nsm8185.tmp.exe

PC Speed Up

Safe Download Limited

The application nsm8185.tmp.exe by Safe Download Limited has been detected as adware by 2 anti-malware scanners. This is a setup program which is used to install the application. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from link.pcspeedup.com and multiple other hosts.
Publisher:
Speedchecker Limited   (signed by Safe Download Limited)

Product:
PC Speed Up

Version:
3.4.5.0

MD5:
715652a32ed8abb89492445a38fc20d0

SHA-1:
24bd4959cb8ba2d14453d3d2fe97a3d34550146e

SHA-256:
e5863642d64eabd2b29a7b950b5d867c8c59e444216ca7bf464c54ffe102a67e

Scanner detections:
2 / 68

Status:
Adware

Analysis date:
4/26/2024 4:07:18 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Speedchecker (variant)
7.9271

Reason Heuristics
PUP.Optional.SafeDownloadLimited.K
14.3.2.9

File size:
5.2 MB (5,484,016 bytes)

Product version:
3.4.5.0

Copyright:
Copyright © Speedchecker Limited 2009-2013

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\nsm8185.tmp.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
7/2/2012 4:00:00 AM

Valid to:
8/26/2014 4:00:00 PM

Subject:
CN=Safe Download Limited, O=Safe Download Limited, L=Douglas, S=Douglas, C=IM

Issuer:
CN=DigiCert High Assurance Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0DD2FC97B3C6597CABD97B29D9383440

File PE Metadata
Compilation timestamp:
12/20/2011 6:16:50 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:MkqSLkOdeSGtK2Eg4YmBe4UuRXTdNW2CurxVXgjNCxiik99ROAV5D:M3SQ8es2IOsXTGpqvMiAPFVd

Entry address:
0x16478

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, B0, 52, 41, 00, E8, AC, 03, FF, FF, 33, C0, 55, 68, 45, 6B, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 01, 6B, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, AB, 41, 00, E8, 4E, EC, FF, FF, E8, F5, E7, FF, FF, 8D, 55, EC, 33, C0, E8, 7F, 84, FF, FF, 8B, 55, EC, B8, AC, D6, 41, 00, E8, E2, E9, FE, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, AC, D6, 41, 00, B2, 01...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
84 KB (86,016 bytes)

The file nsm8185.tmp.exe has been seen being distributed by the following 23 URLs.

http://link.pcspeedup.com/aff_r?offer_id=5&aff_id=1524&redirect_pass=1&url=http://www.pcspeedup.com/.../download.aspx?affID=hoffers&k=1023df30d16debd5e16d959a240452&urlauth=753634293943321753952229395367

Remove nsm8185.tmp.exe - Powered by Reason Core Security