SystemUtilitiesSetup_download_com.exe

Free System Utilities

Freemium GmbH

The file SystemUtilitiesSetup_download_com.exe by Freemium GmbH has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Covus installer. This file is typically installed with the program Free System Utilities by Freetec which is a potentially unwanted software program. It is also typically executed from the user's temporary directory.
Publisher:
Freetec  (signed by Freemium GmbH)

Product:
Free System Utilities

Version:
1.0.0.0

MD5:
193acf95d4e664b16fc9cd9cffd98fff

SHA-1:
b11ada03201fef06e102912cf95b77ce9ebcc0dd

SHA-256:
8f15384d49fe5c5fa22ca2a32203111e5464e3f8f4ef4558a4c86a64abe5a309

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/19/2024 11:37:21 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Covus.Freemium.Bundler (M)
16.1.25.18

File size:
422 KB (432,152 bytes)

Product version:
1.0.0.0

Copyright:
Copyright (c) Freetec. All rights reserved.

Original file name:
SystemUtilitiesSetup_download_com.exe

Bundler/Installer:
Covus

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\del3497.tmp

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
2/13/2012 4:34:07 AM

Valid to:
2/13/2013 4:34:07 AM

Subject:
CN=Freemium GmbH, O=Freemium GmbH, L=Berlin, S=Berlin, C=DE

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121252CF10F5361359FEF99CB5B54F17E94

File PE Metadata
Compilation timestamp:
9/3/2012 9:44:40 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:0LObe2mmLVKEtIipM/VpyFcehHmCoj86wEUxBsfnc2X30fNhwQMpclOISY:0Kbe2meV3IipMkHmCoj86wTBsLMwdJrY

Entry address:
0x474B

Entry point:
E8, AC, 14, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, 8B, 00, 81, 38, 63, 73, 6D, E0, 75, 2A, 83, 78, 10, 03, 75, 24, 8B, 40, 14, 3D, 20, 05, 93, 19, 74, 15, 3D, 21, 05, 93, 19, 74, 0E, 3D, 22, 05, 93, 19, 74, 07, 3D, 00, 40, 99, 01, 75, 05, E8, 01, 15, 00, 00, 33, C0, 5D, C2, 04, 00, 68, 55, 47, 40, 00, FF, 15, 7C, 11, 40, 00, 33, C0, C3, 8B, FF, 55, 8B, EC, 57, BF, E8, 03, 00, 00, 57, FF, 15, 84, 11, 40, 00, FF, 75, 08, FF, 15, 80, 11, 40, 00, 81, C7, E8, 03, 00, 00, 81, FF, 60, EA, 00...
 
[+]

Entropy:
6.9936

Code size:
311.5 KB (318,976 bytes)

The file SystemUtilitiesSetup_download_com.exe has been discovered within the following program.

Free System Utilities  by Freetec
Publisher's description - “Free System Utilities is a free software to maintain your Windows PC. It provides you with 20 powerful tools to optimize performance, safety and comfort of your PC. Four categories of useful tools enable you to quickly speed up and maintain your system.”
About 69% of users remove it
 
Powered by Should I Remove It?

Remove SystemUtilitiesSetup_download_com.exe - Powered by Reason Core Security