usscsetupunad2.exe

US System Care

pc speedup pro

The application usscsetupunad2.exe by pc speedup pro has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The file has been seen being downloaded from www.uspcworks.com and multiple other hosts.
Publisher:
uspcworks.com   (signed by pc speedup pro)

Product:
US System Care

Version:
US System Care

MD5:
50ff3fe533165a1aee236d309a6dca21

SHA-1:
5070dfea5e533158f380657bcf30e30f1aea5b0f

SHA-256:
0698e5d809c76b0689f16428e4e768a36ed12c8472161cbc12bba64b9cb60859

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
1/15/2025 11:52:20 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.PCSpeedupPro.uspcwork.Installer.Meta (L)
16.6.22.12

File size:
4.2 MB (4,392,648 bytes)

Product version:
1.0.0.5742

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\usscsetupunad2.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
2/28/2016 4:00:00 PM

Valid to:
2/28/2017 3:59:59 PM

Subject:
CN=pc speedup pro, OU=management, O=pc speedup pro, STREET=104 Surya Nagar, STREET=MURLIPURA, L=Jaipur, S=Rajasthan, PostalCode=302039, C=IN

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
009CC01DDB723B1B1F926A2A1AEE6744B0

File PE Metadata
Compilation timestamp:
6/19/1992 3:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:U9jo/o9S8VgLPF7UxbZU43z8TZT0IJHiteQvjL797s6ULBueH1FpsvC:e2feM1mbZU4gTZeteQvT9Ij8eH1FpL

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9960

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file usscsetupunad2.exe has been seen being distributed by the following 23 URLs.

http://www.uspcworks.com/download_ip_ad.asp?x-context=AAQjp3ud0wgAA_-LHxsqUpR3AiunQrlJ2uCDKoU3ZMMIAgAAAAAAAAE&utm_source=unwadn2&utm_campaign=ADL&pxl=UNW422_UNW406_RUNT&utm_pubid=40352&x-at=XXXX

http://www.uspcworks.com/download_ip_ad.asp?x-context=AMxPJ7eh0wgAA_-LF1ktAFZ5IIOjTZ2HWBiol-ypxdNTAAAAAAABAAE&utm_source=unwadn2&utm_campaign=ADL&pxl=UNW422_UNW406_RUNT&utm_pubid=32367&x-at=XXXX

http://www.uspcworks.com/download_ip_ad.asp?x-context=AJoFYuWl0wgAA_-LMqBeBJohqdFlTqwU9g5Psob7PCYbAgAAAAACAAE&utm_source=unwadn2&utm_campaign=ADL&pxl=UNW422_UNW406_RUNT&utm_pubid=1073979&x-at=XXXX

http://www.uspcworks.com/download_ip_ad.asp?x-context=N3wxNjF8VVN8M3wxfHx8fA&utm_source=unwadn2&utm_campaign=ADL&pxl=UNW422_UNW406_RUNT&utm_pubid=666615&x-at=XXXX

http://www.uspcworks.com/download_ip_ad.asp?x-context=ADTYuUqp0wgAA_-LF1S7rebpfxdGT4IWGkiVzOEAU54kBAAAAAABAAE&utm_source=unwadn2&utm_campaign=ADL&pxl=UNW422_UNW406_RUNT&utm_pubid=465538&x-at=XXXX

http://www.uspcworks.com/download_ip_ad.asp?x-context=AGhg4q6r0wgAA_-LMMgH3cIIayA6RYWZ-kz5mx_xcGwGAAAAAAAGAAE&utm_source=unwadn2&utm_campaign=ADL&pxl=UNW422_UNW406_RUNT&utm_pubid=91586&x-at=XXXX

http://www.uspcworks.com/download_ip_ad.asp?x-context=AHwfBAGw0wgAA_-LLqvBmlHSsFQoSaq40UhMAvSV_fgKCAAAAAAJAAE&utm_source=unwadn2&utm_campaign=ADL&pxl=UNW422_UNW406_RUNT&utm_pubid=631029&x-at=XXXX

http://www.uspcworks.com/download_ip_ad.asp?x-context=AIracGWd0wgAA_-LMqCKlckRaMotSZJQmgYNNUj-vUYGAgAAAAAHAAE&utm_source=unwadn2&utm_campaign=ADL&pxl=UNW422_UNW406_RUNT&utm_pubid=96259&x-at=XXXX

http://www.uspcworks.com/download_ip_ad.asp?x-context=AOLv6sua0wgAA_-G_arbdKiCLa_6SYncLOusij01wEDlAAAAAAAAAAE&utm_source=unwadn2&utm_campaign=ADL&pxl=UNW422_UNW406_RUNT&utm_pubid=631029&x-at=XXXX

http://www.uspcworks.com/download_ip_ad.asp?x-context=AHDEtamt0wgAA_-G9etCGOihV0joQpBFkYbmr0DFX5akBgAAAAAFAAE&utm_source=unwadn2&utm_campaign=ADL&pxl=UNW422_UNW406_RUNT&utm_pubid=631029&x-at=XXXX

Remove usscsetupunad2.exe - Powered by Reason Core Security