SpeedyPC.exe

SpeedyPC Pro

SpeedyPC Software

This is a part of the SpeedyPC Pro software from ParetoLogic Inc (sometimes bundled through 3rd-party installers). The application SpeedyPC.exe by SpeedyPC Software has been detected as a potentially unwanted program by 6 anti-malware scanners. This file is typically installed with the program SpeedyPC Pro by SpeedyPC Software which is a potentially unwanted software program. While running, it connects to the Internet address h66-38-130-202.gtcust.grouptelecom.net on port 80 using the HTTP protocol.
Publisher:
SpeedyPC Software  (signed and verified)

Product:
SpeedyPC Pro

Description:
SpeedyPC

Version:
3.2.19.83

MD5:
20b896b7c7e528dbe1a780d527fa3e31

SHA-1:
f7d998237899240004c1208dcdf3b75081ecacc5

Scanner detections:
6 / 68

Status:
Potentially unwanted

Analysis date:
11/25/2024 12:42:47 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Program.Unwanted.686
9.0.1.0337

G Data
Win32.Application.SpeedyPC
15.12.25

Panda Antivirus
PUP/SpeedUpMyPC
15.12.03.11

Reason Heuristics
Win32.Generic.ParetoLogic.Meta
15.12.3.23

Trend Micro House Call
Suspicious_GEN.F47V1111
7.2.337

VIPRE Antivirus
Trojan.Win32.Generic
34748

File size:
5.1 MB (5,373,088 bytes)

Product version:
3.2.19.83

Copyright:
Copyright (C) 2015 SpeedyPC Software.

Original file name:
SpeedyPC.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\speedypc software\speedypc\speedypc.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
10/3/2014 6:04:19 PM

Valid to:
12/5/2016 1:45:05 PM

Subject:
E=itgroup@paretologic.com, CN=SpeedyPC Software, O=SpeedyPC Software, L=Victoria, S=British Columbia, C=CA

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11213320B67151B12383D81306118BB25BA1

File PE Metadata
Compilation timestamp:
12/1/2015 5:47:13 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
98304:nhPyq71GZOtvsKJEZ0JCbzLwjAsyancVetQDVzn+hJ8Zxh7FP9r9IE:h6JZKsKJi2gsSF+hJYxh7FP1X

Entry address:
0x307515

Entry point:
E8, F1, 59, 01, 00, E9, 7F, FE, FF, FF, 3B, 0D, 70, 85, 8A, 00, 75, 02, F3, C3, E9, 02, 28, 00, 00, 55, 8B, EC, 56, 8B, 75, 14, 85, F6, 75, 04, 33, C0, EB, 6D, 8B, 45, 08, 85, C0, 75, 13, E8, 3D, D1, 00, 00, 6A, 16, 5E, 89, 30, E8, 19, 62, 01, 00, 8B, C6, EB, 53, 57, 8B, 7D, 10, 85, FF, 74, 14, 39, 75, 0C, 72, 0F, 56, 57, 50, E8, B4, E0, 00, 00, 83, C4, 0C, 33, C0, EB, 36, FF, 75, 0C, 6A, 00, 50, E8, F2, E6, 00, 00, 83, C4, 0C, 85, FF, 75, 09, E8, FC, D0, 00, 00, 6A, 16, EB, 0C, 39, 75, 0C, 73, 13, E8, EE...
 
[+]

Entropy:
6.6529

Code size:
3.7 MB (3,927,552 bytes)

The file SpeedyPC.exe has been discovered within the following program.

SpeedyPC Pro  by SpeedyPC Software
SpeedyPC Pro is registry cleaner utility whose purported purpose is to remove redundant items from the Windows registry. SpeedyPC Pro automates the process of looking for invalid entries, missing file references or broken links within the registry and resolving or removing them.
www.speedypc.com
81% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to h66-38-130-217.gtcust.grouptelecom.net  (66.38.130.217:80)

TCP (HTTP):
Connects to h66-38-130-202.gtcust.grouptelecom.net  (66.38.130.202:80)

TCP (HTTP):
Connects to ec2-52-205-174-195.compute-1.amazonaws.com  (52.205.174.195:80)

TCP (HTTP):
Connects to h66-38-130-201.gtcust.grouptelecom.net  (66.38.130.201:80)

TCP (HTTP):
Connects to ec2-52-45-151-149.compute-1.amazonaws.com  (52.45.151.149:80)

TCP (HTTP):
Connects to server-54-230-216-38.mrs50.r.cloudfront.net  (54.230.216.38:80)

TCP (HTTP):
Connects to server-54-192-29-78.dub2.r.cloudfront.net  (54.192.29.78:80)

TCP (HTTP):
Connects to server-52-85-74-172.lhr3.r.cloudfront.net  (52.85.74.172:80)

TCP (HTTP):
Connects to server-52-85-74-147.lhr3.r.cloudfront.net  (52.85.74.147:80)

TCP (HTTP):
Connects to ec2-54-84-26-40.compute-1.amazonaws.com  (54.84.26.40:80)

TCP (HTTP):
Connects to ec2-52-54-139-246.compute-1.amazonaws.com  (52.54.139.246:80)

TCP (HTTP):

Remove SpeedyPC.exe - Powered by Reason Core Security