pcspsetuprmimg.exe

PC Speedup-Pro

PC Speedup Pro

The application pcspsetuprmimg.exe by PC Speedup Pro has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from www.pcspeeduppro.net and multiple other hosts.
Publisher:
PCSpeedupPro.net   (signed by PC Speedup Pro)

Product:
PC Speedup-Pro

Version:
PC Speedup-Pro

MD5:
c0a13cf85dffd185172101e97f6c1558

SHA-1:
1b638dd829507561b583fc4e15a720445feaadcb

SHA-256:
d3285103d85d3e3ae1688b84d8ae6a21ecbc5a3d5376c4ad64adc3ccce9f2776

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/28/2024 9:37:59 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.PCSpeedupPro.Installer.Meta (L)
16.6.13.19

File size:
4.5 MB (4,750,456 bytes)

Product version:
1.0.0.4684

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\pcspsetuprmimg.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
8/19/2015 2:00:00 AM

Valid to:
8/19/2016 1:59:59 AM

Subject:
CN=PC Speedup Pro, OU=PC Speedup Pro, O=PC Speedup Pro, STREET="104,SURIYA NAGAR MURLIPURA", L=Jaipur, S=Rajasthan, PostalCode=302039, C=IN

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00C5061427713FFD711E8F8302D7B03953

File PE Metadata
Compilation timestamp:
7/9/2014 9:58:13 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:xeRhlcYroT9f3fKmU7hoPnSViTpKfGpebAQx:xKhlc8oTR0o/SViTUfx/x

Entry address:
0x113BC

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 2C, 00, 41, 00, E8, E8, 51, FF, FF, 33, C0, 55, 68, 9E, 1A, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 5A, 1A, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, 5B, 41, 00, E8, 16, D8, FF, FF, E8, 65, D3, FF, FF, 80, 3D, DC, 2A, 41, 00, 00, 74, 0C, E8, 2B, D9, FF, FF, 33, C0, E8, 80, 32, FF, FF, 8D, 55, EC, 33, C0, E8, E2, A3, FF, FF, 8B, 55, EC, B8, 50, 86...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
63.5 KB (65,024 bytes)

The file pcspsetuprmimg.exe has been seen being distributed by the following 50 URLs.

http://www.pcspeeduppro.net/download_ip_mr_new.asp?utm_source=mrg&utm_campaign=mrg&utm_pubid=mr_70678104&x-context=adkm_rQXjJpbeGTSYjG4e1oVVUqytc0z1MiptFIwe9zwu2WuOey8Gndt50XqOW7lC81DgHlwEKyJ31aPsX6YKxPoNxRF4U5Uvp6l6NT3E9pnXS_ivytpRK4nApWYkmVa85Gq9NfbHAjgvDN3qtoFh4g0GnyGyTotTXQjUAKQtubFj-Bm3FDXN7PrW8H2izBQMK0_dSiFNjR6se9sYbTvBsky8dgsprRYNMDeWJum8REENeFVtVV5xX1aMJl3l1eceAWwmnV9pF-m_laE7_cRw24DMEDmjFy6KNBWZ4F8vzuXVCVIs4CJXIGOiRnpUhLmHRbQYE9c3lWXvEdsCJIm1i8s3dr5SF75aPfXMHjC2Luy4NJfn3kWgXGUy2gkIW_4PEyMXDR4akk1HyhNTr6R5lgsqseB4EIohcHrXYsA&x-at={E}

http://www.pcspeeduppro.com/download_ip_mr_new.asp?utm_source=mrg&utm_campaign=mrg&utm_pubid=mr_70445918&x-context=adkm_2VMYd4gNPUV7bs7kA1KMjIVVMgdrO7EKtsI63G20Ulw0B3DUWVLGpLHz78BWfxOIppP_gWP0A-Y_IQ2bIgNaAewHWnQh7hYs9XH4X0ujVxKaId8Eoi-GCNT3vbp0L2qQ0FaEfapq8qc4dtqEYrzlCfsWYLCt4tRVjRES60JcAUwigPyheJssAXto9hH7eV2fVDh-Nzgr2qu-Qufq-Dg6qjjOVZ8TtKM1QkGi8vQPJO-20qS5rG_HRz0WE_pw2j0MtGzJtkZ5ncadkedRXva4VdUA9xHA-KWDu7acup8b_3tJWOgB0HT1BJcS6OeyDEE0o308LdJUZgIUDBBx6x66-beWHRO_AGRMR5yjSlWjmzb5wp5KBDV6gn-Taz8IjI3_C5UllVs-_62Ek5V3sgGDn9CjRcbKQYe2h0d2-0iaauW8RWH7KJvmt1QWLXKNwaH1N7q1NIGJDw&x-at={E}

http://www.pcspeeduppro.com/download_ip_mr_new.asp?utm_source=mrg&utm_campaign=mrg&utm_pubid=mr_70446827&x-context=adkm_8oU2tmyNPORr_7iM81Jqb_qNrpqPMyp_n2oM6XPUYqWCld_KiANfpB39aOC3O_d0vnmKkZGu_rKnR18pEXnc3z7bbH8dX2iRkqtDhWlf5GH8mTmztarNfSE6jAHp36rOAc-a240ZaUy3Pr3RHrX4nqiHT2kF40MZeRh6aAqiHGMcGdZG-kdgY-io5HwHqtbatBx040QZaeSRJJ4aVCQ2BRmSWNx6I85C2qxC9UfIc6NhUfmFtQQ7tUuYxzmEHxftBNjOcwgbV3TDMLG3KAksZQflA2PHDykzz6km1eJ9HTZ7RmFaUXLjkaOWmTImAs2GWDmfFFb9dzuNOy892Lj6TON1V2sqB3G_IM-Mx3NNc7-wvC0wQpzUqbAggjMoiHFbYb7SJrX_A8_cowCS1vZRV6XUOjvKKU1rPMbFwYrA4IOn0JjTZn8tt2Epu1fr623pZOUO-OWRKVL6jJa-GQx8o6NnP0cMcU7Sf482UMsHzNhbfFEg6KM-XRMKUZ8zIg&x-at={D}

http://www.pcspeeduppro.net/download_ip_mr_new.asp?utm_source=mrg&utm_campaign=mrg&utm_pubid=mr_70678104&x-context=adkm_od6g7DTtA4UunxszsqGJ7HILghJiui1i94RHV-XT9ur-GLEBUTZ2qlqZ_DtHa8LV4sjEtTguGfdWlKajvIee3mGUUIabVbLWlMAJO6n3IvTG0_i04DPRSXCtb6CCT5IynwiEJQ0BTTI850dDWE3r62ZotTxnkV6CLpRWf7G2JO021oc40JyL6JWf42tny6eDxukWVnau1qN1IEz2PXQRW2CQvy352F4mOq2CXKsNRghITQq89beThq5uToIRvpFCbiFN90cNskzSlzA0Qt0L5VprQw7iZa65EOubnYtMT5KmHZM7oSd0cR5XrVBjQh6sABjiaXWd3ZRCKNCX1O9gvEUQZIKSl0R1_ZZTrswJMb76g0IVsTEkvx_mREjXb3pmnn2AmgjLv6EqI4W9N6WXxW9-ZQURvR6bz230qw-pCjjAIMH223eyIp0K640&x-at={E}

http://www.pcspeeduppro.com/download_ip_mr_new.asp?utm_source=mrg&utm_campaign=mrg&utm_pubid=mr_70714517&x-context=adkm_DwTzYvlTjvO0z7A9cXVdA9cyjM1YZ339_lpDlC8gtxXQDXuadySU0SAVYssDg4VCiuKZY1lm4mc-mTh1TA1yIlo9VZVqHVuK4wsr0bYIxiAuel9R8osR8ZrU_HRlCsplMS0Hkl5YSvuKoLeDnFnhFmlj08m0hkZK_9pwWrrZlkVlr5Lyw_4nryh_8VFreWuqVcnsSyEbWxKSnDaxrpt4CvyTyzSNrslKHWpVh4EKNcQpOs4P_hNiDrQlj7Zf8GDcKy_1v1tNwfI6dtOuaM45sfvfjs0-7OE9QkJtBeK7mFGOnrFA5YfEy9bB9NdGM3kucvjbin3VuwbipPNvnCeHeFcz2curfhNsjjRR1h05pFzs9cH5Vfwb6lUzB4fd-bMstixiaOwnq9M2Zr93B6dxeevvHWTkFaluFToG6yCdVS8vei44IspBePCL8QLEg1NSY0vAVb_u&x-at={D}

http://www.pcspeeduppro.net/download_ip_mr_new.asp?utm_source=mrg&utm_campaign=mrg&utm_pubid=mr_70649257&x-context=adkm_2PKTS7Qzm2h2EzeFl06EcyiXmSg2uMqlB5eC2ns64oweuc3LBt5TmZ5ozgoXV8iwsmMbaaoPRpg_9euJf8Src_bdXTUzwmHtSvD12pnKPxHZVkxKU1QD1JeUSvRiyGpeS6_Wf1McJkxD4MqvbIPBsqPiMKHsUWgbSL-dexFa-J_vl-UKneWkyhO8tGFS9-22DtMPO8k-PZSLEy4TtymF-z7x6m3tl6D92RDhCw5w2jmXaK738R2ddTtFpcQnUPkuK4xIusLK21OkQtBhqPIvOFUI2D0ADK2-sPX7GT92xmJK5dcFbn_dR-Txr_52L_PQIfYbd0IlpxUQX2MOUuUfbj1N12XwiHLiCrBZFYVVL2WeGobFSVaanOw34hRKZniK1VWabxSYnb-LDBU96f9r95TzwzaIQicyVCK_YnP-5cZ1_z3qmYyx0i8bhfCK359mTbPcwxeoe7fhLlQTupJ7&x-at={E}

Latest 30 of 92 download URLs

Remove pcspsetuprmimg.exe - Powered by Reason Core Security