optimizerproinstaller.exe

Optimizer Pro

PC Utilities Software Limited

Part of the Optimizer Pro / Driver 'PC optimizer' product lines marketed by Adsology and distributed through various bundled software (PPI and commission) channels. The application optimizerproinstaller.exe, “Fix, clean, optimize your PC!” by PC Utilities Software Limited has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software.
Publisher:
PC Utilities Pro  (signed by PC Utilities Software Limited)

Product:
Optimizer Pro

Description:
Fix, clean, optimize your PC!

Version:
3.0.1.0

MD5:
8cbdc4cbe3320d8866b431e82dc793ae

SHA-1:
19d65ec77d99b52b3ad3258ead2080b1f9787e4a

SHA-256:
7ddbd64436da502aa1e52bfee3a19a9e69ef0a2c489abf0c817c5332514a53ac

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Installed with the Optimizer Pro software which is bundled by 3rd-party monetization programs.

Analysis date:
4/24/2024 11:56:24 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.PC Utilities (M)
17.3.15.18

File size:
3.6 MB (3,800,184 bytes)

Product version:
3.0.1.0

Copyright:
PC Utilities Pro

Trademarks:
PC Utilities Pro

Original file name:
OptimizerPro

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\addons\optimizerproinstaller.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
4/5/2013 10:59:35 PM

Valid to:
4/3/2015 6:53:14 PM

Subject:
CN=PC Utilities Software Limited, O=PC Utilities Software Limited, L=London, S=UK, C=GB

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2B239BABC97410

File PE Metadata
Compilation timestamp:
6/20/1992 2:52:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x13474

Entry point:
55, 8B, EC, B9, 27, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 53, 56, 57, B8, EC, 33, 41, 00, E8, F8, 26, FF, FF, 33, C0, 55, 68, 44, 39, 41, 00, 64, FF, 30, 64, 89, 20, B2, 01, A1, 38, 2F, 41, 00, E8, 3A, FB, FF, FF, 8B, D8, BA, 01, 00, 00, 80, 8B, C3, E8, CC, FB, FF, FF, B1, 01, BA, 5C, 39, 41, 00, 8B, C3, E8, 22, FC, FF, FF, 84, C0, 74, 20, 8D, 55, EC, 33, C0, E8, FC, F7, FE, FF, 8B, 4D, EC, BA, 7C, 39, 41, 00, 8B, C3, E8, 29, FD, FF, FF, 8B, C3, E8, 6A, FB, FF, FF, B2, 01, 8B, C3, 8B, 08, FF, 51, FC, 8D...
 
[+]

Entropy:
7.9859

Developed / compiled with:
Microsoft Visual C++

Code size:
75 KB (76,800 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to domore.pcutilitiespro.revenuewire.net  (199.83.128.157:80)

 
http://domore.pcutilitiespro.revenuewire.net/optimizerpro/register?633944330-US-002_D7D3394A-330B-8339-BD80-433943E5

TCP (HTTP):
Connects to dl.softservers.net  (198.20.70.67:80)

TCP (HTTP):
Connects to bi.softservers.net  (184.154.38.36:80)

Remove optimizerproinstaller.exe - Powered by Reason Core Security