Malware

Misleading:Win32/Speesipro (file analysis)

Malware Removal

The Misleading:Win32/Speesipro is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Misleading:Win32/Speesipro virus can do?

  • Scheduled file move on reboot detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Exhibits possible ransomware file modification behavior

How to determine Misleading:Win32/Speesipro?


File Info:

name: 544651C8CE3844EB4C38.mlw
path: /opt/CAPEv2/storage/binaries/f077a2f0659d9d3ea85d8e086b861815cf5b068e9687488214699bbdd2bf2913
crc32: 489EDCFC
md5: 544651c8ce3844eb4c3809fe4de7b32d
sha1: 41a98313c9f99ec1d7da6c3e1a36b1c43f0cd0cd
sha256: f077a2f0659d9d3ea85d8e086b861815cf5b068e9687488214699bbdd2bf2913
sha512: 70341d2035338ff694d1d1c881f9bb4d25b5f5ad67caca9a469c3158aa5532469d6b626cfdf291b9ca1449389c6a7e6b5a8f634f996c1a23c68abbf6682bc549
ssdeep: 196608:lC5b+Q6cSyikYyUB5uEQN7ddJUE33tbzG6B6Mf+Rl5K:ls+YokYysEEQNjtdvG6B6O+RTK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10A96337769D18CE7F237C1FEF5D61000AF14769EED16C1879B682A428DB53638CA82E1
sha3_384: 7979338d8a011899a3e35e410760a8da0a8f9c1f231620a42daf508504dc57623f40bff2dc913ab245da40934d1054fc
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:41

Version Info:

CompanyName: Hiteksquad Corp.
FileDescription: Macro PC Cleaner Installer
FileVersion: 7.5.0.500
LegalCopyright: Copyright © Hiteksquad Corp.
ProductName: Macro PC Cleaner
Translation: 0x0000 0x04e4

Misleading:Win32/Speesipro also known as:

LionicHacktool.Win32.DeceptPCClean.3!c
MicroWorld-eScanApplication.Deceptor.KM
FireEyeApplication.Deceptor.KM
ALYacApplication.Deceptor.KM
CylanceUnsafe
ZillyaTool.DeceptPCClean.Win32.37
SangforRiskware.Win32.DeceptPCClean.gd
K7AntiVirusRiskware ( dec000d91 )
BitDefenderApplication.Deceptor.KM
K7GWRiskware ( dec000d91 )
Cybereasonmalicious.8ce384
VirITDeceptor.MacroPCCleaner.AC
ESET-NOD32a variant of Win32/UwS.MacroPCCleaner.A
APEXMalicious
AvastFileRepMetagen [Adw]
CynetMalicious (score: 99)
TencentWin32.Trojan-psw.Deceptpcclean.Stuc
Ad-AwareApplication.Deceptor.KM
SophosMal/Generic-R + Troj/Decept-GE
ComodoApplicUnwnt@#2ofmztjs117ga
DrWebProgram.Unwanted.1853
VIPREHoax.Win32.DeceptPCClean (not malicious)
TrendMicroPUA_PCCleaner
McAfee-GW-EditionMacroPCCleaner
EmsisoftApplication.Deceptor.KM (B)
Paloaltogeneric.ml
GDataApplication.Deceptor.KM
WebrootW32.Adware.Gen
AviraPUA/MacroPC.EL.2
Antiy-AVLTrojan/Generic.ASMalwS.2403133
ArcabitApplication.Deceptor.KM
MicrosoftMisleading:Win32/Speesipro
McAfeeMacroPCCleaner
MAXmalware (ai score=100)
TrendMicro-HouseCallPUA_PCCleaner
RisingTrojan.Generic@ML.90 (RDML:keJof5+6Z6N+6HUD3eSbfA)
FortinetRiskware/DeceptPCClean
AVGFileRepMetagen [Adw]
PandaPUP/PCCleaner

How to remove Misleading:Win32/Speesipro?

Misleading:Win32/Speesipro removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment