psupeg.exe

The application psupeg.exe has been detected as adware by 5 anti-malware scanners. It runs as a scheduled task under the Windows Task Scheduler triggered daily at a specified time. This file is typically installed with the program PassShow by Revizer Technologies which is a potentially unwanted software program. This is part of the Revizer line of web browser extensions that inject 3rd-party advertisements in the user's web browser as well as setup a proxy server for the browser in order to track behaviors and display context based-ads from various partners (mostly adware).
MD5:
f321efd237b2efd32c2d0841b7217730

SHA-1:
0aec4c77ee4ba3a3f39d39bc178249325f6eb86e

SHA-256:
9ea3467192cf872cd88aade49d43f013993ca253412a7e2c69ad594dac6dea9f

Scanner detections:
5 / 68

Status:
Adware

Analysis date:
4/26/2024 7:35:48 PM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
Adware.Win32.AddLyrics
4.0.3.14102

ESET NOD32
Win32/AdWare.AddLyrics.AI (variant)
8.9633

Malwarebytes
PUP.Optional.AdLyrics.A
v2014.10.02.06

Reason Heuristics
Adware.Revizer.Task.G
14.10.2.6

Trend Micro House Call
TROJ_GEN.F47V0327
7.2.275

File size:
285.5 KB (292,352 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\passshow-soft\psupeg.exe

File PE Metadata
Compilation timestamp:
3/18/2014 7:37:33 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:yw1B3nb6l5wUmUXvMxD2eiI6byUd+rzqFw1tWP9Yg:yQBr6l5UUf4D6byUWzDtWP9Yg

Entry address:
0x6D67

Entry point:
E8, 56, 6F, 00, 00, E9, 89, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 54, 24, 0C, 8B, 4C, 24, 04, 85, D2, 74, 69, 33, C0, 8A, 44, 24, 08, 84, C0, 75, 16, 81, FA, 80, 00, 00, 00, 72, 0E, 83, 3D, 50, C9, 43, 00, 00, 74, 05, E9, B1, 6F, 00, 00, 57, 8B, F9, 83, FA, 04, 72, 31, F7, D9, 83, E1, 03, 74, 0C, 2B, D1, 88, 07, 83, C7, 01, 83, E9, 01, 75, F6, 8B, C8, C1, E0, 08, 03, C1, 8B, C8, C1, E0, 10, 03, C1, 8B, CA, 83, E2, 03, C1, E9, 02, 74, 06, F3, AB, 85, D2, 74, 0A, 88, 07...
 
[+]

Entropy:
6.5980

Code size:
178 KB (182,272 bytes)

Scheduled Task
Task name:
PassShow Update

Trigger:
Daily (Runs daily at 9:21 PM)

Action:
psupeg.exe \update


The file psupeg.exe has been discovered within the following program.

PassShow  by Revizer Technologies
PassShow is an adware program that integrates with the user's web browser (IE, Chrome and Firefox) and will hijack the normal home, search and new tab pages as well as redirections. In addition, it will display ads within the browser including banner, context and popup ads.
passshow.com
88% remove it
 
Powered by Should I Remove It?

Remove psupeg.exe - Powered by Reason Core Security