optimizerpro.exe

Optimizer Pro v3.2

PC Utilities Software Limited

Part of the Optimizer Pro / Driver 'PC optimizer' product lines marketed by Adsology and distributed through various bundled software (PPI and commission) channels. The application optimizerpro.exe, “Fix PC problems and optimize performance” by PC Utilities Software Limited has been detected as a potentially unwanted program by 20 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from dl.softservers.net.
Publisher:
PC Utilities Software Limited  (signed and verified)

Product:
Optimizer Pro v3.2

Description:
Fix PC problems and optimize performance

Version:
3.2.0.2

MD5:
8e32b72bfa383d53e08cc05a3031d676

SHA-1:
f2904c1bfbafd56f8a67f49f9142d56fa6cfe5f4

SHA-256:
71fbfa76b9a1672343a8fd8b73ac6da8a53d3d06228dc4ad45dd0c7e4fd31d58

Scanner detections:
20 / 68

Status:
Potentially unwanted

Explanation:
Installed with the Optimizer Pro software which is bundled by 3rd-party monetization programs.

Analysis date:
4/26/2024 12:48:21 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.OptimizerPro
7.1.1

AhnLab V3 Security
PUP/Win32.Optimizer
2014.10.15

avast!
Adware-gen [Adw]
2014.9-141022

AVG
Generic
2015.0.3313

Baidu Antivirus
Hacktool.Win32.OptimizerPro
4.0.3.141022

Dr.Web
Trojan.PWS.Tibia.2625
9.0.1.05190

ESET NOD32
Win32/AdWare.SpeedingUpMyPC.N application
7.0.302.0

Fortinet FortiGate
Riskware/OptimizerPro
10/22/2014

F-Prot
W32/A-fcdc4a04
v6.4.7.1.166

G Data
Win32.Application.OptimizerPro
14.10.24

K7 AntiVirus
Adware
13.183.13676

Kaspersky
not-a-virus:RiskTool.Win32.OptimizerPro
15.0.0.494

McAfee
Artemis!BD5F1ABCF328
5600.6969

NANO AntiVirus
Riskware.Win32.OptimizerPro.dgmsiw
0.28.2.62671

Panda Antivirus
Trj/CI.A
14.10.22.02

Qihoo 360 Security
HEUR/QVM41.1.Malware.Gen
1.0.0.1015

Reason Heuristics
PUP.PCUtilities.M
14.10.22.14

Total Defense
Win32/Tnega.SZHEWKB
37.0.11227

VIPRE Antivirus
Threat.4150696
33706

Zillya! Antivirus
Trojan.Black.Win32.18731
2.0.0.1956

File size:
5.8 MB (6,058,488 bytes)

Product version:
3.2.0.2

Copyright:
PC Utilities Software Limited

Original file name:
Optimizer Pro

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\opencandy\540e71ae2e8d4751bc988ad16efd961d\optimizerpro.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
7/29/2014 5:00:00 PM

Valid to:
7/30/2015 4:59:59 PM

Subject:
CN=PC Utilities Software Limited, OU=IT Department, O=PC Utilities Software Limited, STREET=78 York Street, L=London, S=England, PostalCode=W1H 1DP, C=GB

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00CF20EDFB9E9D56F429A44E79C3465805

File PE Metadata
Compilation timestamp:
10/11/2014 10:13:42 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
98304:H3k7FnIsqUyiTfFclEwRhiiFTOU4hd/p4Zb/onCdBX4KlI0fv9sMmW6v6j99LRIZ:Xk7jdOEwRh7FTx0d/pwDqCdmefvKMhAJ

Entry address:
0x6869

Entry point:
E8, 67, 5F, 00, 00, E9, 89, FE, FF, FF, FF, 35, 84, E2, 41, 00, FF, 15, 58, 60, 41, 00, 85, C0, 74, 02, FF, D0, 6A, 19, E8, D9, 53, 00, 00, 6A, 01, 6A, 00, E8, FC, 2E, 00, 00, 83, C4, 0C, E9, C1, 2E, 00, 00, CC, CC, CC, 8B, 4C, 24, 04, F7, C1, 03, 00, 00, 00, 74, 24, 8A, 01, 83, C1, 01, 84, C0, 74, 4E, F7, C1, 03, 00, 00, 00, 75, EF, 05, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8B, 01, BA, FF, FE, FE, 7E, 03, D0, 83, F0, FF, 33, C2, 83, C1, 04, A9, 00, 01, 01, 81, 74, E8, 8B...
 
[+]

Entropy:
7.9832  (probably packed)

Code size:
81.5 KB (83,456 bytes)

The file optimizerpro.exe has been seen being distributed by the following URL.

Remove optimizerpro.exe - Powered by Reason Core Security