General Info

File name

872abebdfc932a52ed277e452f706971-wrar561tr.exe

Full analysis
https://app.any.run/tasks/d44e5f13-3d4f-446b-acf3-1f47ae24ac51
Verdict
Malicious activity
Analysis date
6/12/2019, 09:32:45
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows
MD5

872abebdfc932a52ed277e452f706971

SHA1

d768b9e77782bbdc671a81d8fed00aa8a5d7eac9

SHA256

c94b26e7842b6726bb7c592f687f38f2da83453a0979a319dbf83a7c040ad8b2

SSDEEP

49152:LxuBfJXAtJYUo3WddOXZYVNkYbNskNfe12PZVzTg6/UdaqnA2RlS0PIkje:UBfKGGdd3VRB/e12PZVzTg6/UdVNcyK

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
120 seconds
Additional time used
60 seconds
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (73.0.3683.75)
  • Google Update Helper (1.3.33.23)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 65.0.2 (x86 en-US) (65.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Application was dropped or rewritten from another process
  • WinRAR.exe (PID: 1208)
  • WinRAR.exe (PID: 2176)
  • uninstall.exe (PID: 2648)
Reads internet explorer settings
  • hh.exe (PID: 2484)
  • 872abebdfc932a52ed277e452f706971-wrar561tr.exe (PID: 3880)
Creates a software uninstall entry
  • uninstall.exe (PID: 2648)
Creates files in the program directory
  • uninstall.exe (PID: 2648)
  • 872abebdfc932a52ed277e452f706971-wrar561tr.exe (PID: 3880)
Modifies the open verb of a shell class
  • uninstall.exe (PID: 2648)
Creates COM task schedule object
  • uninstall.exe (PID: 2648)
Creates files in the user directory
  • uninstall.exe (PID: 2648)
Executable content was dropped or overwritten
  • 872abebdfc932a52ed277e452f706971-wrar561tr.exe (PID: 3880)
Manual execution by user
  • hh.exe (PID: 2484)
  • WinRAR.exe (PID: 1208)
  • WinRAR.exe (PID: 2176)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win64 Executable (generic) (64.6%)
.dll
|   Win32 Dynamic Link Library (generic) (15.4%)
.exe
|   Win32 Executable (generic) (10.5%)
.exe
|   Generic Win/DOS Executable (4.6%)
.exe
|   DOS Executable Generic (4.6%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2018:09:30 20:01:57+02:00
PEType:
PE32
LinkerVersion:
14
CodeSize:
189440
InitializedDataSize:
304128
UninitializedDataSize:
null
EntryPoint:
0x1cea9
OSVersion:
5.1
ImageVersion:
null
SubsystemVersion:
5.1
Subsystem:
Windows GUI
FileVersionNumber:
5.61.0.0
ProductVersionNumber:
5.61.0.0
FileFlagsMask:
0x0000
FileFlags:
(none)
FileOS:
Win32
ObjectFileType:
Executable application
FileSubtype:
null
LanguageCode:
English (U.S.)
CharacterSet:
Windows, Latin1
ProductName:
WinRAR
CompanyName:
Alexander Roshal
FileDescription:
WinRAR archiver
FileVersion:
5.61.0
ProductVersion:
5.61.0
InternalName:
WinRAR
LegalCopyright:
Copyright © Alexander Roshal 1993-2018
OriginalFileName:
WinRAR.exe
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
30-Sep-2018 18:01:57
Detected languages
English - United States
Debug artifacts
D:\Projects\WinRAR\sfx\setup\build\sfxrar32\Release\sfxrar.pdb
ProductName:
WinRAR
CompanyName:
Alexander Roshal
FileDescription:
WinRAR archiver
FileVersion:
5.61.0
ProductVersion:
5.61.0
InternalName:
WinRAR
LegalCopyright:
Copyright © Alexander Roshal 1993-2018
OriginalFilename:
WinRAR.exe
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0090
Pages in file:
0x0003
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x0000
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x0000
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x00000110
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
6
Time date stamp:
30-Sep-2018 18:01:57
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x0002E254 0x0002E400 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 6.69532
.rdata 0x00030000 0x000099DC 0x00009A00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 5.16021
.data 0x0003A000 0x00020388 0x00000C00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 3.19639
.gfids 0x0005B000 0x000000E8 0x00000200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 2.07073
.rsrc 0x0005C000 0x0001F000 0x0001E400 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 7.66682
.reloc 0x0007B000 0x00001F88 0x00002000 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_DISCARDABLE,IMAGE_SCN_MEM_READ 6.66229
Resources
1

2

3

4

5

6

7

8

9

10

11

12

13

15

16

100

201

202

LICENSEDLG

RENAMEDLG

REPLACEFILEDLG

STARTDLG

Imports
    KERNEL32.dll

    gdiplus.dll

    COMCTL32.dll (delay-loaded)

Exports

    No exports.

Screenshots

Processes

Total processes
43
Monitored processes
6
Malicious processes
3
Suspicious processes
1

Behavior graph

+
drop and start start 872abebdfc932a52ed277e452f706971-wrar561tr.exe no specs 872abebdfc932a52ed277e452f706971-wrar561tr.exe uninstall.exe no specs winrar.exe no specs hh.exe no specs winrar.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3448
CMD
"C:\Users\admin\AppData\Local\Temp\872abebdfc932a52ed277e452f706971-wrar561tr.exe"
Path
C:\Users\admin\AppData\Local\Temp\872abebdfc932a52ed277e452f706971-wrar561tr.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
3221226540
Version:
Company
Alexander Roshal
Description
WinRAR archiver
Version
5.61.0
Modules
Image
c:\users\admin\appdata\local\temp\872abebdfc932a52ed277e452f706971-wrar561tr.exe
c:\systemroot\system32\ntdll.dll

PID
3880
CMD
"C:\Users\admin\AppData\Local\Temp\872abebdfc932a52ed277e452f706971-wrar561tr.exe"
Path
C:\Users\admin\AppData\Local\Temp\872abebdfc932a52ed277e452f706971-wrar561tr.exe
Indicators
Parent process
––
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Alexander Roshal
Description
WinRAR archiver
Version
5.61.0
Modules
Image
c:\users\admin\appdata\local\temp\872abebdfc932a52ed277e452f706971-wrar561tr.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\riched20.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\oleaut32.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\msimtf.dll
c:\windows\system32\mlang.dll
c:\windows\system32\propsys.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\program files\winrar\uninstall.exe
c:\windows\system32\sfc.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\mpr.dll

PID
2648
CMD
"C:\Program Files\WinRAR\uninstall.exe" /setup
Path
C:\Program Files\WinRAR\uninstall.exe
Indicators
No indicators
Parent process
872abebdfc932a52ed277e452f706971-wrar561tr.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Alexander Roshal
Description
Uninstall WinRAR
Version
5.61.0
Modules
Image
c:\program files\winrar\uninstall.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\riched20.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\program files\winrar\winrar.exe
c:\windows\system32\apphelp.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\sxs.dll
c:\windows\system32\actxprxy.dll
c:\windows\system32\netutils.dll

PID
2176
CMD
"C:\Program Files\WinRAR\WinRAR.exe"
Path
C:\Program Files\WinRAR\WinRAR.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Alexander Roshal
Description
WinRAR archiver
Version
5.61.0
Modules
Image
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\uxtheme.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\riched20.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\slc.dll
c:\windows\system32\imageres.dll
c:\windows\system32\mpr.dll
c:\windows\system32\drprov.dll
c:\windows\system32\winsta.dll
c:\windows\system32\ntlanman.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\davhlpr.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\netutils.dll
c:\windows\system32\wpdshext.dll
c:\windows\system32\winmm.dll
c:\windows\system32\portabledeviceapi.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\audiodev.dll
c:\windows\system32\wmvcore.dll
c:\windows\system32\wmasf.dll
c:\windows\system32\ehstorapi.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\iertutil.dll
c:\windows\installer\{90140000-003d-0000-0000-0000000ff1ce}\wordicon.exe

PID
2484
CMD
"C:\Windows\hh.exe" C:\Program Files\WinRAR\WinRAR.chm
Path
C:\Windows\hh.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft® HTML Help Executable
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\hh.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\hhctrl.ocx
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\profapi.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\itss.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\sxs.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\version.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\msimtf.dll
c:\windows\system32\mlang.dll
c:\windows\system32\uxtheme.dll

PID
1208
CMD
"C:\Program Files\WinRAR\WinRAR.exe"
Path
C:\Program Files\WinRAR\WinRAR.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Alexander Roshal
Description
WinRAR archiver
Version
5.61.0
Modules
Image
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\uxtheme.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\riched20.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\slc.dll
c:\windows\system32\imageres.dll
c:\windows\system32\mpr.dll
c:\windows\system32\drprov.dll
c:\windows\system32\winsta.dll
c:\windows\system32\ntlanman.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\davhlpr.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\netutils.dll
c:\windows\system32\wpdshext.dll
c:\windows\system32\winmm.dll
c:\windows\system32\portabledeviceapi.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\audiodev.dll
c:\windows\system32\wmvcore.dll
c:\windows\system32\wmasf.dll
c:\windows\system32\ehstorapi.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\iertutil.dll
c:\windows\installer\{90140000-003d-0000-0000-0000000ff1ce}\wordicon.exe

Registry activity

Total events
1094
Read events
915
Write events
177
Delete events
2

Modification events

PID
Process
Operation
Key
Name
Value
3880
872abebdfc932a52ed277e452f706971-wrar561tr.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3880
872abebdfc932a52ed277e452f706971-wrar561tr.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3880
872abebdfc932a52ed277e452f706971-wrar561tr.exe
write
HKEY_CURRENT_USER\Software\WinRAR SFX
C%%Program Files%WinRAR
C:\Program Files\WinRAR
2648
uninstall.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.rar\ShellNew
2648
uninstall.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zip\ShellNew
2648
uninstall.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Setup\.rar
Set
1
2648
uninstall.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Setup\.zip
Set
1
2648
uninstall.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Setup\.cab
Set
1
2648
uninstall.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Setup\.arj
Set
1
2648
uninstall.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Setup\.lz
Set
1
2648
uninstall.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Setup\.lzh
Set
1
2648
uninstall.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Setup\.ace
Set
1
2648
uninstall.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Setup\.7z
Set
1
2648
uninstall.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Setup\.tar
Set
1
2648
uninstall.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Setup\.gz
Set
1
2648
uninstall.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Setup\.uue
Set
1
2648
uninstall.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Setup\.bz2
Set
1
2648
uninstall.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Setup\.jar
Set
0
2648
uninstall.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Setup\.iso
Set
0
2648
uninstall.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Setup\.z
Set
1
2648
uninstall.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Setup\.xz
Set
1
2648
uninstall.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Setup\.zipx
Set
1
2648
uninstall.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Setup\.001
Set
1
2648
uninstall.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Setup\Links
Desktop
0
2648
uninstall.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Setup\Links
StartMenu
0
2648
uninstall.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Setup\Links
Programs
1
2648
uninstall.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Setup
ShellExt
1
2648
uninstall.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Setup
CascadedMenu
0
2648
uninstall.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Setup
MenuIcons
1
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\WinRAR.exe
C:\Program Files\WinRAR\WinRAR.exe
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\WinRAR
exe32
C:\Program Files\WinRAR\WinRAR.exe
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\WinRAR.exe
Path
C:\Program Files\WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B41DB860-8EE4-11D2-9906-E49FADC173CA}
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B41DB860-8EE4-11D2-9906-E49FADC173CA}\InProcServer32
C:\Program Files\WinRAR\rarext.dll
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B41DB860-8EE4-11D2-9906-E49FADC173CA}\InProcServer32
ThreadingModel
Apartment
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinRAR\shellex\ContextMenuHandlers\{B41DB860-8EE4-11D2-9906-E49FADC173CA}
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinRAR\shellex\PropertySheetHandlers\{B41DB860-8EE4-11D2-9906-E49FADC173CA}
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinRAR.ZIP\shellex\ContextMenuHandlers\{B41DB860-8EE4-11D2-9906-E49FADC173CA}
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinRAR.ZIP\shellex\PropertySheetHandlers\{B41DB860-8EE4-11D2-9906-E49FADC173CA}
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shellex\PropertySheetHandlers\{B41DB860-8EE4-11D2-9906-E49FADC173CA}
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinRAR\shellex\DropHandler
{B41DB860-8EE4-11D2-9906-E49FADC173CA}
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinRAR.ZIP\shellex\DropHandler
{B41DB860-8EE4-11D2-9906-E49FADC173CA}
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\WinRAR
{B41DB860-8EE4-11D2-9906-E49FADC173CA}
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\ShellEx\ContextMenuHandlers\WinRAR
{B41DB860-8EE4-11D2-9906-E49FADC173CA}
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\ShellEx\DragDropHandlers\WinRAR
{B41DB860-8EE4-11D2-9906-E49FADC173CA}
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\DragDropHandlers\WinRAR
{B41DB860-8EE4-11D2-9906-E49FADC173CA}
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
{B41DB860-8EE4-11D2-9906-E49FADC173CA}
WinRAR shell extension
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\RegisteredApplications
WinRAR
Software\WinRAR\Capabilities
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\WinRAR\Capabilities
ApplicationDescription
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\WinRAR\Capabilities\FileAssociations
.rar
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\WinRAR\Capabilities\FileAssociations
.zip
WinRAR.ZIP
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\WinRAR\Capabilities\FileAssociations
.cab
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\WinRAR\Capabilities\FileAssociations
.arj
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\WinRAR\Capabilities\FileAssociations
.lz
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\WinRAR\Capabilities\FileAssociations
.tlz
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\WinRAR\Capabilities\FileAssociations
.lzh
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\WinRAR\Capabilities\FileAssociations
.lha
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\WinRAR\Capabilities\FileAssociations
.ace
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\WinRAR\Capabilities\FileAssociations
.7z
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\WinRAR\Capabilities\FileAssociations
.tar
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\WinRAR\Capabilities\FileAssociations
.gz
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\WinRAR\Capabilities\FileAssociations
.tgz
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\WinRAR\Capabilities\FileAssociations
.uue
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\WinRAR\Capabilities\FileAssociations
.xxe
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\WinRAR\Capabilities\FileAssociations
.uu
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\WinRAR\Capabilities\FileAssociations
.bz2
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\WinRAR\Capabilities\FileAssociations
.tbz2
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\WinRAR\Capabilities\FileAssociations
.bz
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\WinRAR\Capabilities\FileAssociations
.tbz
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\WinRAR\Capabilities\FileAssociations
.jar
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\WinRAR\Capabilities\FileAssociations
.iso
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\WinRAR\Capabilities\FileAssociations
.z
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\WinRAR\Capabilities\FileAssociations
.taz
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\WinRAR\Capabilities\FileAssociations
.xz
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\WinRAR\Capabilities\FileAssociations
.txz
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\WinRAR\Capabilities\FileAssociations
.zipx
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\WinRAR\Capabilities\FileAssociations
.001
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
57
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.rar
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.r00
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.r01
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.r02
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.r03
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.r04
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.r05
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.r06
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.r07
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.r08
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.r09
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.r10
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.r11
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.r12
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.r13
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.r14
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.r15
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.r16
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.r17
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.r18
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.r19
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.r20
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.r21
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.r22
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.r23
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.r24
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.r25
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.r26
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.r27
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.r28
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.r29
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.rar\ShellNew
FileName
C:\Program Files\WinRAR\rarnew.dat
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zip
WinRAR.ZIP
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zip\ShellNew
FileName
C:\Program Files\WinRAR\zipnew.dat
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.cab
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.arj
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.lz
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.tlz
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.lzh
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.lha
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.ace
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.7z
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.tar
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.gz
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.tgz
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.uue
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.xxe
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.uu
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.bz2
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.tbz2
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.bz
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.tbz
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.z
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.taz
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.xz
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.txz
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zipx
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.001
WinRAR
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinRAR
WinRAR arşivi
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinRAR\shell\open\command
"C:\Program Files\WinRAR\WinRAR.exe" "%1"
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinRAR.ZIP
WinRAR ZIP arşivi
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinRAR.ZIP\shell\open\command
"C:\Program Files\WinRAR\WinRAR.exe" "%1"
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.rev
WinRAR.REV
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinRAR.REV
RAR kurtarma cildi
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinRAR.REV\shell\open\command
"C:\Program Files\WinRAR\WinRAR.exe" "%1"
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
58
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinRAR archiver
DisplayName
WinRAR 5.61 (32-bit)
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinRAR archiver
DisplayVersion
5.61.0
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinRAR archiver
VersionMajor
5
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinRAR archiver
VersionMinor
61
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinRAR archiver
UninstallString
C:\Program Files\WinRAR\uninstall.exe
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinRAR archiver
DisplayIcon
C:\Program Files\WinRAR\WinRAR.exe
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinRAR archiver
InstallLocation
C:\Program Files\WinRAR\
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinRAR archiver
NoModify
1
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinRAR archiver
NoRepair
1
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinRAR archiver
Language
0
2648
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinRAR archiver
Publisher
win.rar GmbH
2176
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\General
VerInfo
003D0500AC36522DF120D501
2176
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
ShellExtBMP
2176
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
ShellExtIcon
2176
WinRAR.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
LanguageList
en-US
2176
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Placement
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
2176
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\General
LastFolder
C:\Users\admin\Desktop
2176
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
name
120
2176
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
size
80
2176
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
type
120
2176
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
mtime
100
2176
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\General\Toolbar\Layout
Band56_0
38000000730100000402000000000000D4D0C800000000000000000000000000C20203000000000039000000B40200000000000001000000
2176
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\General\Toolbar\Layout
Band56_1
38000000730100000500000000000000D4D0C800000000000000000000000000F802020000000000160000002A0000000000000002000000
2176
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\General\Toolbar\Layout
Band56_2
38000000730100000400000000000000D4D0C800000000000000000000000000200302000000000016000000640000000000000003000000
2484
hh.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2484
hh.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
1208
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
ShellExtBMP
1208
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
ShellExtIcon
1208
WinRAR.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
LanguageList
en-US

Files activity

Executable files
11
Suspicious files
1
Text files
12
Unknown types
8

Dropped files

PID
Process
Filename
Type
3880
872abebdfc932a52ed277e452f706971-wrar561tr.exe
C:\Program Files\WinRAR\RarExt64.dll
executable
MD5: 4036eae89659a3c8c1bafa2536ecfb24
SHA256: 4122367ccb8cc349f23fdc52b3252d806b156bd7bfe74522cc1389c84e16b99c
3880
872abebdfc932a52ed277e452f706971-wrar561tr.exe
C:\Program Files\WinRAR\UNACEV2.DLL
executable
MD5: de02c4d04088b69e64ecc30a3d9e22e5
SHA256: c9d28800e740a1569aec8fe27df10ef186d883f94cec15a5c228826b45a24f9d
3880
872abebdfc932a52ed277e452f706971-wrar561tr.exe
C:\Program Files\WinRAR\Default.SFX
executable
MD5: 637767d8e604969183dc00bed42bba38
SHA256: 0fd628c81841c76863563a39ca87ba573f09d6c4859bcb86aacceaaf77278bbd
3880
872abebdfc932a52ed277e452f706971-wrar561tr.exe
C:\Program Files\WinRAR\RarExt.dll
executable
MD5: 531d2ae9409906b0a511077f709dd457
SHA256: 750f6f9d70e4465f2fa201d4a3e54e8ece27a6a9045134a96bbd80f312b6790e
3880
872abebdfc932a52ed277e452f706971-wrar561tr.exe
C:\Program Files\WinRAR\Zip.SFX
executable
MD5: 49a82698afd9023b56352de45b4d707f
SHA256: c49278e959a2652e9614e8125756122b5a46ddc58604f292dd86065e4b11d519
3880
872abebdfc932a52ed277e452f706971-wrar561tr.exe
C:\Program Files\WinRAR\UnRAR.exe
executable
MD5: 99f5f4642140f01cdae3b50395826e7d
SHA256: a2ee3d312c4d92346d47c35346276db10b525452e88c11142bd2ea72a9f035f5
3880
872abebdfc932a52ed277e452f706971-wrar561tr.exe
C:\Program Files\WinRAR\Uninstall.exe
executable
MD5: 2aca14cc6303cd00028d46f3665cf704
SHA256: d39a3965755875ff0063501e820cbdaee98671765a51b986d9da371a68aa9404
3880
872abebdfc932a52ed277e452f706971-wrar561tr.exe
C:\Program Files\WinRAR\Rar.exe
executable
MD5: 33a75bfb1b9038899b9ba5e2a06d5d57
SHA256: f210868e696b4219f213bc4fe8652380570f60b6f4d5b440f6cf786adf301778
3880
872abebdfc932a52ed277e452f706971-wrar561tr.exe
C:\Program Files\WinRAR\WinRAR.exe
executable
MD5: ea20b2da750f1bf20fe124d520ac5b13
SHA256: 934807f7e1680c5863ab508de56291423ac6674fea70e293e3dbab444f571443
3880
872abebdfc932a52ed277e452f706971-wrar561tr.exe
C:\Program Files\WinRAR\WinCon.SFX
executable
MD5: 225281764558c63fb94c90b94359c15d
SHA256: 11e9ba63c3bff55a8d4026fcd9930dc44be534ef0aac705973f35eba3afb360c
3880
872abebdfc932a52ed277e452f706971-wrar561tr.exe
C:\Program Files\WinRAR\7zxa.dll
executable
MD5: 44e6fef5c8175eeafa6a3b79ed15a395
SHA256: a6196e42202e5b41077473989847e5f213d9958df86139e252cb1cab2eb120bb
2484
hh.exe
C:\Users\admin\AppData\Roaming\Microsoft\HTML Help\hh.dat
chm
MD5: 69d39f577a467d864ac0c5da024af4cd
SHA256: 1f7a36df6aeb6d03da8461edbbcf9e6f8ab65e5213bfb52264c216021b0c047d
2484
hh.exe
C:\Users\admin\AppData\Local\Temp\~DFA6E4E4CB976E225B.TMP
––
MD5:  ––
SHA256:  ––
3880
872abebdfc932a52ed277e452f706971-wrar561tr.exe
C:\Program Files\WinRAR\uninstall.lng
text
MD5: 15b20156bafbf3b6a5de70caddc40825
SHA256: 2bf759effd3d65e65117ef01dc34d76c0104d1c9cb88fab02337029f3c450a30
3880
872abebdfc932a52ed277e452f706971-wrar561tr.exe
C:\Program Files\WinRAR\winrar.lng
text
MD5: e74164a6ffd6969df3178e8b321fef64
SHA256: e5f5ee8057f9210e95166bbeac11730820052d75540c9aaf1d6f03d084711292
2176
WinRAR.exe
C:\Users\admin\AppData\Roaming\WinRAR\version.dat
binary
MD5: 453a822d56cd72c0224bb3a8d9e24424
SHA256: aae5e806df444fb39671b5080833acf0f1b263fa4b2762b0d542ce350e541de4
3880
872abebdfc932a52ed277e452f706971-wrar561tr.exe
C:\Program Files\WinRAR\rar.lng
text
MD5: 9ac89d5c6a625837b5151ba9a91a3e23
SHA256: 126477a9a235bee9f50c20122bdf2acff18d64696d4ace14c953708a6faf4e94
