Skip to content

Rar — 20882

: C:\Users\admin\AppData\Local\Temp\20882\ (or similar Temp subdirectories).

: The analysis shows a file named Rar$Scan19941.bat being launched from the 20882 directory via cmd.exe . 20882 rar

: Look for variations of Rar$Scan[Number].bat . 20882 rar

: WinRAR.exe spawning cmd.exe to run .bat scripts from temporary folders. 20882 rar