37988hijackremovaltool.exe

Security Stronghold LLC

The application 37988hijackremovaltool.exe by Security Stronghold has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This file is typically installed with the program Startpins Toolbar Removal Tool by Security Stronghold.
Publisher:
Security Stronghold LLC  (signed and verified)

Version:
1.0.0.0

MD5:
0b5ac91edfc03e58af003ea9b543b39e

SHA-1:
f00efa82655ea8a81d8e72bac41564379261b6c7

SHA-256:
a31289c05b68603ab6c0f92534fefa649743716a588d97b33e19b63eec7cec61

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/26/2024 5:31:02 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Win32.Generic
16.10.14.8

File size:
5.3 MB (5,590,968 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\37988hijack removal tool\37988hijackremovaltool.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
8/16/2012 5:41:30 AM

Valid to:
11/10/2013 8:49:56 AM

Subject:
E=manager@securitystronghold.com, CN=Security Stronghold LLC, O=Security Stronghold LLC, L=Astrakhan, S=Astrakhan region, C=RU

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121A8E6D4E8876A9E02DB5215F60B91C5F5

File PE Metadata
Compilation timestamp:
11/19/2012 6:53:18 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:uCaKV/WP4955eSrIPHA5ISZH10DaFBHarBYSiNAPmK1stPW1OqLbNWbTceDQG5nW:upK1Wyp+Y0M8lYSCAGPW1OqLb2rmwmCq

Entry address:
0x3B8BCC

Entry point:
55, 8B, EC, B9, 0A, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 51, 53, 56, B8, 50, 94, 7A, 00, E8, 14, 33, C5, FF, 8B, 35, 08, FA, 7E, 00, 33, C0, 55, 68, E2, 8D, 7B, 00, 64, FF, 30, 64, 89, 20, 8D, 55, E4, 33, C0, E8, 66, BF, C4, FF, 8B, 45, E4, 8D, 55, E8, E8, 9F, AD, C6, FF, 8B, 45, E8, 8D, 4D, EC, 33, D2, E8, 9E, AB, C6, FF, 8B, 55, EC, 8B, C6, E8, E4, F0, C4, FF, BB, 02, 00, 00, 00, 8D, 45, DC, 8B, 16, 0F, B7, 54, 5A, FC, E8, 28, FC, C4, FF, 8B, 45, DC, 8D, 55, E0, E8, 45, 8D, C6, FF, 8B, 45, E0, 50, 8D...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
3.7 MB (3,898,880 bytes)

The file 37988hijackremovaltool.exe has been discovered within the following program.

Startpins Toolbar Removal Tool  by Security Stronghold
During installation, the Security Stronghold Removal Tool utility will provide various bundled applications including RegClean Pro registry cleaner. It will then download utilities from its server and scan the user's PC.
www.SecurityStronghold.com
63% remove it
 
Powered by Should I Remove It?

Remove 37988hijackremovaltool.exe - Powered by Reason Core Security