PCSpeedUp.exe

PC Speed Up

Speedchecker Limited

This is the Performersoft setup installer. The application PCSpeedUp.exe by Speedchecker Limited has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the InstallBrain installer. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘PCSpeedUp’.
Publisher:
Speedchecker  (signed by Speedchecker Limited)

Product:
PC Speed Up

Version:
1.2.2

MD5:
69eb1aeef10e1dd6db683a90ab6bdc6d

SHA-1:
5506bbab51d2835cc8489ec49f6214f90face86a

SHA-256:
0b4868041489d159e8889a7a53847f3ba593bc40203c991cd2361b65c0c98a7c

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/26/2024 2:46:01 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Performersoft.Bundler (M)
16.7.4.17

File size:
836.2 KB (856,312 bytes)

Product version:
1.2.2

Copyright:
Copyright © Speedchecker Limited 2009-2010

Original file name:
PCSpeedUp.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
InstallBrain

Common path:
C:\Program Files\zrychleni pocitace\pcspeedup.exe

Digital Signature
Authority:
The USERTRUST Network

Valid from:
1/4/2010 1:00:00 AM

Valid to:
1/5/2011 12:59:59 AM

Subject:
CN=Speedchecker Limited, O=Speedchecker Limited, STREET=2 High Royd Lane, L=Sheffield, S=Hoylandswaine, PostalCode=S36 7JR, C=GB

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
009ED66F7111FA28F3B9F3C93F2C5CEF0A

File PE Metadata
Compilation timestamp:
9/21/2010 10:51:58 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:Ww7+xy/tEfvbhbbnb3wDTEkhCMjqeJ13PBTmXtIsZm1:f1Qv9bbnkD3EMB13PpmdDm1

Entry address:
0xCB68E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
806 KB (825,344 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
PCSpeedUp

Command:
"C:\Program Files\zrychleni pocitace\pcspeedup.exe"


Remove PCSpeedUp.exe - Powered by Reason Core Security