WINCAB.SYS – Trojan OnLineGames

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

WINCAB.SYS – Trojan OnLineGames removal

FileMD5Virus Alias
WINCAB.SYS 72e6f0b9d0e303112fe81961f4aaa244 Trojan OnLineGames
WINCAB.SYS 72e6f0b9d0e303112fe81961f4aaa244 Trojan Small

WINCAB.SYS size: 21516 bytes
WINCAB.SYS hash: 72E6F0B9D0E303112FE81961F4AAA244

Created files:

%SysDir%\wincab.sys
%Temp%\hyhhqff5.sys
%Temp%\yx7vbhes.sys

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\junzhang\Type: 01000000
HKLM\System\CurrentControlSet\Services\junzhang\Start: 03000000
HKLM\System\CurrentControlSet\Services\junzhang\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\junzhang\DisplayName: junzhang
HKLM\System\CurrentControlSet\Services\junzhang\ImagePath: %WinDir%\System32\wincab.sys

Detected by UnHackMe:

WINCAB.SYS
Default location: %SYSDIR%\WINCAB.SYS

Dropper information:
MD5: 082f232d677c98a73dd355857bea40b8
File size: 42013 bytes

Leave a Reply