9804_webprotectpd.exe

wprotectplus0c

wprotectplus0

The application 9804_webprotectpd.exe has been detected as a potentially unwanted program by 17 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from webprotectionfree.com.
Publisher:
wprotectplus0

Product:
wprotectplus0c

Version:
4.3.0.51

MD5:
dd297e237ceeac005199c220f0b09d89

SHA-1:
67445bc21607bedc545ad37682eb97085066f518

SHA-256:
5b39501888622ed3767947c3bde508a78fcfa861cfcf349db88bc2688b70665d

Scanner detections:
17 / 68

Status:
Potentially unwanted

Analysis date:
1/9/2025 11:14:26 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Dldr.Megone.73264
8.3.1.6

avast!
Win32:Dropper-gen [Drp]
2014.9-150523

Baidu Antivirus
Adware.Win32.Genome
4.0.3.15523

Dr.Web
Trojan.DownLoader13.14263
9.0.1.0143

ESET NOD32
Win32/Adware.Similagro
9.11623

herdProtect (fuzzy)
2015.7.30.4

K7 AntiVirus
Adware
13.203.15903

Kaspersky
Trojan-Downloader.Win32.Genome
15.0.0.543

McAfee
RDN/Generic Downloader.x!nk
5600.6756

Norman
Downloader
11.20150430

Panda Antivirus
Generic Suspicious
15.05.23.02

Qihoo 360 Security
HEUR/QVM42.0.Malware.Gen
1.0.0.1015

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
Suspicious_GEN.F47V0429
7.2.120

Trend Micro
TROJ_GEN.R000C0EE815
10.465.23

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
40212

File size:
71.5 KB (73,264 bytes)

Product version:
4.3.0.51

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\9804_webprotectpd.exe

File PE Metadata
Compilation timestamp:
5/11/2014 11:03:30 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:MwJOoN1oYaoZ5iV685XJPC04Romu/Tpy8uTT0e8O5a9:MwJ52Y7ZoH5XJa045N1i9

Entry address:
0x30B6

Entry point:
81, EC, 84, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 90, 91, 40, 00, 89, 5C, 24, 20, C6, 44, 24, 14, 20, FF, 15, 34, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, 1C, 71, 40, 00, 53, FF, 15, 8C, 72, 40, 00, 6A, 08, A3, 78, 37, 42, 00, E8, 95, 2D, 00, 00, A3, C4, 36, 42, 00, 53, 8D, 44, 24, 38, 68, 60, 01, 00, 00, 50, 53, 68, 80, EC, 41, 00, FF, 15, 64, 71, 40, 00, 68, 80, 91, 40, 00, 68, C0, 2E, 42, 00, E8, 3F, 2A, 00, 00, FF, 15, 20, 71, 40, 00, BD, 00, 90, 42, 00, 50, 55, E8, 2D, 2A...
 
[+]

Entropy:
7.1089

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file 9804_webprotectpd.exe has been seen being distributed by the following URL.

Remove 9804_webprotectpd.exe - Powered by Reason Core Security