PUA

How to remove “PUA:Win32/MediaDrug”?

Malware Removal

The PUA:Win32/MediaDrug is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA:Win32/MediaDrug virus can do?

  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

dj-updates.com

How to determine PUA:Win32/MediaDrug?


File Info:

crc32: 9D0EE8F6
md5: f2f19e702f152f5b65784f9186b72300
name: ppi_8w.exe
sha1: ab139c1199bb49eaef15cd44bd68d157bebf8736
sha256: dcdc20d86a7772a7412e17aaf286b6c249f0484cf02af13427dcfc85ba765f15
sha512: 17987e9cc302dca3e6c790a27cb7d33ccbdba08aee6975d0c40ab801d8c47d46e898ccc25b6348242f9bc94af3518c924d3ce4aa9723d7b710125ec4ac49935c
ssdeep: 196608:NDXNV38Ax19PHeAHHoanjzSMqyN4ftKr/10oJTjZrJpptSZl1:NDXn38AxnPHeAPXSyXGoJTjlJ7tOT
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

LegalCopyright:
InternalName:
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName:
ProductVersion: 1.0.0.0
FileDescription: Setup VK DJ
OriginalFilename:
Translation: 0x0419 0x04e3

PUA:Win32/MediaDrug also known as:

MicroWorld-eScanGen:Variant.Ulise.98438
FireEyeGen:Variant.Ulise.98438
CAT-QuickHealPUA.MediadrugPMF.S11139230
Qihoo-360HEUR/QVM41.1.8E77.Malware.Gen
K7AntiVirusTrojan ( 0055dbb61 )
BitDefenderGen:Variant.Ulise.98438
K7GWTrojan ( 0055dbb61 )
APEXMalicious
GDataGen:Variant.Ulise.98438
Kasperskynot-a-virus:HEUR:AdWare.Win32.VKDJ.vho
RisingTrojan.Agent!8.B1E (TFE:dGZlOgWX43iDON7o0Q)
Ad-AwareGen:Variant.Ulise.98438
EmsisoftGen:Variant.Ulise.98438 (B)
F-SecureHeuristic.HEUR/AGEN.1044928
DrWebProgram.VKontakteDJ.74
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1044928
Endgamemalicious (high confidence)
ArcabitTrojan.Ulise.D18086
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.VKDJ.vho
MicrosoftPUA:Win32/MediaDrug
AhnLab-V3PUP/Win32.Helper.R325967
ALYacGen:Variant.Ulise.98438
MAXmalware (ai score=83)
VBA32BScope.Adware.VKDJ
MalwarebytesPUP.Optional.VkontakteDJ
PandaTrj/Genetic.gen
ESET-NOD32a variant of JS/Agent.OHD
IkarusTrojan.JS.Agent
FortinetW32/VKontakte.DJ!tr
AVGWin32:PUPX-gen [PUP]
AvastWin32:PUPX-gen [PUP]

How to remove PUA:Win32/MediaDrug?

PUA:Win32/MediaDrug removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment