WinRAR.exe

WinRAR

Alexander Roshal

WinRAR provides the full RAR and ZIP file support, can decompress CAB, GZIP, ACE and other archive formats. The executable WinRAR.exe has been detected as malware by 34 anti-virus scanners.
Publisher:
Alexander Roshal

Product:
WinRAR

Description:
WinRAR archiver

Version:
4.0.0

MD5:
276b19bcf73faa6be57d5b178ddb8d87

SHA-1:
502996f7353ef96e576fc40eb1521d2a5256c460

SHA-256:
a546664d90e0deec97baa516eac7b4dfb8d611cf09d5d9cc42a89acddd95e983

Scanner detections:
34 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/26/2024 11:27:21 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Virtob.Gen.12
918

Agnitum Outpost
Win32.Virut.AB.Gen
7.1.1

AhnLab V3 Security
Win32/Virut.F
2014.08.01

Avira AntiVirus
W32/Virut.Gen
7.11.30.172

avast!
Win32:Vitro
140617-1

AVG
Win32/Virut.AN
2014.0.3986

Bitdefender
Win32.Virtob.Gen.12
1.0.20.1060

Bkav FE
W32.Vetor.PE
1.3.0.4959

Dr.Web
Win32.Virut.56
9.0.1.05190

Emsisoft Anti-Malware
Win32.Virtob.Gen.12
8.14.07.31.03

ESET NOD32
Win32/Virut.NBP virus
7.0.302.0

Fortinet FortiGate
W32/FakeAV.RQ!tr
7/31/2014

F-Prot
W32/Heuristic-210!Eldorado (not disinfectable)
4.6.5.141

F-Secure
Win32.Virtob.Gen.12
11.2014-31-07_5

G Data
Win32.Virtob.Gen.12
14.7.24

IKARUS anti.virus
Win32.Virtob
t3scan.1.6.1.0

K7 AntiVirus
Virus
13.182.12911

Kaspersky
Virus.Win32.Virut
15.0.0.494

McAfee
W32/Virut.n.gen
5600.7052

Microsoft Security Essentials
Threat.Undefined
1.179.1743.0

MicroWorld eScan
Win32.Virtob.Gen.12
15.0.0.636

NANO AntiVirus
Virus.Win32.Virut.hpeg
0.28.2.61148

nProtect
Virus/W32.Virut.Gen
14.07.31.01

Panda Antivirus
W32/Sality.AO
14.07.31.03

Qihoo 360 Security
Virus.Win32.Virut.O
1.0.0.1015

Quick Heal
W32.Virut.G
7.14.14.00

Rising Antivirus
PE:Win32.Virut.cx!1553679
23.00.65.14729

Sophos
W32/Scribble-B
4.98

Total Defense
Win32/Virut.17408
37.0.11091

Trend Micro House Call
PE_VIRUX.R-3
7.2.212

Trend Micro
PE_VIRUX.R-3
10.465.31

Vba32 AntiVirus
Virus.Virut.14
3.12.26.3

VIPRE Antivirus
Threat.4120919
31208

ViRobot
Win32.Virut.AM
2011.4.7.4223

File size:
1.1 MB (1,120,768 bytes)

Product version:
4.0.0

Copyright:
Copyright © Alexander Roshal 1993-2011

Original file name:
WinRAR.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\winrar\winrar.exe

File PE Metadata
Compilation timestamp:
8/16/2009 1:27:50 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:md9nwsxFYoiX4wXUsVbxXY4ouO2kp7MMMMMMRjsM:wLmIwXUsLdokGMMMMMMa

Entry address:
0xB9321

Entry point:
68, 30, 6B, 00, 00, F8, 5A, 0F, 98, C1, B1, 4A, EB, 43, 00, 00, 00, F5, EE, 00, 00, 7E, 47, 00, 00, 00, B4, 21, C0, BC, EB, 4B, 00, 45, 00, 6F, 06, 00, 15, 00, 00, CC, 83, 94, D5, EE, 00, 87, 7D, 82, AB, 24, 9F, 00, A6, AA, CD, 8B, 81, 00, 51, E8, B8, 4B, 85, D7, B0, A2, 16, 30, ED, 00, 80, 00, AB, 0F, 1A, 85, 9B, A3, CA, 90, B9, 75, 90, 50, AB, 66, 81, 92, 00, 0E, 56, 00, 77, E5, E9, 2D, FF, FF, FF, 00, 27, 4F, 2F, BF, 00, F8, AA, 0F, 92, BD, D1, A0, AF, 89, A4, 06, C3, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.4760

Code size:
737 KB (754,688 bytes)

Shell Open Command
Open type:
WinRAR

Command:
"C:\Program Files\winrar\winrar.exe" "%1"


Remove WinRAR.exe - Powered by Reason Core Security