3880
872abebdfc932a52ed277e452f706971-wrar561tr.exe
C:\Program Files\WinRAR\Descript.ion
text
MD5: 903303679370a9c3cdbb215b65131c3e
SHA256: ee892269ec28a2a688335ad02f141348d02cdc5bf08d28df248ea26439f69820
3880
872abebdfc932a52ed277e452f706971-wrar561tr.exe
C:\Program Files\WinRAR\rarext.lng
text
MD5: c5931546842d674a492f47654dd32ad4
SHA256: ba3228c10e4cb407bb6f613124f5bd1d1a4f3778d5bcd9ebcb063eea211c0bd0
2648
uninstall.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\Konsol RAR kılavuzu.lnk
lnk
MD5: 0b271c073fda54cb009b9eec677ccb19
SHA256: bea4f3ab7c2c2a5a988f9d74bdfb59604868fd0b4eae4399e4c372831d234c9a
2648
uninstall.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR yardımı.lnk
lnk
MD5: 9543fbcf30de55108e9cd991f6a2b28b
SHA256: 5d16a3b912355ff06756be15714336ec74b870fcfc964a4a62d0e069c4f7d7ef
2648
uninstall.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR.lnk
lnk
MD5: 91859e4dd5afafd2b1b3ff5d7574a80a
SHA256: ef70fdacedaaab3afffc7f597e24eda99e2b3322047b50eeed4cfd66b2bfa250
2648
uninstall.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR.lnk
lnk
MD5: d3e39db3062b10fb91ab28e407b21f8d
SHA256: 62257a3f2a8905a0496bbf9737b09ab2e78cbb9b919bb40a1737b1ec5390b99f
2648
uninstall.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\Konsol RAR kılavuzu.lnk
lnk
MD5: 0d13c952a9671c6435f161daad7f2e07
SHA256: c3e9e4ede1fcf0ab95ce6f1c8fb732c603d3a8c3b3c86d362d16079922d798f1
2648
uninstall.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR yardımı.lnk
lnk
MD5: 7c0377908601b2242ab2a0a547c9a621
SHA256: 8c0813407287f0113e06a4e196710061451199ca4f93a2fa5fcaa712ace84daa
3880
872abebdfc932a52ed277e452f706971-wrar561tr.exe
C:\Program Files\WinRAR\WinRAR.chm
chm
MD5: 2bd140bb651421e3d4d4e8b2ec2161a2
SHA256: ed465e560d032499ec9e5e61ad4c748c317fea7e8d6b4601e69ce008fab1ce71
3880
872abebdfc932a52ed277e452f706971-wrar561tr.exe
C:\Program Files\WinRAR\Uninstall.lst
text
MD5: a6532d31ee969112cb1b9f43091b2e28
SHA256: 9f414240f7e1bde5eccfc439b882d61f2b2cc6cd8b52f3c442f4074bc8660dba
3880
872abebdfc932a52ed277e452f706971-wrar561tr.exe
C:\Program Files\WinRAR\WhatsNew.txt
text
MD5: 84d75564255cfe5704f79df903ecf0dc
SHA256: d2cb389e70e2f071187ecbd84fa997c9eb73d059da78fd1cce174686eaef4a24
3880
872abebdfc932a52ed277e452f706971-wrar561tr.exe
C:\Program Files\WinRAR\Order.htm
html
MD5: b245c18aec29d07673ab44c5aa7ab454
SHA256: af9793b58528839021d59aac2dfda28e578fadbcd8e315c2f601cc73a4e0ffc4
3880
872abebdfc932a52ed277e452f706971-wrar561tr.exe
C:\Program Files\WinRAR\RarFiles.lst
text
MD5: 08ea0309d72a874c182f08cbf9da2cc3
SHA256: 12787f8204eedb0b8bdabf5d68d557334fddb2d70b46e1422510713dda5e6a01
3880
872abebdfc932a52ed277e452f706971-wrar561tr.exe
C:\Program Files\WinRAR\ReadMe.txt
text
MD5: d1996129f4509bb905999c1fe9c1e846
SHA256: aadb1c5c21e526f0badc26b155bef26660cfa62515a11e5ce56ca37c297c6062
3880
872abebdfc932a52ed277e452f706971-wrar561tr.exe
C:\Program Files\WinRAR\Rar.txt
text
MD5: 0fb2565ff4342acfd592477c504b8ef8
SHA256: be15ee8511ef506ed2022c0046c5ea97fb3816c5cbbade9df00bae68550f0206
3880
872abebdfc932a52ed277e452f706971-wrar561tr.exe
C:\Program Files\WinRAR\License.txt
text
MD5: 715b33385def389971a1c74e755a1276
SHA256: 1a96719f0b4244f02c3ad34eb8e82262d604646230ef84cd5e873133cb8ce8f5
2484
hh.exe
C:\Users\admin\AppData\Local\Temp\~DF77C3C7BFB7562A21.TMP
––
MD5:  ––
SHA256:  ––

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

No network activity.

Debug output strings

No debug info.