virusremovaltool.exe

Security Stronghold LLC

The application virusremovaltool.exe by Security Stronghold has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. Additionally, the file is typically installed by a number of programs including Snap Toolbar Removal Tool by Security Stronghold and Mixi Dj Removal Tool by Security Stronghold.
Publisher:
Security Stronghold  (signed by Security Stronghold LLC)

Version:
1.0.0.143

MD5:
5288b2a086d672a5ef773ec90c0c2e31

SHA-1:
8888fde60f752b5c4eca8f9d3cada75d19efa9cc

SHA-256:
d23836dde985dbdd515ded4e71e0acd614737b495d85407f74a3330ab926e90b

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 2:15:40 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Win32.Generic
16.1.2.7

File size:
5.3 MB (5,582,776 bytes)

Product version:
1.0.0.143

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\virus removal tool\virusremovaltool.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
8/16/2012 3:41:30 AM

Valid to:
11/10/2013 4:49:56 AM

Subject:
E=manager@securitystronghold.com, CN=Security Stronghold LLC, O=Security Stronghold LLC, L=Astrakhan, S=Astrakhan region, C=RU

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121A8E6D4E8876A9E02DB5215F60B91C5F5

File PE Metadata
Compilation timestamp:
7/15/2013 6:30:47 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:je626oVzsxRsSf43vLHD2K8OTbGVvyyaM7iP0vUJwbzKIRNYTgg18jI8Nr98qjAP:K6GV/8VylP0vUJKzK8NdOz8YP

Entry address:
0x3FED6C

Entry point:
55, 8B, EC, B9, 0A, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 51, 53, 56, B8, FC, CB, 7E, 00, E8, 28, D1, C0, FF, 8B, 35, 60, D8, 85, 00, 33, C0, 55, 68, 82, EF, 7F, 00, 64, FF, 30, 64, 89, 20, 8D, 55, E4, 33, C0, E8, 26, 5E, C0, FF, 8B, 45, E4, 8D, 55, E8, E8, 9B, 4C, C2, FF, 8B, 45, E8, 8D, 4D, EC, 33, D2, E8, 9A, 4A, C2, FF, 8B, 55, EC, 8B, C6, E8, 3C, 90, C0, FF, BB, 02, 00, 00, 00, 8D, 45, DC, 8B, 16, 0F, B7, 54, 5A, FC, E8, 0C, 9B, C0, FF, 8B, 45, DC, 8D, 55, E0, E8, D9, 2C, C2, FF, 8B, 45, E0, 50, 8D...
 
[+]

Entropy:
6.6267

Developed / compiled with:
Microsoft Visual C++

Code size:
4 MB (4,183,552 bytes)

The file virusremovaltool.exe has been discovered within the following programs.

Hao 123 Search Removal Tool  by Security Stronghold
During installation, the Security Stronghold Removal Tool utility will provide various bundled applications including RegClean Pro registry cleaner. It will then download utilities from its server and scan the user's PC.
www.SecurityStronghold.com
68% remove it
ILivid Removal Tool  by Security Stronghold
ILivid Removal Tool is designed to remove the adware from the user PC however it also bundles various applications including the Pro registry cleaner which will download utilities from its server and scan the user's PC.
52% remove it
Mixi Dj Removal Tool  by Security Stronghold
Publisher's description - “Mixi.DJ Delta Toolbar copies its file(s) to your hard disk. Its typical file name is MixiDJ.exe. Then it creates new startup key with name Mixi.DJ Delta Toolbar and value MixiDJ.exe. You can also find it in your processes list with name MixiDJ.exe or Mixi.DJ Delta Toolbar. Mixi.”
69% remove it
My Search Dial Removal Tool  by Security Stronghold
60% remove it
Snap Toolbar Removal Tool  by Security Stronghold
58% remove it
Sweetpacks Removal Tool  by Security Stronghold
Distributes a version of SpyHunter by Enigma Software Group with various offers.
74% remove it
Torn TVRemoval Tool  by Security Stronghold
52% remove it
Widgi Toolbar Removal Tool  by Security Stronghold
Widgi Toolbar Removal Tool is designed to remove the adware from the user PC however it also bundles various applications including the Pro registry cleaner which will download utilities from its server and scan the user's PC.
www.securitystronghold.com/gates/remove-widgi-toolbar.html
55% remove it
 
Powered by Should I Remove It?

Remove virusremovaltool.exe - Powered by Reason Core Security