Malicious
WPD.exe matches three YARA rules for suspicious behavior including disabling Windows Defender, despite clean scans from 76 engines including all Tier-1.
c21e9de5b28de8edfb…eb5f0a09d7The reasoning behind this verdict
The MT AI Engine weighs every signal from this scan — antivirus detections, sandbox behaviour, code signing, prevalence and historical matches — to reach a single, evidence-based verdict.
The file WPD.exe is an unsigned 590KB Win32 executable first seen in 2021 with a negative reputation score of -7 from community flags. Our antivirus network of 76 engines, including 17 Tier-1 scanners like Avast, BitDefender, ESET-NOD32, and Kaspersky, all report it undetected with zero malicious hits. However, it matches three community YARA rules: one for registry keys that disable Windows Defender, plus two imphash indicators tied to malware. Network tags reveal anti-analysis tricks like detecting debug environments and checking network adapters, plus WMI calls and direct CPU access. These YARA hits override the clean scans, indicating hacktool behavior that could weaken your defenses if run. With the file's age and tags, it's likely offensive tooling—do not run it.
- Zero malicious detections across 76 engines, including all Tier-1 like BitDefender, Kaspersky, ESET-NOD32.
- 17 Tier-1 engines explicitly clean.
- Old file age of 1646 days since first seen in 2021, with consistent clean scans over time.
- Matches YARA rule INDICATOR_SUSPICIOUS_EXE_RegKeyComb_DisableWinDefender, indicating attempts to turn off Windows Defender.
- Two additional YARA imphash matches linked to malware by independent researchers.
- Network tags show anti-analysis behavior like detect-debug-environment and direct-cpu-clock-access.
- Calls WMI and checks network adapters, common in tools that prepare for deeper infection.
- Negative reputation of -7 from community reports.
- Unsigned executable with PE imphash f34d5f2d4577ed6d9ceec516c1f5a744 shared by suspicious samples.
Quarantine or delete WPD.exe immediately. Run a full antivirus scan on your system and enable real-time protection if it was disabled.
What to do now
This file is dangerous. Treat it as harmful and remove it.
Don't open or run this file. Delete it from your Downloads (or wherever you saved it), then empty the Recycle Bin.
If you already opened it, disconnect from the internet and run a full scan with your antivirus — Windows Security, built into Windows, is sufficient.
If you typed any passwords while it was open, change them from a device you trust.
In future, only download software from the official website or an official app store.
INDICATOR SUSPICIOUS EXE RegKeyComb DisableWinDefender corroborated by 2 sources
- 3 YARA rulesINDICATOR_SUSPICIOUS_EXE_RegKeyComb_DisableWinDefender, pe_imphash, Skystars_Malware_Imphash
- MT AI EngineDefenderDisabler
1 corroborating signal from researcher-curated sources
- INDICATOR_SUSPICIOUS_EXE_RegKeyComb_DisableWinDefenderby ditekSHenDetects executables embedding registry key / value combination indicative of disabling Windows Defedner features
- pe_imphash
- Skystars_Malware_Imphashby Skystars LightDefenderimphash
0 detections across 76 engines
Forensic fingerprint
- File name
- WPD.exe
- Size
- 576.5 KB
- MIME type
- (unknown)
- Detected type
- Win32 EXE
- SHA-256
- c21e9de5b28de8edfb6b2264b33846e842f7954ad70fa07b3c652feb5f0a09d7
- MD5
- 65325f636ac238568a21f389387f0299
- SHA-1
- acf8022648f3eab3b6da50e0f90301eefe64a3f7
- PE imphash
- f34d5f2d4577ed6d9ceec516c1f5a744
- First seen (VT)
- 10/17/2021, 5:24:41 PM
- Last analysis (VT)
- 4/20/2026, 2:10:47 AM
- First scan (MalwareTips)
- 4/20/2026, 3:33:08 PM
- Last scan (MalwareTips)
- 4/20/2026, 3:33:08 PM
- Community reputation
- -7flagged
Safety FAQ
Common questions about WPD.exe, answered from the scan data above.
- Yes — WPD.exe is malicious, so do not run it, and delete it. 0 of 76 antivirus engines flag it (family: INDICATOR SUSPICIOUS EXE RegKeyComb DisableWinDefender). If you've already run it, see the removal and recovery steps below.
- WPD.exe is a Windows executable program, about 577 KB. Our analysis identifies it as malicious (family: INDICATOR SUSPICIOUS EXE RegKeyComb DisableWinDefender). Because a file's name and icon can be faked, the safest way to identify it is by its cryptographic hash (below), not its filename.
- None — all 76 antivirus engines we queried report WPD.exe as clean. That's reassuring, though brand-new malware can briefly evade detection before vendors add signatures, so we also weigh the file's behaviour and reputation.
- Act quickly. 1) Disconnect the device from the internet to stop the malware communicating or spreading. 2) Run a full scan with reputable anti-malware software (such as Malwarebytes) and quarantine everything it finds. 3) Change your important passwords from a DIFFERENT, clean device — many threats log keystrokes or steal saved credentials. 4) If you bank or shop on this device, watch closely for fraud and alert your bank. 5) For a confirmed infection, the most reliable fix is to back up your personal files and reinstall the operating system for a clean start.
- To remove WPD.exe: 1) restart into Safe Mode (Safe Mode with Networking if you need to download a tool) so the malware doesn't auto-start. 2) Run a full scan with reputable anti-malware software and let it quarantine or delete the detections. 3) Delete the original WPD.exe file and empty the Recycle Bin/Trash. 4) Check your browser extensions, startup items, and scheduled tasks for anything unfamiliar. 5) Reboot and scan again to confirm it's gone. If detections keep coming back, a clean operating-system reinstall is the most dependable cure.
- WPD.exe is flagged as malicious (family: INDICATOR SUSPICIOUS EXE RegKeyComb DisableWinDefender). Engines attribute it to the INDICATOR SUSPICIOUS EXE RegKeyComb DisableWinDefender family. Knowing the family matters because it tells you the likely impact — data theft, remote control, file encryption, or unwanted ads — and guides the cleanup.
- The SHA-256 hash of WPD.exe is c21e9de5b28de8edfb6b2264b33846e842f7954ad70fa07b3c652feb5f0a09d7, and its MD5 is 65325f636ac238568a21f389387f0299. This hash is the file's unique fingerprint — two files with the same SHA-256 are identical. Use it to confirm you're looking at exactly this file (not just one with the same name) when comparing against antivirus databases or a download's published checksum.
- This report reflects the scan run on April 20, 2026. Because a file's hash never changes, the identity of WPD.exe is fixed — but antivirus coverage improves over time, so a file that looks clean today can pick up detections later (and vice-versa). If you need the latest picture, MalwareTips staff can re-run the analysis from scratch.
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.