WINCAB.SYS – Trojan OnLineGames

I will tell you in this post how to fix the issue manually and how to clean it automatically using a special powerful removal tool. You can download the removal program for free here:

Manual removal instructions:

WINCAB.SYS – Trojan OnLineGames removal

File MD5 Virus Alias
WINCAB.SYS 72e6f0b9d0e303112fe81961f4aaa244 Trojan OnLineGames
WINCAB.SYS 72e6f0b9d0e303112fe81961f4aaa244 Trojan Small

WINCAB.SYS size: 21516 bytes
WINCAB.SYS hash: 72E6F0B9D0E303112FE81961F4AAA244

Created files:

%SysDir%\wincab.sys
%Temp%\hyhhqff5.sys
%Temp%\yx7vbhes.sys

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\junzhang\Type: 01000000
HKLM\System\CurrentControlSet\Services\junzhang\Start: 03000000
HKLM\System\CurrentControlSet\Services\junzhang\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\junzhang\DisplayName: junzhang
HKLM\System\CurrentControlSet\Services\junzhang\ImagePath: %WinDir%\System32\wincab.sys

Detected by UnHackMe:

WINCAB.SYS
Default location: %SYSDIR%\WINCAB.SYS

Dropper information:
MD5: 082f232d677c98a73dd355857bea40b8
File size: 42013 bytes

Leave a Reply