InnoMod (PUA) malicious file

Malware Removal

The InnoMod (PUA) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Review

GridinSoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend to use GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the TRIAL period.
6-day free trial available.

What InnoMod (PUA) virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine InnoMod (PUA)?


File Info:

crc32: BEFE8176
md5: d8778159365a1dc689b08fa9bb072852
name: MediaGet_0022445721.exe
sha1: 3c3747b65a7812046a0a6530df239cd28d727650
sha256: 87500ac5ea638a4393c92fcf2558e0e233f47bf24587e56bfdf1da7b855bcf1d
sha512: 74ae5a01202b23ae18da71a3f63d40e3aa2c49eda8fcdf712b6c1967cc2b7c4fa61fa93c8c39ad8a4048832c03547d873e976e2c623d2326704824f34db94307
ssdeep: 49152:kttfZZsILZa+QZlyEP519feI17cOUYM/BYz346Ec8Ui4OLXvRFOv:Ctk9nPXfe+cOnKc8UDOZEv
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion: 3.7.2.1
CompanyName:
Comments: This installation was built with Inno Setup.
ProductName: Tufekepega
ProductVersion: 2.1
FileDescription: Tufekepega Setup
Translation: 0x0000 0x04b0

InnoMod (PUA) also known as:

DrWebProgram.MediaGet.160
CylanceUnsafe
K7AntiVirusRiskware ( 0040eff71 )
Invinceaheuristic
Endgamemalicious (high confidence)
SophosInnoMod (PUA)
WebrootW32.Adware.Gen
MicrosoftPUA:Win32/MediaGet
VBA32SigAdware.GLOBALMICROTRADINGPTE.LTD
RisingPacker.Win32.Obfuscator.n (CLASSIC)
GDataWin32.Application.InstallCore.LR@gen

How to remove InnoMod (PUA)?

InnoMod (PUA) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

Leave a Comment