Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

5.10.4 0.23%
5.10.0 0.46%
5.10.0 0.12%
5.1.0 2.44%
5.1.0 0.35%
5.1.0 0.23%
5.1.0 0.23%
5.0.8 0.12%
5.0.8 0.12%
5.0.8 0.12%
5.0.8 0.12%
5.0.8 0.12%
5.0.8 0.12%
5.0.7 0.12%
5.0.6 0.12%
5.0.6 0.46%
5.0.6 0.12%
5.0.6 0.12%
5.0.5 0.12%
5.0.5 0.12%
5.0.5 0.12%
5.0.5 0.12%
5.0.5 0.12%
5.0.5 0.12%
5.0.4 0.12%
View more

Relationships

Parent process
Child process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
LookupPrivilegeValueA, OpenProcessToken, SetFileSecurityA, SetFileSecurityW, GetSecurityDescriptorLength, GetFileSecurityA, GetFileSecurityW, RegCloseKey, RegQueryValueExA, RegOpenKeyExA, RegEnumValueA, RegQueryValueExW, RegSetValueExW, RegSetValueExA, RegCreateKeyExA, RegEnumKeyExA, RegDeleteValueA, RegDeleteKeyA, AdjustTokenPrivileges, LookupPrivilegeValueW, IsTextUnicode, RegEnumValueW, RegCreateKeyExW, RegDeleteValueW, RegEnumKeyExW, RegDeleteKeyW, RegOpenKeyExW, CryptGenRandom, CryptAcquireContextW, CryptReleaseContext
comctl32.dll
ImageList_ReplaceIcon, ImageList_Create, ImageList_Destroy, ImageList_Remove, ImageList_AddMasked, ImageList_Add, PropertySheetA, InitCommonControlsEx, CreateStatusWindowW, PropertySheetW
comdlg32.dll
GetOpenFileNameW, GetOpenFileNameA, GetSaveFileNameA, CommDlgExtendedError, ChooseFontA, GetSaveFileNameW, ChooseFontW
gdi32.dll
MoveToEx, Rectangle, LineTo, CreatePatternBrush, GetDeviceCaps, CreateCompatibleBitmap, CreateBitmap, GetMapMode, SetPixel, SetMapMode, StretchBlt, GetTextExtentPoint32A, SetBkColor, BitBlt, GetObjectA, CreateCompatibleDC, GetPixel, DeleteDC, ExtTextOutA, TextOutA, CreatePen, CreateSolidBrush, SetTextColor, Polygon, Polyline, SelectObject, GetTextFaceA, GetTextMetricsA, CreateFontA, DPtoLP, DeleteObject, GetTextExtentPoint32W, ExtTextOutW, GetObjectW, TextOutW, GetTextFaceW, GetTextMetricsW, CreateFontW
kernel32.dll
DllMain
ole32.dll
OleInitialize, CoCreateInstance, OleSetClipboard, DoDragDrop, OleUninitialize, CreateStreamOnHGlobal, CoTaskMemFree, CoTaskMemAlloc, CLSIDFromString, CoInitializeEx
shell32.dll
DragFinish, DragQueryFileA, DragQueryFileW, DragAcceptFiles, Shell_NotifyIconA, ShellExecuteA, ExtractIconExA, SHFileOperationA, ShellExecuteExA, SHGetMalloc, SHBrowseForFolderA, SHChangeNotify, SHGetDesktopFolder, SHGetSpecialFolderLocation, SHGetPathFromIDListA, SHGetFileInfoA, FindExecutableA, SHGetPathFromIDListW, FindExecutableW, Shell_NotifyIconW, ShellExecuteW, SHGetFileInfoW, SHAddToRecentDocs, SHFileOperationW, ShellExecuteExW, SHBrowseForFolderW
shlwapi.dll
StrCmpLogicalW, SHAutoComplete
user32.dll
CreateDialogParamA, PostThreadMessageA, CharToOemBuffA, IsChild, GetLastActivePopup, GetClipboardData, GetMenuItemID, PostQuitMessage, InsertMenuA, LoadMenuA, RegisterClassA, LoadAcceleratorsA, FindWindowA, GetMenuState, SetDlgItemTextW, CreateIconIndirect, TranslateAcceleratorA, IsDialogMessageA, SetPropA, RegisterWindowMessageA, SetMenu, EnumWindows, FindWindowExA, CreateIcon, SetWindowTextW, GetWindowTextW, FlashWindow, CharUpperW, IsIconic, IntersectRect, ValidateRect, GetSysColor, CopyImage, FillRect, ExitWindowsEx, SetScrollPos, DrawIconEx, LoadStringA, GetWindow, SetMenuItemInfoA, IsCharUpperW, IsCharAlphaW, CharLowerW, IsCharUpperA, IsCharAlphaA, CharLowerA, OpenClipboard, EmptyClipboard, SetClipboardData, CharToOemA, CloseClipboard, MessageBeep, PeekMessageA, GetFocus, SetForegroundWindow, CopyIcon, EnableMenuItem, CheckMenuItem, LoadBitmapA, InsertMenuItemA, LoadImageA, MapWindowPoints, SetTimer, KillTimer, UpdateWindow, CharUpperA, GetClientRect, BeginPaint, EndPaint, SetWindowTextA, IsWindow, GetWindowTextLengthA, AppendMenuA, ScrollWindowEx, LoadIconA, SetScrollRange, GetDialogBaseUnits, PtInRect, SendMessageW, GetWindowPlacement, SetWindowPlacement, CreateDialogIndirectParamA, GetPropA, RemovePropA, GetSystemMenu, BringWindowToTop, GetMessageA, TranslateMessage, DispatchMessageA, RedrawWindow, GetIconInfo, SendMessageA, SetFocus, SetWindowPos, CreateWindowExA, DestroyWindow, GetWindowTextA, AppendMenuW, DrawMenuBar, GetMenu, GetSubMenu, DeleteMenu, GetMenuItemCount, GetMenuItemInfoA, ScreenToClient, ClientToScreen, CreatePopupMenu, SetWindowLongA, TrackPopupMenu, DestroyMenu, CallWindowProcA, RegisterClipboardFormatA, GetKeyState, LoadCursorA, SetCursor, GetCursorPos, WindowFromPoint, GetWindowThreadProcessId, InvalidateRect, GetDC, ReleaseDC, GetDesktopWindow, GetWindowLongA, GetSystemMetrics, ShowWindow, EnableWindow, IsWindowEnabled, SetDlgItemInt, GetDlgItemInt, IsDlgButtonChecked, PostMessageA, EnumChildWindows, GetParent, GetDlgItem, GetWindowRect, GetClassNameA, CheckDlgButton, MessageBoxA, IsWindowVisible, OemToCharBuffA, DialogBoxParamA, SendDlgItemMessageA, DestroyIcon, GetDlgItemTextA, SetDlgItemTextA, EndDialog, OemToCharA, DefWindowProcA, MoveWindow, CreateDialogIndirectParamW, LoadIconW, CreateDialogParamW, PostThreadMessageW, InsertMenuW, LoadMenuW, RegisterClassW, LoadAcceleratorsW, LoadStringW, SetMenuItemInfoW, SystemParametersInfoW, GetComboBoxInfo, GetPropW, GetMessageW, PeekMessageW, LoadBitmapW, InsertMenuItemW, LoadImageW, GetWindowTextLengthW, GetMenuItemInfoW, CharToOemBuffW, SetWindowLongW, CallWindowProcW, RegisterClipboardFormatW, LoadCursorW, RemovePropW, TranslateAcceleratorW, IsDialogMessageW, SetPropW, FindWindowW, GetForegroundWindow, RegisterWindowMessageW, FindWindowExW, RegisterClassExW, DispatchMessageW, DefWindowProcW, CreateWindowExW, GetDlgItemTextW, CopyRect, GetWindowLongW, SystemParametersInfoA, PostMessageW, GetClassNameW, MessageBoxW, DialogBoxParamW, SendDlgItemMessageW, GetMonitorInfoW
uxtheme.dll
IsAppThemed, IsThemeActive

WinRAR.exe

WinRAR by win.rar GmbH (Signed)

Remove WinRAR.exe
Version:   4.20.0
MD5:   9213c294bbfcaa9aa063367a1647452b
SHA1:   46eb83356cbbd7500cd2e6728112205f43ca69d6
SHA256:   b908109795e2bae549c34e8011e4e128207af90502b1129f0487310ef615ab3f

What is WinRAR.exe?

WinRAR is a powerful archive manager. It can backup your data and reduce the size of email attachments, decompress RAR, ZIP and other files downloaded from Internet and create new archives in RAR and ZIP file format.

About WinRAR.exe (from win.rar GmbH)

There is no better way to compress files for efficient and secure file transfer, faster e-mail transmission and well organized data storage. Over 500 million users world-wide make WinRAR the worlds's

Overview

winrar.exe executes as a process with the local user's privileges typically within the context of its parent firefox.exe (Firefox by Mozilla Corporation). It is installed with a couple of know programs including WinRAR 4.20 (32-bit) published by win.rar GmbH, WinRAR 4.01 (32-bit) from win.rar GmbH and WinRAR 4.01 (32-bit) by win.rar GmbH. The file is digitally signed by win.rar GmbH which was issued by the COMODO CA Limited certificate authority (CA).

DetailsDetails

File name:winrar.exe
Publisher:Alexander Roshal
Product name:WinRAR
Description:WinRAR archiver
Typical file path:C:\Program Files\winrar\winrar.exe
File version:4.20.0
Size:1.11 MB (1,159,168 bytes)
Certificate
Issued to:win.rar GmbH
Authority (CA):COMODO CA Limited
Expiration date:Sunday, June 14, 2015
Digital DNA
Entropy:6.415815
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following programs will install this file
Artifex Software Inc.
1% remove
Ghostscript is a suite of software based on an interpreter for Adobe Systems' PostScript and Portable Document Format (PDF) page description languages. Its main purposes are the rasterization or rendering of such page description language files, for the display or printing of document pages, and the conversion between PostScript and PDF files. Ghostscript can also be used as a file format converter, such as PostScript to PDF converter; ...
ASUS
8% remove
ASUS makes serious hardware for die-hard overclockers who want to squeeze every ounce of performance out of their gear and never back down from a challenge. This experience is enhanced further with the all new and intuitive ASUS exclusive GPU Tweak utility - allowing you to monitor and optimize settings for ultimate performance on any graphics cards! Of course, ASUS graphics cards will come with more exclusive features.
BitTorrent Inc.
12% remove
µTorrent is a is a free, ad-supported, lighter-weight BitTorrent client designed to consume less resources then the full BitTorrent version. Some uTorrent installs include potentially unwanted applications in the form of the Conduit Engine, which installs a toolbar, and makes homepage and default search engine changes to a user's web browser.
Hyperdrive Systems
7% remove
Metaboli
  53% remove
S.P.D.
4% remove
Taiwan Shui Mu Chih Ching Technology Limited.
  75% remove
The free and trial versions bundle various potentually unwanted toolbars and web browser extensions including the AVG Toolbar which modifies the browser's search and home page settings..
Team-ScKorP
8% remove
Thomas Baumann
7% remove
TrueCrypt Foundation
10% remove
Free open-source disk encryption software for Windows. Creates a virtual encrypted disk within a file and mounts it as a real disk. Encrypts an entire partition or storage device such as USB flash drive or hard drive. Encrypts a partition or drive where Windows is installed (pre-boot authentication). Encryption is automatic, real-time (on-the-fly) and transparent.
Tweaking.com
  51% remove
Tweaking.com - Windows Repair is an all-in-one repair tool to help fix a large majority of known Windows problems including registry errors and file permissions as well as issues with Internet Explorer, Windows Update, Windows Firewall and more. Malware and installed programs can modify your default settings. With Tweaking.com - Windows Repair you can restore Windows original settings.
win.rar GmbH
5% remove
Since version 4.20 Compression speed in SMP mode has been increased significantly. ZIP compression now uses SMP as well. WinRAR is a shareware file archiver and data compression utility that is able to create RAR archives natively. WinRAR supports RAR (WinRAR native conversion format) and ZIP archives, and unpacking of ARJ, LZH, TAR, GZ, ACE, UUE, BZ2, JAR, ISO, EXE, 7z, and Z archives.
win.rar GmbH
5% remove
WinRAR is a shareware file archiver and data compression utility. It is one of the few applications that is able to create RAR archives natively, because the encoding method is held to be proprietary. Complete support for RAR (WinRAR native conversion format) and ZIP archives, and unpacking of ARJ, LZH, TAR, GZ, ACE, UUE, BZ2, JAR, ISO, EXE, 7z, and Z archives. Optional archive encryption using AES (Advanced Encryption Standard) with a ...
win.rar GmbH
8% remove
WinRAR is a shareware file archiver and data compression utility that is able to create RAR archives natively. WinRAR supports RAR (WinRAR native conversion format) and ZIP archives, and unpacking of ARJ, LZH, TAR, GZ, ACE, UUE, BZ2, JAR, ISO, EXE, 7z, and Z archives.
win.rar GmbH
12% remove
WinRAR archiver is a shareware file archiver that is able to create RAR archives natively.
win.rar GmbH
10% remove
Since version 4.20 Compression speed in SMP mode has been increased significantly. ZIP compression now uses SMP as well. WinRAR is a shareware file archiver and data compression utility that is able to create RAR archives natively. WinRAR supports RAR (WinRAR native conversion format) and ZIP archives, and unpacking of ARJ, LZH, TAR, GZ, ACE, UUE, BZ2, JAR, ISO, EXE, 7z, and Z archives.
win.rar GmbH
9% remove
WinRAR is a shareware file archiver and data compression utility that is able to create RAR archives natively. WinRAR supports RAR (WinRAR native conversion format) and ZIP archives, and unpacking of ARJ, LZH, TAR, GZ, ACE, UUE, BZ2, JAR, ISO, EXE, 7z, and Z archives.
win.rar GmbH
6% remove
WinRAR version 4 speeds up decompression by up to 30%. Windows 98, Windows Me, and Windows NT are no longer supported; the minimum Windows version required is Windows 2000. WinRAR is a shareware file archiver and data compression utility that is able to create RAR archives natively. WinRAR supports RAR (WinRAR native conversion format) and ZIP archives, and unpacking of ARJ, LZH, TAR, GZ, ACE, UUE, BZ2, JAR, ISO, EXE, 7z, and Z archives...
win.rar GmbH
4% remove
WinRAR is one of the most efficient compactors known and available, with the main highlight compatibility with various formats. In addition, while using the program you have more space available to store different types of files on your computer - after all, compressed documents take up very little space in the machine.

