WebShield is a software usually installs without your knowledge vith the download of freeware. In fact some sites use the method of repackaging. This is an operation that is to redo the module software installation by adding download options. These options allow to add other software as for example toolbars browser, or potentially unwanted software. The addition of these new programs can decrease the performance of the system but also slow or redirect internet surfing. As a general rule, should focus on the author’s official site to download your software.
-Identified the 05/16/2015.


– It belongs to a family of PUP (Potentially Unwanted Program).
– Vendor : PUP.Optional

Main actions :

– It installs as a process launched at startup of the system (RP),
– It installs as a service to be launched each time the system (O23),(SS/SR).
– It starts a task planned in automatic (O39),
– It installs as a program (O42),
– It creates to many registry keys ‘Software’
– It creates additional folders (O43),
– It moved to the Windows prefetcher folder (O45).

ZHPDiag report:

[MD5.352EA0C6338056E2B2880559B22B8F65] [APT] [{2039F4F3-C249-4F68-837E-855DF8123123}] (…) — C:\ProgramData\WebShield\uninstall.exe [537080]
[MD5.352EA0C6338056E2B2880559B22B8F65] [APT] [{F8A34CD2-5F47-4BDB-91A6-459CE13977CC}] (…) — C:\ProgramData\WebShield\uninstall.exe [537080]
[MD5.7D394F34D31419C15FFD265FF40512B8] – (.Irrational Number Applications – WebShield Service.) — C:\ProgramData\jETVAy\vtLHBxjZ.exe [2732024] [PID.1392]
O23 – Service: vtLHBxjZ (vtLHBxjZ) . (.Irrational Number Applications – WebShield Service.) – C:\ProgramData\jETVAy\vtLHBxjZ.exe
O42 – Logiciel: Web Shield – (.Irrational Number Applications.) [HKLM][64Bits] — WebShield
O43 – CFD: 15/05/2015 – 20:08:38 – [] —-D C:\ProgramData\WebShield
O43 – CFD: 16/05/2015 – 16:59:16 – [] —-D C:\Users\Coolman\AppData\Local\WebShield
SR – Auto [2015/08/09 22:25:05] [ 2732024] vtLHBxjZ (vtLHBxjZ) . (.Irrational Number Applications.) – C:\ProgramData\jETVAy\vtLHBxjZ.exe


PUP.Optional.WebShield.A [ Malwarebytes Antimalware ]


– Remove software in Windows Configuration Panel,
Remove with ZHPcleaner
Diagnose with ZHPDiag