optimizerpro.exe

PC Utilities Software Limited

Part of the Optimizer Pro / Driver 'PC optimizer' product lines marketed by Adsology and distributed through various bundled software (PPI and commission) channels. The application optimizerpro.exe by PC Utilities Software Limited has been detected as a potentially unwanted program by 15 anti-malware scanners. Also know as BrowserDefender, this bundled service will prevent various web browser toolbars and extensions from running as well as block changes to the search page and provider. It is also typically executed from the user's temporary directory.
Publisher:
PC Utilities Software Limited  (signed and verified)

MD5:
6d21a068e3ffd11c18cc108a0d89027a

SHA-1:
41915460c623e6caf5ca636894d37a4196f2f67a

SHA-256:
04d63294ea81147f1093b7bb6a57d72601384205b345de3c9eeca8adc1a2f4cd

Scanner detections:
15 / 68

Status:
Potentially unwanted

Explanation:
Installed with the Optimizer Pro software which is bundled by 3rd-party monetization programs.

Analysis date:
4/20/2024 1:13:36 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Agent
7.1.1

AhnLab V3 Security
PUP/Win32.OptimizerPro
2014.07.18

Avira AntiVirus
Adware/SpeedingUpMyPC.C.1
7.11.162.112

AVG
OptimizerPro
2015.0.3405

Dr.Web
Trojan.NtRootKit.17528
9.0.1.0204

ESET NOD32
Win32/AdWare.SpeedingUpMyPC (variant)
8.10115

G Data
Win32.Application.OptimizerPro
14.7.24

IKARUS anti.virus
AdWare.Bprotector
t3scan.1.6.1.0

Kaspersky
not-a-virus:RiskTool.Win32.Agent
14.0.0.3518

McAfee
Artemis!6D21A068E3FF
5600.7061

NANO AntiVirus
Riskware.Win32.Agent.dchcep
0.28.2.60881

Qihoo 360 Security
Win32/Virus.Adware.bab
1.0.0.1015

Reason Heuristics
PUP.PCUtilities.M
14.8.8.3

Total Defense
Win32/Tnega.MHdEFO
37.0.11065

Zillya! Antivirus
Trojan.Black.Win32.16768
2.0.0.1860

File size:
7 MB (7,390,216 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\optimizerpro.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
4/18/2014 4:34:54 PM

Valid to:
4/18/2015 4:34:54 PM

Subject:
CN=PC Utilities Software Limited, O=PC Utilities Software Limited, L=London, C=GB

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
4B6A44F88EC8CF

File PE Metadata
Compilation timestamp:
7/13/2014 7:42:24 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
196608:ZPfB2/T4SbbYSBrPMdhM3gTfqt+Ahy/J05zNR3s5d+f:Dy4SJShQgTfqt+Ak+x3syf

Entry address:
0x3D74C

Entry point:
55, 8B, EC, 83, C4, F0, B8, F8, A5, 43, 00, E8, 14, C4, FC, FF, E8, 03, 86, FC, FF, 8D, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
240.5 KB (246,272 bytes)

Remove optimizerpro.exe - Powered by Reason Core Security