optimizerpro-uninstaller.exe

Optimizer Pro v3.2

PC Utilities Software Limited

Part of the Optimizer Pro / Driver 'PC optimizer' product lines marketed by Adsology and distributed through various bundled software (PPI and commission) channels. The application optimizerpro-uninstaller.exe, “Optimizer Pro – Clean up your PC” by PC Utilities Software Limited has been detected as a potentially unwanted program by 25 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. Also know as BrowserDefender, this bundled service will prevent various web browser toolbars and extensions from running as well as block changes to the search page and provider.
Publisher:
PCUtilities Software Limited  (signed by PC Utilities Software Limited)

Product:
Optimizer Pro v3.2

Description:
Optimizer Pro – Clean up your PC

Version:
3.3.1.7

MD5:
a9691f84836f0f6fc4737736870fdd22

SHA-1:
b150c05d7bde4c21a35bb88e2d4da67489f2c982

SHA-256:
597e872042e41026f10e3006aff6dea8f768ab925e70c2fc8e5504c24f554d1f

Scanner detections:
25 / 68

Status:
Potentially unwanted

Explanation:
Installed with the Optimizer Pro software which is bundled by 3rd-party monetization programs.

Analysis date:
4/19/2024 9:14:45 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.SpeedingUpMyPC
7.1.1

AhnLab V3 Security
PUP/Win32.OptimizerPro
2015.03.28

Avira AntiVirus
TR/Bprotector.1969704
7.11.217.232

avast!
Win32:Agent-AYGM [PUP]
2014.9-150328

AVG
Generic
2016.0.3156

Bkav FE
W32.HfsAdware
1.3.0.6379

Comodo Security
Application.Win32.OptimizerPro.MMAP
21587

Dr.Web
Program.Unwanted.295
9.0.1.087

ESET NOD32
Win32/Adware.SpeedingUpMyPC.AA (variant)
9.11389

Fortinet FortiGate
W32/Inject.AA!tr
3/28/2015

G Data
Win32.Application.OptimizerPro
15.3.25

K7 AntiVirus
Adware
13.202.15417

Kaspersky
Trojan.Win32.Inject
14.0.0.2276

Malwarebytes
PUP.Optional.OptimizerPR0
v2015.03.28.06

McAfee
Artemis!D920E4044A64
5600.6812

NANO AntiVirus
Trojan.Win32.Inject.dprbqo
0.30.8.659

Panda Antivirus
Trj/Genetic.gen
15.03.28.06

Qihoo 360 Security
HEUR/QVM41.1.Malware.Gen
1.0.0.1015

Reason Heuristics
PUP.Installer.PC Utilities
15.3.28.18

Sophos
Generic PUA EH
4.98

Trend Micro House Call
Suspicious_GEN.F47V0329
7.2.87

Vba32 AntiVirus
Trojan.Inject
3.12.26.3

VIPRE Antivirus
OptimizerPro
38844

Zillya! Antivirus
Trojan.Inject.Win32.159225
2.0.0.2121

File size:
7.4 MB (7,717,328 bytes)

Product version:
3.3.1.7

Copyright:
PCUtilities Software Limited

Original file name:
OptimizerPR0

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\ProgramData\{ebdcbe93-cb35-c65c-ebdc-cbe93cb3fa4f}\optimizerpro-uninstaller.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
11/20/2014 4:00:00 PM

Valid to:
11/21/2015 3:59:59 PM

Subject:
CN=PC Utilities Software Limited, O=PC Utilities Software Limited, STREET=78 York Street, L=London, PostalCode=W1H 1DP, C=GB

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00F10854548D47F74C920D7091D9057D6E

File PE Metadata
Compilation timestamp:
3/4/2015 6:22:03 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
196608:G3AGFTFsKpXBFzmWMlsP0FZTLMuPzG65PKBLaX+4uPYsu2rMT:G3ACTFsKpBdMdZEurZ5yIXPKYbH

Entry address:
0x131D7

Entry point:
E8, 86, 7A, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, 20, 55, 42, 00, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 5F, 89, 45, FC, 5E, 85, C0, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, 1C, 51, 42, 00, C9, C2, 08, 00, CC, CC, CC, 8B, 4C, 24, 04, F7, C1, 03, 00, 00, 00, 74, 24, 8A, 01, 83, C1, 01, 84, C0, 74, 4E, F7, C1, 03, 00, 00, 00, 75, EF, 05, 00, 00, 00, 00, 8D, A4, 24, 00, 00...
 
[+]

Entropy:
7.9820  (probably packed)

Code size:
142.5 KB (145,920 bytes)

Remove optimizerpro-uninstaller.exe - Powered by Reason Core Security