optimizerpro.exe

Optimizer Pro v3.2

PC Utilities Software Limited

Part of the Optimizer Pro / Driver 'PC optimizer' product lines marketed by Adsology and distributed through various bundled software (PPI and commission) channels. The application optimizerpro.exe, “Fix PC problems and optimize performance” by PC Utilities Software Limited has been detected as a potentially unwanted program by 29 anti-malware scanners. This is a setup program which is used to install the application. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from dl.softservers.net.
Publisher:
PC Utilities Software Limited  (signed and verified)

Product:
Optimizer Pro v3.2

Description:
Fix PC problems and optimize performance

Version:
3.2.0.2

MD5:
2317072e3d53dc6fb7139090683920e2

SHA-1:
963391529a6c79e91ea199acae564881b5320cde

SHA-256:
7cb6dc873dcb788a74a8cdc4a0b5b444a4cfaa703c3afce60f2ef767cc609929

Scanner detections:
29 / 68

Status:
Potentially unwanted

Explanation:
Installed with the Optimizer Pro software which is bundled by 3rd-party monetization programs.

Analysis date:
4/25/2024 4:17:54 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Strictor.66909
388

Agnitum Outpost
Riskware.OptimizerPro
7.1.1

AhnLab V3 Security
PUP/Win32.Optimizer
2014.10.23

Avira AntiVirus
APPL/OptimizPro.RE
7.11.183.254

avast!
Adware-gen [Adw]
2014.9-160112

AVG
Generic
2017.0.2866

Bitdefender
Gen:Variant.Strictor.66909
1.0.20.60

Clam AntiVirus
Win.Trojan.Optimizerpro-18
0.98/21411

Comodo Security
ApplicUnwnt
20002

Dr.Web
Trojan.PWS.Tibia.2625
9.0.1.012

Emsisoft Anti-Malware
Gen:Variant.Strictor.66909
8.16.01.12.01

ESET NOD32
Win32/AdWare.SpeedingUpMyPC.N application
10.7.0.302.0

Fortinet FortiGate
Riskware/OptimizerPro
1/12/2016

F-Prot
W32/A-fcdc4a04
v6.4.7.1.166

F-Secure
Gen:Variant.Strictor.66909
11.2016-12-01_3

G Data
Win32.Application.OptimizerPro
16.1.24

K7 AntiVirus
Adware
13.184.13741

McAfee
Artemis!D9C65562DB38
5600.6522

MicroWorld eScan
Gen:Variant.Strictor.66909
17.0.0.36

NANO AntiVirus
Riskware.Win32.OptimizerPro.dgmsiw
0.28.2.62841

Panda Antivirus
Trj/CI.A
16.01.12.01

Qihoo 360 Security
HEUR/QVM41.1.Malware.Gen
1.0.0.1015

Reason Heuristics
PUP.PC Utilities.PCUtilities (M)
16.1.12.13

Rising Antivirus
PE:Trojan.Win32.Generic.17876B26!394750758
23.00.65.16110

Total Defense
Win32/Tnega.SZHEWKB
37.0.11244

Trend Micro House Call
TROJ_GEN.R02KC0OK314
7.2.12

Trend Micro
TROJ_GEN.R02KC0OK314
10.465.12

VIPRE Antivirus
Trojan.Win32.Generic
34556

Zillya! Antivirus
Trojan.Black.Win32.18731
2.0.0.1965

File size:
5.9 MB (6,159,352 bytes)

Product version:
3.2.0.2

Copyright:
PC Utilities Software Limited

Original file name:
Optimizer Pro

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\optimizerpro.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
7/29/2014 9:00:00 PM

Valid to:
7/30/2015 8:59:59 PM

Subject:
CN=PC Utilities Software Limited, OU=IT Department, O=PC Utilities Software Limited, STREET=78 York Street, L=London, S=England, PostalCode=W1H 1DP, C=GB

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00CF20EDFB9E9D56F429A44E79C3465805

File PE Metadata
Compilation timestamp:
11/20/2014 1:47:23 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
98304:x3LrAAE5YmJpRHbnwKDU6lMNK5Yj/2CRb4c0m9LfVrN6r55rfJASRO73BSDgqt3k:tLkAGdJ/7nwKDtlMsYTtREBmt4XNCBfZ

Entry address:
0x6869

Entry point:
E8, 67, 5F, 00, 00, E9, 89, FE, FF, FF, FF, 35, 84, E2, 41, 00, FF, 15, 58, 60, 41, 00, 85, C0, 74, 02, FF, D0, 6A, 19, E8, D9, 53, 00, 00, 6A, 01, 6A, 00, E8, FC, 2E, 00, 00, 83, C4, 0C, E9, C1, 2E, 00, 00, CC, CC, CC, 8B, 4C, 24, 04, F7, C1, 03, 00, 00, 00, 74, 24, 8A, 01, 83, C1, 01, 84, C0, 74, 4E, F7, C1, 03, 00, 00, 00, 75, EF, 05, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8B, 01, BA, FF, FE, FE, 7E, 03, D0, 83, F0, FF, 33, C2, 83, C1, 04, A9, 00, 01, 01, 81, 74, E8, 8B...
 
[+]

Code size:
81.5 KB (83,456 bytes)

The file optimizerpro.exe has been seen being distributed by the following URL.

Remove optimizerpro.exe - Powered by Reason Core Security