Jump to content

Removal instructions for Media Downloader


Recommended Posts

  • Staff

What is Media Downloader?

The Malwarebytes research team has determined that Media Downloader is adware. These adware applications display advertisements not originating from the sites you are browsing.

How do I know if my computer is affected by Media Downloader?

This is how the main screen of the applictaion looks:

main.png

You may see this icon on your desktop:

icons.png

and this entry in your list of installed programs:

warning4.png

and these warnings:

warning1.png

warning2.png

How did Media Downloader get on my computer?

Adware applications use different methods for distributing themselves. This particular one was offered as a download manager for videos.

How do I remove Media Downloader?

Our program Malwarebytes Anti-Malware can detect and remove this potentially unwanted program.

  • Please download Malwarebytes Anti-Malware to your desktop.
  • Double-click mbam-setup-version.exe and follow the prompts to install the program.
  • At the end, be sure a check-mark is placed next to the following:
    • Enable free trial of Malwarebytes Anti-Malware Premium
    • Launch Malwarebytes Anti-Malware
  • Then click Finish.
  • If an update is found, you will be prompted to download and install the latest version.
  • Once the program has loaded, select Scan now. Or select the Threat Scan from the Scan menu.
  • When the scan is complete , make sure that everything is set to "Quarantine", and click Apply Actions.
  • Reboot your computer if prompted.
Is there anything else I need to do to get rid of Media Downloader?
  • The shortcut called Media Downloader on the desktop can be deleted if it belonged to the potentially unwanted application.
How would the full version of Malwarebytes Anti-Malware help protect me?

We hope our application and this guide have helped you eradicate this hijacker.

As you can see below the full version of Malwarebytes Anti-Malware would have protected you against the Media Downloader adware. �It would have warned you before the rogue could install itself, giving you a chance to stop it before it became too late.

protection1.png

Technical details for experts

You will see these signs in a HijackThis log:

O23 - Service: EZ Software Updater - Unknown owner - C:\Program Files\EZ Software Updater\EZ Software Updater.exe
Alterations made by the installer:

