startisback64.dll

StartIsBack

Stanislav Zinukhov

Publisher:
www.startisback.com  (signed by Stanislav Zinukhov)

Product:
StartIsBack

Description:
StartIsBack+ brains and soul

Version:
3.7.5

MD5:
f76ab5125f4efaca2e495294920e900c

SHA-1:
c86a819ded07110887d7c6020faf6fa5a38aa5d6

SHA-256:
31657e1a2ecfef0879b795180dde600796ec0a3aa4e9631ad8d066bed19b3514

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/27/2024 8:28:23 AM UTC  (today)

File size:
524 KB (536,568 bytes)

Product version:
3.7.5

Copyright:
Copyright (C) 2013-2015, Tihiy

Original file name:
STARTISBACK.NEXT.dll

File type:
Dynamic link library (Win64 DLL)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\startisback64.dll

Digital Signature
Authority:
StartCom Ltd.

Valid from:
2/5/2016 7:15:14 AM

Valid to:
2/5/2018 7:15:14 AM

Subject:
CN=Stanislav Zinukhov, O=Stanislav Zinukhov, L=Moscow, S=Moscow City, C=RU

Issuer:
CN=StartCom Class 2 Object CA, OU=StartCom Certification Authority, O=StartCom Ltd., C=IL

Serial number:
5271F4614E0F58C89FEE1FA7211D7308

File PE Metadata
Compilation timestamp:
3/6/2015 4:16:37 AM

OS version:
6.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
6144:EA8JiDpU7ZaJ5/KJVD2qENPUHZtecX0km9O4pPxdCT1:ETJiDp15/hSZbXUjta

Entry address:
0x285B0

Entry point:
40, 53, 48, 83, EC, 40, 48, 8B, D9, FF, CA, 0F, 85, 23, 01, 00, 00, FF, 15, C9, 7B, 00, 00, B9, 43, 00, 00, 00, 48, 89, 1D, 25, AC, 01, 00, FF, 15, 67, 84, 00, 00, 33, DB, 85, C0, 0F, 84, 93, 00, 00, 00, 48, 8D, 44, 24, 68, 44, 8D, 4B, 10, 4C, 8D, 05, 15, 3F, 01, 00, 48, 89, 44, 24, 30, 48, 8D, 44, 24, 58, 48, 8D, 15, 5C, 04, 01, 00, 48, 89, 44, 24, 28, 48, C7, C1, 01, 00, 00, 80, 89, 5C, 24, 58, 48, 89, 5C, 24, 20, C7, 44, 24, 68, 04, 00, 00, 00, FF, 15, 71, 7F, 00, 00, 48, 8D, 44, 24, 68, 44, 8D, 4B, 10...
 
[+]

Entropy:
5.9964

Code size:
184.5 KB (188,928 bytes)

The file startisback64.dll has been discovered within the following program.

StartIsBack+  by startisback.com
About 7% of users remove it
 
Powered by Should I Remove It?

Scan startisback64.dll - Powered by Reason Core Security