mweshield.exe

Chichek Konstrakshn, TOV

The application mweshield.exe by Chichek Konstrakshn, TOV has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a separate (within the context of its own process) windows Service named “My Web Shield Sentinel”.
Publisher:
Chichek Konstrakshn, TOV  (signed and verified)

MD5:
79e848c5b6765dd5c96d787ab7b624fe

SHA-1:
0ad1645b420d845ed3f9cabfb7728bc030d9c2a5

SHA-256:
3d9db480e29795d874d74204ef53331473680873c298bead6799a7dc9bc5ea66

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/29/2024 1:50:42 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.MyWebShield (M)
17.3.15.21

File size:
909.3 KB (931,128 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\Program Files\my web shield\mweshield.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
8/22/2016 3:00:00 AM

Valid to:
8/23/2017 2:59:59 AM

Subject:
CN="Chichek Konstrakshn, TOV", OU=IT, O="Chichek Konstrakshn, TOV", STREET="vul. Kikvidze, 5", L=Kyyiv, S=Kyyiv, PostalCode=01103, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
39D3FCDE4532A63BD298039D0555D0C2

File PE Metadata
Compilation timestamp:
8/31/2016 3:16:25 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x718C0

Code size:
556 KB (569,344 bytes)

Service
Display name:
My Web Shield Sentinel

Service name:
mweshield

Type:
Win32OwnProcess

Depends on:
RPCSS


Remove mweshield.exe - Powered by Reason Core Security