utorrentspeeduppro_setup.exe

uTorrent SpeedUp Pro

Prospera Software, Inc.

The application utorrentspeeduppro_setup.exe by Prospera Software has been detected as a potentially unwanted program by 8 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from www.boostyourdownload.com.
Publisher:
BoostYourDownload, Inc.  (signed by Prospera Software, Inc.)

Product:
uTorrent SpeedUp Pro

Version:
3.6.0.0

MD5:
ae9d0b7b8edf236cf53009beb8bd59f3

SHA-1:
162e1f1548840939d58ed7e9d399fcc1f1c3a1ef

SHA-256:
4a7bb65383e2a91af20786274e9684dc9cf30db46b546d8d3c0aecdb2fb3de10

Scanner detections:
8 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 12:02:23 AM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
W32.Clodbdb.Trojan
1.3.0.4613

ESET NOD32
Win32/DownWare
8.9190

Fortinet FortiGate
Riskware/Adload
2/1/2014

K7 AntiVirus
Unwanted-Program
13.174.10588

Kaspersky
not-a-virus:Downloader.Win32.AdLoad
14.0.0.4375

McAfee
Artemis!D793278831BC
5600.7232

Reason Heuristics
PUP.Installer.ProsperaSoftware.Y
14.3.29.10

Vba32 AntiVirus
Downloader.AdLoad
3.12.24.3

File size:
784.1 KB (802,920 bytes)

Copyright:
� BoostYourDownload, Inc.

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\utorrentspeeduppro_setup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/28/2013 2:00:00 AM

Valid to:
4/28/2014 2:59:59 AM

Subject:
CN="Prospera Software, Inc.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Prospera Software, Inc.", L=Suwanee, S=Georgia, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5B2765F2A1838273DA2D54A0DF7C3C00

File PE Metadata
Compilation timestamp:
2/24/2012 9:19:59 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:+8MyhZc+CndtqKrKyqs7nUJVC9MmLm3LeY12USL4+aZ:XJCnXrKyqM+VC9MbBYUSs+aZ

Entry address:
0x39E3

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, D8, 91, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B8, 80, 40, 00, 55, FF, 15, C0, 82, 40, 00, 6A, 08, A3, B8, 2E, 47, 00, E8, 37, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, D0, 2D, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 1C, 93, 40, 00, FF, 15, 84, 81, 40, 00, 68, 04, 93, 40, 00, 68, C0, AD, 46, 00, E8, 19, 27, 00, 00, FF, 15, B4, 80, 40, 00, 50, BF, A0, 30, 4C, 00, 57, E8, 07, 27, 00, 00...
 
[+]

Entropy:
7.9390

Packer / compiler:
Nullsoft install system v2.x

Code size:
28 KB (28,672 bytes)

The file utorrentspeeduppro_setup.exe has been seen being distributed by the following URL.

Remove utorrentspeeduppro_setup.exe - Powered by Reason Core Security