optimizerpro.exe

PC Utilities Software Limited

Part of the Optimizer Pro / Driver 'PC optimizer' product lines marketed by Adsology and distributed through various bundled software (PPI and commission) channels. The application optimizerpro.exe by PC Utilities Software Limited has been detected as a potentially unwanted program by 13 anti-malware scanners. Also know as BrowserDefender, this bundled service will prevent various web browser toolbars and extensions from running as well as block changes to the search page and provider. It is also typically executed from an Internet Explorer cache folder.
Publisher:
PC Utilities Software Limited  (signed and verified)

MD5:
0034be1bd1904345a83bb25773d2982d

SHA-1:
9712ae08a05bd0d37de820ddfc3811428daa68b1

SHA-256:
c4de9cdf10e88a5126d1dfac03524ca36a7daf9b4c72450e1e844daa1dc63236

Scanner detections:
13 / 68

Status:
Potentially unwanted

Explanation:
Installed with the Optimizer Pro software which is bundled by 3rd-party monetization programs.

Analysis date:
4/24/2024 12:55:34 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Agent
7.1.1

AhnLab V3 Security
PUP/Win32.OptimizerPro
2014.07.23

Avira AntiVirus
Adware/SpeedingUpMyPC.C.1
7.11.163.92

AVG
Adware Generic5.ATRO
2014.0.3986

Dr.Web
Trojan.NtRootKit.17528
9.0.1.05190

ESET NOD32
Win32/AdWare.SpeedingUpMyPC.L application
7.0.302.0

G Data
Win32.Application.OptimizerPro
14.7.24

IKARUS anti.virus
AdWare.Bprotector
t3scan.1.6.1.0

Kaspersky
not-a-virus:RiskTool.Win32.Agent
15.0.0.494

McAfee
Artemis!134B8E481DCD
5600.7062

NANO AntiVirus
Riskware.Win32.Agent.dchcep
0.28.2.60990

Reason Heuristics
PUP.PCUtilities.M
14.8.8.3

Total Defense
Win32/Tnega.MHdEFO
37.0.11074

File size:
7 MB (7,390,216 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\optimizerpro.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
4/18/2014 4:34:54 PM

Valid to:
4/18/2015 4:34:54 PM

Subject:
CN=PC Utilities Software Limited, O=PC Utilities Software Limited, L=London, C=GB

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
4B6A44F88EC8CF

File PE Metadata
Compilation timestamp:
7/13/2014 7:42:24 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
196608:ZPfB2/T4SbbYSBrPMdhM3gTfqt+Ahy/J05zNR3s5d+F:Dy4SJShQgTfqt+Ak+x3syF

Entry address:
0x3D74C

Entry point:
55, 8B, EC, 83, C4, F0, B8, F8, A5, 43, 00, E8, 14, C4, FC, FF, E8, 03, 86, FC, FF, 8D, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
240.5 KB (246,272 bytes)

Remove optimizerpro.exe - Powered by Reason Core Security