WebShieldService.exe

Web Shield Service

Parallel Lines Development, LLC

This is part of an adware program designed to inject advertising in the web browser (banners, text-links) as well as modify the normal behavior of the browser as well as modify the computer’s system settings that control applications to run on startup. Part of the Injekt brand of unwanted programs. The application WebShieldService.exe by Parallel Lines Development has been detected as adware by 9 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “Web Shield”.
Publisher:
Parallel Lines Development, LLC  (signed and verified)

Product:
Web Shield Service

Version:
1.0.0.0

MD5:
ead59614c636c5fc2341844eb38fd389

SHA-1:
3ee25e973973eade0f0ec88e6a056456ae4679ef

SHA-256:
4728b71c1f661f45a2507c0c2801c902f8d0ff55f5eb3196f5444c0e465033b9

Scanner detections:
9 / 68

Status:
Adware

Explanation:
Injects display ads (banner ads), in-text ads, interstitial ads, or other types of ads in the web browser as well as alters the browsers settings (home page, search, DNS, and security protocols).

Analysis date:
4/25/2024 4:15:43 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.PullUpdate
7.1.1

Comodo Security
ApplicUnwnt
18149

Dr.Web
Adware.Plugin.175
9.0.1.0169

ESET NOD32
MSIL/Adware.PullUpdate (variant)
8.9706

Fortinet FortiGate
Adware/PullUpdate
6/18/2014

Malwarebytes
PUP.Optional.WebShield
v2014.06.18.11

Qihoo 360 Security
Win32/Trojan.Adware.988
1.0.0.1015

Reason Heuristics
PUP.Service.ParallelLinesDevelopment.Q
14.8.8.0

Trend Micro House Call
TROJ_GEN.F47V0419
7.2.169

File size:
64.4 KB (65,920 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © Parallel Lines Development, LLC 2014

Original file name:
WebShieldService.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\ProgramData\webshield\up\2.6.78\webshieldservice.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/9/2014 8:00:00 AM

Valid to:
7/10/2015 7:59:59 AM

Subject:
CN="Parallel Lines Development, LLC", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Parallel Lines Development, LLC", L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5942FEB110EDE4092448C0AA0969CD7F

File PE Metadata
Compilation timestamp:
4/19/2014 1:48:35 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
1536:sLnfc6r+N1MeKaqMP6419CaqvZZm1XPwZDJtNl:srhrLeKzo6419CaqvMXPwZDpl

Entry address:
0xFBCE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 02, 00, 10, 00, 00, 00, 20, 00, 00, 80, 18, 00, 00, 00, 38, 00, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 01, 00, 01, 00, 00, 00, 50, 00, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 01, 00, 01, 00, 00, 00, 68, 00...
 
[+]

Entropy:
5.8427

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
55 KB (56,320 bytes)

Service
Display name:
Web Shield

Service name:
WebShield

Description:
Provides system level support for Web Shield.

Type:
Win32OwnProcess


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ec2-54-171-43-206.eu-west-1.compute.amazonaws.com  (54.171.43.206:80)

TCP (HTTP):
Connects to ec2-52-16-174-255.eu-west-1.compute.amazonaws.com  (52.16.174.255:80)

TCP (HTTP):
Connects to ec2-34-250-194-62.eu-west-1.compute.amazonaws.com  (34.250.194.62:80)

TCP (HTTP):
Connects to ec2-54-246-181-97.eu-west-1.compute.amazonaws.com  (54.246.181.97:80)

TCP (HTTP):
Connects to server-52-84-102-142.del51.r.cloudfront.net  (52.84.102.142:80)

TCP (HTTP):
Connects to ec2-54-76-91-10.eu-west-1.compute.amazonaws.com  (54.76.91.10:80)

TCP (HTTP):
Connects to ec2-54-76-250-20.eu-west-1.compute.amazonaws.com  (54.76.250.20:80)

TCP (HTTP):
Connects to ec2-54-171-226-204.eu-west-1.compute.amazonaws.com  (54.171.226.204:80)

TCP (HTTP):
Connects to ec2-50-112-218-190.us-west-2.compute.amazonaws.com  (50.112.218.190:80)

Remove WebShieldService.exe - Powered by Reason Core Security