pcspeedup_3.2.6.exe

PC Speed Up

Safe Download Limited

The application pcspeedup_3.2.6.exe by Safe Download Limited has been detected as adware by 2 anti-malware scanners. This is a setup program which is used to install the application. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from www.pcspeedup.com and multiple other hosts.
Publisher:
Speedchecker Limited   (signed by Safe Download Limited)

Product:
PC Speed Up

Version:
3.2.6

MD5:
98b470d16e4316965e74d717f9de91fb

SHA-1:
35c96f72a5d6a44fce7ce68df1bcaf7b48350091

SHA-256:
638ae314550f62f9ae70b4ce06eee3bcc0ac98edb54757f36dd2bdb380042f46

Scanner detections:
2 / 68

Status:
Adware

Analysis date:
4/25/2024 6:29:02 PM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Speedchecker (variant)
7.8527

Reason Heuristics
PUP.Optional.SafeDownloadLimited.N
14.2.16.4

File size:
3.5 MB (3,693,240 bytes)

Product version:
3.2.6

Copyright:
Copyright © Speedchecker Limited 2009-2012

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\pcspeedup_3.2.6.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
7/2/2012 2:00:00 AM

Valid to:
8/26/2014 2:00:00 PM

Subject:
CN=Safe Download Limited, O=Safe Download Limited, L=Douglas, S=Douglas, C=IM

Issuer:
CN=DigiCert High Assurance Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0DD2FC97B3C6597CABD97B29D9383440

File PE Metadata
Compilation timestamp:
12/20/2011 4:16:50 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:jkqSLdoFE29B98+B+epjAJgFCGBCekN6VV5F:j3SeFE29DpJpjs6CVepVv

Entry address:
0x16478

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, B0, 52, 41, 00, E8, AC, 03, FF, FF, 33, C0, 55, 68, 45, 6B, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 01, 6B, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, AB, 41, 00, E8, 4E, EC, FF, FF, E8, F5, E7, FF, FF, 8D, 55, EC, 33, C0, E8, 7F, 84, FF, FF, 8B, 55, EC, B8, AC, D6, 41, 00, E8, E2, E9, FE, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, AC, D6, 41, 00, B2, 01...
 
[+]

Entropy:
7.9874

Developed / compiled with:
Microsoft Visual C++

Code size:
84 KB (86,016 bytes)

The file pcspeedup_3.2.6.exe has been seen being distributed by the following 3 URLs.

http://www.pcspeedup.com/downloads/.../pcspeedup_3.2.6.exe

Remove pcspeedup_3.2.6.exe - Powered by Reason Core Security