optimizerproinstaller.exe

PC Utilities Software Limited

Part of the Optimizer Pro / Driver 'PC optimizer' product lines marketed by Adsology and distributed through various bundled software (PPI and commission) channels. The application optimizerproinstaller.exe by PC Utilities Software Limited has been detected as a potentially unwanted program by 21 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. It is also typically executed from the user's temporary directory. While running, it connects to the Internet address dl.softservers.net on port 80 using the HTTP protocol.
Publisher:
PC Utilities Software Limited  (signed and verified)

MD5:
9b7f7ca65fbb0cfa7dc5a43dbc5fe04e

SHA-1:
0d98bedd47333c91afd7d30b041c77a00cdfb710

SHA-256:
56ee7dc9d60f33609b7b64ecabf97709f0724480b48d17d205615b87c11ac28b

Scanner detections:
21 / 68

Status:
Potentially unwanted

Explanation:
Installed with the Optimizer Pro software which is bundled by 3rd-party monetization programs.

Analysis date:
4/27/2024 1:54:16 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Agent
7.1.1

AhnLab V3 Security
PUP/Win32.OptimizerPro
2014.09.09

Avira AntiVirus
TR/Dropper.Gen
7.11.30.172

AVG
SHeur4
2015.0.3253

Clam AntiVirus
Win.Trojan.Agent-826030
0.98/19819

Comodo Security
ApplicUnwnt
19459

Dr.Web
Trojan.NtRootKit.17156
9.0.1.05190

ESET NOD32
Win32/Adware.SpeedingUpMyPC.T.gen application
7.0.302.0

F-Prot
W32/OptimizePro.B.gen
v6.4.7.1.166

G Data
Win32.Application.OptimizerPro
14.12.24

IKARUS anti.virus
PUA.SpeedingUpMyPC
t3scan.1.6.1.0

K7 AntiVirus
Adware
13.183.13504

Kaspersky
not-a-virus:RiskTool.Win32.Agent
15.0.0.543

McAfee
Artemis!EB475FA035A0
5600.6909

NANO AntiVirus
Trojan.Win32.Generic.dbyggj
0.28.2.61942

Panda Antivirus
Trj/Genetic.gen
14.12.22.07

Reason Heuristics
PUP.PCUtilities.V
14.12.22.7

Total Defense
Win32/Tnega.BUCBNZC
37.0.10926

Trend Micro House Call
TROJ_GEN.F47V0418
7.2.356

VIPRE Antivirus
Trojan.Win32.Generic!SB.0
28570

Zillya! Antivirus
Trojan.Black.Win32.16778
2.0.0.1915

File size:
5.1 MB (5,306,992 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\addons\optimizerproinstaller.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
2/20/2014 1:00:00 AM

Valid to:
2/21/2016 12:59:59 AM

Subject:
CN=PC Utilities Software Limited, O=PC Utilities Software Limited, STREET=78 York Street, L=London, S=England, PostalCode=W1H 1DP, C=GB

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00950E57C386D6B1EDADD9385C821B8BC8

File PE Metadata
Compilation timestamp:
4/16/2014 4:00:23 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:UOhwYUUBbUAfdUYH2i20ivyw+G7qgzwlP4n0bUcQgVkM1:UOhJnNUiiv90QywVqD4+UoV/

Entry address:
0x3D74C

Entry point:
55, 8B, EC, 83, C4, F0, B8, EC, A5, 43, 00, E8, 14, C4, FC, FF, E8, 03, 86, FC, FF, 8D, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
240.5 KB (246,272 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to domore.pcutilitiespro.revenuewire.net  (199.83.128.157:80)

 
http://domore.pcutilitiespro.revenuewire.net/optimizerpro/register?15332599-US-002_D7D5331A-530B-8533-BD80-433314E5

TCP (HTTP):
Connects to dl.softservers.net  (198.20.70.67:80)

TCP (HTTP):
Connects to bi.softservers.net  (184.154.38.36:80)

Remove optimizerproinstaller.exe - Powered by Reason Core Security