PUA

About “PUA:Win32/SpeedChecker” infection

Malware Removal

The PUA:Win32/SpeedChecker is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA:Win32/SpeedChecker virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • A named pipe was used for inter-process communication
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Attempts to create or modify system certificates
  • Uses suspicious command line tools or Windows utilities

Related domains:

ocsp.usertrust.com
crl.usertrust.com
ocsp.comodoca.com
crl.comodoca.com

How to determine PUA:Win32/SpeedChecker?


File Info:

crc32: B7609C42
md5: 81216436632e8d46027bef8dba48ce53
name: mscsetup.exe
sha1: e1ef0d48b6e77250e6a2f107a0f64da082a9132b
sha256: bd4a0a8383c781393d2b37a14cfbbe093fdde597772bf74a54ae6800fec397f4
sha512: 3af5697b5dba273faa382bed69c634dd2150f3dbfb0ca43a11689847ab9ee1e75341dab7b859c85c1fb22e1229720b15525f95c12490394d0bce9419d16cd8f3
ssdeep: 196608:MyhoJjXS6z4PXlsTzzvS9OPm3T/mO5GPtP9Lyl7YOl59Pcp:/Mj5KO/+4m3TuO07y+O5pcp
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 mysystemcare.com 2018
FileVersion: 1.0.0.0
CompanyName: PC Speedup Tools Inc
Comments: This installation was built with Inno Setup.
ProductName: My System Care
ProductVersion: 1.0.0.0
FileDescription: My System Care Setup
Translation: 0x0000 0x04b0

PUA:Win32/SpeedChecker also known as:

CAT-QuickHealTrojan.Speedchecker
McAfeeArtemis!81216436632E
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SymantecTrojan.Gen.2
TrendMicro-HouseCallTROJ_GEN.R002H0CC820
AvastWin32:Malware-gen
GDataWin32.Application.PCvarkWintonic.B
KasperskyHoax.Win32.PCFixer.gen
AlibabaRiskWare:Win32/PCFixer.6c2add2d
TencentWin32.Trojan-psw.Pcfixer.Dwsn
SophosGeneric PUA EB (PUA)
ComodoMalware@#1ofzppr73lbnb
DrWebProgram.Unwanted.3052
McAfee-GW-EditionArtemis
ZoneAlarmHoax.Win32.PCFixer.gen
MicrosoftPUA:Win32/SpeedChecker
VBA32CIL.StupidPInvoker-2.Heur
MalwarebytesPUP.Optional.MySystemCare
PandaPUP/SpeedUpMyPC
ESET-NOD32a variant of Win32/GT32SupportGeeks.P potentially unwanted
RisingPUA.GT32SupportGeeks!8.E56B (CLOUD)
YandexRiskware.Agent!
eGambitUnsafe.AI_Score_99%
FortinetW32/GT32SupportGeeks.P
AVGWin32:Malware-gen

How to remove PUA:Win32/SpeedChecker?

PUA:Win32/SpeedChecker removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment