upsell1.exe

Driver Pro v3.2

PC Utilities Software Limited

Part of the Optimizer Pro / Driver 'PC optimizer' product lines marketed by Adsology and distributed through various bundled software (PPI and commission) channels. The application upsell1.exe, “Keep your PC drivers up to date” by PC Utilities Software Limited has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
PC Utilities Software Limited  (signed and verified)

Product:
Driver Pro v3.2

Description:
Keep your PC drivers up to date

Version:
3.2.0.2

MD5:
10259313ab4f237e352d985d0734a96e

SHA-1:
0df131c0bc6ffadf39acf9e64b130c44fc046e2c

SHA-256:
7c468e3e13c79d09c035c10d53a96cf6388f0d9593f2668cd9be81e7d96ef45b

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Installed with the Optimizer Pro software which is bundled by 3rd-party monetization programs.

Analysis date:
1/24/2025 7:30:47 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.PC Utilities (M)
17.3.14.10

File size:
3.4 MB (3,542,112 bytes)

Product version:
3.2.0.2

Copyright:
PC Utilities Software Limited

Original file name:
Driver Pro

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\one system care\upsell1.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
12/22/2014 6:00:00 PM

Valid to:
12/23/2015 5:59:59 PM

Subject:
CN=PC Utilities Software Limited, O=PC Utilities Software Limited, L=London, S=London, C=GB

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
64CF3882C80993A7C8405784254E3F0F

File PE Metadata
Compilation timestamp:
9/4/2015 9:18:35 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x6869

Entry point:
E8, 67, 5F, 00, 00, E9, 89, FE, FF, FF, FF, 35, 84, E2, 41, 00, FF, 15, 58, 60, 41, 00, 85, C0, 74, 02, FF, D0, 6A, 19, E8, D9, 53, 00, 00, 6A, 01, 6A, 00, E8, FC, 2E, 00, 00, 83, C4, 0C, E9, C1, 2E, 00, 00, CC, CC, CC, 8B, 4C, 24, 04, F7, C1, 03, 00, 00, 00, 74, 24, 8A, 01, 83, C1, 01, 84, C0, 74, 4E, F7, C1, 03, 00, 00, 00, 75, EF, 05, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8B, 01, BA, FF, FE, FE, 7E, 03, D0, 83, F0, FF, 33, C2, 83, C1, 04, A9, 00, 01, 01, 81, 74, E8, 8B...
 
[+]

Entropy:
7.8219  (probably packed)

Code size:
81.5 KB (83,456 bytes)

Remove upsell1.exe - Powered by Reason Core Security