Should I block it?

No, this file is 100% safe to run.

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
RegQueryValueExA, RegCloseKey, RegOpenKeyA, RegCreateKeyA, RegSetValueExA, SetThreadToken, DuplicateTokenEx, RegEnumKeyExA, RegQueryInfoKeyA, AdjustTokenPrivileges, LookupPrivilegeValueA, GetTokenInformation, OpenProcessToken, RegOpenKeyExA
crypt32.dll
CertCloseStore, CryptMsgClose, CertGetNameStringW, CertFindCertificateInStore
kernel32.dll
CreateFileA, SetLastError, lstrcpynA, SetFilePointer, FlushFileBuffers, WriteFile, SizeofResource, LockResource, LoadResource, FindResourceA, FindResourceExA, WideCharToMultiByte, GetLocalTime, MultiByteToWideChar, OutputDebugStringW, GetWindowsDirectoryA, GetPrivateProfileIntA, GetPrivateProfileStringA, WritePrivateProfileStringA, GetModuleFileNameA, lstrlenW, GetModuleFileNameW, IsBadWritePtr, ExpandEnvironmentStringsA, GetCurrentThreadId, GetCurrentProcessId, GetModuleHandleA, GetSystemInfo, GetCurrentProcess, CreateEventA, CreateMutexA, CreateWaitableTimerA, SetWaitableTimer, ResetEvent, WaitForSingleObject, GetFileAttributesA, CopyFileA, CreateToolhelp32Snapshot, Process32First, OpenProcess, Process32Next, FindFirstChangeNotificationA, ReadDirectoryChangesW, FindNextChangeNotification, CreateProcessA, Sleep, CreateThread, WaitForMultipleObjects, GetVersionExA, SetEvent, OpenMutexA, TerminateThread, CreateNamedPipeA, ConnectNamedPipe, ReadFile, DisconnectNamedPipe, GetTickCount, GetExitCodeProcess, Module32First, Module32Next, ReleaseMutex, SetEnvironmentVariableA, CompareStringW, CompareStringA, WriteConsoleW, GetConsoleOutputCP, WriteConsoleA, SetStdHandle, GetLocaleInfoW, DeviceIoControl, CloseHandle, LocalFree, LocalAlloc, lstrcpyA, lstrcatA, LoadLibraryA, GetProcAddress, FreeLibrary, DisableThreadLibraryCalls, InterlockedDecrement, InterlockedIncrement, OutputDebugStringA, TlsFree, InterlockedExchange, GetConsoleMode, GetConsoleCP, IsValidLocale, EnumSystemLocalesA, GetLocaleInfoA, GetUserDefaultLCID, TlsSetValue, TlsAlloc, TlsGetValue, GetModuleHandleW, VirtualAlloc, VirtualFree, HeapCreate, GetCommandLineA, GetSystemTimeAsFileTime, IsDebuggerPresent, SetUnhandledExceptionFilter, UnhandledExceptionFilter, InitializeCriticalSectionAndSpinCount, RtlUnwind, QueryPerformanceCounter, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsA, GetStartupInfoA, GetFileType, SetHandleCount, GetTimeZoneInformation, LCMapStringW, LCMapStringA, GetStringTypeW, GetStringTypeA, lstrlenA, GetLastError, ExitProcess, CancelWaitableTimer, IsValidCodePage, GetOEMCP, GetACP, GetCPInfo, HeapDestroy, HeapAlloc, HeapFree, HeapReAlloc, HeapSize, GetProcessHeap, RaiseException, EnterCriticalSection, LeaveCriticalSection, InitializeCriticalSection, DeleteCriticalSection, TerminateProcess, GetStdHandle
ole32.dll
CoUninitialize, CoTaskMemFree, CoCreateInstance, CoInitializeSecurity, CoInitialize
psapi.dll
GetModuleFileNameExA
rpcrt4.dll
UuidCreate
shell32.dll
SHGetPathFromIDListA, SHGetSpecialFolderLocation
user32.dll
CallNextHookEx, GetSystemMetrics, SetWindowsHookExA, UnhookWindowsHookEx
version.dll
GetFileVersionInfoSizeA, GetFileVersionInfoA, VerQueryValueA
wininet.dll
InternetAttemptConnect, InternetReadFile, InternetCloseHandle, HttpQueryInfoA, HttpSendRequestA, InternetCrackUrlA, InternetOpenA, InternetSetOptionA, InternetConnectA, HttpOpenRequestA
Export table
DllCanUnloadNow
DllGetClassObject
DllRegisterServer
DllUnregisterServer
fnhookdll
fnunhookdll

wbprotect.dll

Rising AntiVirus 2012 by Beijing Rising Information Technology Corporation Limited (Signed)

Remove wbprotect.dll
Version:   24, 0, 0, 16
MD5:   62bd0280317d57817aefb38a0a11da47
SHA1:   3a0825f4bf55a3fdd977df1c263c6a5d9336c35e
SHA256:   c7224c3bd59beed1c9627d37f9bc05d63e222d2310e38ac728be6fc9d91dd1b3

Overview

wbprotect.dll is loaded as dynamic link library that runs in the context of a process. The file is digitally signed by Beijing Rising Information Technology Corporation Limited which was issued by the VeriSign certificate authority (CA). This particular version is usually found on Microsoft Windows XP (5.1.2600.196608).

DetailsDetails

File name:wbprotect.dll
Publisher:Beijing Rising Information Technology Co., Ltd.
Product name:Rising AntiVirus 2012
Description:wbprotect DLL
Typical file path:C:\Program Files\rising\rav\wbprotect.dll
Original name:wbprotec.dll
File version:24, 0, 0, 16
Product version:24, 0, 0, 0
Size:451.77 KB (462,616 bytes)
Build date:3/13/2013 10:03 AM
Certificate
Issued to:Beijing Rising Information Technology Corporation Limited
Authority (CA):VeriSign
Effective date:Friday, May 11, 2012
Expiration date:Tuesday, August 11, 2015
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 100.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE