usscvelmw2.exe

US System Care

pc speedup pro

The executable usscvelmw2.exe has been detected as malware by 1 anti-virus scanner. This is a setup program which is used to install the application. The file has been seen being downloaded from www.uspcworks.com and multiple other hosts.
Publisher:
uspcworks.com   (signed by pc speedup pro)

Product:
US System Care

Version:
US System Care

MD5:
fbe35de783c5eb53e99ce838269e350e

SHA-1:
2ec6b6a2972582d662a6c1a6346276c98288550e

SHA-256:
09d7d912f2ed4c157c6c733232f629da4fceebbbc7c34dd9c0ab7f908f721b8a

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
1/15/2025 11:57:00 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
(M)
16.6.17.18

File size:
4.4 MB (4,592,232 bytes)

Product version:
1.0.0.5742

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\usscvelmw2.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
2/28/2016 6:00:00 PM

Valid to:
2/28/2017 5:59:59 PM

Subject:
CN=pc speedup pro, OU=management, O=pc speedup pro, STREET=104 Surya Nagar, STREET=MURLIPURA, L=Jaipur, S=Rajasthan, PostalCode=302039, C=IN

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
009CC01DDB723B1B1F926A2A1AEE6744B0

File PE Metadata
Compilation timestamp:
7/9/2014 2:58:13 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:OhoKzS3INsyUTZtG5XFqQ7SgAicW630r7+fxssf4dzcmjj2hknLYXjHEkKA4BHC8:nwsXTLoCisrxs1njG34Ppan8Xk9FI

Entry address:
0x113BC

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 2C, 00, 41, 00, E8, E8, 51, FF, FF, 33, C0, 55, 68, 9E, 1A, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 5A, 1A, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, 5B, 41, 00, E8, 16, D8, FF, FF, E8, 65, D3, FF, FF, 80, 3D, DC, 2A, 41, 00, 00, 74, 0C, E8, 2B, D9, FF, FF, 33, C0, E8, 80, 32, FF, FF, 8D, 55, EC, 33, C0, E8, E2, A3, FF, FF, 8B, 55, EC, B8, 50, 86...
 
[+]

Entropy:
7.9883

Developed / compiled with:
Microsoft Visual C++

Code size:
63.5 KB (65,024 bytes)

The file usscvelmw2.exe has been seen being distributed by the following 21 URLs.

http://www.uspcworks.com/download_ip.asp?def_utm_source=velmw2&utm_source=velmw2&utm_campaign=velmw2&pxl=VEL675_VEL661_RUNT&utm_pubid=1220697&x-at=v1_7948557_202358_3pn_56D597F72D557244374699239_-1_4290107_1582p_535_56D597F72D557243388616375_m_19_-5686032448505172849_801568___-1_73_46lk_19

http://www.uspcworks.com/download_ip.asp?def_utm_source=velmw2&utm_source=velmw2&utm_campaign=velmw2&pxl=VEL675_VEL661_RUNT&utm_pubid=1253387&x-at=v1_7970557_266447_3o1_327DBEFECA552638641545796519_-1_4330177_1680b_536_327DBEFECA55263863475968191_m_19_-6630239667339962767_914007___-1_73_4o9b_19_

http://www.uspcworks.com/download_ip.asp?def_utm_source=velmw2&utm_source=velmw2&utm_campaign=velmw2&pxl=VEL675_VEL661_RUNT&utm_pubid=1241927&x-at=v1_7970557_224557_3o1_ABF69C18982507200131986394777_-1_4330307_15sq7_533_ABF69C189825072001271703046_m_19_-2888094968894013391_857487___2_73_4hej_19_

http://www.uspcworks.com/download_ip.asp?def_utm_source=velmw2&utm_source=velmw2&utm_campaign=velmw2&pxl=VEL675_VEL661_RUNT&utm_pubid=1241927&x-at=v1_7970557_238257_3pn_3B45C5CC363024592621142498294_-1_4331097_15sq7_532_3B45C5CC36302459261195897689_m_19_2968247605454023053_878157___2_73_4lhh_19_

http://www.uspcworks.com/download_ip.asp?def_utm_source=velmw2&utm_source=velmw2&utm_campaign=velmw2&pxl=VEL675_VEL661_RUNT&utm_pubid=1248257&x-at=v1_7970557_256917_3o1_D97FCF3C1D169794655340805550_-1_4330077_16301_536_D97FCF3C1D1697946541801109639_m_19_-7187360378870184300_903777___-1_73_4pk5_19_

http://www.uspcworks.com/download_ip.asp?def_utm_source=velmw2&utm_source=velmw2&utm_campaign=velmw2&pxl=VEL675_VEL661_RUNT&utm_pubid=1253387&x-at=v1_7970557_266447_3o1_B33E499C86250199511175457505_-1_4330097_1680b_533_B33E499C86250199501978444629_m_19_-5834920613878279555_914007___-1_73_4o9b_19_

http://www.uspcworks.com/download_ip.asp?def_utm_source=velmw2&utm_source=velmw2&utm_campaign=velmw2&pxl=VEL675_VEL661_RUNT&utm_pubid=1253387&x-at=v1_7970557_266447_3o1_9BD4B75D13990168931324448416_-1_4330097_1680b_536_9BD4B75D1399016892784902399_m_19_7440346882518637659_914007___-1_73_4o9b_19_

http://www.uspcworks.com/download_ip.asp?def_utm_source=velmw2&utm_source=velmw2&utm_campaign=velmw2&pxl=VEL675_VEL661_RUNT&utm_pubid=1246197&x-at=v1_7970557_190438_3pn_FD13CB10FB39589363229638795_-1_4330197_160vl_522_FD13CB10FB395893621862206306_m_19_8241653069516508213_906177___-1_73_3qka_19_

http://www.uspcworks.com/download_ip.asp?def_utm_source=velmw2&utm_source=velmw2&utm_campaign=velmw2&pxl=VEL675_VEL661_RUNT&utm_pubid=1245817&x-at=v1_7970557_255647_3o1_3B45C5CC3644498405579933817_-1_4330177_160jp_533_3B45C5CC3644498404549071524_m_19_3653776330426415057_904297___-1_73_4pdt_19_

Remove usscvelmw2.exe - Powered by Reason Core Security