20882 Rar Info
: The process was observed reading Internet Explorer security settings , a common tactic used by malware to lower system defenses or prepare for credential theft.
: WinRAR.exe spawning cmd.exe to run .bat scripts from temporary folders. 20882 rar
: The analysis shows a file named Rar$Scan19941.bat being launched from the 20882 directory via cmd.exe . : The process was observed reading Internet Explorer
