velocidadedopc_0667bf1f73a64ecc8f9d336095d61a89_.exe

PC Speed Up

Safe Download Limited

The application velocidadedopc_0667bf1f73a64ecc8f9d336095d61a89_.exe by Safe Download Limited has been detected as adware by 2 anti-malware scanners. This is a setup program which is used to install the application. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from www.pcspeedup.com and multiple other hosts.
Publisher:
Speedchecker Limited   (signed by Safe Download Limited)

Product:
PC Speed Up

Version:
3.2.2

MD5:
792ce4b6cf165fe8acaf8f38c3082c52

SHA-1:
bb48aa3dd44478ed4ffb075f9c7b6f1359612571

SHA-256:
329598c056d433f24ed4f4b0c2d69a095469f98a3fa67645cc8ea1b7f9523043

Scanner detections:
2 / 68

Status:
Adware

Analysis date:
4/20/2024 1:18:20 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Speedchecker (variant)
7.8980

Reason Heuristics
PUP.Optional.SafeDownloadLimited.q
14.3.2.12

File size:
3.4 MB (3,545,896 bytes)

Product version:
3.2.2

Copyright:
Copyright © Speedchecker Limited 2009-2012

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\velocidadedopc_0667bf1f73a64ecc8f9d336095d61a89_.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
7/1/2012 9:00:00 PM

Valid to:
8/26/2014 9:00:00 AM

Subject:
CN=Safe Download Limited, O=Safe Download Limited, L=Douglas, S=Douglas, C=IM

Issuer:
CN=DigiCert High Assurance Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0DD2FC97B3C6597CABD97B29D9383440

File PE Metadata
Compilation timestamp:
12/20/2011 12:16:50 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:2kqSLew9ZWTeNf7hwB5SBDFxm8U3OvfSkVERqg:23SXWiNfkItFU3ofS/qg

Entry address:
0x16478

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, B0, 52, 41, 00, E8, AC, 03, FF, FF, 33, C0, 55, 68, 45, 6B, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 01, 6B, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, AB, 41, 00, E8, 4E, EC, FF, FF, E8, F5, E7, FF, FF, 8D, 55, EC, 33, C0, E8, 7F, 84, FF, FF, 8B, 55, EC, B8, AC, D6, 41, 00, E8, E2, E9, FE, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, AC, D6, 41, 00, B2, 01...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
84 KB (86,016 bytes)

The file velocidadedopc_0667bf1f73a64ecc8f9d336095d61a89_.exe has been seen being distributed by the following 7 URLs.

http://www.pcspeedup.com/.../download.aspx?affid=hoffers&k=1020eab95a7f5107274ef58682dc8d&autocountry=1&referencedWebsite=www.pcspeedup.com&language=en

http://www.pcspeedup.com/.../download.aspx?affid=hoffers&k=102ad675cf806c24bde89c4c289c81&autocountry=1&referencedWebsite=www.pcspeedup.com&language=en

http://www.pcspeedup.com/.../download.aspx?affID=janusz&keyword=speedtest2&referencedWebsite=www.przyspieszkomputer.pl