RarExt.dll

WinRAR

Alexander Roshal

This is the Windows Shell Extension for WinRAR which provides the full RAR and ZIP file support, can decompress CAB, GZIP, ACE and other archive formats. The library RarExt.dll, “WinRAR shell extension” has been detected as malware by 38 anti-virus scanners. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server.
Publisher:
Alexander Roshal

Product:
WinRAR

Description:
WinRAR shell extension

Version:
3.80

MD5:
7aa7edf5821cdc251d2e9cf97703a99d

SHA-1:
08aba706657cf3a7bea6caad42b7f179914faeba

SHA-256:
bdd1efcbed3ebdba73566b3697ed3488b357dc432f80c26670814d436c647caf

Scanner detections:
38 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/29/2024 12:31:53 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Ramnit.N
921

Agnitum Outpost
Win32.Nimnul.Gen.2
7.1.1

AhnLab V3 Security
Win32/Ramnit.F
2014.07.29

Avira AntiVirus
W32/Ramnit.C
7.11.30.172

avast!
Win32:RmnDrp
140617-1

AVG
Win32/Zbot.G
2014.0.3986

Baidu Antivirus
Virus.Win32.Nimnul.$a
4.0.3.14729

Bitdefender
Win32.Ramnit.N
1.0.20.1050

Bkav FE
W32.Tmgrtext.PE
1.3.0.4959

Clam AntiVirus
W32.Ramnit-1
0.98/19185

Comodo Security
Virus.Win32.Ramnit.K
19008

Dr.Web
Win32.Siggen.7
9.0.1.05190

Emsisoft Anti-Malware
Win32.Ramnit.N
8.14.07.29.02

ESET NOD32
Win32/Ramnit.H virus
7.0.302.0

Fortinet FortiGate
W32/Ramnit.C
7/29/2014

F-Prot
W32/Ramnit.D
4.6.5.141

F-Secure
Win32.Ramnit.N
11.2014-29-07_3

G Data
Win32.Ramnit
14.7.24

IKARUS anti.virus
Virus.Win32.Ramnit
t3scan.1.6.1.0

K7 AntiVirus
Virus
13.181.12872

Kaspersky
Virus.Win32.Nimnul
15.0.0.494

McAfee
W32/Ramnit.a
5600.7055

Microsoft Security Essentials
Threat.Undefined
1.179.1326.0

MicroWorld eScan
Win32.Ramnit.N
15.0.0.630

NANO AntiVirus
Virus.Win32.Nimnul.bmnup
0.28.2.61148

Norman
Ramnit.AS
11.20140729

nProtect
Virus/W32.SpyEye
14.07.28.01

Panda Antivirus
W32/Cosmu.C
14.07.29.02

Qihoo 360 Security
Virus.Win32.Ramnit.A
1.0.0.1015

Quick Heal
W32.Ramnit.A
7.14.14.00

Rising Antivirus
PE:Win32.Ramnit.i!1075353400
23.00.65.14727

Sophos
W32/Ramnit-A
4.98

Total Defense
Win32/Ramnit.C
37.0.11086

Trend Micro House Call
PE_RAMNIT.DEN
7.2.210

Trend Micro
PE_RAMNIT.DEN
10.465.29

Vba32 AntiVirus
Virus.Win32.Nimnul.b
3.12.26.3

VIPRE Antivirus
Threat.4732184
31208

ViRobot
Win32.Nimnul.A
2011.4.7.4223

File size:
191.9 KB (196,466 bytes)

Copyright:
Copyright © Alexander Roshal 1993-2008

Original file name:
RarExt.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\winrar\rarext.dll

Registration
CLSID:
{B41DB860-8EE4-11D2-9906-E49FADC173CA}

COM registered:
Yes

File PE Metadata
Compilation timestamp:
9/16/2008 9:18:04 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.0

CTPH (ssdeep):
3072:YZ/EI0fGGoxrPQh87N2jPqAAI4VD6AdeN4Q1dNbEOp3iV92COsohRz7R5:YZ/ef1ox7k87N2jCAF48d1dNbZ3irnGh

Entry address:
0x2E000

Entry point:
60, E8, 00, 00, 00, 00, 5D, 8B, C5, 81, ED, 1E, A5, 01, 20, 2B, 85, 85, AC, 01, 20, 89, 85, 81, AC, 01, 20, B0, 00, 86, 85, B6, AE, 01, 20, 3C, 01, 0F, 85, BC, 01, 00, 00, 83, BD, B1, AD, 01, 20, 00, 74, 33, 83, BD, B5, AD, 01, 20, 00, 74, 2A, 8B, 85, 81, AC, 01, 20, 2B, 85, B1, AD, 01, 20, 8B, 00, 89, 85, EE, AD, 01, 20, 8B, 85, 81, AC, 01, 20, 2B, 85, B5, AD, 01, 20, 8B, 00, 89, 85, F2, AD, 01, 20, EB, 61, 83, BD, B9, AD, 01, 20, 00, 74, 58, 8B, 85, 81, AC, 01, 20, 2B, 85, B9, AD, 01, 20, FF, 30, 8D, 85...
 
[+]

Entropy:
7.0570

Packer / compiler:
ASPack v1.08.04

Code size:
100 KB (102,400 bytes)

Approved Shell Extension
Name:
WinRAR shell extension

CLSID:
{B41DB860-8EE4-11D2-9906-E49FADC173CA}

CLSID name:
WinRAR


Remove RarExt.dll - Powered by Reason Core Security