Rar — 20882
: C:\Users\admin\AppData\Local\Temp\20882\ (or similar Temp subdirectories).
: The analysis shows a file named Rar$Scan19941.bat being launched from the 20882 directory via cmd.exe . 20882 rar
: Look for variations of Rar$Scan[Number].bat . 20882 rar
: WinRAR.exe spawning cmd.exe to run .bat scripts from temporary folders. 20882 rar