How to remove Rar64.exe
Rar64.exe
The module Rar64.exe has been detected as Trojan.Wacapew
File Details
| Product Name: | SevenZip |
| Company Name: | Alexander Roshal |
| MD5: | b22c66a32bd476754a8de0392690490d |
| Size: | 22 KB |
| First Published: | 2025-06-09 23:01:06 (10 months ago) |
| Latest Published: | 2025-10-28 23:01:10 (6 months ago) |
| Status: | Trojan.Wacapew (on last analysis) | |
| Analysis Date: | 2025-10-28 23:01:10 (6 months ago) |
Common Places:
| %programfiles% |
| %localappdata% |
| %programfiles% |
Geography:
| 66.7% | ||
| 33.3% |
OS Version:
| Windows 10 | 100.0% |
Analysis
| Subsystem: | Windows GUI |
| PE Type: | pe |
| OS Bitness: | 32 |
| Image Base: | 0x00400000 |
| Entry Address: | 0x00006c01 |
.NET Info:
| MVID: | 6ff24103-2d31-445b-85e8-4b44d5f74f1f |
| Typelib ID: | ac6e2d70-d9fa-49e4-9e8e-6adf9915e980 |
PE Sections:
| Name | Size of data | MD5 |
| .text | 19968 | 0f89b077120f359b07a812b4e9e7508f |
| .rsrc | 1536 | 6ffaf9b567bbd9f16198b5133f86c78d |
| .reloc | 512 | db1a7639290eaf6208243483c769458b |
More information:
Download GridinSoft
Anti-Malware - Removal tool for Rar64.exe