upsell1.exe

Driver Pro v3.2

PC Utilities Software Limited

Part of the Optimizer Pro / Driver 'PC optimizer' product lines marketed by Adsology and distributed through various bundled software (PPI and commission) channels. The application upsell1.exe, “Keep your PC drivers up to date” by PC Utilities Software Limited has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
PC Utilities Software Limited  (signed and verified)

Product:
Driver Pro v3.2

Description:
Keep your PC drivers up to date

Version:
3.2.0.2

MD5:
0f6b433d9ce09fdecccb8ad8ca429bf6

SHA-1:
51d48e2dd4354129081cb162da1579d3b7cb0719

SHA-256:
86d651ea2ed626cac2de34748ebb2b0fd3d750ff92f2fb05f5050d6f45048387

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Installed with the Optimizer Pro software which is bundled by 3rd-party monetization programs.

Analysis date:
12/23/2024 10:29:51 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.PC Utilities (M)
17.2.28.0

File size:
3.5 MB (3,655,704 bytes)

Product version:
3.2.0.2

Copyright:
PC Utilities Software Limited

Original file name:
Driver Pro

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\one system care\upsell1.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
11/6/2015 12:00:00 AM

Valid to:
11/5/2016 11:59:59 PM

Subject:
CN=PC Utilities Software Limited, OU=IT Department, O=PC Utilities Software Limited, STREET=78 York Street, L=London, S=England, PostalCode=W1H 1DP, C=GB

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
547CFDC5D70FD7C944A9BA11E88CCB1C

File PE Metadata
Compilation timestamp:
11/1/2016 9:22:02 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x6869

Entry point:
E8, 67, 5F, 00, 00, E9, 89, FE, FF, FF, FF, 35, 84, E2, 41, 00, FF, 15, 58, 60, 41, 00, 85, C0, 74, 02, FF, D0, 6A, 19, E8, D9, 53, 00, 00, 6A, 01, 6A, 00, E8, FC, 2E, 00, 00, 83, C4, 0C, E9, C1, 2E, 00, 00, CC, CC, CC, 8B, 4C, 24, 04, F7, C1, 03, 00, 00, 00, 74, 24, 8A, 01, 83, C1, 01, 84, C0, 74, 4E, F7, C1, 03, 00, 00, 00, 75, EF, 05, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8B, 01, BA, FF, FE, FE, 7E, 03, D0, 83, F0, FF, 33, C2, 83, C1, 04, A9, 00, 01, 01, 81, 74, E8, 8B...
 
[+]

Entropy:
7.8298  (probably packed)

Code size:
81.5 KB (83,456 bytes)

Remove upsell1.exe - Powered by Reason Core Security