File system details  ---------------------------------------------    Adds the folder C:\Program Files\EZ Software Updater       Adds the file cfg.ini"="1/8/2015 8:23 AM, 317 bytes, A       Adds the file EZ Software Updater.exe"="9/7/2014 2:59 PM, 220672 bytes, A       Adds the file unins000.dat"="1/8/2015 8:23 AM, 18161 bytes, A       Adds the file unins000.exe"="1/8/2015 8:23 AM, 1164489 bytes, A       Adds the file updateStatus.ini"="1/8/2015 8:23 AM, 322 bytes, A    Adds the folder C:\Program Files\EZ Software Updater\lib       Adds the file EZ Software Updater.dll"="9/7/2014 2:59 PM, 263680 bytes, A    Adds the folder C:\Program Files\EZ Software Updater\temp       Adds the file response.ini"="1/8/2015 8:23 AM, 39 bytes, A       Adds the file update.ini"="1/8/2015 8:23 AM, 322 bytes, A    Adds the folder C:\Program Files\EZ Software Updater\update    Adds the folder C:\Program Files\Media Downloader       Adds the file appicon.ico"="7/2/2014 6:05 PM, 9662 bytes, A       Adds the file arrayFunctions.js"="7/2/2014 9:44 PM, 537 bytes, A       Adds the file browseDirectory.vbe"="6/8/2014 1:46 PM, 409 bytes, A       Adds the file Downloader.js"="7/3/2014 5:59 PM, 8680 bytes, A       Adds the file eula.txt"="7/2/2014 10:58 PM, 15454 bytes, A       Adds the file ffmpeg.exe"="12/12/2011 9:52 PM, 17468416 bytes, A       Adds the file fileTypeRecognizer.js"="7/3/2014 11:46 AM, 2040 bytes, A       Adds the file location.js"="6/5/2014 6:20 PM, 156 bytes, A       Adds the file MediaDownloader.hta"="7/3/2014 2:25 PM, 3647 bytes, A       Adds the file playButtonSettings.js"="7/3/2014 11:25 AM, 1803 bytes, A       Adds the file statusMsg.js"="7/3/2014 11:15 AM, 3245 bytes, A       Adds the file style.css"="7/3/2014 10:44 AM, 5402 bytes, A       Adds the file uiActions.js"="7/3/2014 10:58 AM, 2741 bytes, A       Adds the file unins000.dat"="1/8/2015 8:23 AM, 8921 bytes, A       Adds the file unins000.exe"="1/8/2015 8:23 AM, 1169609 bytes, A       Adds the file Video.js"="7/2/2014 3:11 PM, 728 bytes, A       Adds the file videoDownload.js"="7/3/2014 5:44 PM, 2634 bytes, A    Adds the folder C:\Program Files\Media Downloader\skin       Adds the file appicon.ico"="7/2/2014 6:05 PM, 9662 bytes, A       Adds the file background.jpg"="7/2/2014 6:59 PM, 35266 bytes, A       Adds the file button_click.png"="11/20/2013 11:30 AM, 1311 bytes, A       Adds the file button_disabled.png"="7/2/2014 6:14 PM, 3380 bytes, A       Adds the file button_hover.png"="7/2/2014 6:11 PM, 3150 bytes, A       Adds the file button_standard.png"="11/20/2013 11:30 AM, 1298 bytes, A       Adds the file download.PNG"="7/2/2014 6:12 PM, 3126 bytes, A       Adds the file file_options.png"="5/22/2014 4:22 PM, 455 bytes, A       Adds the file help_options.png"="5/22/2014 4:49 PM, 395 bytes, A       Adds the file loader.gif"="6/9/2014 1:16 PM, 2883 bytes, A       Adds the file menu.PNG"="5/22/2014 3:59 PM, 371 bytes, A       Adds the file play.PNG"="7/2/2014 6:13 PM, 3071 bytes, A       Adds the file status.PNG"="5/22/2014 1:15 PM, 1911 bytes, A    Adds the folder C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Downloader       Adds the file Media Downloader.lnk"="1/8/2015 8:23 AM, 1078 bytes, A       Adds the file Uninstall Media Downloader.lnk"="1/8/2015 8:23 AM, 1043 bytes, A    In the existing folder C:\Users\Public\Desktop       Adds the file Media Downloader.lnk"="1/8/2015 8:23 AM, 1974 bytes, ARegistry details  ------------------------------------------    [HKEY_LOCAL_MACHINE\SOFTWARE\EZ Software Updater]       "LastUpdateTimeMSec"="REG_DWORD", -111505736       "Version"="REG_SZ", "1.2.0.4"    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EZ Software Updater_is1]       "DisplayIcon"="REG_SZ", "setup.ico"       "DisplayName"="REG_SZ", "EZ Software Updater version 1.2.0.4"       "DisplayVersion"="REG_SZ", "1.2.0.4"       "EstimatedSize"="REG_DWORD", 1588       "Inno Setup: App Path"="REG_SZ", "C:\Program Files\EZ Software Updater"       "Inno Setup: Icon Group"="REG_SZ", "EZ Software Updater"       "Inno Setup: Language"="REG_SZ", "default"       "Inno Setup: Setup Version"="REG_SZ", "5.5.3 (u)"       "Inno Setup: User"="REG_SZ", "Malwarebytes"       "InstallDate"="REG_SZ", "20150108"       "InstallLocation"="REG_SZ", "C:\Program Files\EZ Software Updater\"       "MajorVersion"="REG_DWORD", 1       "MinorVersion"="REG_DWORD", 2       "NoModify"="REG_DWORD", 1       "NoRepair"="REG_DWORD", 1       "QuietUninstallString"="REG_SZ", ""C:\Program Files\EZ Software Updater\unins000.exe" /SILENT"       "UninstallString"="REG_SZ", ""C:\Program Files\EZ Software Updater\unins000.exe""    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Media Downloader_is1]       "DisplayIcon"="REG_SZ", "W:\Development\Projects\mediaDownloader\appicon.ico"       "DisplayName"="REG_SZ", "Media Downloader version 1.5"       "DisplayVersion"="REG_SZ", "1.5"       "EstimatedSize"="REG_DWORD", 18299       "Inno Setup: App Path"="REG_SZ", "C:\Program Files\Media Downloader"       "Inno Setup: Icon Group"="REG_SZ", "Media Downloader"       "Inno Setup: Language"="REG_SZ", "default"       "Inno Setup: Setup Version"="REG_SZ", "5.5.3 (u)"       "Inno Setup: User"="REG_SZ", "Malwarebytes"       "InstallDate"="REG_SZ", "20150108"       "InstallLocation"="REG_SZ", "C:\Program Files\Media Downloader\"       "MajorVersion"="REG_DWORD", 1       "MinorVersion"="REG_DWORD", 5       "NoModify"="REG_DWORD", 1       "NoRepair"="REG_DWORD", 1       "Publisher"="REG_SZ", "Media Downloader"       "QuietUninstallString"="REG_SZ", ""C:\Program Files\Media Downloader\unins000.exe" /SILENT"       "UninstallString"="REG_SZ", ""C:\Program Files\Media Downloader\unins000.exe""    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\EZ Software Updater]       "DisplayName"="REG_SZ", "EZ Software Updater"       "ErrorControl"="REG_DWORD", 1       "ImagePath"="REG_EXPAND_SZ, "C:\Program Files\EZ Software Updater\EZ Software Updater.exe"       "ObjectName"="REG_SZ", "LocalSystem"       "Start"="REG_DWORD", 2       "Type"="REG_DWORD", 16
Malwarebytes Anti-Malware log:

