SpeedyPC.exe

SpeedyPC Pro

SpeedyPC Software (ParetoLogic Inc.)

The application SpeedyPC.exe by SpeedyPC Software (ParetoLogic) has been detected as a potentially unwanted program by 2 anti-malware scanners. This file is typically installed with the program SpeedyPC Pro by SpeedyPC Software which is a potentially unwanted software program. While running, it connects to the Internet address h66-38-130-217.gtcust.grouptelecom.net on port 80 using the HTTP protocol.
Publisher:
SpeedyPC Software, Inc.  (signed by SpeedyPC Software (ParetoLogic Inc.))

Product:
SpeedyPC Pro

Description:
SpeedyPC

Version:
3, 0, 0, 0

MD5:
466e1b9170ea9cbf04912865d97e94db

SHA-1:
26c2e0eb981e2c95e4b09ece98fc02bab2d0315c

SHA-256:
99a112d22bba4036ea06ac8c1450f4530925ce785d1c7f3e4f6dc16288625179

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
11/23/2024 2:36:38 PM UTC  (today)

Scan engine
Detection
Engine version

Boost by Reason
Optional.SpeedyPCSoftwareParetoLogic.I
188163

Reason Heuristics
PUP.Optional.SpeedyPCSoftwareParetoLogic.I
14.2.28.20

File size:
4.4 MB (4,613,296 bytes)

Product version:
3, 0, 0, 0

Copyright:
Copyright (C) 2011 SpeedyPC Software Inc.

Original file name:
SpeedyPC.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
9/26/2011 3:00:00 AM

Valid to:
9/26/2012 2:59:59 AM

Subject:
CN=SpeedyPC Software (ParetoLogic Inc.), OU=Digital ID Class 3 - Microsoft Software Validation v2, OU=ICT, O=SpeedyPC Software (ParetoLogic Inc.), L=Victoria, S=British Columbia, C=CA

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
263D81E73DB3B97C46C271D31F2444A7

File PE Metadata
Compilation timestamp:
10/9/2011 4:19:43 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
98304:lqwEygXNgn/He68++X9bcsQ8l5idC6O+fwryHCL45dbFFHoSu:lqw5CNoHe32dKX6C45dbFm

Entry address:
0x26B25A

Entry point:
E8, 49, B2, 00, 00, E9, 89, FE, FF, FF, 3B, 0D, 70, AE, 7E, 00, 75, 02, F3, C3, E9, D0, B2, 00, 00, 8B, FF, 55, 8B, EC, 56, 8B, 75, 14, 85, F6, 75, 04, 33, C0, EB, 61, 83, 7D, 08, 00, 75, 13, E8, 21, 5D, 00, 00, 6A, 16, 5E, 89, 30, E8, 3A, B5, 00, 00, 8B, C6, EB, 48, 83, 7D, 10, 00, 74, 16, 39, 75, 0C, 72, 11, 56, FF, 75, 10, FF, 75, 08, E8, FC, 96, 00, 00, 83, C4, 0C, EB, C7, FF, 75, 0C, 6A, 00, FF, 75, 08, E8, 9A, 60, 00, 00, 83, C4, 0C, 83, 7D, 10, 00, 74, BB, 39, 75, 0C, 73, 0E, E8, D7, 5C, 00, 00, 6A...
 
[+]

Entropy:
6.6398

Code size:
3.2 MB (3,309,568 bytes)

The file SpeedyPC.exe has been discovered within the following programs.

SpeedyPC Pro  by SpeedyPC Software
SpeedyPC Pro is registry cleaner utility whose purported purpose is to remove redundant items from the Windows registry. SpeedyPC Pro automates the process of looking for invalid entries, missing file references or broken links within the registry and resolving or removing them.
www.speedypc.com
81% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to h66-38-130-202.gtcust.grouptelecom.net  (66.38.130.202:80)

TCP (HTTP):
Connects to h66-38-130-201.gtcust.grouptelecom.net  (66.38.130.201:80)

TCP (HTTP):
Connects to h66-38-130-217.gtcust.grouptelecom.net  (66.38.130.217:80)

Remove SpeedyPC.exe - Powered by Reason Core Security