PUP.PC Booster

Threat Scorecard

Popularity Rank: 20,064
Threat Level: 10 % (Normal)
Infected Computers: 48
First Seen: December 23, 2022
Last Seen: April 28, 2026
OS(es) Affected: Windows

SpyHunter Detects & Remove PUP.PC Booster

File System Details

PUP.PC Booster may create the following file(s):
# File Name MD5 Detections
1. pcbooster.exe daffa0f7b409e02d147360340e4b8ae5 8
2. pcbinstall.exe 7d56bb2750ff7e8308a5579a7adab90a 0

Analysis Report

General information

Family Name: PUP.PC Booster
Signature status: Self Signed

Known Samples

MD5: 9a44708543c08a71122e48fceb5b96d3
SHA1: 603b70f4c977a37de5895de6c27c62f70a4ff92a
SHA256: 084C50CC2438A66807D7C87EB7053F9DF48C8509EA31522465DC233951778284
File Size: 2.80 MB, 2801432 bytes
MD5: 1ca6f2434dba3df11ae92e0c9516d7ca
SHA1: 7e47b074c42dec581dc603163def4829121e5a52
SHA256: DB31D2BD8E2666FEEBCEDC26B3AB8A428ABD7EBF2C8F1F75FCBB01AFE706E7AD
File Size: 2.91 MB, 2910624 bytes
MD5: e8018216efeb02066c0fdee87c4b1e45
SHA1: 20ec857713b547ec81dad1e9b1030983ee01b508
SHA256: E4D50317971CB49520C904B9AD5D6EA21E3C282B63AA16D816254689043BE5CB
File Size: 74.70 KB, 74704 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments This installation was built with Inno Setup.
Company Name
  • Boost Software Inc.
  • BoostSoftware Inc.
File Description
  • GoUP - PC HealthBoost user's rights elevator
  • PC HealthBoost is a Boost Software Inc. product
  • PCHealthBoost Stub Installer KEN2-V
File Version
  • 2.1.6
  • 2.1.1.10
Legal Copyright
  • Boost Software Inc.™
  • Copyright BoostSoftware Inc.
Legal Trademarks GoUP and PC HealthBoost are trademarks of Boost Software Inc.
Product Name
  • GoUP
  • PC HealthBoost
  • PCHealthBoost-Setup
Product Version 2.1.1.10

Digital Signatures

Signer Root Status
Boost Software Inc VeriSign Class 3 Code Signing 2010 CA Self Signed

File Traits

  • HighEntropy
  • Inno
  • InnoSetup Installer
  • Installer Manifest
  • Installer Version
  • Nullsoft Installer
  • x86

Block Information

Total Blocks: 77
Potentially Malicious Blocks: 0
Whitelisted Blocks: 77
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.MH
  • Agent.MI
  • Agent.MU
  • Autorun.LA
  • FakeAV.AU
Show More
  • Trojan.Downloader.Gen.BQ

Files Modified

File Attributes
c:\programdata\pchealthboost\pchealthboost-setup.exe Synchronize,Write Data
c:\programdata\pchealthboost\pchealthboost-setup.exe.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\nsn444.tmp\crccheck.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsn444.tmp\langdll.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsn444.tmp\system.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsn444.tmp\uac_unicode.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsn444.tmp\userinfo.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsy434.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\local\temp\nsze479.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\local\temp\nsze489.tmp Synchronize,Write Attributes
Show More
c:\users\user\appdata\local\temp\nsze489.tmp\uac.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsze489.tmp\uac.dll Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations *1\??\C:\Windows\SystemTemp\MicrosoftEdgeUpdate.exe.old122e4*1\??\C:\Windows\SystemTemp\CopilotUpdate.exe.old12352*1\??\C:\P RegNtPreCreateKey

Windows API Usage

Category API
User Data Access
  • GetUserName

Related Posts

Trending

Most Viewed

Loading...