optimizerpro.exe

Optimizer Pro

PC Utilities Software Limited

Part of the Optimizer Pro / Driver 'PC optimizer' product lines marketed by Adsology and distributed through various bundled software (PPI and commission) channels. The application optimizerpro.exe by PC Utilities Software Limited has been detected as a potentially unwanted program by 22 anti-malware scanners. While running, it connects to the Internet address static.105.2.9.176.clients.your-server.de on port 80 using the HTTP protocol.
Publisher:
PC Utilities Software Limited  (signed and verified)

Product:
Optimizer Pro

Version:
3.2.0.0

MD5:
1f692aba28e934452e9be1aef15b78e1

SHA-1:
bc4cdb9b1e9e01921a229e4cc7c7b984d5b91c68

SHA-256:
8a0f0a41a1635b44364077cfec16c0dba75c5e29b8df9a222aad6c34678c4ba6

Scanner detections:
22 / 68

Status:
Potentially unwanted

Explanation:
Installed with the Optimizer Pro software which is bundled by 3rd-party monetization programs.

Analysis date:
4/25/2024 11:41:47 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.SpeedingUpMyPC
7.1.1

AhnLab V3 Security
PUP/Win32.OptimizerPro
2014.11.08

Avira AntiVirus
APPL/OptimizPro.RE
7.11.184.224

AVG
Generic
2015.0.3283

Baidu Antivirus
Hacktool.Win32.OptimizerPro
4.0.3.141121

Comodo Security
UnclassifiedMalware
20018

Dr.Web
riskware program Program.Unwanted.99
9.0.1.0325

ESET NOD32
Win32/SpeedingUpMyPC application
7.0.302.0

Fortinet FortiGate
Riskware/OptimizerPro
11/21/2014

G Data
Win32.Application.OptimizerPro
14.11.24

K7 AntiVirus
Trojan
13.185.13943

Kaspersky
not-a-virus:RiskTool.Win32.OptimizerPro
15.0.0.543

McAfee
Artemis!387B9AC8AA00
5600.6939

NANO AntiVirus
Riskware.Win32.OptimizerPro.dgmsiw
0.28.6.62995

Panda Antivirus
Trj/Chgt.G
14.11.21.12

Qihoo 360 Security
Trojan.Generic
1.0.0.1015

Quick Heal
RiskTool.OptimizerPro.g8 (Not a Virus)
11.14.14.00

Reason Heuristics
PUP.PCUtilities.M
14.11.21.12

Sophos
Generic PUA GA
4.98

Trend Micro House Call
TROJ_GEN.R02KC0OJD14
7.2.325

Trend Micro
TROJ_GEN.R02KC0OJD14
10.465.21

VIPRE Antivirus
Trojan.Win32.Generic!SB.0
32740

File size:
3.5 MB (3,653,712 bytes)

Product version:
3.2.0.0

Copyright:
2014 ® PC Utilities Software Limited

Trademarks:
PC Utilities Software Limited

Original file name:
OptimizerPro

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\optimizer pro 3.11\optimizerpro.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
7/29/2014 8:00:00 PM

Valid to:
7/30/2015 7:59:59 PM

Subject:
CN=PC Utilities Software Limited, OU=IT Department, O=PC Utilities Software Limited, STREET=78 York Street, L=London, S=England, PostalCode=W1H 1DP, C=GB

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00CF20EDFB9E9D56F429A44E79C3465805

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:HJpc//////Jgm+XfrrfTNzm7V+bHgIu/G6:Hm+vrbTNzmcgIu/G6

Entry address:
0x21D60C

Entry point:
55, 8B, EC, B9, 07, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, B8, E4, CE, 61, 00, E8, F7, 9F, DE, FF, 33, C0, 55, 68, 88, D8, 61, 00, 64, FF, 30, 64, 89, 20, 8D, 55, EC, B8, 01, 00, 00, 00, E8, 74, 59, DE, FF, 8B, 45, EC, BA, 9C, D8, 61, 00, E8, A3, 7A, DE, FF, 0F, 84, 1A, 02, 00, 00, 8D, 55, E8, B8, 01, 00, 00, 00, E8, 54, 59, DE, FF, 8B, 45, E8, BA, B0, D8, 61, 00, E8, 83, 7A, DE, FF, 75, 4D, 8D, 45, E4, 50, B9, C8, D8, 61, 00, BA, D8, D8, 61, 00, B8, 01, 00, 00, 80, E8, C9, 0B, EB, FF, 8B, 55, E4, B8, A0...
 
[+]

Entropy:
6.6791

Developed / compiled with:
Microsoft Visual C++

Code size:
2.1 MB (2,214,400 bytes)

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to static.105.2.9.176.clients.your-server.de  (176.9.2.105:80)

Remove optimizerpro.exe - Powered by Reason Core Security