StrongholdAntiMalware.exe

Stronghold AntiMalware

Security Stronghold LLC

The application StrongholdAntiMalware.exe by Security Stronghold has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Stronghold AntiMalware’. This file is typically installed with the program Stronghold AntiMalware by Security Stronghold which is a potentially unwanted software program.
Publisher:
Security Stronghold  (signed by Security Stronghold LLC)

Product:
Stronghold AntiMalware

Version:
1.0.0.9

MD5:
b8106727c0b802077d323c2d811d8de8

SHA-1:
c8e5073d22f28592384197a484a0b28f7155b716

SHA-256:
457e4605b43cbf46ad5c07f6314ec541d7b644f369b5d69ed562c6d0f1ff1c6b

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/27/2024 2:46:33 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Optional.SecurityStronghold.V
14.9.4.13

File size:
6.2 MB (6,495,144 bytes)

Product version:
1.0.0.9

Copyright:
Copyright 2003-2014 Security Stronghold

Original file name:
StrongholdAntiMalware.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\stronghold antimalware\strongholdantimalware.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
10/14/2013 6:55:31 PM

Valid to:
12/11/2014 11:49:56 AM

Subject:
E=manager@securitystronghold.com, CN=Security Stronghold LLC, O=Security Stronghold LLC, L=Astrakhan, C=RU

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121ACD1A0DCFFA94069288588DCC5FFCF18

File PE Metadata
Compilation timestamp:
9/3/2014 2:51:47 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:rw+EBrWTPrQWB+ShcwuIa0D9Q6zAx66wc:s+EBraDQWMvwuJ8Rc

Entry address:
0x4AC068

Entry point:
55, 8B, EC, B9, 08, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 51, 53, 56, 57, B8, 50, 90, 89, 00, E8, 13, 03, B6, FF, 33, C0, 55, 68, FD, C6, 8A, 00, 64, FF, 30, 64, 89, 20, E8, E4, 8A, B5, FF, 85, C0, 7E, 32, 8D, 55, EC, B8, 01, 00, 00, 00, E8, 33, 8B, B5, FF, 8B, 45, EC, BA, 18, C7, 8A, 00, E8, E2, CE, B5, FF, 75, 16, B8, 3C, C7, 8A, 00, E8, 8E, CE, FE, FF, A1, 0C, 1B, 8F, 00, 8B, 00, E8, 06, 47, CB, FF, E8, 79, A0, FD, FF, A1, 0C, 1B, 8F, 00, 8B, 00, E8, 59, 44, CB, FF, A1, 0C, 1B, 8F, 00, 8B, 00, 33, D2...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
4.7 MB (4,896,768 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Stronghold AntiMalware

Command:
C:\Program Files\stronghold antimalware\strongholdantimalware.exe


The file StrongholdAntiMalware.exe has been discovered within the following program.

Stronghold AntiMalware  by Security Stronghold
Publisher's description - “Stronghold Antivirus is a lightweight and user-friendly antivirus and antimalware for everyday use both at home and in the office. Unlike other antiviruses it doesn't consume a lot of resources, it doesn't confuse you with difficult to understand windows and complex options.”
www.securitystronghold.com/stronghold-antivirus
65% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to ns1.vistaglance.com  (66.7.217.40:80)

Remove StrongholdAntiMalware.exe - Powered by Reason Core Security