Technical Information
- [<HKLM>\Software\Classes\WinRAR\shell\open\command] '' = '"%ProgramFiles%\WinRAR\WinRAR.exe" "%1"'
- [<HKLM>\Software\Classes\WinRAR.ZIP\shell\open\command] '' = '"%ProgramFiles%\WinRAR\WinRAR.exe" "%1"'
- [<HKLM>\Software\Classes\WinRAR.REV\shell\open\command] '' = '"%ProgramFiles%\WinRAR\WinRAR.exe" "%1"'
- '<SYSTEM32>\taskkill.exe' /F /IM WinRAR.exe
- '<SYSTEM32>\taskkill.exe' /IM WinRAR.exe /F
- %TEMP%\b623.tmp\b624.bat
- %APPDATA%\winrar\themes\delato_32x32\sfx.ico
- %APPDATA%\winrar\themes\delato_32x32\setup.ico
- %APPDATA%\winrar\themes\delato_32x32\rev.ico
- %APPDATA%\winrar\themes\delato_32x32\rarsmall.bmp
- %APPDATA%\winrar\themes\delato_32x32\rar.ico
- %APPDATA%\winrar\themes\delato_32x32\passwordon.ico
- %APPDATA%\winrar\themes\delato_32x32\passwordoff.ico
- %APPDATA%\winrar\themes\delato_32x32\folderup.bmp
- %APPDATA%\winrar\themes\delato_32x32\file.ico
- %APPDATA%\winrar\themes\delato_32x32\sfxlogo.bmp
- %APPDATA%\winrar\themes\delato_32x32\estimate.bmp
- %APPDATA%\winrar\themes\delato_32x32\diskon.ico
- %APPDATA%\winrar\themes\delato_32x32\diskoff.ico
- %APPDATA%\winrar\themes\delato_32x32\aboutlogo.bmp
- %PROGRAMDATA%\microsoft\windows\start menu\programs\winrar\quelles sont les nouveautГ©s de la derniГЁre version.lnk
- %PROGRAMDATA%\microsoft\windows\start menu\programs\winrar\manuel de la console rar.lnk
- %PROGRAMDATA%\microsoft\windows\start menu\programs\winrar\aide de winrar.lnk
- %APPDATA%\microsoft\windows\start menu\programs\winrar\quelles sont les nouveautГ©s de la derniГЁre version.lnk
- %APPDATA%\microsoft\windows\start menu\programs\winrar\manuel de la console rar.lnk
- %APPDATA%\microsoft\windows\start menu\programs\winrar\aide de winrar.lnk
- %APPDATA%\winrar\themes\delato_32x32\dragcopy.cur
- %APPDATA%\winrar\themes\delato_32x32\sortdown.bmp
- %APPDATA%\winrar\themes\delato_32x32\sortup.bmp
- %APPDATA%\winrar\themes\delato_32x32\tray.ico
- %APPDATA%\winrar\themes\delato_32x32\toolbar\virusscan.bmp
- %APPDATA%\winrar\themes\delato_32x32\toolbar\view.bmp
- %APPDATA%\winrar\themes\delato_32x32\toolbar\test.bmp
- %APPDATA%\winrar\themes\delato_32x32\toolbar\sfx.bmp
- %APPDATA%\winrar\themes\delato_32x32\toolbar\report.bmp
- %APPDATA%\winrar\themes\delato_32x32\toolbar\repair.bmp
- %APPDATA%\winrar\themes\delato_32x32\toolbar\protect.bmp
- %APPDATA%\winrar\themes\delato_32x32\toolbar\print.bmp
- %APPDATA%\winrar\themes\delato_32x32\toolbar\lock.bmp
- %APPDATA%\winrar\themes\delato_32x32\toolbar\info.bmp
- %APPDATA%\winrar\themes\delato_32x32\toolbar\find.bmp
- %APPDATA%\winrar\themes\delato_32x32\toolbar\extractto.bmp
- %APPDATA%\winrar\themes\delato_32x32\toolbar\extract.bmp
- %APPDATA%\winrar\themes\delato_32x32\toolbar\exit.bmp
- %APPDATA%\winrar\themes\delato_32x32\toolbar\delete.bmp
- %APPDATA%\winrar\themes\delato_32x32\toolbar\convert.bmp
- %APPDATA%\winrar\themes\delato_32x32\toolbar\comment.bmp
- %APPDATA%\winrar\themes\delato_32x32\toolbar\benchmark.bmp
- %APPDATA%\winrar\themes\delato_32x32\toolbar\add.bmp
- %APPDATA%\winrar\themes\delato_32x32\wizardlogo.bmp
- %APPDATA%\winrar\themes\delato_32x32\winrar_theme_description.txt
- %ProgramFiles%\winrar\winrar.lng
- %APPDATA%\winrar\themes\delato_32x32\toolbar\wizard.bmp
- %ProgramFiles%\winrar\uninstall.lng
- %ProgramFiles%\winrar\rar.lng
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\sfxlogo.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\sfx.ico
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\setup.ico
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\rev.ico
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\rarsmall.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\rar.ico
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\passwordon.ico
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\passwordoff.ico
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\folderup.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\sortdown.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\file.ico
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\dragcopy.cur
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\diskon.ico
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\diskoff.ico
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\aboutlogo.bmp
- %TEMP%\b623.tmp\crack\rarreg.key
- %TEMP%\b623.tmp\winrar-x64-58b3fr.exe
- %TEMP%\b623.tmp\themeregxp.reg
- %TEMP%\b623.tmp\themereg.reg
- %TEMP%\b623.tmp\wrar58b3fr.exe
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\estimate.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\sortup.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\toolbar\add.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\toolbar\benchmark.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\wizardlogo.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\winrar_theme_description.txt
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\tray.ico
