I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:
Free DownloadFully Functional 30-day Trial. No credit card is required.
Reviews. EULA. Privacy Policy. Uninstall.
WINMEMS.EXE – Trojan Artemis removal
File | MD5 | Virus Alias |
---|---|---|
WINMEMS.EXE | db176b7767b783786e47589dccc82637 | Trojan Artemis |
WINMEMS.EXE | db176b7767b783786e47589dccc82637 | Trojan (Suspicious File) |
WINMEMS.EXE | db176b7767b783786e47589dccc82637 | Trojan Generic |
WINMEMS.EXE | db176b7767b783786e47589dccc82637 | Trojan Downloader |
WINMEMS.EXE | db176b7767b783786e47589dccc82637 | Trojan Agent |
WINMEMS.EXE size: 374321 bytes
WINMEMS.EXE hash: DB176B7767B783786E47589DCCC82637
Created files:
%Program Files%\adobe\Media\mediacash.exe
%WinDir%\Njorth.bin
%SysDir%\ExtDLL.DLL
%SysDir%\ExtDLL32.DLL
%SysDir%\mediacash.exe
%SysDir%\RWDSK16.DLL
%SysDir%\RWDSKD32.DLL
%SysDir%\RWDSKDLL.DLL
%SysDir%\winmems.exe
%SysDir%\~~0sta.DLL
Autostart registry keys:
HKLM\System\CurrentControlSet\Services\MediaCache3.1.2.4\Type: 10010000
HKLM\System\CurrentControlSet\Services\MediaCache3.1.2.4\Start: 02000000
HKLM\System\CurrentControlSet\Services\MediaCache3.1.2.4\DisplayName: Windows Presentation Foundation Media Cache 3.1.2.4
HKLM\System\CurrentControlSet\Services\MediaCache3.1.2.4\ImagePath: %Program Files%\adobe\Media\\mediacash.exe
HKLM\System\CurrentControlSet\Services\MediaCache3.1.2.4\Description: ??x? $?????l? ????? ??t?? ? ????? ?l?|? t??X?? ??X?
Detected by UnHackMe:
WINMEMS.EXE
Default location: %SYSDIR%\WINMEMS.EXE
Dropper information:
MD5: 97bcbcb2ba3dae6e03dffa0244795dd2
File size: 1870336 bytes