Sync.exe

PCSpeed

Speed Software Inc

The application Sync.exe, “PCSpeed synchronization tool” by Speed Software Inc has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a scheduled task under the Windows Task Scheduler triggered daily at a specified time.
Publisher:
SpeedSoftware  (signed by Speed Software Inc)

Product:
PCSpeed

Description:
PCSpeed synchronization tool

Version:
2.3.125.88

MD5:
17e95a897518ee00863e284d59e4438b

SHA-1:
63caae84264d7f9238a2cc5428b83a41c48cc919

SHA-256:
f29856c2ff2c62c21ee6c19ad09728a5bd42f76730c59aa9da42d140ff713690

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/16/2024 6:15:08 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Optional.Task
15.1.28.10

File size:
431.9 KB (442,272 bytes)

Product version:
2.3.125.88

Copyright:
(c) SpeedSoftware. All rights reserved.

Original file name:
Sync.exe

File type:
Executable application (Win64 EXE)

Common path:
C:\Program Files\pcspeed\pcspeed\sync.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
1/31/2014 11:04:49 PM

Valid to:
1/31/2017 11:04:49 PM

Subject:
CN=Speed Software Inc, O=Speed Software Inc, L=Beaverton, S=Oregon, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
280393C0146B62

File PE Metadata
Compilation timestamp:
2/13/2014 8:00:21 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:XGF+APg60Dgp/XePv+pq4nojwpe06kMT86Ik:orXePvs/nojwfjCrIk

Entry address:
0x2CBA0

Entry point:
48, 83, EC, 28, E8, 6F, 56, 00, 00, 48, 83, C4, 28, E9, 1A, FE, FF, FF, CC, CC, 48, 89, 0D, 25, A0, 03, 00, C3, 40, 53, 48, 81, EC, E0, 05, 00, 00, 83, 64, 24, 70, 00, 48, 8D, 4C, 24, 74, 33, D2, 41, B8, 94, 00, 00, 00, E8, 64, 29, 00, 00, 4C, 8D, 5C, 24, 70, 48, 8D, 84, 24, 10, 01, 00, 00, 48, 8D, 8C, 24, 10, 01, 00, 00, 4C, 89, 5C, 24, 48, 48, 89, 44, 24, 50, FF, 15, AF, D5, 01, 00, 48, 8B, 9C, 24, 08, 02, 00, 00, 48, 8D, 54, 24, 40, 48, 8B, CB, 45, 33, C0, E8, 87, 3B, 01, 00, 48, 85, C0, 74, 3B, 48, 83...
 
[+]

Code size:
290.5 KB (297,472 bytes)

Scheduled Task
Task name:
PCSpeed64-Beheerder-Notification

Trigger:
Daily (Runs daily at 17:07)


Remove Sync.exe - Powered by Reason Core Security