pcspeedup_3107-a1dc7cbb.exe

PC Speed Up

Safe Download Limited

The application pcspeedup_3107-a1dc7cbb.exe by Safe Download Limited has been detected as adware by 3 anti-malware scanners. This is a setup program which is used to install the application. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from www.pcspeedup.com and multiple other hosts.
Publisher:
Speedchecker Limited   (signed by Safe Download Limited)

Product:
PC Speed Up

Version:
3.2.10.2

MD5:
6caa0c73c3a031ff4edaae73a740177a

SHA-1:
964b7dcf0264a240b7ef03ef60ef4f5b406cf64c

SHA-256:
8d3cef998ecbe4b320628eb924a838207ba509f54e67c738e167226057ad0502

Scanner detections:
3 / 68

Status:
Adware

Analysis date:
12/25/2024 12:24:13 PM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Speedchecker (variant)
8.9150

Malwarebytes
PUP.Optional.PCSpeedUp.A
v2014.01.07.05

Reason Heuristics
PUP.Optional.SafeDownloadLimited.X
14.2.21.6

File size:
3.5 MB (3,715,096 bytes)

Product version:
3.2.10.2

Copyright:
Copyright © Speedchecker Limited 2009-2013

File type:
Executable application (Win32 EXE)

Language:
Swedish (Sweden)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\pcspeedup_3107-a1dc7cbb.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
7/2/2012 2:00:00 AM

Valid to:
8/26/2014 2:00:00 PM

Subject:
CN=Safe Download Limited, O=Safe Download Limited, L=Douglas, S=Douglas, C=IM

Issuer:
CN=DigiCert High Assurance Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0DD2FC97B3C6597CABD97B29D9383440

File PE Metadata
Compilation timestamp:
12/20/2011 3:16:50 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:OkqSLhu5KdEfaRzIJN8mMOYd/Ai4d3eJn90dQNi1Pflk/TjV5R:O3SVu57iRzZNd7WOr6QNOPtGjVn

Entry address:
0x16478

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, B0, 52, 41, 00, E8, AC, 03, FF, FF, 33, C0, 55, 68, 45, 6B, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 01, 6B, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, AB, 41, 00, E8, 4E, EC, FF, FF, E8, F5, E7, FF, FF, 8D, 55, EC, 33, C0, E8, 7F, 84, FF, FF, 8B, 55, EC, B8, AC, D6, 41, 00, E8, E2, E9, FE, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, AC, D6, 41, 00, B2, 01...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
84 KB (86,016 bytes)

The file pcspeedup_3107-a1dc7cbb.exe has been seen being distributed by the following 6 URLs.

http://www.pcspeedup.com/.../download.aspx?affid=janusz&k=bottombanner&referencedWebsite=www.pcspeedup.co.uk&language=en

Remove pcspeedup_3107-a1dc7cbb.exe - Powered by Reason Core Security