startnowsearchredirectremovaltool.exe

Security Stronghold LLC

The application startnowsearchredirectremovaltool.exe by Security Stronghold has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Security Stronghold LLC  (signed and verified)

Version:
1.0.0.0

MD5:
966e7eab18bfa1b24335f0ce9bdcba08

SHA-1:
32fab2c12edb0bfba3625eadc0566aabaf96034f

SHA-256:
be46282ed9bea391d2199d8ad8f2828b8bfce7cfe201317fef32aaa570cb0d2b

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/26/2024 6:13:52 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Win32.Generic
16.6.28.8

File size:
5.4 MB (5,669,304 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\startnow search redirect removal tool\startnowsearchredirectremovaltool.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
8/16/2012 3:41:30 AM

Valid to:
11/10/2013 4:49:56 AM

Subject:
E=manager@securitystronghold.com, CN=Security Stronghold LLC, O=Security Stronghold LLC, L=Astrakhan, S=Astrakhan region, C=RU

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121A8E6D4E8876A9E02DB5215F60B91C5F5

File PE Metadata
Compilation timestamp:
6/19/2013 7:14:06 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:Vb3dmsxbVzDfSEz54H6HmPlhEE7MZZNDmao/A8PK7Hhpt8TS9HLzOppb+b6xn98q:/mUVm7MMaoA8PUHhXFfENcO6g

Entry address:
0x3A5BF4

Entry point:
55, 8B, EC, B9, 0A, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 51, 53, 56, B8, 50, 60, 79, 00, E8, E0, 61, C6, FF, 8B, 35, 2C, 42, 80, 00, 33, C0, 55, 68, 0A, 5E, 7A, 00, 64, FF, 30, 64, 89, 20, 8D, 55, E4, 33, C0, E8, 9E, EF, C5, FF, 8B, 45, E4, 8D, 55, E8, E8, 97, DB, C7, FF, 8B, 45, E8, 8D, 4D, EC, 33, D2, E8, 96, D9, C7, FF, 8B, 55, EC, 8B, C6, E8, 28, 21, C6, FF, BB, 02, 00, 00, 00, 8D, 45, DC, 8B, 16, 0F, B7, 54, 5A, FC, E8, F8, 2B, C6, FF, 8B, 45, DC, 8D, 55, E0, E8, ED, BB, C7, FF, 8B, 45, E0, 50, 8D...
 
[+]

Entropy:
6.7228

Developed / compiled with:
Microsoft Visual C++

Code size:
3.6 MB (3,820,544 bytes)

Remove startnowsearchredirectremovaltool.exe - Powered by Reason Core Security