spsetup125.exe

Speccy

Piriform Ltd

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This file is installed with multiple programs including Speccy. The file has been seen being downloaded from secure.piriform.com and multiple other hosts.
Publisher:
Piriform Ltd  (signed and verified)

Product:
Speccy

Description:
Speccy Installer

Version:
1.0.0.0

MD5:
024542793ef5b061ea2ae16d991d2dd3

SHA-1:
c3263c889c59de6ee0fec6d0e3186e2f1f5d245a

SHA-256:
9bacac9c6dc040fcea3a18ef6e508a566894c17561c5aa825cf6443cf8e94a1c

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/25/2024 9:53:47 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Bundled.Toolbar.Google
8.9369

File size:
4.6 MB (4,845,384 bytes)

Copyright:
Copyright © 2006-2014 Piriform Ltd

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\spsetup125.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
6/25/2013 1:00:00 AM

Valid to:
9/25/2015 12:59:59 AM

Subject:
CN=Piriform Ltd, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Piriform Ltd, L=London, S=London, C=GB

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
785AF6D521F67E132D53385742CE9B35

File PE Metadata
Compilation timestamp:
2/24/2012 7:19:59 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
98304:pYQnh8cPJIgFbXYWacWgw8r3vIPNcTG8jxkSDC3Ma+XqVJ:pTGMmgNXYWaA04qSOMTqVJ

Entry address:
0x39E3

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, D8, 91, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B8, 80, 40, 00, 55, FF, 15, C0, 82, 40, 00, 6A, 08, A3, B8, 2E, 47, 00, E8, 37, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, D0, 2D, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 1C, 93, 40, 00, FF, 15, 84, 81, 40, 00, 68, 04, 93, 40, 00, 68, C0, AD, 46, 00, E8, 19, 27, 00, 00, FF, 15, B4, 80, 40, 00, 50, BF, A0, 30, 4C, 00, 57, E8, 07, 27, 00, 00...
 
[+]

Entropy:
7.9970

Packer / compiler:
Nullsoft install system v2.x

Code size:
28 KB (28,672 bytes)

The file spsetup125.exe has been discovered within the following programs.

Publisher's description - “BlueScreenView scans all your minidump files created during 'blue screen of death' crashes, and displays the information about all crashes in one table.”
www.nirsoft.net/utils/blue_screen_view.html
7% remove it
Speccy  by Piriform
Speccy is a tool that allows the user to see information about hardware and software of the computer.
www.piriform.com/speccy
11% remove it
 
Powered by Should I Remove It?

The file spsetup125.exe has been seen being distributed by the following 50 URLs.

https://secure.piriform.com/502/cookie?affiliate=32372&redirectto=http://.../spsetup125.exe&product=71030

http://filehippo.com/download/file/.../

http://filehippo.com/download/file/.../

http://www.filehippo.com/download/file/.../

http://filehippo.com/download/file/.../

http://www.techtudo.com.br/_/software/.../download

http://filehippo.com/download/file/.../

http://filehippo.com/download/file/.../

http://www.filehippo.com/de/download/file/.../

&onid=2094&oid=3001-2094_4-75181811&rsid=cbsidownloadcomsite&sl=en&sc=us&pdguid=download:13700927&topicguid=utilities/sys&topicbrcrm=windows software&pid=13700927&mfgid=6300943&merid=6300943&ctype=dm&cval=NONE&devicetype=desktop&pguid=96c386a3b6895fefb563dab9&viewguid=QzNRwq3xP@qT31@tY-JyJ0vDSGPBPKaR4GgW&destUrl=http://software-files-a.cnet.com/s/software/13/70/09/.../spsetup126.exe

Latest 30 of 180 download URLs

Scan spsetup125.exe - Powered by Reason Core Security