Malwarebytes Anti-Malwarewww.malwarebytes.orgScan Date: 1/8/2015Scan Time: 8:28:45 AMLogfile: mbamMediaDownloader.txtAdministrator: YesVersion: 2.00.4.1028Malware Database: v2015.01.08.06Rootkit Database: v2015.01.07.01License: FreeMalware Protection: DisabledMalicious Website Protection: DisabledSelf-protection: DisabledOS: Windows 7 Service Pack 1CPU: x86File System: NTFSUser: MalwarebytesScan Type: Threat ScanResult: CompletedObjects Scanned: 287236Time Elapsed: 3 min, 24 secMemory: EnabledStartup: EnabledFilesystem: EnabledArchives: EnabledRootkits: DisabledHeuristics: EnabledPUP: EnabledPUM: EnabledProcesses: 1PUP.Optional.EZSoftware.A, C:\Program Files\EZ Software Updater\EZ Software Updater.exe, 3484, Delete-on-Reboot, [21d5e01460296bcb74b478fec53ef808]Modules: 0(No malicious items detected)Registry Keys: 3PUP.Optional.EZSoftware.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EZ Software Updater, Quarantined, [21d5e01460296bcb74b478fec53ef808], PUP.Optional.EZSoftware.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\EZ Software Updater_is1, Quarantined, [21d5e01460296bcb74b478fec53ef808], PUP.Optional.EZSoftware.A, HKLM\SOFTWARE\EZ Software Updater, Quarantined, [5e98569e642505319c8d4432ec17b947], Registry Values: 0(No malicious items detected)Registry Data: 0(No malicious items detected)Folders: 4PUP.Optional.EZSoftware.A, C:\Program Files\EZ Software Updater, Delete-on-Reboot, [21d5e01460296bcb74b478fec53ef808], PUP.Optional.EZSoftware.A, C:\Program Files\EZ Software Updater\lib, Quarantined, [21d5e01460296bcb74b478fec53ef808], PUP.Optional.EZSoftware.A, C:\Program Files\EZ Software Updater\temp, Quarantined, [21d5e01460296bcb74b478fec53ef808], PUP.Optional.EZSoftware.A, C:\Program Files\EZ Software Updater\update, Quarantined, [21d5e01460296bcb74b478fec53ef808], Files: 9PUP.Optional.Bundlore, C:\Users\{username}\Desktop\MediaDownloader.exe, Quarantined, [787e46aea6e341f5b59caad64bba8f71], PUP.Optional.EZSoftware.A, C:\Program Files\EZ Software Updater\unins000.dat, Quarantined, [21d5e01460296bcb74b478fec53ef808], PUP.Optional.EZSoftware.A, C:\Program Files\EZ Software Updater\cfg.ini, Quarantined, [21d5e01460296bcb74b478fec53ef808], PUP.Optional.EZSoftware.A, C:\Program Files\EZ Software Updater\EZ Software Updater.exe, Delete-on-Reboot, [21d5e01460296bcb74b478fec53ef808], PUP.Optional.EZSoftware.A, C:\Program Files\EZ Software Updater\unins000.exe, Quarantined, [21d5e01460296bcb74b478fec53ef808], PUP.Optional.EZSoftware.A, C:\Program Files\EZ Software Updater\updateStatus.ini, Quarantined, [21d5e01460296bcb74b478fec53ef808], PUP.Optional.EZSoftware.A, C:\Program Files\EZ Software Updater\lib\EZ Software Updater.dll, Quarantined, [21d5e01460296bcb74b478fec53ef808], PUP.Optional.EZSoftware.A, C:\Program Files\EZ Software Updater\temp\response.ini, Quarantined, [21d5e01460296bcb74b478fec53ef808], PUP.Optional.EZSoftware.A, C:\Program Files\EZ Software Updater\temp\update.ini, Quarantined, [21d5e01460296bcb74b478fec53ef808], Physical Sectors: 0(No malicious items detected)(end)
As mentioned before the full version of Malwarebytes Anti-Malware could have protected your computer against this threat.

We use different ways of protecting your computer(s):

  • Dynamically Blocks Malware Sites & Servers
  • Malware Execution Prevention
Save yourself the hassle and get protected.
Link to post
Share on other sites

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.