PUA

About “PUABundler:Win32/MediaGet” infection

Malware Removal

The PUABundler:Win32/MediaGet is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUABundler:Win32/MediaGet virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine PUABundler:Win32/MediaGet?


File Info:

name: 378425AF387F2F19BBB4.mlw
path: /opt/CAPEv2/storage/binaries/16db93144d6a0d99eebe3770d2678c75a5bad63662f82d85a288b48b49a8764f
crc32: 6E5CAAF4
md5: 378425af387f2f19bbb4336decf908bf
sha1: 6b0dea0fac28e6a54c17e2fb890cd592fb211648
sha256: 16db93144d6a0d99eebe3770d2678c75a5bad63662f82d85a288b48b49a8764f
sha512: 1cd5b2785cbcc666136021e39f1ad0c3688aff1c83f6e2f12457f4270463fa10b361655b72d9bfe250cd1a2e43323247c2894561893825a2ac2247440ebe33c3
ssdeep: 3072:m9lKPtLoOTVh4p9DH6hmnxmCJ28cbGGo1pY5Wabprw5rEroQ9glyWVqg0SHCF1:OWLtT4fH6Qxmxlo1pYdNaAroHfVqg3Cz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18DE3021DD6B1DB39DCA74335DDEB40E85CB64E1BE190C21B06643FE828FE1D8C6615A2
sha3_384: 805fe3241f1064672a09c4e02a61d6a1c6a90b69f057b9b811736893aaf7b7cfe9df9f758666cbd934ad21357e94cf46
ep_bytes: 60be005049008dbe00c0f6ff57eb0b90
timestamp: 2011-07-01 11:12:34

Version Info:

CompanyName: MediaGet LLC
FileDescription: MediaGet downloader module
FileVersion: 1, 0, 0, 1
InternalName: mediaget_downloader
LegalCopyright: Copyright 2010
OriginalFilename: mediaget_downloader.exe
ProductName: MediaGet downloader
ProductVersion: 1, 0, 0, 1
Translation: 0x0409 0x04b0

PUABundler:Win32/MediaGet also known as:

BkavW32.AIDetectMalware
CyrenCloudW32/MediaGet.B.gen!Eldorado
LionicRiskware.Win32.MediaGet.1!c
Elasticmalicious (moderate confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.378425af387f2f19
CAT-QuickHealTrojanDownloader.Mediaget.A3
SkyhighBehavesLike.Win32.Generic.cc
Cylanceunsafe
ZillyaTrojan.FakeAV.Win32.194708
SangforPUP.Win32.Mediaget.Vum2
K7AntiVirusAdware ( 004b90011 )
AlibabaDownloader:Win32/MediaGet.63b30d29
K7GWAdware ( 004b90011 )
CrowdStrikewin/grayware_confidence_70% (D)
VirITTrojan.Win32.Generic.AXXK
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/MediaGet potentially unwanted
APEXMalicious
ClamAVWin.Trojan.Agent-321625
Kasperskynot-a-virus:Downloader.Win32.MediaGet.elg
NANO-AntivirusTrojan.Win32.FakeAV.dnqsgu
SUPERAntiSpywarePUP.MediaGet/Variant
TencentMalware.Win32.Gencirc.10bdeeed
EmsisoftApplication.MGet (A)
F-SecurePotentialRisk.PUA/MediaGet.I.1
DrWebProgram.MediaGet.4
TrendMicroTSPY_MEDIAGET_CA082940.TOMC
Trapminemalicious.moderate.ml.score
SophosGeneric Reputation PUA (PUA)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/JmGenGeneric.sc
WebrootW32.Malware.Gen
VaristW32/MediaGet.B.gen!Eldorado
AviraPUA/MediaGet.I.1
Antiy-AVLTrojan/Win32.FakeAV
XcitiumTrojWare.Win32.FakeAV.MES@4o4zrz
MicrosoftPUABundler:Win32/MediaGet
ZoneAlarmnot-a-virus:Downloader.Win32.MediaGet.elg
GDataWin32.Adware.MediaGet.C
GoogleDetected
McAfeeGeneric FakeAV.lp
DeepInstinctMALICIOUS
VBA32BScope.Downloader.Snojan
MalwarebytesPUP.Optional.MediaGet
TrendMicro-HouseCallTSPY_MEDIAGET_CA082940.TOMC
RisingDownloader.MediaGet!8.13A69 (TFE:5:AfuhjFEcNgK)
YandexTrojan.GenAsa!YugB/OGm8ps
IkarusPUA.Optional.Install
MaxSecureTrojan.Malware.300983.susgen
FortinetAdware/MediaGet

How to remove PUABundler:Win32/MediaGet?

PUABundler:Win32/MediaGet removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment