c20a1a0a257ec574e40f74d424f41f7a3ca45b9f718b4145aa3eacsha512: ddf14f1ddaf40b64a8de3708bd972001c7994f68df71828ef43adc14f23ce2fd747e77f4b8893b917de1f4f2df3386470a2ebc86b2c36b70641bcd3c548c7afcssdeep: 12288:7ZTHuBb23YYnjVzD25pn4w9U77VgNqyK/r1c6RdFst7veBoOS3KNoNclY20Bl:7Bu8jVzIp39SGNqyW1c6RdF0W+HGitype: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: InternalName: FileVersion: 1.0.0.0CompanyName: LegalTrademarks: Comments: ProductName: Download LauncherProductVersion: 1.0.0.0FileDescription: Free Downloader (Mini webhard)OriginalFilename: Translation: 0x0412 0x03b5

Adware.MediaSave also known as:

K7AntiVirus Trojan ( 7000000f1 )
Lionic Riskware.Win32.Filenolja.1!c
DrWeb Trojan.PWS.Tibia.2231
Cynet Malicious (score: 100)
ALYac Gen:Variant.Ulise.198585
Cylance Unsafe
Zillya Trojan.Delf.Win32.48832
Sangfor Trojan.Win32.Save.a
Alibaba Downloader:Win32/Filenolja.c1a482d0
K7GW Trojan ( 7000000f1 )
Cybereason malicious.e90bf6
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Adware.Filenolja.A
APEX Malicious
Avast Win32:Adware-gen [Adw]
Kaspersky not-a-virus:Downloader.Win32.Filenolja.m
BitDefender Gen:Variant.Ulise.198585
NANO-Antivirus Trojan.Win32.Agent.cnepmv
MicroWorld-eScan Gen:Variant.Ulise.198585
Tencent Malware.Win32.Gencirc.10c2a26a
Ad-Aware Gen:Variant.Ulise.198585
Sophos Generic ML PUA (PUA)
Comodo ApplicUnwnt@#2lj50b7jyav4p
VIPRE Trojan.Win32.Generic!BT
FireEye Generic.mg.56ab8a8ee68a421d
Emsisoft Gen:Variant.Ulise.198585 (B)
SentinelOne Static AI – Suspicious PE
Avira TR/Taranis.4023
eGambit Unsafe.AI_Score_99%
Microsoft Trojan:Win32/Occamy.C
ZoneAlarm not-a-virus:Downloader.Win32.Filenolja.m
GData Gen:Variant.Ulise.198585
AhnLab-V3 PUP/Win32.MulDown.R25854
McAfee GenericRXAA-AA!56AB8A8EE68A
MAX malware (ai score=100)
VBA32 TScope.Trojan.Delf
Malwarebytes Adware.MediaSave
Rising Adware.Filenolja!1.C074 (CLASSIC)
Yandex Trojan.GenAsa!d8WZ5VGsoRA
Ikarus Trojan-GameThief.Win32.Tibia
Fortinet W32/Delf.AOU!tr.dldr
AVG Win32:Adware-gen [Adw]
Paloalto generic.ml

How to remove Adware.MediaSave?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

MSIL/GenKryptik.GXIZ information

The MSIL/GenKryptik.GXIZ is considered dangerous by lots of security experts. When this infection is active,…

3 weeks ago

Malware.AI.2789448175 (file analysis)

The Malware.AI.2789448175 is considered dangerous by lots of security experts. When this infection is active,…

3 weeks ago

Jalapeno.1878 removal instruction

The Jalapeno.1878 is considered dangerous by lots of security experts. When this infection is active,…

3 weeks ago

What is “Trojan.Heur3.LPT.YmKfaKBcBekib”?

The Trojan.Heur3.LPT.YmKfaKBcBekib is considered dangerous by lots of security experts. When this infection is active,…

3 weeks ago

How to remove “Worm.Win32.Vobfus.exmt”?

The Worm.Win32.Vobfus.exmt is considered dangerous by lots of security experts. When this infection is active,…

3 weeks ago

About “TrojanDownloader:Win32/Beebone.JO” infection

The TrojanDownloader:Win32/Beebone.JO is considered dangerous by lots of security experts. When this infection is active,…

3 weeks ago