pcspeedup.exe

PC Speed Up

Safe Download Limited

The application pcspeedup.exe by Safe Download Limited has been detected as adware by 4 anti-malware scanners. This is a setup program which is used to install the application. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from cdn.airdlr1.com and multiple other hosts.
Publisher:
Speedchecker Limited   (signed by Safe Download Limited)

Product:
PC Speed Up

Version:
3.2.9.1

MD5:
5ed1d340ad73cf6d9ea7343fe0412c96

SHA-1:
f5c37d6bd0b6dca0c28a4f464c962f087687368b

SHA-256:
c213bddf85b467f1c943e4f15894bc6f1916cafa396c463a54564a557506a2af

Scanner detections:
4 / 68

Status:
Adware

Analysis date:
12/23/2024 11:37:37 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Bkav FE
W32.Clod8eb.Trojan
1.3.0.4923

ESET NOD32
Win32/Speedchecker (variant)
8.9341

Malwarebytes
PUP.Optional.PCChecker.A
v2014.02.22.03

Reason Heuristics
PUP.Optional.SafeDownloadLimited.J
14.2.22.3

File size:
3.5 MB (3,712,680 bytes)

Product version:
3.2.9.1

Copyright:
Copyright © Speedchecker Limited 2009-2013

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\pcspeedup.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
7/2/2012 2:00:00 AM

Valid to:
8/26/2014 2:00:00 PM

Subject:
CN=Safe Download Limited, O=Safe Download Limited, L=Douglas, S=Douglas, C=IM

Issuer:
CN=DigiCert High Assurance Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0DD2FC97B3C6597CABD97B29D9383440

File PE Metadata
Compilation timestamp:
12/20/2011 3:16:50 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:0kqSLGBDYSQpRQLNJ3CeBg9H0DfifLkvV5x:03SiSfPQBfgl0DcLGVr

Entry address:
0x16478

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, B0, 52, 41, 00, E8, AC, 03, FF, FF, 33, C0, 55, 68, 45, 6B, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 01, 6B, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, AB, 41, 00, E8, 4E, EC, FF, FF, E8, F5, E7, FF, FF, 8D, 55, EC, 33, C0, E8, 7F, 84, FF, FF, 8B, 55, EC, B8, AC, D6, 41, 00, E8, E2, E9, FE, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, AC, D6, 41, 00, B2, 01...
 
[+]

Code size:
84 KB (86,016 bytes)

The file pcspeedup.exe has been seen being distributed by the following 2 URLs.

Remove pcspeedup.exe - Powered by Reason Core Security