StartScreen.exe

StartIsBack

Stanislav Zinukhov

It runs as a scheduled task under the Windows Task Scheduler triggered to execute each time a user logs in.
Publisher:
www.startisback.com  (signed by Stanislav Zinukhov)

Product:
StartIsBack

Description:
StartIsBack Helper Tool

Version:
4.3.0

MD5:
a1f95732f579916c54d48f358299a426

SHA-1:
af8011291ca59be4fa539348ae84143e17b6db69

SHA-256:
8a36ec2cdad343c4a2ce9a516931e350903637f189e1e9dcca44149d1714d4c0

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
11/23/2024 10:23:22 PM UTC  (today)

Scan engine
Detection
Engine version

Qihoo 360 Security
HEUR/QVM20.1.0000.Malware.Gen
1.0.0.1120

File size:
54.3 KB (55,608 bytes)

Product version:
4.3.0

Copyright:
Copyright (C) 2013+, Tihiy

Original file name:
StartScreen.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\startisback\startscreen.exe

Digital Signature
Authority:
StartCom Ltd.

Valid from:
2/5/2016 2:15:14 AM

Valid to:
2/5/2018 2:15:14 AM

Subject:
CN=Stanislav Zinukhov, O=Stanislav Zinukhov, L=Moscow, S=Moscow City, C=RU

Issuer:
CN=StartCom Class 2 Object CA, OU=StartCom Certification Authority, O=StartCom Ltd., C=IL

Serial number:
5271F4614E0F58C89FEE1FA7211D7308

File PE Metadata
Compilation timestamp:
7/17/2016 3:59:52 PM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
384:BrRjwHgiJyjEmv3/BMAG+S41WE9KEIiz4iU0Ci0o7tVitk3:BxPjEmv5llIEIozA0PjjiW

Entry address:
0x19F0

Entry point:
55, 8B, EC, 83, EC, 08, 8D, 45, F8, 50, FF, 15, 14, 20, 40, 00, 50, FF, 15, 54, 20, 40, 00, 89, 45, FC, 83, 7D, F8, 02, 7D, 0A, E8, 8B, F6, FF, FF, E9, F9, 00, 00, 00, 68, 1C, 26, 40, 00, B9, 04, 00, 00, 00, C1, E1, 00, 8B, 55, FC, 8B, 04, 0A, 50, FF, 15, A4, 20, 40, 00, 83, C4, 08, 85, C0, 75, 21, 83, 7D, F8, 02, 7E, 1B, B9, 04, 00, 00, 00, D1, E1, 8B, 55, FC, 8B, 04, 0A, 50, E8, DC, FB, FF, FF, 83, C4, 04, E9, B7, 00, 00, 00, 68, 3C, 26, 40, 00, B9, 04, 00, 00, 00, C1, E1, 00, 8B, 55, FC, 8B, 04, 0A, 50...
 
[+]

Entropy:
5.5861

Developed / compiled with:
Microsoft Visual C++

Code size:
3 KB (3,072 bytes)

Scheduled Task
Task name:
StartIsBack health check

Trigger:
Logon (Runs on logon)

Description:
This task ensures StartIsBack files and registry entries are in place. Required to survive Windows build upgrade.


The file StartScreen.exe has been discovered within the following program.

StartIsBack++  by startisback.com
About 1% of users remove it
 
Powered by Should I Remove It?

Scan StartScreen.exe - Powered by Reason Core Security