The entire domain mediaget.com was blocked by Malwarebytes because it was associated with a potentially unwanted program (PUP) and some subdomains are blocked because they were associated with a Trojan.
This morning I started to receive the ballon with the message "succesfully blocked access to a potentially malicious website "IP number" (different each time) mediaget.exe then a Port number (again different each time)"
Search and delete these components [ Learn More ][ back ] There may be some components that are hidden. Please make sure you check the Search Hidden Files and Folders checkbox in the "More advanced options" option to include all hidden files and folders in the search result.
- %User Temp%\mediaget-installer-tmp\img\claro.jpg
- %User Temp%\mediaget-installer-tmp\img\pbar-ani.gif
- %User Temp%\mediaget-installer-tmp\img\kaspersky.gif
- %User Temp%\mediaget-installer-tmp\img\start.png
- %User Temp%\mediaget-installer-tmp\img\preloader.gif
- %User Temp%\mediaget-installer-tmp\index.template
- %User Temp%\mediaget-installer-tmp\img\orbitum.jpg
- %User Temp%\mediaget-installer-tmp\img\orbitum_logo.jpg
- %User Temp%\mediaget-installer-tmp\js\jquery.min.1.6.4.js
- %User Temp%\mediaget-installer-tmp\img\poster.jpg
- %User Temp%\mediaget-installer-tmp\js\jquery-ui.min.1.8.0.js
- %User Temp%\mediaget-installer-tmp\stub.html
- %User Temp%\mediaget-installer-tmp\img\line.jpg
- %User Temp%\mediaget-installer-tmp\img\yandex.jpg
- %AppDataLocal%\Microsoft\Internet Explorer\MSIMGSIZ.DAT
- %User Temp%\mediaget-installer-tmp\img\babylon.jpg
- %User Temp%\mediaget-installer-tmp\img\bg.png
- %User Temp%\mediaget-installer-tmp\index.html
To manually delete a malware/grayware file from an affected system:Search and delete these folders [ Learn More ][ back ] Please make sure you check the Search Hidden Files and Folders checkbox in the More advanced options option to include all hidden folders in the search result.
- %User Temp%\mediaget-installer-tmp
- %User Temp%\mediaget-installer-tmp\js
- %User Temp%\mediaget-installer-tmp\img
To delete malware/grayware/spyware folders: