torpigremovaltool.exe

Security Stronghold LLC

The application torpigremovaltool.exe by Security Stronghold has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. Additionally, the file is typically installed by a number of programs including Browser Protect Removal Tool by Security Stronghold and Mixidj Toolbar Removal Tool by Security Stronghold.
Publisher:
Security Stronghold  (signed by Security Stronghold LLC)

Version:
1.0.0.100

MD5:
e60e634f1d37101e01f4b2c5b304fa86

SHA-1:
8bf880f4b2743f51fe36925507e76710fe92460e

SHA-256:
11c8e1191f852caa9ab829a60b6d83c4de17e2a096aa9d02df2aeb8294c3f47d

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/18/2024 5:59:08 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Win32.Generic.SecurityStronghold.Meta
15.10.15.13

File size:
5.4 MB (5,668,792 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\torpig removal tool\torpigremovaltool.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
8/16/2012 10:41:30 AM

Valid to:
11/10/2013 11:49:56 AM

Subject:
E=manager@securitystronghold.com, CN=Security Stronghold LLC, O=Security Stronghold LLC, L=Astrakhan, S=Astrakhan region, C=RU

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121A8E6D4E8876A9E02DB5215F60B91C5F5

File PE Metadata
Compilation timestamp:
6/19/2013 2:13:28 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:Gb3dmsxbVzDfSEz54H6HmPlhEE7MZZNDmao/A8PK7HhpyTS9zLzOppb+b6i298LR:UmUVm7MMaoA8PUHhFDENcUNu

Entry address:
0x3A5BF4

Entry point:
55, 8B, EC, B9, 0A, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 51, 53, 56, B8, 94, 5E, 79, 00, E8, E0, 61, C6, FF, 8B, 35, 2C, 42, 80, 00, 33, C0, 55, 68, 0A, 5E, 7A, 00, 64, FF, 30, 64, 89, 20, 8D, 55, E4, 33, C0, E8, 9E, EF, C5, FF, 8B, 45, E4, 8D, 55, E8, E8, 97, DB, C7, FF, 8B, 45, E8, 8D, 4D, EC, 33, D2, E8, 96, D9, C7, FF, 8B, 55, EC, 8B, C6, E8, 28, 21, C6, FF, BB, 02, 00, 00, 00, 8D, 45, DC, 8B, 16, 0F, B7, 54, 5A, FC, E8, F8, 2B, C6, FF, 8B, 45, DC, 8D, 55, E0, E8, ED, BB, C7, FF, 8B, 45, E0, 50, 8D...
 
[+]

Entropy:
6.7229

Developed / compiled with:
Microsoft Visual C++

Code size:
3.6 MB (3,820,032 bytes)

The file torpigremovaltool.exe has been discovered within the following programs.

Browser Protect Removal Tool  by Security Stronghold
During installation, the Security Stronghold Removal Tool utility will provide various bundled applications including RegClean Pro registry cleaner. It will then download utilities from its server and scan the user's PC.
www.SecurityStronghold.com
61% remove it
Mixidj Toolbar Removal Tool  by Security Stronghold
Mixi DJRemoval Tool is designed to remove the adware from the user PC however it also bundles various applications including the Pro registry cleaner which will download utilities from its server and scan the user's PC.
60% remove it
Solid Savings Removal Tool  by Security Stronghold
Publisher's description - “Solid Savings adware may seem a very helpful browser add-on, because it shows different advertising pop-ups, and helps to save money, but actually it is an undesired program that should be removed from your computer.”
59% remove it
Webshots Removal Tool  by Security Stronghold
Webshots Removal Tool is designed to remove the adware from the user PC however it also bundles various applications including the Pro registry cleaner which will download utilities from its server and scan the user's PC.
54% remove it
 
Powered by Should I Remove It?

Remove torpigremovaltool.exe - Powered by Reason Core Security