WebShield.exe

Web Shield

Parallel Lines Development, LLC

This is part of an adware program designed to inject advertising in the web browser (banners, text-links) as well as modify the normal behavior of the browser as well as modify the computer’s system settings that control applications to run on startup. Part of the Injekt brand of unwanted programs. The application WebShield.exe by Parallel Lines Development has been detected as adware by 18 anti-malware scanners.
Publisher:
Parallel Lines Development, LLC  (signed and verified)

Product:
Web Shield

Version:
1.0.0.0

MD5:
9f845f3ca47592e913b146d1f71d8546

SHA-1:
ba9899c33d8cd02f76ecc8414a54119ff59fa766

SHA-256:
b4c765fe3a055ef311316c65c812c79d8ff6fcc0e6f7ae38ccabcca785c01162

Scanner detections:
18 / 68

Status:
Adware

Explanation:
Injects display ads (banner ads), in-text ads, interstitial ads, or other types of ads in the web browser as well as alters the browsers settings (home page, search, DNS, and security protocols).

Analysis date:
4/27/2024 3:16:59 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.PullUpdate
7.1.1

Bkav FE
W32.HfsAdware
1.3.0.6379

Comodo Security
ApplicUnwnt
17981

Dr.Web
Adware.Plugin.173
9.0.1.018

ESET NOD32
MSIL/Adware.PullUpdate (variant)
10.9581

Fortinet FortiGate
Adware/SaMon
1/18/2016

IKARUS anti.virus
not-a-virus:AdWare.Win32.SaMon
t3scan.1.6.1.0

K7 AntiVirus
Unwanted-Program
13.1712403

Kaspersky
not-a-virus:AdWare.Win32.SaMon
14.0.0.799

Malwarebytes
PUP.Optional.WebShield
v2016.01.18.02

McAfee
Artemis!E0B17E38000D
5600.6517

Qihoo 360 Security
Win32/Trojan.Adware.fb2
1.0.0.1015

Quick Heal
AdWare.SaMon.r3 (Not a Virus)
1.16.14.00

Reason Heuristics
PUP.Injekt.ParallelLinesDevelopment (M)
16.1.18.2

Sophos
Generic PUA OO
4.98

Trend Micro House Call
TROJ_GEN.F47V0308
7.2.18

Vba32 AntiVirus
AdWare.SaMon
3.12.26.0

VIPRE Antivirus
Adware.Win32.SaMon
30272

File size:
130.9 KB (134,016 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © Parallel Lines Development, LLC

Original file name:
WebShield.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\ProgramData\webshield\webshield.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/5/2013 7:00:00 AM

Valid to:
6/6/2014 6:59:59 AM

Subject:
CN="Parallel Lines Development, LLC", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Parallel Lines Development, LLC", L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
064A26D7B85E090E11BEBC6B460594A8

File PE Metadata
Compilation timestamp:
1/9/2014 7:20:42 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
768:NrYRAFmvNFrmh/Qn1gwZfVmg4irHdw2OwnaQufPmsj/BCBuNuJmrQ0JB/1PfyPZ4:N0+kFrq/Q1LZfVE+ebJ2LOIDqGB2

Entry address:
0x51FE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
4.2089

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
13 KB (13,312 bytes)

Remove WebShield.exe - Powered by Reason Core Security