Parent process
Child process
PE structurePE file structure

Show functions
Import table
LookupPrivilegeValueA, OpenProcessToken, SetFileSecurityA, SetFileSecurityW, GetSecurityDescriptorLength, GetFileSecurityA, GetFileSecurityW, RegCloseKey, RegQueryValueExA, RegOpenKeyExA, RegEnumValueA, RegQueryValueExW, RegSetValueExW, RegSetValueExA, RegCreateKeyExA, RegEnumKeyExA, RegDeleteValueA, RegDeleteKeyA, AdjustTokenPrivileges, LookupPrivilegeValueW, IsTextUnicode, RegEnumValueW, RegCreateKeyExW, RegDeleteValueW, RegEnumKeyExW, RegDeleteKeyW, RegOpenKeyExW, CryptGenRandom, CryptAcquireContextW, CryptReleaseContext
ImageList_ReplaceIcon, ImageList_Create, ImageList_Destroy, ImageList_Remove, ImageList_AddMasked, ImageList_Add, PropertySheetA, InitCommonControlsEx, CreateStatusWindowW, PropertySheetW
GetOpenFileNameW, GetOpenFileNameA, GetSaveFileNameA, CommDlgExtendedError, ChooseFontA, GetSaveFileNameW, ChooseFontW
MoveToEx, Rectangle, LineTo, CreatePatternBrush, GetDeviceCaps, CreateCompatibleBitmap, CreateBitmap, GetMapMode, SetPixel, SetMapMode, StretchBlt, GetTextExtentPoint32A, SetBkColor, BitBlt, GetObjectA, CreateCompatibleDC, GetPixel, DeleteDC, ExtTextOutA, TextOutA, CreatePen, CreateSolidBrush, SetTextColor, Polygon, Polyline, SelectObject, GetTextFaceA, GetTextMetricsA, CreateFontA, DPtoLP, DeleteObject, GetTextExtentPoint32W, ExtTextOutW, GetObjectW, TextOutW, GetTextFaceW, GetTextMetricsW, CreateFontW
OleInitialize, CoCreateInstance, OleSetClipboard, DoDragDrop, OleUninitialize, CreateStreamOnHGlobal, CoTaskMemFree, CoTaskMemAlloc, CLSIDFromString, CoInitializeEx
DragFinish, DragQueryFileA, DragQueryFileW, DragAcceptFiles, Shell_NotifyIconA, ShellExecuteA, ExtractIconExA, SHFileOperationA, ShellExecuteExA, SHGetMalloc, SHBrowseForFolderA, SHChangeNotify, SHGetDesktopFolder, SHGetSpecialFolderLocation, SHGetPathFromIDListA, SHGetFileInfoA, FindExecutableA, SHGetPathFromIDListW, FindExecutableW, Shell_NotifyIconW, ShellExecuteW, SHGetFileInfoW, SHAddToRecentDocs, SHFileOperationW, ShellExecuteExW, SHBrowseForFolderW
StrCmpLogicalW, SHAutoComplete
CreateDialogParamA, PostThreadMessageA, CharToOemBuffA, IsChild, GetLastActivePopup, GetClipboardData, GetMenuItemID, PostQuitMessage, InsertMenuA, LoadMenuA, RegisterClassA, LoadAcceleratorsA, FindWindowA, GetMenuState, SetDlgItemTextW, CreateIconIndirect, TranslateAcceleratorA, IsDialogMessageA, SetPropA, RegisterWindowMessageA, SetMenu, EnumWindows, FindWindowExA, CreateIcon, SetWindowTextW, GetWindowTextW, FlashWindow, CharUpperW, IsIconic, IntersectRect, ValidateRect, GetSysColor, CopyImage, FillRect, ExitWindowsEx, SetScrollPos, DrawIconEx, LoadStringA, GetWindow, SetMenuItemInfoA, IsCharUpperW, IsCharAlphaW, CharLowerW, IsCharUpperA, IsCharAlphaA, CharLowerA, OpenClipboard, EmptyClipboard, SetClipboardData, CharToOemA, CloseClipboard, MessageBeep, PeekMessageA, GetFocus, SetForegroundWindow, CopyIcon, EnableMenuItem, CheckMenuItem, LoadBitmapA, InsertMenuItemA, LoadImageA, MapWindowPoints, SetTimer, KillTimer, UpdateWindow, CharUpperA, GetClientRect, BeginPaint, EndPaint, SetWindowTextA, IsWindow, GetWindowTextLengthA, AppendMenuA, ScrollWindowEx, LoadIconA, SetScrollRange, GetDialogBaseUnits, PtInRect, SendMessageW, GetWindowPlacement, SetWindowPlacement, CreateDialogIndirectParamA, GetPropA, RemovePropA, GetSystemMenu, BringWindowToTop, GetMessageA, TranslateMessage, DispatchMessageA, RedrawWindow, GetIconInfo, SendMessageA, SetFocus, SetWindowPos, CreateWindowExA, DestroyWindow, GetWindowTextA, AppendMenuW, DrawMenuBar, GetMenu, GetSubMenu, DeleteMenu, GetMenuItemCount, GetMenuItemInfoA, ScreenToClient, ClientToScreen, CreatePopupMenu, SetWindowLongA, TrackPopupMenu, DestroyMenu, CallWindowProcA, RegisterClipboardFormatA, GetKeyState, LoadCursorA, SetCursor, GetCursorPos, WindowFromPoint, GetWindowThreadProcessId, InvalidateRect, GetDC, ReleaseDC, GetDesktopWindow, GetWindowLongA, GetSystemMetrics, ShowWindow, EnableWindow, IsWindowEnabled, SetDlgItemInt, GetDlgItemInt, IsDlgButtonChecked, PostMessageA, EnumChildWindows, GetParent, GetDlgItem, GetWindowRect, GetClassNameA, CheckDlgButton, MessageBoxA, IsWindowVisible, OemToCharBuffA, DialogBoxParamA, SendDlgItemMessageA, DestroyIcon, GetDlgItemTextA, SetDlgItemTextA, EndDialog, OemToCharA, DefWindowProcA, MoveWindow, CreateDialogIndirectParamW, LoadIconW, CreateDialogParamW, PostThreadMessageW, InsertMenuW, LoadMenuW, RegisterClassW, LoadAcceleratorsW, LoadStringW, SetMenuItemInfoW, SystemParametersInfoW, GetComboBoxInfo, GetPropW, GetMessageW, PeekMessageW, LoadBitmapW, InsertMenuItemW, LoadImageW, GetWindowTextLengthW, GetMenuItemInfoW, CharToOemBuffW, SetWindowLongW, CallWindowProcW, RegisterClipboardFormatW, LoadCursorW, RemovePropW, TranslateAcceleratorW, IsDialogMessageW, SetPropW, FindWindowW, GetForegroundWindow, RegisterWindowMessageW, FindWindowExW, RegisterClassExW, DispatchMessageW, DefWindowProcW, CreateWindowExW, GetDlgItemTextW, CopyRect, GetWindowLongW, SystemParametersInfoA, PostMessageW, GetClassNameW, MessageBoxW, DialogBoxParamW, SendDlgItemMessageW, GetMonitorInfoW
IsAppThemed, IsThemeActive


WinRAR by win.rar GmbH (Signed)

Version:   4.20.0
MD5:   9213c294bbfcaa9aa063367a1647452b
SHA1:   46eb83356cbbd7500cd2e6728112205f43ca69d6
SHA256:   b908109795e2bae549c34e8011e4e128207af90502b1129f0487310ef615ab3f

What is WinRAR.exe?

WinRAR is a powerful archive manager. It can backup your data and reduce the size of email attachments, decompress RAR, ZIP and other files downloaded from Internet and create new archives in RAR and ZIP file format.

About WinRAR.exe (from win.rar GmbH)

There is no better way to compress files for efficient and secure file transfer, faster e-mail transmission and well organized data storage. Over 500 million users world-wide make WinRAR the worlds's


winrar.exe executes as a process with the local user's privileges typically within the context of its parent firefox.exe (Firefox by Mozilla Corporation). It is installed with a couple of know programs including WinRAR 4.20 (32-bit) published by win.rar GmbH, WinRAR 4.01 (32-bit) from win.rar GmbH and WinRAR 4.01 (32-bit) by win.rar GmbH. The file is digitally signed by win.rar GmbH which was issued by the COMODO CA Limited certificate authority (CA).


File name:winrar.exe
Publisher:Alexander Roshal
Product name:WinRAR
Description:WinRAR archiver
Typical file path:C:\Program Files\winrar\winrar.exe
File version:4.20.0
Size:1.11 MB (1,159,168 bytes)
Issued to:win.rar GmbH
Authority (CA):COMODO CA Limited
Expiration date:Sunday, June 14, 2015
Digital DNA
File packed:No
More details


ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Total CPU:0.02714795%
Kernel CPU:0.01770178%
User CPU:0.00944617%
Kernel CPU time:109,464 ms/min
Context switches:22/sec
Private memory:7.41 MB
21.59 MB
Private (maximum):10.2 MB
Private (minimum):8.73 MB
Non-paged memory:7.41 MB
21.59 MB
Virtual memory:99.51 MB
140.96 MB
Virtual memory (peak):128.16 MB
169.69 MB
Working set:8.96 MB
18.61 MB
Working set (peak):14.76 MB
37.95 MB
I/O read transfer:3.73 KB/sec
1.02 MB/min
I/O read operations:1/sec
I/O write transfer:2 KB/sec
274.99 KB/min
I/O write operations:1/sec
I/O other transfer:603 Bytes/sec
448.09 KB/min
I/O other operations:19/sec
Resource allocations
GUI GDI count:149
GUI GDI peak:185
GUI USER count:52
GUI USER peak:78

BehaviorsProcess properties

Integrety level:Undefined
Command lines:
  • "C:\Program Files\winrar\winrar.exe" "C:\Documents and Settings\user\My documents\downloads\minecraft launcher offline"
  • "C:\Program Files\winrar\winrar.exe" "C:\???? dmc devil may cry 2013\dmc.devil.may.cry[].rar"
Parent process:firefox.exe (Firefox by Mozilla Corporation)


WinRAR.exe (main module)
Total CPU:0.01335779%
Kernel CPU:0.00821258%
User CPU:0.00514521%
CPU cycles:29,066,483/sec
Context switches:9/sec
Memory:1.56 MB
1.16 MB
CPU cycles:17,713/sec
Memory:1.41 MB

Common loaded modules

These are modules that are typiclaly loaded within the context of this process.

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 28.00%
Windows 7 Ultimate 24.00%
Microsoft Windows XP 9.00%
Windows 8.1 Pro 6.00%
Windows 8 Pro 5.50%
Windows 7 Professional 5.00%
Windows 8.1 4.50%
Windows 8.1 Single Language 2.50%
Windows 7 Home Basic 2.50%
Windows 8.1 Pro with Media Center 2.00%
Windows 8 Single Language 2.00%
Windows 8 1.50%
Windows 8 Enterprise 1.00%
Windows Vista Home Premium 1.00%
Windows 8.1 Enterprise 1.00%
Windows 8 Pro with Media Center 1.00%
Windows 8.1 N 0.50%
Windows 8 Enterprise N 0.50%
Windows Vista Home Basic 0.50%
Windows 8 Enterprise Evaluation 0.50%
Windows 8.1 Pro Preview 0.50%
23 other Windows OS version

Distribution by countryDistribution by country

United States installs about 22.11% of WinRAR.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 22.39%
ASUS 18.66%
Hewlett-Packard 11.57%
Acer 10.82%
Lenovo 9.70%
Toshiba 6.72%
Intel 5.22%
Compaq 2.99%
Sony 2.24%
Samsung 1.87%
Alienware 1.49%
American Megatrends 1.12%
Gateway 0.75%
MSI 0.75%
