How to remove webshieldfilter.sys

webshieldfilter.sys

The module webshieldfilter.sys has been detected as PUP.PCProtect

webshieldfilter.sys
Product Name:

Windows (R) Win 7 DDK driver

Company Name:

Windows (R) Win 7 DDK provider

MD5: bd970986784248585942722846edc406
Size: 85 KB
First Published: 2018-11-17 01:11:33 (6 years ago)
Latest Published: 2025-02-08 23:03:33 (3 months ago)
Status: PUP.PCProtect (on last analysis)
Analysis Date: 2025-02-08 23:03:33 (3 months ago)
Signed By: Protected Antivirus Limited
Status: Valid
%programfiles%\totalav\urldrv\wfp\windows7
%programfiles%\totalav\urldrv\wfp\windows7
%programfiles%\totalav\urldrv\wfp\windows7
%programfiles%\totalav\urldrv\wfp\windows7
%programfiles%\totalav\urldrv\wfp\windows7
%programfiles%\totalav\urldrv\wfp\windows7
%programfiles%\totalav\urldrv\wfp\windows7
%programfiles%\totalav\urldrv\wfp\windows7
%programfiles%\totalav\urldrv\wfp\windows7
%programfiles%\totalav\urldrv\wfp\windows7
20.4%
7.4%
6.4%
5.4%
4.8%
4.8%
4.3%
4.3%
2.3%
2.3%
2.0%
2.0%
1.8%
1.8%
1.8%
1.5%
1.3%
1.3%
1.3%
1.3%
1.3%
1.0%
1.0%
1.0%
1.0%
1.0%
0.8%
0.8%
0.8%
0.8%
0.8%
0.8%
0.8%
0.5%
0.5%
0.5%
0.5%
0.5%
0.5%
0.5%
0.5%
0.5%
0.5%
0.5%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
Windows 10 71.0%
Windows 7 22.6%
Windows 8.1 4.2%
Windows Server 2008 R2 1.0%
Windows XP 0.5%
Windows Vista 0.2%
Windows Server 2016 0.2%
Windows 8 0.2%
Subsystem: Native
PE Type: pe
OS Bitness: 64
Image Base: 0x0000000000010000
Entry Address: 0x00013064

PE Sections:

Name Size of data MD5
.text 55808 5a7e7ab7288fbb18aa7d7e067cff5156
.rdata 3072 714ec5453dddb54f4baacd09e04b2a7a
.data 2048 1a7b804c4ac4b1d6aecdbc7c4a0cf82b
.pdata 2048 09869f63122fbd6d9d1032c3f14c26e1
INIT 4096 8de91052bca94b1dd2dab5244f654b5e
.rsrc 1024 9962eaaf84435280d840b36c441c17fe
.reloc 512 520f4fd30fa60e4381a5449e9c38ccbf

More information:

Download GridinSoft Anti-Malware - Removal tool for webshieldfilter.sys