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\toolbar\wizard.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\toolbar\virusscan.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\toolbar\view.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\toolbar\test.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\toolbar\sfx.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\toolbar\report.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\toolbar\repair.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\toolbar\protect.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\toolbar\print.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\toolbar\lock.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\toolbar\info.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\toolbar\find.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\toolbar\extractto.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\toolbar\extract.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\toolbar\exit.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\toolbar\delete.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\toolbar\convert.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\toolbar\comment.bmp
- %ProgramFiles%\winrar\rarext.lng
- %ProgramFiles%\winrar\rarreg.key
- %TEMP%\b623.tmp\wrar58b3fr.exe
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\toolbar\delete.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\toolbar\exit.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\toolbar\extract.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\toolbar\extractto.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\toolbar\find.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\toolbar\info.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\toolbar\lock.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\toolbar\print.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\folderup.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\toolbar\protect.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\toolbar\report.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\toolbar\sfx.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\toolbar\test.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\toolbar\view.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\toolbar\virusscan.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\toolbar\wizard.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\tray.ico
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\winrar_theme_description.txt
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\toolbar\comment.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\toolbar\convert.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\toolbar\benchmark.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\toolbar\add.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\sortup.bmp
- %TEMP%\b623.tmp\themeregxp.reg
- %TEMP%\b623.tmp\winrar-x64-58b3fr.exe
- %TEMP%\b623.tmp\crack\rarreg.key
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\aboutlogo.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\diskoff.ico
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\diskon.ico
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\dragcopy.cur
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\estimate.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\wizardlogo.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\toolbar\repair.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\file.ico
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\passwordon.ico
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\rar.ico
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\rarsmall.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\rev.ico
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\setup.ico
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\sfx.ico
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\sfxlogo.bmp
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\sortdown.bmp
- %TEMP%\b623.tmp\themereg.reg
- %TEMP%\b623.tmp\xxx\themes\delato_32x32\passwordoff.ico
- %TEMP%\b623.tmp\b624.bat
- %ProgramFiles%\WinRAR\RarExt.dll
- %ProgramFiles%\WinRAR\RarExt32.dll
- %APPDATA%\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR.lnk
- %PROGRAMDATA%\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR.lnk
- ClassName: '' WindowName: ''
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- '%TEMP%\b623.tmp\winrar-x64-58b3fr.exe' /S
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\B623.tmp\B624.bat <Full path to file>"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\B623.tmp\B624.bat <Full path to file>"
- '%ProgramFiles%\winrar\uninstall.exe' /setup
- '<SYSTEM32>\xcopy.exe' /s /e /i /y /h /r /k "xxx" "%APPDATA%\WinRAR"
- '%WINDIR%\regedit.exe' /s ThemeREG.reg
- '<SYSTEM32>\xcopy.exe' /s /e /i /y /h /r /k "crack" "%ProgramFiles%\WinRAR"