BehaviorsBehaviors

Shell open command
  • WinRAR

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.02714795%
0.028634%
Kernel CPU:0.01770178%
0.013761%
User CPU:0.00944617%
0.014873%
Kernel CPU time:109,464 ms/min
100,923,805ms/min
Context switches:22/sec
284/sec
Memory
Private memory:7.41 MB
21.59 MB
Private (maximum):10.2 MB
Private (minimum):8.73 MB
Non-paged memory:7.41 MB
21.59 MB
Virtual memory:99.51 MB
140.96 MB
Virtual memory (peak):128.16 MB
169.69 MB
Working set:8.96 MB
18.61 MB
Working set (peak):14.76 MB
37.95 MB
I/O
I/O read transfer:3.73 KB/sec
1.02 MB/min
I/O read operations:1/sec
343/min
I/O write transfer:2 KB/sec
274.99 KB/min
I/O write operations:1/sec
227/min
I/O other transfer:603 Bytes/sec
448.09 KB/min
I/O other operations:19/sec
1,671/min
Resource allocations
Threads:4
12
Handles:232
600
GUI GDI count:149
103
GUI GDI peak:185
142
GUI USER count:52
49
GUI USER peak:78
71

BehaviorsProcess properties

Integrety level:Undefined
Platform:32-bit
Command lines:
  • "C:\Program Files\winrar\winrar.exe" "C:\Documents and Settings\user\My documents\downloads\minecraft launcher offline patcher.zip"
  • "C:\Program Files\winrar\winrar.exe" "C:\???? dmc devil may cry 2013\dmc.devil.may.cry[www.bazikids.com].rar"
Owner:User
Parent process:firefox.exe (Firefox by Mozilla Corporation)

ResourcesThreads

Averages
 
WinRAR.exe (main module)
Total CPU:0.01335779%
0.272967%
Kernel CPU:0.00821258%
0.107585%
User CPU:0.00514521%
0.165382%
CPU cycles:29,066,483/sec
5,741,424/sec
Context switches:9/sec
79/sec
Memory:1.56 MB
1.16 MB
ntdll.dll
CPU cycles:17,713/sec
Memory:1.41 MB

Common loaded modules

These are modules that are typiclaly loaded within the context of this process.

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 28.00%
Windows 7 Ultimate 24.00%
Microsoft Windows XP 9.00%
Windows 8.1 Pro 6.00%
Windows 8 Pro 5.50%
Windows 7 Professional 5.00%
Windows 8.1 4.50%
Windows 8.1 Single Language 2.50%
Windows 7 Home Basic 2.50%
Windows 8.1 Pro with Media Center 2.00%
Windows 8 Single Language 2.00%
Windows 8 1.50%
Windows 8 Enterprise 1.00%
Windows Vista Home Premium 1.00%
Windows 8.1 Enterprise 1.00%
Windows 8 Pro with Media Center 1.00%
Windows 8.1 N 0.50%
Windows 8 Enterprise N 0.50%
Windows Vista Home Basic 0.50%
Windows 8 Enterprise Evaluation 0.50%
Windows 8.1 Pro Preview 0.50%
23 other Windows OS version

Distribution by countryDistribution by country

United States installs about 22.11% of WinRAR.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 22.39%
ASUS 18.66%
Hewlett-Packard 11.57%
Acer 10.82%
Lenovo 9.70%
Toshiba 6.72%
Intel 5.22%
GIGABYTE 3.73%
Compaq 2.99%
Sony 2.24%
Samsung 1.87%
Alienware 1.49%
American Megatrends 1.12%
Gateway 0.75%
MSI 0.75%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE