winrar.exe

WinRAR

{70166A21-2F6A-4CC0-822C-607696D8F4B7}

WinRAR provides the full RAR and ZIP file support, can decompress CAB, GZIP, ACE and other archive formats. The application winrar.exe, “Archiwizer WinRAR” by {70166A21-2F6A-4CC0-822C-607696D8F4B7} has been detected as a potentially unwanted program by 33 anti-malware scanners.
Publisher:
Alexander Roshal  (signed by {70166A21-2F6A-4CC0-822C-607696D8F4B7})

Product:
WinRAR

Description:
Archiwizer WinRAR

Version:
5.1.1

MD5:
97ecfee870724618da799ec6588cd55f

SHA-1:
bd5e8e8e9aa7331046d89764b18701175aa2dabf

SHA-256:
20d00febfa5af493829cd87a18b9622b1165de32979e37d0f5cf031818a89ff3

Scanner detections:
33 / 68

Status:
Potentially unwanted

Analysis date:
4/24/2024 10:08:16 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.1656381
533

Agnitum Outpost
Trojan.Blocker
7.1.1

AhnLab V3 Security
Trojan/Win32.MDA
2015.05.29

Avira AntiVirus
TR/Krypt.UU.31
8.3.1.6

avast!
MSIL:GenMalicious-BB [Trj]
2014.9-150820

AVG
Zbot
2016.0.3011

Baidu Antivirus
Adware.MSIL.iBryte
4.0.3.15820

Bitdefender
Trojan.GenericKD.1656381
1.0.20.1160

Comodo Security
UnclassifiedMalware
22258

Dr.Web
BackDoor.Andromeda.22
9.0.1.0232

Emsisoft Anti-Malware
Trojan.GenericKD.1656381
8.15.08.20.11

ESET NOD32
MSIL/Kryptik.UU (variant)
9.11700

Fortinet FortiGate
MSIL/Injector.DUB!tr
8/20/2015

F-Secure
Trojan.GenericKD.1656381
11.2015-20-08_5

G Data
Trojan.GenericKD.1656381
15.8.25

IKARUS anti.virus
Trojan-Signed:Agent
t3scan.1.9.2.0

K7 AntiVirus
Trojan
13.204.16062

Kaspersky
Trojan-Ransom.Win32.Blocker
14.0.0.1550

Malwarebytes
Spyware.Password
v2015.08.20.11

McAfee
PWSZbot-FXD!97ECFEE87072
5600.6667

MicroWorld eScan
Trojan.GenericKD.1656381
16.0.0.696

NANO AntiVirus
Trojan.Win32.Blocker.cxapbx
0.30.24.1636

Norman
Injector.HFED
11.20150820

nProtect
Trojan.GenericKD.1656381
15.05.28.01

Panda Antivirus
Trj/CI.A
15.08.20.11

Qihoo 360 Security
Win32/Trojan.2b0
1.0.0.1015

Quick Heal
TrojanRansom.Blocker.r3
8.15.14.00

Rising Antivirus
PE:Trojan.Win32.Generic.16BE0AFE!381553406
23.00.65.15818

Sophos
Troj/MSIL-RD
4.98

Total Defense
Heur/TrojanHorse.ZCFH!suspicious
37.1.62.1

Vba32 AntiVirus
Hoax.Blocker
3.12.26.4

VIPRE Antivirus
Trojan.Win32.Generic
40632

ViRobot
Trojan.Win32.S.Agent.190496[h]
2014.3.20.0

File size:
186 KB (190,496 bytes)

Product version:
5.1.1

Copyright:
Copyright © Alexander Roshal 1993-2013

Original file name:
Archiwizer WinRAR.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\roaming\datawork\winrar.exe

Digital Signature
Authority:
{70166A21-2F6A-4CC0-822C-607696D8F4B7}

Valid from:
4/19/2014 5:47:18 AM

Valid to:
4/19/2015 11:47:18 AM

Subject:
CN={70166A21-2F6A-4CC0-822C-607696D8F4B7}

Issuer:
CN={70166A21-2F6A-4CC0-822C-607696D8F4B7}

Serial number:
3F0DF1EBD88FB1B94D119CFFAC6B01C9

File PE Metadata
Compilation timestamp:
4/25/2014 8:51:14 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
3072:CaZ9otDyT2y6dFMFtkXoJl4FRz22lMO74PNwY8oIfV5y2P:PZForMOo8XrSPSuq

Entry address:
0x2D10E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
172.5 KB (176,640 bytes)

Remove winrar.exe - Powered by Reason Core Security