opprosetup.exe

Optimizer Pro v3.2

PC Utilities Software Limited

Part of the Optimizer Pro / Driver 'PC optimizer' product lines marketed by Adsology and distributed through various bundled software (PPI and commission) channels. The application opprosetup.exe, “Fix PC problems and optimize performance” by PC Utilities Software Limited has been detected as a potentially unwanted program by 27 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. It is also typically executed from the user's temporary directory.
Publisher:
PC Utilities Software Limited  (signed and verified)

Product:
Optimizer Pro v3.2

Description:
Fix PC problems and optimize performance

Version:
3.2.0.2

MD5:
7a35368cc65fa1d5ee39d3a9d60059d8

SHA-1:
e489be438e8f7f9e5fb7acbe9857a42aecdc3ef1

SHA-256:
625c9d927284ecd95c0c504ae3d8b83d36790ad8cada56a41e57aadc6713b076

Scanner detections:
27 / 68

Status:
Potentially unwanted

Explanation:
Installed with the Optimizer Pro software which is bundled by 3rd-party monetization programs.

Analysis date:
4/25/2024 7:39:50 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Agent.GN
5829361

Agnitum Outpost
Riskware.OptimizerPro
7.1.1

AhnLab V3 Security
PUP/Win32.Optimizer
2014.11.03

Avira AntiVirus
APPL/OptimizPro.RE
7.11.184.22

AVG
Generic
2015.0.3281

Bitdefender
Application.Agent.GN
1.0.20.1635

Clam AntiVirus
Win.Trojan.Optimizerpro-27
0.98/19664

Dr.Web
Trojan.PWS.Tibia.2625
9.0.1.05190

Emsisoft Anti-Malware
Application.Agent.GN
9.0.0.4570

ESET NOD32
Win32/AdWare.SpeedingUpMyPC.N application
7.0.302.0

Fortinet FortiGate
Riskware/SpeedingUpMyPC
11/23/2014

F-Prot
W32/A-fcdc4a04
v6.4.7.1.166

F-Secure
Application.Agent.GN
11.2014-23-11_1

G Data
Win32.Application.OptimizerPro
14.11.24

K7 AntiVirus
Adware
13.185.13866

Kaspersky
not-a-virus:RiskTool.Win32.OptimizerPro
15.0.0.543

McAfee
Artemis!A45E522261BA
5600.6937

MicroWorld eScan
Application.Agent.GN
15.0.0.981

NANO AntiVirus
Riskware.Win32.OptimizerPro.dgmsiw
0.28.6.62995

Panda Antivirus
Trj/Genetic.gen
14.11.23.10

Qihoo 360 Security
HEUR/Malware.QVM06.Gen
1.0.0.1015

Reason Heuristics
PUP.Installer.PCUtilities.K
14.11.23.22

Total Defense
Win32/Tnega.SZHEWKB
37.0.11260

Trend Micro House Call
TROJ_GEN.R0C2C0OK114
7.2.327

Trend Micro
TROJ_GEN.R0C2C0OK114
10.465.23

VIPRE Antivirus
Trojan.Win32.Generic
34472

Zillya! Antivirus
Trojan.Black.Win32.18731
2.0.0.1974

File size:
4.3 MB (4,469,240 bytes)

Product version:
3.2.0.2

Copyright:
PC Utilities Software Limited

Original file name:
Optimizer Pro

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\temp\opprosetup.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
7/30/2014 7:00:00 AM

Valid to:
7/31/2015 6:59:59 AM

Subject:
CN=PC Utilities Software Limited, OU=IT Department, O=PC Utilities Software Limited, STREET=78 York Street, L=London, S=England, PostalCode=W1H 1DP, C=GB

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00CF20EDFB9E9D56F429A44E79C3465805

File PE Metadata
Compilation timestamp:
11/20/2014 10:57:31 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
98304:03rOY6rhADRTGiJIgWhVcLzyFTKHy6WNZj7tA2T:mrObr2QOIgAValSL7JA2T

Entry address:
0x6869

Entry point:
E8, 67, 5F, 00, 00, E9, 89, FE, FF, FF, FF, 35, 84, E2, 41, 00, FF, 15, 58, 60, 41, 00, 85, C0, 74, 02, FF, D0, 6A, 19, E8, D9, 53, 00, 00, 6A, 01, 6A, 00, E8, FC, 2E, 00, 00, 83, C4, 0C, E9, C1, 2E, 00, 00, CC, CC, CC, 8B, 4C, 24, 04, F7, C1, 03, 00, 00, 00, 74, 24, 8A, 01, 83, C1, 01, 84, C0, 74, 4E, F7, C1, 03, 00, 00, 00, 75, EF, 05, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8B, 01, BA, FF, FE, FE, 7E, 03, D0, 83, F0, FF, 33, C2, 83, C1, 04, A9, 00, 01, 01, 81, 74, E8, 8B...
 
[+]

Entropy:
7.9744  (probably packed)

Code size:
81.5 KB (83,456 bytes)

Remove opprosetup.exe - Powered by Reason Core Security