How to remove QtWebEngineProcess.exe

QtWebEngineProcess.exe

The module QtWebEngineProcess.exe has been detected as PUP.MediaGet

QtWebEngineProcess.exe

QtWebEngineProcess.exe is a Windows file recorded in the ThreatInfo database. It is associated with Qt5. The reported company name is The Qt Company Ltd.. The current detection status is PUP.MediaGet, based on the latest analysis from 2021-09-27 20:33:49 (4 years ago).

If QtWebEngineProcess.exe appears on your computer unexpectedly, treat it as suspicious. Check its location, digital signature, and recent system changes before allowing it to run. A full anti-malware scan is recommended when this file is detected as PUP.MediaGet.

Product Name: Qt5
Company Name: The Qt Company Ltd.
MD5: 13adc0fdf0127566e748779c5c10d6ee
Size: 21 KB
First Published: 2019-12-08 21:06:50 (6 years ago)
Latest Published: 2021-09-27 20:33:49 (4 years ago)
Status: PUP.MediaGet (on last analysis)
Analysis Date: 2021-09-27 20:33:49 (4 years ago)
Signed By: The Qt Company Oy
Status: Valid

The signature on QtWebEngineProcess.exe is reported as valid. A valid signature helps confirm publisher identity, but it does not automatically make the file safe if the installer was bundled, abused, or downloaded from an untrusted source.

%programfiles%
%profile%
%profile%
%profile%
%profile%
%profile%
%profile%
%profile%
%profile%
%profile%

ThreatInfo has observed QtWebEngineProcess.exe in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

65.5%
9.1%
7.3%
7.3%
5.5%
1.8%
1.8%

The strongest geographic signal for this file is Russian Federation with 65.5% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 10 72.6%
Windows 7 24.2%
Windows 8.1 3.2%

The most common operating system signal for QtWebEngineProcess.exe is Windows 10 with 72.6% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

QtWebEngineProcess.exe is identified as pe for 32 systems. The subsystem is Windows GUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x00001991

PE Sections:

Name Size of data MD5
.text 6144 8b21316e24e95f34af36e3d5494ec977
.rdata 5632 3456cdf8427ae07bd792f8606be7dea9
.data 512 a385b616e4041a3c40ca9886aef2cdb3
.rsrc 2048 215eadc3439fc86320fff9bf468082b9
.reloc 1024 c00968a7e0aa528ad29ce7747ce9ab55

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information:

Download GridinSoft Anti-Malware - Removal tool for QtWebEngineProcess.exe