Solved! Use MEDIACASH.EXE (Trojan Downloader) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

MEDIACASH.EXE – Trojan Downloader removal

File MD5 Virus Alias
MEDIACASH.EXE 2afdac0ffb667aa8ed05662e889d2bfe Trojan Downloader
MEDIACASH.EXE 2afdac0ffb667aa8ed05662e889d2bfe Trojan SuspiciousFile
MEDIACASH.EXE 2afdac0ffb667aa8ed05662e889d2bfe Trojan Generic
MEDIACASH.EXE 2afdac0ffb667aa8ed05662e889d2bfe Trojan Delf

MEDIACASH.EXE size: 130560 bytes
MEDIACASH.EXE hash: 2AFDAC0FFB667AA8ED05662E889D2BFE

Created files:

%Program Files%\adobe\Media\mediacash.exe
%WinDir%\Njorth.bin
%SysDir%\ExtDLL.DLL
%SysDir%\ExtDLL32.DLL
%SysDir%\mediacash.exe
%SysDir%\RWDSK16.DLL
%SysDir%\RWDSKD32.DLL
%SysDir%\RWDSKDLL.DLL
%SysDir%\winmems.exe
%SysDir%\~~0sta.DLL

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\MediaCache3.1.2.4\Type: 10010000
HKLM\System\CurrentControlSet\Services\MediaCache3.1.2.4\Start: 02000000
HKLM\System\CurrentControlSet\Services\MediaCache3.1.2.4\DisplayName: Windows Presentation Foundation Media Cache 3.1.2.4
HKLM\System\CurrentControlSet\Services\MediaCache3.1.2.4\ImagePath: %Program Files%\adobe\Media\\mediacash.exe
HKLM\System\CurrentControlSet\Services\MediaCache3.1.2.4\Description: ??x? $?????l? ????? ??t?? ? ????? ?l?|? t??X?? ??X?

Detected by UnHackMe:

MEDIACASH.EXE
Default location: %SYSDIR%\MEDIACASH.EXE

Dropper information:
MD5: 051db9ca63d9b69027bf0f53f6f27000
File size: 1866752 bytes

Leave a Reply