How to remove wshelper.exe

wshelper.exe

The module wshelper.exe has been detected as Ransom.Wacatac

wshelper.exe
Product Name:

Wondershare Studio

Company Name:

Wondershare

MD5: 33205adabce4cbe9d0ea05153154acfc
Size: 113 KB
First Published: 2020-05-28 05:07:42 (5 years ago)
Latest Published: 2023-12-11 23:21:23 (2 years ago)
Status: Ransom.Wacatac (on last analysis)
Analysis Date: 2023-12-11 23:21:23 (2 years ago)
%commondir%\wondershare
%commondir%\wondershare
%commondir%\wondershare
%commondir%\wondershare
%commondir%\wondershare
%commondir%\wondershare
%commondir%\wondershare
%commondir%\wondershare
%commondir%\wondershare
%commondir%\wondershare
India 14.7%
Pakistan 9.3%
Israel 9.3%
Indonesia 6.7%
Morocco 5.3%
Iran 2.7%
Malaysia 2.7%
Italy 2.7%
Colombia 2.7%
Egypt 2.7%
Poland 2.7%
Algeria 2.7%
Brazil 2.7%
Philippines 2.7%
Taiwan 2.7%
Spain 1.3%
Peru 1.3%
Turkey 1.3%
Venezuela 1.3%
Sri Lanka 1.3%
Germany 1.3%
Nepal 1.3%
Nigeria 1.3%
Uganda 1.3%
United Arab Emirates 1.3%
Bangladesh 1.3%
Jamaica 1.3%
Albania 1.3%
Brunei 1.3%
Thailand 1.3%
Kuwait 1.3%
Ecuador 1.3%
Sierra Leone 1.3%
Côte d'Ivoire 1.3%
Chile 1.3%
Mexico 1.3%
Windows 10 92.9%
Windows 7 5.9%
Windows 8.1 1.2%
Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x00001000

PE Sections:

Name Size of data MD5
.code 14336 6c0f4094a5493360ae8c9032ef3a9f47
.text 54272 1da643e4b1937b50550f9d9e8250428e
.rdata 13312 4fb07923b0eb72c40319d48fd2d4f13f
.data 4608 d477976ab5abaaeca9beb8758404fc02
.rsrc 28160 a796349b257349fa471a7437f85e4162

More information:

Download GridinSoft Anti-Malware - Removal tool for wshelper.exe
­