PUA

PUP.Optional.MediaWatch removal tips

Malware Removal

The PUP.Optional.MediaWatch is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUP.Optional.MediaWatch virus can do?

  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Steals private information from local Internet browsers
  • Creates a copy of itself

How to determine PUP.Optional.MediaWatch?


File Info:

name: 0DE65EDC01433DB08283.mlw
path: /opt/CAPEv2/storage/binaries/71021200c96ab2b5b3d08d5b6ec027202c93eea6105e151795b72cc669cc2141
crc32: 78FADEFD
md5: 0de65edc01433db08283c01824c1f6d0
sha1: 3e29e25168f62e944f8f59f6d63c7dfe29c0cb0e
sha256: 71021200c96ab2b5b3d08d5b6ec027202c93eea6105e151795b72cc669cc2141
sha512: ce96c00867518312058c2156d511868b91a7a17f9398a8bd3b8116b6f9c1b9341a5c0eb8eef8bfab3a9cc79c71b282e4250671e179b0d3c5c175d0af48d8db8a
ssdeep: 6144:Ee34T8peZH+zpyuuz6GZkDOJ/7OafSH5KmrWym09x1C:igeZHkwuPikQ7lKH5p5H9x1C
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18B54229F2FD155B3E9DB703A0630FFADDAF2E48940D356874F5A1EAA3EE12876600140
sha3_384: 06454e361961b2f0391209b45a394169b43497b78e0c00ddd25cfb77982a65842805fba40f2661635b83409b338873fa
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:52

Version Info:

CompanyName: Media Watch
CompanyWebsite:
FileDescription:
FileVersion: 1.1
LegalCopyright:
ProductName: Media Watch home 1172
ProductVersion: 1.1
Translation: 0x0000 0x04e4

PUP.Optional.MediaWatch also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Amonetize.10
MicroWorld-eScanGen:Variant.Mikey.74011
FireEyeGen:Variant.Mikey.74011
CAT-QuickHealAdware.Bettersurf.PR5
ALYacGen:Variant.Mikey.74011
MalwarebytesPUP.Optional.MediaWatch
SangforAdware.Win32.Amonetize.Gen7
K7AntiVirusTrojan ( 0049026a1 )
AlibabaAdWare:Win32/Amonetize.fb662ed8
K7GWTrojan ( 0049026a1 )
Cybereasonmalicious.c01433
VirITTrojan.Win32.Siggen6.BXQM
CyrenW32/Amonetize.CN.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Amonetize.X potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002C0CGQ21
Kasperskynot-a-virus:AdWare.Win32.Amonetize.fqpg
BitDefenderGen:Variant.Mikey.74011
NANO-AntivirusTrojan.Win32.Amonetize.deipam
AvastWin32:Adware-gen [Adw]
TencentWin32.Adware.Amonetize.Kgc
EmsisoftApplication.InstallMon (A)
VIPREAdware.Bettersurf (fs)
TrendMicroTROJ_GEN.R002C0CGQ21
McAfee-GW-EditionBehavesLike.Win32.AdwareBSurf.dc
SophosBetterSurf (PUA)
SentinelOneStatic AI – Malicious PE
GDataWin32.Adware.Amonetize.M
JiangminAdWare.Amonetize.arbm
WebrootW32.Adware.Gen
AviraADWARE/Adware.Gen7
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwNS.28D0
SUPERAntiSpywarePUP.BetterSurf/Variant
MicrosoftTrojan:Win32/Occamy.C
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.Amonetize.R96015
McAfeeArtemis!0DE65EDC0143
VBA32Adware.Amonetize
CylanceUnsafe
APEXMalicious
RisingTrojan.Win32.Generic.17BE35A0 (C64:YzY0Og1COjyeFRbr)
YandexPUA.Amonetize!x4hpwO88bPY
FortinetNSIS/Amonetize.F!tr
AVGWin32:Adware-gen [Adw]
CrowdStrikewin/grayware_confidence_100% (D)

How to remove PUP.Optional.MediaWatch?

PUP.Optional.MediaWatch removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment