General Info

File name

RWipeAndClean20.exe

Full analysis
https://app.any.run/tasks/f10e315b-607a-4b75-8dff-3b76b603b1b0
Verdict
Malicious activity
Analysis date
12/6/2018, 13:55:56
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows
MD5

cff1ad9ef6eaef95ce9733d9df05c11b

SHA1

2fea4c2e906907d8707a9fb0eb1f34d55691bc8a

SHA256

73c12b3d462e7425814490e6f3edf38a703052732512fb51f66a6cb5437f87b5

SSDEEP

393216:xNUujjjjDjjNIag/Zw5bqBI4GEkRdS2Cxsx9/kF57VtwnIYThI6Hy0tKRp8vyL0N:xNxjjjjDjjuaZBp2jjShPHk2nJ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
300 seconds
Additional time used
240 seconds
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Loads dropped or rewritten executable
  • RwcRun.exe (PID: 2616)
  • regsvr32.exe (PID: 2888)
  • RwcRun.exe (PID: 3700)
Application was dropped or rewritten from another process
  • RwcRun.exe (PID: 2616)
  • RwcRun.exe (PID: 3108)
  • _RwcSetup.exe (PID: 2900)
  • RwcRun.exe (PID: 3700)
Registers / Runs the DLL via REGSVR32.EXE
  • _RwcSetup.exe (PID: 2900)
Creates files in the program directory
  • _RwcSetup.exe (PID: 2900)
Creates COM task schedule object
  • regsvr32.exe (PID: 2888)
Application launched itself
  • RwcRun.exe (PID: 3700)
Executable content was dropped or overwritten
  • RWipeAndClean20.tmp (PID: 2704)
  • _RwcSetup.exe (PID: 2900)
  • RWipeAndClean20.exe (PID: 312)
  • RWipeAndClean20.exe (PID: 3448)
Reads Windows owner or organization settings
  • RWipeAndClean20.tmp (PID: 2704)
Reads the Windows organization settings
  • RWipeAndClean20.tmp (PID: 2704)
Creates a software uninstall entry
  • RWipeAndClean20.tmp (PID: 2704)
Creates files in the program directory
  • RWipeAndClean20.tmp (PID: 2704)
Application was dropped or rewritten from another process
  • RWipeAndClean20.tmp (PID: 2704)
  • RWipeAndClean20.tmp (PID: 2376)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win32 Executable (generic) (42.6%)
.exe
|   Win16/32 Executable Delphi generic (19.5%)
.exe
|   Generic Win/DOS Executable (18.9%)
.exe
|   DOS Executable Generic (18.9%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2018:06:14 15:27:46+02:00
PEType:
PE32
LinkerVersion:
2.25
CodeSize:
66560
InitializedDataSize:
628736
UninitializedDataSize:
null
EntryPoint:
0x1181c
OSVersion:
5
ImageVersion:
6
SubsystemVersion:
5
Subsystem:
Windows GUI
FileVersionNumber:
0.0.0.0
ProductVersionNumber:
0.0.0.0
FileFlagsMask:
0x003f
FileFlags:
(none)
FileOS:
Win32
ObjectFileType:
Executable application
FileSubtype:
null
LanguageCode:
Neutral
CharacterSet:
Unicode
Comments:
This installation was built with Inno Setup.
CompanyName:
R-Tools Technology Inc.
FileDescription:
R-Wipe & Clean Setup
FileVersion:
LegalCopyright:
ProductName:
R-Wipe & Clean
ProductVersion:
20.0.2219
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
14-Jun-2018 13:27:46
Detected languages
English - United States
Comments:
This installation was built with Inno Setup.
CompanyName:
R-Tools Technology Inc.
FileDescription:
R-Wipe & Clean Setup
FileVersion:
null
LegalCopyright:
null
ProductName:
R-Wipe & Clean
ProductVersion:
20.0.2219
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0050
Pages in file:
0x0002
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x000F
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x001A
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x00000100
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
8
Time date stamp:
14-Jun-2018 13:27:46
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x0000F25C 0x0000F400 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 6.37588
.itext 0x00011000 0x00000FA4 0x00001000 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 5.77877
.data 0x00012000 0x00000C8C 0x00000E00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 2.30283
.bss 0x00013000 0x000056BC 0x00000000 IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0
.idata 0x00019000 0x00000E04 0x00001000 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 4.59781
.tls 0x0001A000 0x00000008 0x00000000 IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0
.rdata 0x0001B000 0x00000018 0x00000200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 0.204488
.rsrc 0x0001C000 0x0009762C 0x00097800 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 5.92226
Resources
1

2

3

4

5

6

7

8

9

10

11

12

4091

4092

4093

4094

4095

4096

11111

CHARTABLE

DVCLAL

PACKAGEINFO

MAINICON

Imports
    oleaut32.dll

    advapi32.dll

    user32.dll

    kernel32.dll

    comctl32.dll

Exports

    No exports.

Screenshots

Processes

Total processes
44
Monitored processes
9
Malicious processes
2
Suspicious processes
3

Behavior graph

+
drop and start start drop and start drop and start rwipeandclean20.exe rwipeandclean20.tmp no specs rwipeandclean20.exe rwipeandclean20.tmp _rwcsetup.exe regsvr32.exe no specs rwcrun.exe no specs rwcrun.exe rwcrun.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3448
CMD
"C:\Users\admin\AppData\Local\Temp\RWipeAndClean20.exe"
Path
C:\Users\admin\AppData\Local\Temp\RWipeAndClean20.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
R-Tools Technology Inc.
Description
R-Wipe & Clean Setup
Version
Modules
Image
c:\users\admin\appdata\local\temp\rwipeandclean20.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\version.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shell32.dll
c:\users\admin\appdata\local\temp\is-usah0.tmp\rwipeandclean20.tmp

PID
2376
CMD
"C:\Users\admin\AppData\Local\Temp\is-USAH0.tmp\RWipeAndClean20.tmp" /SL5="$2011C,18195316,696320,C:\Users\admin\AppData\Local\Temp\RWipeAndClean20.exe"
Path
C:\Users\admin\AppData\Local\Temp\is-USAH0.tmp\RWipeAndClean20.tmp
Indicators
No indicators
Parent process
RWipeAndClean20.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Setup/Uninstall
Version
51.1052.0.0
Modules
Image
c:\users\admin\appdata\local\temp\is-usah0.tmp\rwipeandclean20.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\version.dll
c:\windows\system32\mpr.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shdocvw.dll

PID
312
CMD
"C:\Users\admin\AppData\Local\Temp\RWipeAndClean20.exe" /SPAWNWND=$20116 /NOTIFYWND=$2011C
Path
C:\Users\admin\AppData\Local\Temp\RWipeAndClean20.exe
Indicators
Parent process
RWipeAndClean20.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
R-Tools Technology Inc.
Description
R-Wipe & Clean Setup
Version
Modules
Image
c:\users\admin\appdata\local\temp\rwipeandclean20.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\version.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shell32.dll
c:\users\admin\appdata\local\temp\is-r9v75.tmp\rwipeandclean20.tmp

PID
2704
CMD
"C:\Users\admin\AppData\Local\Temp\is-R9V75.tmp\RWipeAndClean20.tmp" /SL5="$30122,18195316,696320,C:\Users\admin\AppData\Local\Temp\RWipeAndClean20.exe" /SPAWNWND=$20116 /NOTIFYWND=$2011C
Path
C:\Users\admin\AppData\Local\Temp\is-R9V75.tmp\RWipeAndClean20.tmp
Indicators
Parent process
RWipeAndClean20.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Setup/Uninstall
Version
51.1052.0.0
Modules
Image
c:\users\admin\appdata\local\temp\is-r9v75.tmp\rwipeandclean20.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\version.dll
c:\windows\system32\mpr.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\rstrtmgr.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\imageres.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\msftedit.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll
c:\program files\r-wipe & clean\_rwcsetup.exe

PID
2900
CMD
"C:\Program Files\R-Wipe & Clean\_RwcSetup.exe" /installrwc
Path
C:\Program Files\R-Wipe & Clean\_RwcSetup.exe
Indicators
Parent process
RWipeAndClean20.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
R-Tools Inc.
Description
R-Wipe & Clean Installer
Version
20.0.0.2219
Modules
Image
c:\program files\r-wipe & clean\_rwcsetup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\profapi.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\regsvr32.exe

PID
2888
CMD
regsvr32 /s RwcShl32.dll
Path
C:\Windows\system32\regsvr32.exe
Indicators
No indicators
Parent process
_RwcSetup.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft(C) Register Server
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\program files\r-wipe & clean\rwcshl32.dll

PID
3108
CMD
"C:\Program Files\R-Wipe & Clean\RwcRun.exe"
Path
C:\Program Files\R-Wipe & Clean\RwcRun.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
3221226540
Version:
Company
R-Tools Inc.
Description
R-Wipe & Clean
Version
20.0.0.2219
Modules
Image
c:\program files\r-wipe & clean\rwcrun.exe
c:\systemroot\system32\ntdll.dll

PID
3700
CMD
"C:\Program Files\R-Wipe & Clean\RwcRun.exe"
Path
C:\Program Files\R-Wipe & Clean\RwcRun.exe
Indicators
Parent process
––
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
R-Tools Inc.
Description
R-Wipe & Clean
Version
20.0.0.2219
Modules
Image
c:\program files\r-wipe & clean\rwcrun.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\version.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\profapi.dll
c:\windows\system32\sspicli.dll
c:\program files\r-wipe & clean\rwcdialogs.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\cryptbase.dll
c:\program files\r-wipe & clean\rwcstrings.dll
c:\program files\r-wipe & clean\rwcimages.dll
c:\program files\r-wipe & clean\rwcclassic.dll
c:\windows\system32\apphelp.dll

PID
2616
CMD
"C:\Program Files\R-Wipe & Clean\RwcRun.exe" /changeinterface
Path
C:\Program Files\R-Wipe & Clean\RwcRun.exe
Indicators
No indicators
Parent process
RwcRun.exe
User
admin
Integrity Level
HIGH
Version:
Company
R-Tools Inc.
Description
R-Wipe & Clean
Version
20.0.0.2219
Modules
Image
c:\program files\r-wipe & clean\rwcrun.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\version.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\r-wipe & clean\rwcclassic.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\oleaut32.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\propsys.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\profapi.dll
c:\windows\system32\sspicli.dll
c:\program files\r-wipe & clean\rwcimages.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\slc.dll
c:\windows\system32\imageres.dll
c:\windows\system32\uiribbon.dll
c:\windows\system32\uiribbonres.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\eventvwr.exe
c:\windows\explorer.exe
c:\windows\system32\cmd.exe
c:\windows\system32\control.exe
c:\program files\windows defender\msascui.exe
c:\windows\system32\wbem\winmgmt.exe
c:\program files\adobe\acrobat reader dc\reader\acrord32.exe
c:\program files\winrar\winrar.exe
c:\program files\google\chrome\application\chrome.exe
c:\program files\internet explorer\iexplore.exe
c:\program files\mozilla firefox\firefox.exe
c:\program files\opera\opera.exe
c:\program files\microsoft\skype for desktop\skype.exe
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\program files\filezilla ftp client\filezilla.exe
c:\program files\videolan\vlc\vlc.exe
c:\progra~1\micros~1\office14\excel.exe
c:\progra~1\micros~1\office14\onenote.exe
c:\progra~1\micros~1\office14\powerpnt.exe
c:\progra~1\micros~1\office14\winword.exe
c:\progra~1\micros~1\office14\msaccess.exe
c:\progra~1\micros~1\office14\mspub.exe
c:\program files\java\jre1.8.0_92\bin\javaws.exe
c:\windows\system32\fxscover.exe
c:\windows\system32\mmc.exe
c:\windows\system32\mspaint.exe
c:\windows\system32\perfmon.exe
c:\windows\system32\mstsc.exe
c:\windows\system32\wfs.exe
c:\program files\windows mail\winmail.exe
c:\windows\ehome\ehshell.exe
c:\program files\windows media player\wmplayer.exe
c:\program files\windows nt\accessories\wordpad.exe
c:\windows\system32\xpsrchvw.exe
c:\program files\r-wipe & clean\rwcstrings.dll

Registry activity

Total events
630
Read events
577
Write events
52
Delete events
1

Modification events

PID
Process
Operation
Key
Name
Value
2704
RWipeAndClean20.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Owner
900A0000CA807320638DD401
2704
RWipeAndClean20.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
SessionHash
3694ED5DFD82081B56C347B790791A5A0DCCA628BC0DF6553FC21876BACF5169
2704
RWipeAndClean20.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Sequence
1
2704
RWipeAndClean20.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
RegFiles0000
C:\Program Files\R-Wipe & Clean\_RwcAdds.dll
2704
RWipeAndClean20.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
RegFilesHash
E4550ADD3A11790A8A55165D086E82178B95255051F2AF937D5749BD7F11AB05
2704
RWipeAndClean20.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\R-Wipe & Clean_is1
Inno Setup: Setup Version
5.6.1 (u)
2704
RWipeAndClean20.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\R-Wipe & Clean_is1
Inno Setup: App Path
C:\Program Files\R-Wipe & Clean
2704
RWipeAndClean20.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\R-Wipe & Clean_is1
InstallLocation
C:\Program Files\R-Wipe & Clean\
2704
RWipeAndClean20.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\R-Wipe & Clean_is1
Inno Setup: Icon Group
R-Wipe & Clean
2704
RWipeAndClean20.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\R-Wipe & Clean_is1
Inno Setup: User
admin
2704
RWipeAndClean20.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\R-Wipe & Clean_is1
Inno Setup: Selected Tasks
desktopicon,desktopicon\common
2704
RWipeAndClean20.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\R-Wipe & Clean_is1
Inno Setup: Deselected Tasks
desktopicon\user
2704
RWipeAndClean20.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\R-Wipe & Clean_is1
Inno Setup: Language
default
2704
RWipeAndClean20.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\R-Wipe & Clean_is1
DisplayName
R-Wipe & Clean 20.0
2704
RWipeAndClean20.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\R-Wipe & Clean_is1
DisplayIcon
C:\Program Files\R-Wipe & Clean\RwcSetup.exe
2704
RWipeAndClean20.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\R-Wipe & Clean_is1
UninstallString
"C:\Program Files\R-Wipe & Clean\unins000.exe"
2704
RWipeAndClean20.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\R-Wipe & Clean_is1
QuietUninstallString
"C:\Program Files\R-Wipe & Clean\unins000.exe" /SILENT
2704
RWipeAndClean20.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\R-Wipe & Clean_is1
DisplayVersion
20.0.2219
2704
RWipeAndClean20.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\R-Wipe & Clean_is1
Publisher
R-Tools Technology Inc.
2704
RWipeAndClean20.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\R-Wipe & Clean_is1
URLInfoAbout
http://www.r-tt.com
2704
RWipeAndClean20.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\R-Wipe & Clean_is1
HelpLink
http://www.r-tt.com
2704
RWipeAndClean20.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\R-Wipe & Clean_is1
URLUpdateInfo
http://www.r-tt.com
2704
RWipeAndClean20.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\R-Wipe & Clean_is1
NoModify
1
2704
RWipeAndClean20.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\R-Wipe & Clean_is1
NoRepair
1
2704
RWipeAndClean20.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\R-Wipe & Clean_is1
InstallDate
20181206
2704
RWipeAndClean20.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\R-Wipe & Clean_is1
MajorVersion
20
2704
RWipeAndClean20.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\R-Wipe & Clean_is1
MinorVersion
0
2704
RWipeAndClean20.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\R-Wipe & Clean_is1
VersionMajor
20
2704
RWipeAndClean20.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\R-Wipe & Clean_is1
VersionMinor
0
2704
RWipeAndClean20.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\R-Wipe & Clean_is1
EstimatedSize
44138
2704
RWipeAndClean20.tmp
delete key
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
2900
_RwcSetup.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager
PendingFileRenameOperations
\??\C:\Program Files\R-Wipe & Clean\_RwcSetup.exe
2900
_RwcSetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\R-TT\RWC
Settings1
15
2900
_RwcSetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\shellex\ContextMenuHandlers\{B482AE79-23AE-402E-AA76-F364C4655289}
RwcShellExtensionHandler.RwcShellExtension
2900
_RwcSetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\ContextMenuHandlers\{B482AE79-23AE-402E-AA76-F364C4655289}
RwcShellExtensionHandler.RwcShellExtension
2900
_RwcSetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\shellex\ContextMenuHandlers\{B482AE79-23AE-402E-AA76-F364C4655289}
RwcShellExtensionHandler.RwcShellExtension
2900
_RwcSetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\R-TT\RWC
Path
C:\Program Files\R-Wipe & Clean
2888
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B482AE79-23AE-402E-AA76-F364C4655289}
RwcShellExtensionHandler.RwcShellExtension Class
2888
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B482AE79-23AE-402E-AA76-F364C4655289}\InprocServer32
C:\Program Files\R-Wipe & Clean\RwcShl32.dll
2888
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B482AE79-23AE-402E-AA76-F364C4655289}\InprocServer32
ThreadingModel
Apartment
3700
RwcRun.exe
write
HKEY_CURRENT_USER\Console
CursorMode1
3468887583
3700
RwcRun.exe
write
HKEY_CURRENT_USER\Console
ScreenState1
986187602
3700
RwcRun.exe
write
HKEY_CURRENT_USER\Control Panel\Accessibility\Keyboard Response
Last Valid Mode1
3337357281
3700
RwcRun.exe
write
HKEY_CURRENT_USER\Control Panel\Accessibility\SoundSentry
Mode1
3920388225
3700
RwcRun.exe
write
HKEY_CURRENT_USER\Control Panel\Desktop
ForegroundState1
1673535350
3700
RwcRun.exe
write
HKEY_CURRENT_USER\Control Panel\Desktop
ScreenFlags1
51204822
3700
RwcRun.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\BrowserEmulation
IECompatState1
3137519384
3700
RwcRun.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\BrowserEmulation
IECompatFlags1
1796744221
3700
RwcRun.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
DOMNodes1
7A00000060F78731638DD40100000000
3700
RwcRun.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Document Windows
WindowSizes1
2725478891
3700
RwcRun.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
SmoothFlags1
4194977238
3700
RwcRun.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes
SearchFlags1
2333397469
3700
RwcRun.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
SQMFlags1
2931563330

Files activity

Executable files
37
Suspicious files
0
Text files
3
Unknown types
6

Dropped files

PID
Process
Filename
Type
3448
RWipeAndClean20.exe
C:\Users\admin\AppData\Local\Temp\is-USAH0.tmp\RWipeAndClean20.tmp
executable
MD5: ce8c7be5e30df59da495256136c5b2b6
SHA256: 115ff264c52c73c1f6a255bdd455046987257a5cfb1a8c534f465a4cbbdc2b8f
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\_RwcProcs.dll
executable
MD5: b3cfe79cfe48dd5a3249c18a9b5813aa
SHA256: 0a07d9d58d7d94359ca87fa680d99dd076a028a99ee0ab9425fa19531a730a37
2900
_RwcSetup.exe
C:\Program Files\R-Wipe & Clean\RwcClassic.dll
executable
MD5: d6b30d7446a33542db87111628f3990a
SHA256: 9e8a7fd043fb01366f598bf0988561e3ed33aff2f80f0728afb4643a90916548
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\_RwcMonitor.dll
executable
MD5: 03ed6057cb83018922ea00718c37f753
SHA256: bdcd5e85fa6e21d793752376bbf18ed001c26de258950d664b7ac23599a8155c
2900
_RwcSetup.exe
C:\Program Files\R-Wipe & Clean\RwcFonts.dll
executable
MD5: f5508a7f376db695fc4e094ddd36d501
SHA256: 648ba59a32566d98f88ad0972fba74aae3d9bc39b68979384cd220ffbf8ff783
2900
_RwcSetup.exe
C:\Program Files\R-Wipe & Clean\RwcAdds.dll
executable
MD5: 1cbe44c63b16054b9e789e67f4d495eb
SHA256: c0357636ffde645bf4b8aa8bcd0c38f82ad34d626a09f078193f64265fe88aea
2900
_RwcSetup.exe
C:\Program Files\R-Wipe & Clean\RwcDialogs.dll
executable
MD5: 39905a94039d107dab9e0ed8d8eeec91
SHA256: b9f3cbd3309560024e9f62851b24ce60c0b17f3c2660be8f9420dc8e68ae7e52
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\_RwcImages.dll
executable
MD5: 58eb06a0bcfb7788565201f1ea9e68ec
SHA256: 7a37888161214a675ed7522253b2ca280369946a0f26189a2fbce35ae27f8d63
2900
_RwcSetup.exe
C:\Program Files\R-Wipe & Clean\RwcImages.dll
executable
MD5: 58eb06a0bcfb7788565201f1ea9e68ec
SHA256: 7a37888161214a675ed7522253b2ca280369946a0f26189a2fbce35ae27f8d63
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\_RwcFonts.dll
executable
MD5: f5508a7f376db695fc4e094ddd36d501
SHA256: 648ba59a32566d98f88ad0972fba74aae3d9bc39b68979384cd220ffbf8ff783
2900
_RwcSetup.exe
C:\Program Files\R-Wipe & Clean\RwcRun.exe
executable
MD5: 5942c8ec759a22d78bd64950efbfc5af
SHA256: 2fc34b64a5b40067068500f1b9aaf16f83c1a876fe25d14710f1a47f042ca193
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\_RwcProxy.dll
executable
MD5: dab223e1778164991e3dbec4b0940219
SHA256: 6d028410636cec5b827a1eb3a3ceb658e282e969f3fc015c19da83cdd72e4e7c
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\_RwcDialogs.dll
executable
MD5: 39905a94039d107dab9e0ed8d8eeec91
SHA256: b9f3cbd3309560024e9f62851b24ce60c0b17f3c2660be8f9420dc8e68ae7e52
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\_RwcWorker.exe
executable
MD5: 264c27fe3f94428d866b7019947d0611
SHA256: aa156e8e08636f75fb9f703a7a887f8a4e53e2affdf8821de804096fb2be8703
2900
_RwcSetup.exe
C:\Program Files\R-Wipe & Clean\RwcProxy.dll
executable
MD5: dab223e1778164991e3dbec4b0940219
SHA256: 6d028410636cec5b827a1eb3a3ceb658e282e969f3fc015c19da83cdd72e4e7c
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\_RwcRun.exe
executable
MD5: 5942c8ec759a22d78bd64950efbfc5af
SHA256: 2fc34b64a5b40067068500f1b9aaf16f83c1a876fe25d14710f1a47f042ca193
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\_RwcClassic.dll
executable
MD5: d6b30d7446a33542db87111628f3990a
SHA256: 9e8a7fd043fb01366f598bf0988561e3ed33aff2f80f0728afb4643a90916548
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\_RwcWork.dll
executable
MD5: 38feea5264545740745c72598384adb6
SHA256: 8cb686fd9e150c769c7ae584ed2c60dc86dd2095473c7755f7d706482247796a
2900
_RwcSetup.exe
C:\Program Files\R-Wipe & Clean\RwcInetAuxy.exe
executable
MD5: 4ef6fe5bebf87d89fad3a782cf2e4bad
SHA256: cec0679faf956f2deca8828091490f01a120a49d5b31bfac3085fd7a880760fe
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\_RwcScheduler.exe
executable
MD5: 78406f725c78dab3691d641462573577
SHA256: 4a1987b8ef270b7caaebb96c11e5ffbfba37d229f54ac97062c12d3ad3f4c0c7
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\_RwcBossKey.exe
executable
MD5: eb073e87393316c8dd2a1d177c08b5cd
SHA256: 355b1d37287a0b75e11e265bc852971ccd6d85ae5a35277fe5667a147055a60e
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\_RwcSecure.exe
executable
MD5: 657d767d0a2e878bf4b7d76a6dc8ea4a
SHA256: cfcd1378bdc77d67a892284f2d0aa593b8e19078d87091866074a27354a59b31
2900
_RwcSetup.exe
C:\Program Files\R-Wipe & Clean\RwcProcs.dll
executable
MD5: b3cfe79cfe48dd5a3249c18a9b5813aa
SHA256: 0a07d9d58d7d94359ca87fa680d99dd076a028a99ee0ab9425fa19531a730a37
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\_RwcService.exe
executable
MD5: 8d0abb3e571ce2d15c82a9fcfb540173
SHA256: 0db0bfca003c74ba718ea73b20f7d97d0d69d4d1218e69dcdd77fd5f42e49343
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\_RwcAdds.dll
executable
MD5: 1cbe44c63b16054b9e789e67f4d495eb
SHA256: c0357636ffde645bf4b8aa8bcd0c38f82ad34d626a09f078193f64265fe88aea
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\_RwcSetup.exe
executable
MD5: 216acab429fc6f246b3d0ec842cbccd6
SHA256: 762f078017a02d80137be377a6ecc2f6f4c76738b1970f49e3cdbf90d52c83c9
2900
_RwcSetup.exe
C:\Program Files\R-Wipe & Clean\RwcSecure.exe
executable
MD5: 657d767d0a2e878bf4b7d76a6dc8ea4a
SHA256: cfcd1378bdc77d67a892284f2d0aa593b8e19078d87091866074a27354a59b31
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\_RwcShl32.dll
executable
MD5: 836bfe98c940825971d6f6c490bffe84
SHA256: fd775cbc7805733c8cecd86d8efb305806c0a5116e83dec632a57289ca702157
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\unins000.exe
executable
MD5: cf3db1c917bd0d2036713fa9449ccf54
SHA256: 8fcc11a9acbf0af9a19f2e59a4fc7bff8f8fc68d681c430b96b2b4be34195b08
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\_RwcTouch.dll
executable
MD5: fc328f53d664d7dc5351e254036ecfc4
SHA256: 672de1b919936a4aa7420dc6dc7d30fbfe9ade7209d50c49c9045050e4172ba5
2900
_RwcSetup.exe
C:\Program Files\R-Wipe & Clean\RwcSetup.exe
executable
MD5: 216acab429fc6f246b3d0ec842cbccd6
SHA256: 762f078017a02d80137be377a6ecc2f6f4c76738b1970f49e3cdbf90d52c83c9
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\_RwcShl64.dll
executable
MD5: 2837845d2e4cc3fd794899372db9c5d9
SHA256: eabdc45c6440f4580f97f8cc89b7f23917da7abef578738306188c17eeaf6138
312
RWipeAndClean20.exe
C:\Users\admin\AppData\Local\Temp\is-R9V75.tmp\RWipeAndClean20.tmp
executable
MD5: ce8c7be5e30df59da495256136c5b2b6
SHA256: 115ff264c52c73c1f6a255bdd455046987257a5cfb1a8c534f465a4cbbdc2b8f
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\_RwcSmart.dll
executable
MD5: 13298a40fb27ef117c665713ff9d3b7d
SHA256: e63a43309104f8afe207396f1baf46aeaa9fc10a5d88dc5fc87322576b2a92d0
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\_RwcStrings.dll
executable
MD5: 668990551c69db899c65b7b442dccc23
SHA256: 01b9a0bfc4794d727f40b64e31ff1a9d7d208093219592413de7957bf23834bc
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\_RwcInetAuxy.exe
executable
MD5: 4ef6fe5bebf87d89fad3a782cf2e4bad
SHA256: cec0679faf956f2deca8828091490f01a120a49d5b31bfac3085fd7a880760fe
2900
_RwcSetup.exe
C:\Program Files\R-Wipe & Clean\RwcSmart.dll
executable
MD5: 13298a40fb27ef117c665713ff9d3b7d
SHA256: e63a43309104f8afe207396f1baf46aeaa9fc10a5d88dc5fc87322576b2a92d0
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\is-2BGBG.tmp
––
MD5:  ––
SHA256:  ––
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\_R-Wipe & Clean.chm
chm
MD5: 6f180d10ebeff7932253b65f33539df6
SHA256: 0fb5609a5797e8156a872e33de83b85eb5d71ef5a388668979d43867333f494f
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\_eula.txt
text
MD5: ebff7dd42413bb9bc93d5769aa2e93e0
SHA256: 30321e8bef89181de4fcbbfdb3f13740270ae530d4cab214ef086da73973f314
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\is-70BM8.tmp
––
MD5:  ––
SHA256:  ––
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\is-F90FI.tmp
––
MD5:  ––
SHA256:  ––
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\is-4LFIV.tmp
––
MD5:  ––
SHA256:  ––
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\is-FL8NA.tmp
––
MD5:  ––
SHA256:  ––
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\is-GCBC5.tmp
––
MD5:  ––
SHA256:  ––
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\main.ico
image
MD5: c9bfc78aac2bca94d113176abfef66ca
SHA256: 08f61758bce56b538740f7f3e81037188eea04c55220cafef1bb4165ceb4a5db
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\is-9VR4E.tmp
––
MD5:  ––
SHA256:  ––
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\is-2PSTH.tmp
––
MD5:  ––
SHA256:  ––
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\is-O86D5.tmp
––
MD5:  ––
SHA256:  ––
2900
_RwcSetup.exe
C:\Program Files\R-Wipe & Clean\RwcStrings.dll
––
MD5:  ––
SHA256:  ––
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\is-8CITO.tmp
––
MD5:  ––
SHA256:  ––
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\is-L6H4Q.tmp
––
MD5:  ––
SHA256:  ––
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\is-RKGOG.tmp
––
MD5:  ––
SHA256:  ––
2900
_RwcSetup.exe
C:\Program Files\R-Wipe & Clean\eula.txt
text
MD5: ebff7dd42413bb9bc93d5769aa2e93e0
SHA256: 30321e8bef89181de4fcbbfdb3f13740270ae530d4cab214ef086da73973f314
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\is-JGF4U.tmp
––
MD5:  ––
SHA256:  ––
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\is-VI3CS.tmp
––
MD5:  ––
SHA256:  ––
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\is-40IGO.tmp
––
MD5:  ––
SHA256:  ––
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\unins000.dat
dat
MD5: 623fb0c23a98429cb3f74e2be7ba6909
SHA256: 883331d9b5c837f314c4aab07a423136117cc8295834ac3e30142e74db7b96ad
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\is-1RLKL.tmp
––
MD5:  ––
SHA256:  ––
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\is-6P1MJ.tmp
––
MD5:  ––
SHA256:  ––
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\is-TLJTM.tmp
––
MD5:  ––
SHA256:  ––
2704
RWipeAndClean20.tmp
C:\Users\Public\Desktop\R-Wipe & Clean.lnk
lnk
MD5: a5fd004befbd81e70c9178aed6548fb0
SHA256: d7ba8b9c9d79b3740b495b75672f6681e781fc0f88bb7fa2c58e071579843fd2
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\is-LRMKB.tmp
––
MD5:  ––
SHA256:  ––
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\is-4TS2P.tmp
––
MD5:  ––
SHA256:  ––
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\is-N3BUB.tmp
––
MD5:  ––
SHA256:  ––
2704
RWipeAndClean20.tmp
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\R-Wipe & Clean\R-Wipe & Clean Help.lnk
lnk
MD5: af65253800345ed1d86c764f40350d37
SHA256: a9768dbe854f05bcad9be5fb0d6bf32ab1e70eb39f9fcd8ef3c81251c67ba157
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\is-KN23V.tmp
––
MD5:  ––
SHA256:  ––
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\is-2AIC2.tmp
––
MD5:  ––
SHA256:  ––
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\is-38LAV.tmp
––
MD5:  ––
SHA256:  ––
2704
RWipeAndClean20.tmp
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\R-Wipe & Clean\License Agreement.lnk
lnk
MD5: deebbdb078d2d15d0beb392f6e940bb4
SHA256: 9553f02737e743261299b996e894757aec4a67c256e8c6dea911f3360b847f88
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\is-U8VL7.tmp
––
MD5:  ––
SHA256:  ––
2704
RWipeAndClean20.tmp
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\R-Wipe & Clean\R-Wipe & Clean.lnk
lnk
MD5: e07a59606ca221a8028f3fabb1663f1b
SHA256: 98aac2b637708fb1615efa1826961a83c41e1beafbcb839fbf5b1d8f4958dfea
2704
RWipeAndClean20.tmp
C:\Program Files\R-Wipe & Clean\is-G1PTC.tmp
––
MD5:  ––
SHA256:  ––

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

No network activity.

Debug output strings

No debug info.