File verdict·Decided by the MT AI Engine
Our call

Malicious

WPD.exe matches three YARA rules for suspicious behavior including disabling Windows Defender, despite clean scans from 76 engines including all Tier-1.

INDICATOR SUSPICIOUS EXE RegKeyComb DisableWinDefender
Trust score88High trust
WPD.exe
576.5 KB
c21e9de5b28de8edfbeb5f0a09d7
Antivirus engines
0 of 76 flagged
Code signing
Unsigned
Age
First seen 5y ago
MT AI Engine · Verdict analysis

The reasoning behind this verdict

The MT AI Engine weighs every signal from this scan — antivirus detections, sandbox behaviour, code signing, prevalence and historical matches — to reach a single, evidence-based verdict.

90%Confidence
Very high
Reasoning

The file WPD.exe is an unsigned 590KB Win32 executable first seen in 2021 with a negative reputation score of -7 from community flags. Our antivirus network of 76 engines, including 17 Tier-1 scanners like Avast, BitDefender, ESET-NOD32, and Kaspersky, all report it undetected with zero malicious hits. However, it matches three community YARA rules: one for registry keys that disable Windows Defender, plus two imphash indicators tied to malware. Network tags reveal anti-analysis tricks like detecting debug environments and checking network adapters, plus WMI calls and direct CPU access. These YARA hits override the clean scans, indicating hacktool behavior that could weaken your defenses if run. With the file's age and tags, it's likely offensive tooling—do not run it.

Points in its favour
  • Zero malicious detections across 76 engines, including all Tier-1 like BitDefender, Kaspersky, ESET-NOD32.
  • 17 Tier-1 engines explicitly clean.
  • Old file age of 1646 days since first seen in 2021, with consistent clean scans over time.
Points against
  • Matches YARA rule INDICATOR_SUSPICIOUS_EXE_RegKeyComb_DisableWinDefender, indicating attempts to turn off Windows Defender.
  • Two additional YARA imphash matches linked to malware by independent researchers.
  • Network tags show anti-analysis behavior like detect-debug-environment and direct-cpu-clock-access.
  • Calls WMI and checks network adapters, common in tools that prepare for deeper infection.
  • Negative reputation of -7 from community reports.
  • Unsigned executable with PE imphash f34d5f2d4577ed6d9ceec516c1f5a744 shared by suspicious samples.
Recommended action

Quarantine or delete WPD.exe immediately. Run a full antivirus scan on your system and enable real-time protection if it was disabled.

What to do now

This file is dangerous. Treat it as harmful and remove it.

  1. Don't open or run this file. Delete it from your Downloads (or wherever you saved it), then empty the Recycle Bin.

  2. If you already opened it, disconnect from the internet and run a full scan with your antivirus — Windows Security, built into Windows, is sufficient.

  3. If you typed any passwords while it was open, change them from a device you trust.

  4. In future, only download software from the official website or an official app store.

Threat family attribution

INDICATOR SUSPICIOUS EXE RegKeyComb DisableWinDefender corroborated by 2 sources

  • 3 YARA rules
    INDICATOR_SUSPICIOUS_EXE_RegKeyComb_DisableWinDefender, pe_imphash, Skystars_Malware_Imphash
  • MT AI Engine
    DefenderDisabler
External threat intelligence

1 corroborating signal from researcher-curated sources

YARAify HIT·3 community rules matchedView on YARAify
  • INDICATOR_SUSPICIOUS_EXE_RegKeyComb_DisableWinDefenderby ditekSHen
    Detects executables embedding registry key / value combination indicative of disabling Windows Defedner features
  • pe_imphash
  • Skystars_Malware_Imphashby Skystars LightDefender
    imphash
Cross-referenced against MalwareBazaar (abuse.ch), YARAify, and the CIRCL hashlookup reference DB.
Antivirus engine breakdown

0 detections across 76 engines

0 malicious0 suspicious76 clean
Tier-117 engines
0flag
Top commercial AVs (low FP rate)
Tier-241 engines
0flag
Mainstream engines with mixed FP rates
Low-trust18 engines
0flag
Heuristic / generic-AI engines (high FP rate)
All 76 engines report this file as clean.
Hash c21e9de5b28d… cross-referenced against 76 AV engines via our AV network.
File identity

Forensic fingerprint

File biography
First seen (VT)
10/17/2021, 5:24:41 PM
First seen (MalwareBazaar)
Last analysis (VT)
4/20/2026, 2:10:47 AM
Scanned here
4/20/2026, 3:33:08 PM
File name
WPD.exe
Size
576.5 KB
MIME type
(unknown)
Detected type
Win32 EXE
SHA-256
c21e9de5b28de8edfb6b2264b33846e842f7954ad70fa07b3c652feb5f0a09d7
MD5
65325f636ac238568a21f389387f0299
SHA-1
acf8022648f3eab3b6da50e0f90301eefe64a3f7
PE imphash
f34d5f2d4577ed6d9ceec516c1f5a744
First seen (VT)
10/17/2021, 5:24:41 PM
Last analysis (VT)
4/20/2026, 2:10:47 AM
First scan (MalwareTips)
4/20/2026, 3:33:08 PM
Last scan (MalwareTips)
4/20/2026, 3:33:08 PM
Community reputation
-7flagged
Behavior tags
assemblychecks-network-adaptersruntime-modulescalls-wmidirect-cpu-clock-accesspeexedetect-debug-environment
Frequently asked

Safety FAQ

Common questions about WPD.exe, answered from the scan data above.

  • Yes — WPD.exe is malicious, so do not run it, and delete it. 0 of 76 antivirus engines flag it (family: INDICATOR SUSPICIOUS EXE RegKeyComb DisableWinDefender). If you've already run it, see the removal and recovery steps below.
  • WPD.exe is a Windows executable program, about 577 KB. Our analysis identifies it as malicious (family: INDICATOR SUSPICIOUS EXE RegKeyComb DisableWinDefender). Because a file's name and icon can be faked, the safest way to identify it is by its cryptographic hash (below), not its filename.
  • None — all 76 antivirus engines we queried report WPD.exe as clean. That's reassuring, though brand-new malware can briefly evade detection before vendors add signatures, so we also weigh the file's behaviour and reputation.
  • Act quickly. 1) Disconnect the device from the internet to stop the malware communicating or spreading. 2) Run a full scan with reputable anti-malware software (such as Malwarebytes) and quarantine everything it finds. 3) Change your important passwords from a DIFFERENT, clean device — many threats log keystrokes or steal saved credentials. 4) If you bank or shop on this device, watch closely for fraud and alert your bank. 5) For a confirmed infection, the most reliable fix is to back up your personal files and reinstall the operating system for a clean start.
  • To remove WPD.exe: 1) restart into Safe Mode (Safe Mode with Networking if you need to download a tool) so the malware doesn't auto-start. 2) Run a full scan with reputable anti-malware software and let it quarantine or delete the detections. 3) Delete the original WPD.exe file and empty the Recycle Bin/Trash. 4) Check your browser extensions, startup items, and scheduled tasks for anything unfamiliar. 5) Reboot and scan again to confirm it's gone. If detections keep coming back, a clean operating-system reinstall is the most dependable cure.
  • WPD.exe is flagged as malicious (family: INDICATOR SUSPICIOUS EXE RegKeyComb DisableWinDefender). Engines attribute it to the INDICATOR SUSPICIOUS EXE RegKeyComb DisableWinDefender family. Knowing the family matters because it tells you the likely impact — data theft, remote control, file encryption, or unwanted ads — and guides the cleanup.
  • The SHA-256 hash of WPD.exe is c21e9de5b28de8edfb6b2264b33846e842f7954ad70fa07b3c652feb5f0a09d7, and its MD5 is 65325f636ac238568a21f389387f0299. This hash is the file's unique fingerprint — two files with the same SHA-256 are identical. Use it to confirm you're looking at exactly this file (not just one with the same name) when comparing against antivirus databases or a download's published checksum.
  • This report reflects the scan run on April 20, 2026. Because a file's hash never changes, the identity of WPD.exe is fixed — but antivirus coverage improves over time, so a file that looks clean today can pick up detections later (and vice-versa). If you need the latest picture, MalwareTips staff can re-run the analysis from scratch.
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Scanned by
harlan4096Staff
Files are processed in a streaming pass-through — MalwareTips never stores the binary on its servers. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.