ToolbarRemover.exe

Toolbar Remover

Security Stronghold LLC

The file ToolbarRemover.exe by Security Stronghold has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Security Stringhold  (signed by Security Stronghold LLC)

Product:
Toolbar Remover

Version:
1.1.0.0

MD5:
a2e7228b59ad9cf7111b4b025070df1c

SHA-1:
3d4a65a8865d47d96c8e04f8305b3fd156325f01

SHA-256:
4fda5a4a5b0a3d6a1d5e3a715e7b3c521dae5b4b46a2b01c9c87113cf2223046

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/26/2024 5:02:51 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Win32.Generic
17.3.14.21

File size:
4.2 MB (4,353,408 bytes)

Product version:
1.1.0.0

Copyright:
Copyright 2003-2015 Security Stronghold

Original file name:
ToolbarRemover.exe

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\scs69b7.tmp

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
1/30/2017 3:35:42 AM

Valid to:
3/13/2018 6:49:56 AM

Subject:
E=manager@securitystronghold.com, CN=Security Stronghold LLC, O=Security Stronghold LLC, L=Astrakhan, S=Astrakhan Oblast, C=RU

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G3, O=GlobalSign nv-sa, C=BE

Serial number:
5BA3B7B6EC10E094571B5F3F

File PE Metadata
Compilation timestamp:
2/3/2015 8:36:41 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x3668F4

Entry point:
55, 8B, EC, 83, C4, F0, B8, 9C, 5B, 75, 00, E8, 80, 6A, CA, FF, A1, C4, A2, 77, 00, 8B, 00, E8, E4, B0, DD, FF, A1, C4, A2, 77, 00, 8B, 00, B2, 01, E8, F6, CD, DD, FF, 8B, 0D, 3C, A3, 77, 00, A1, C4, A2, 77, 00, 8B, 00, 8B, 15, 58, FD, 74, 00, E8, D6, B0, DD, FF, 8B, 0D, 18, 97, 77, 00, A1, C4, A2, 77, 00, 8B, 00, 8B, 15, F4, 82, 74, 00, E8, BE, B0, DD, FF, A1, C4, A2, 77, 00, 8B, 00, E8, 16, B2, DD, FF, E8, 0D, 1D, CA, FF, 90, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.5484

Developed / compiled with:
Microsoft Visual C++

Code size:
3.4 MB (3,558,400 bytes)

Remove ToolbarRemover.exe - Powered by Reason Core Security