Table of Contents
About WinExt Pro
WinExt Pro is a useful software that allows you to fix Registry issues, clean up system junk, protect your privacy, and find duplicate files or larger resources. This software enables you to quickly see all drive/directory/file sizes in 1 tree view in order to allow you to do the manual disk cleaning work easily. Besides, it automatically or manually synchronizes your resources to other places, and you are able to set the sync mode as “Once changed”, “Fixed frequency (mins)”, and specific times.

Key Features:
- Fix Registry issues and clean Registry junk
- Secure cleaning up useless or invalid system resources
- Protects your privacy
- Find and delete large/duplicate files
- Lets you quickly see all drives/directories/files size in 1 tree view
- See more information on recently accessed resources
- Monitor file operations in watched directories
- Make batch operation on multiple resources
- Automatically or manually synchronize resources
Supported OS: Windows 7/8/8.1/10/11 (x32/x64)
Price: $19.99/1-year license
How to get the TriSun WinExt Pro license key for free?
No need to spend your money on TriSun WinExt Pro, you can easily get a license for free right now and right here. Simply take the following steps:
Step 1. Download the installer from the homepage –> https://www.trisunsoft.com/files/win-ext.exe
Install the software on your computer.

Step 2. Use the free license code below to activate WinExt Pro
License code
Just open the application and register it:

Step 3. Enjoy TriSun WinExt for 1 year with a free update!

Terms of use
- License info: 1 Year Single License (1 PC)
- Update policy: free updates for 1-year
- Tech support policy: No tech support


Nope, aren’t gonna deal with keylogger type stalker. So many warning from many good Antirus vendors.
Verdict: MALICIOUS
Confidence: 100/100
Tags: installer,overlay,packed,setupapi.dll,shell32.dll,peexe,html,xml
Domains: crl.comodo.net,crl.comodoca.com,crl.sectigo.com,crl.usertrust.com,crt.sectigo.com,crt.usertrust.com,jrsoftware.org,schemas.microsoft.com,sectigo.com
Hosts: 30.0.099.0,30.0.099.0,172.64.155.188,172.64.155.188,172.64.155.188,91.199.212.52,91.199.212.52,75.119.223.113,151.139.128.14
Report: https://www.filescan.io/reports/5389c84f22e61bb925b3b06b2203f9020160ca67681dbb852aee64765f0676c9/7b38fbf8-0552-4336-bc6a-001e3c80b591
Analysis Report: https://www.vmray.com/analyses/_vt/5389c84f22e6/report/overview.html
IOC Tab: https://www.vmray.com/analyses/_vt/5389c84f22e6/report/ioc.html
Function Log: https://www.vmray.com/analyses/_vt/5389c84f22e6/logs/flog.txt
STIX 2.0 IOCs: https://www.vmray.com/analyses/_vt/5389c84f22e6/report/artifacts/stix-report-2-0-iocs.json
summary.json: https://www.vmray.com/analyses/_vt/5389c84f22e6/logs/summary_v2.json
MWDB Link : https://mwdb.cert.pl/file/5389c84f22e61bb925b3b06b2203f9020160ca67681dbb852aee64765f0676c9
Triage Link : https://tria.ge/240413-bjj2hshe27
VirusShare Link : https://virusshare.com/file?5389c84f22e61bb925b3b06b2203f9020160ca67681dbb852aee64765f0676c9
Only virus
AhnLab-V3
PUP/Win.Agent.C5612914
AliCloud
SypWare:MSIL/TriSun.WQfZtj
Antiy-AVL
GrayWare/Win32.Lodi
Arctic Wolf
Unsafe
Avast
Win32:PUP-gen [PUP]
AVG
Win32:PUP-gen [PUP]
Avira (no cloud)
PUA/WinExt.ake
CTX
Exe.unknown.winext
DeepInstinct
MALICIOUS
ESET-NOD32
MSIL/TriSun.WinExt.A Potentially Unwanted Application
GData
Win32.Application.Agent.1L3U43
Google
Detected
Kaspersky
Hoax.Win32.Agent.zyb
Kingsoft
Win32.NotVirus.Agent.a
Lionic
Hacktool.Win32.WinExt.3!c
Malwarebytes
PUP.Optional.WinExt
MaxSecure
Trojan.Malware.320772.susgen
McAfee Scanner
Ti!5389C84F22E6
Microsoft
Misleading:Win32/Lodi!MTB
NANO-Antivirus
Riskware.Win32.TriSun.juxhlo
Panda
PUP/BundleInstaller
Rising
PUF.TriSun!8.13100 (CLOUD)
Skyhigh (SWG)
Artemis!PUP
Sophos
Mal/Generic-S
Symantec
PUA.Superfluss
Trellix ENS
Artemis!71C8CC4A3EB6
Varist
W32/ABApplication.HVXY-6547
VBA32
TrojanLoader.MSIL.DaVinci.Heur
VirIT
Deceptor.WinExt.DPQ
ViRobot
Adware.Winext.2727320
Webroot
W32.Malware.gen
WithSecure
PotentialRisk.PUA/WinExt.SL
MD5
71c8cc4a3eb667dd784ff6a7137b832a
SHA-1
4f38bd2fa2c466a33001023588e17020079561b0
SHA-256
5389c84f22e61bb925b3b06b2203f9020160ca67681dbb852aee64765f0676c9
Vhash
026086665d1c0d1c0515103016z2az3bz4fz
Authentihash
1ff02c847fd311218b706db4646cc86c79076e2205758b2c9c10bb63fc3eb877
Imphash
20dd26497880c05caed9305b3c8b9109
SSDEEP
49152:0h6ncCeDq6ij7wLEC8miAqmMB23orOmRT7w+eOlMHQkXZMNRtqbwdcy:HncCcqnwLkmiAe2YrOmRT7w+ZMwkmNRf
TLSH
T19EC523A2BAD70832F8B55934C876D110AD23BDBA04F1700B2DF4ED4E6DBF6D16835A52
Thanks to whoever offered this key.