nsa6590.tmp.exe

PC Speed Up

Safe Download Limited

The application nsa6590.tmp.exe by Safe Download Limited has been detected as adware by 2 anti-malware scanners. This is a setup program which is used to install the application. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from www.wifiprotector.com and multiple other hosts.
Publisher:
Speedchecker Limited   (signed by Safe Download Limited)

Product:
PC Speed Up

Version:
3.3.2.0

MD5:
79ed3c9b0279456cd0847a1917618689

SHA-1:
6c741f6207db68fba9cdd09036cfb3c529329b65

SHA-256:
ec72d29de0e9e73c61a8f6ebb56d13c7467fe927155de0bd1f9216a1a2f58852

Scanner detections:
2 / 68

Status:
Adware

Analysis date:
12/25/2024 3:46:59 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Speedchecker (variant)
7.9164

Reason Heuristics
PUP.Optional.SafeDownloadLimited.K
14.2.16.7

File size:
3.8 MB (3,973,640 bytes)

Product version:
3.3.2.0

Copyright:
Copyright © Speedchecker Limited 2009-2013

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\nsa6590.tmp.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
7/2/2012 2:00:00 AM

Valid to:
8/26/2014 2:00:00 PM

Subject:
CN=Safe Download Limited, O=Safe Download Limited, L=Douglas, S=Douglas, C=IM

Issuer:
CN=DigiCert High Assurance Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0DD2FC97B3C6597CABD97B29D9383440

File PE Metadata
Compilation timestamp:
12/20/2011 3:16:50 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:kkqSLHGeFhIOqrs3a4kS4Y82/nQroGAljTAYkhRGBV5R:k3Sj5hir94krI/nWBAljTLmRsVP

Entry address:
0x16478

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, B0, 52, 41, 00, E8, AC, 03, FF, FF, 33, C0, 55, 68, 45, 6B, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 01, 6B, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, AB, 41, 00, E8, 4E, EC, FF, FF, E8, F5, E7, FF, FF, 8D, 55, EC, 33, C0, E8, 7F, 84, FF, FF, 8B, 55, EC, B8, AC, D6, 41, 00, E8, E2, E9, FE, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, AC, D6, 41, 00, B2, 01...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
84 KB (86,016 bytes)

The file nsa6590.tmp.exe has been seen being distributed by the following 19 URLs.

https://www.wifiprotector.com/.../response.aspx?&requestId=e6fa26b83c2342558018f51d9e9248da&encodedInstallerPath=QzpcaW5ldHB1Ylx3d3dyb290XHByenlzcGllc3prb21wdXRlclxkb3dubG9hZHMvcGNzcGVlZHVwLmV4ZQ==

http://www.pcspeedup.com/.../download.aspx?k=lol&affId=aed&keyword=lol&referencedWebsite=www.acelerarelpc.es&language=es

http://www.pcspeedup.com/.../download.aspx?k=102579273b13b9aa887572ea031947&affId=hoffers&keyword=102579273b13b9aa887572ea031947&referencedWebsite=www.pcspeedup.com&language=en

https://www.wifiprotector.com/.../response.aspx?&requestId=ae9d0e4266584f548d72e5bb0278a769&encodedInstallerPath=QzpcaW5ldHB1Ylx3d3dyb290XHByenlzcGllc3prb21wdXRlclxkb3dubG9hZHMvcGNzcGVlZHVwLmV4ZQ==

Remove nsa6590.tmp.exe - Powered by Reason Core Security