optprolauncher.exe

Optimizer Pro Launcher

PC Utilities Software Limited

Part of the Optimizer Pro / Driver 'PC optimizer' product lines marketed by Adsology and distributed through various bundled software (PPI and commission) channels. The application optprolauncher.exe by PC Utilities Software Limited has been detected as a potentially unwanted program by 9 anti-malware scanners. It runs as a scheduled task under the Windows Task Scheduler triggered to execute each time a user logs in.
Publisher:
PC Utilities Software Limited  (signed and verified)

Product:
Optimizer Pro Launcher

Version:
3.2.0.0

MD5:
eab5d7e6717cf879412ce65285916262

SHA-1:
7115a7e57d3f7d7d3fdfc30a7bbd08fc20dd7351

SHA-256:
3997195847ded1c941432de5b163f3a7d32bf92f0ae7efa0a1fb2563337e27d1

Scanner detections:
9 / 68

Status:
Potentially unwanted

Explanation:
Installed with the Optimizer Pro software which is bundled by 3rd-party monetization programs.

Analysis date:
4/24/2024 12:15:48 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Dropper/Win32.Agent
2014.07.08

AVG
OptimizerPro
2015.0.3345

Clam AntiVirus
Win.Trojan.Wpbrutebot-2
0.98/21411

Kaspersky
not-a-virus:RiskTool.Win32.Agent
14.0.0.3221

McAfee
Artemis!357C2AD47E5D
5600.7001

Panda Antivirus
Trj/Chgt.C
14.09.20.06

Qihoo 360 Security
Win32/Virus.RiskTool.825
1.0.0.1015

Reason Heuristics
PUP.Task.PCUtilities.O
14.9.20.18

Trend Micro House Call
Suspicious_GEN.F47V0708
7.2.263

File size:
143.4 KB (146,888 bytes)

Product version:
3.2.0.0

Copyright:
2014 ® PC Utilities Software Limited

Trademarks:
PC Utilities Software Limited

Original file name:
OptProLauncher

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\optimizer pro\optprolauncher.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
4/18/2014 9:34:54 PM

Valid to:
4/18/2015 9:34:54 PM

Subject:
CN=PC Utilities Software Limited, O=PC Utilities Software Limited, L=London, C=GB

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
4B6A44F88EC8CF

File PE Metadata
Compilation timestamp:
6/20/1992 5:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
3072:6l1LmyuXDIv9hr/S5SeQTcd8uLTO+/9C+gH0Vjuh6+95FSp:6l1LxsY9he1Lf9nYfSp

Entry address:
0x1506C

Entry point:
55, 8B, EC, B9, 08, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, B8, BC, 4F, 41, 00, E8, 03, 0B, FF, FF, 33, C0, 55, 68, 13, 54, 41, 00, 64, FF, 30, 64, 89, 20, 8D, 55, E8, 33, C0, E8, 33, DC, FE, FF, 8B, 45, E8, 8D, 55, EC, E8, 60, 24, FF, FF, 8B, 55, EC, B8, 00, 79, 41, 00, E8, 13, EE, FE, FF, B9, 28, 54, 41, 00, BA, 40, 54, 41, 00, B8, 01, 00, 00, 80, E8, 1F, FE, FF, FF, 3C, 01, 75, 6E, FF, 35, 00, 79, 41, 00, 68, 60, 54, 41, 00, 68, 6C, 54, 41, 00, 68, 84, 54, 41, 00, 8D, 45, E4, BA, 04, 00, 00, 00, E8, E1...
 
[+]

Entropy:
6.5809

Developed / compiled with:
Microsoft Visual C++

Code size:
81.5 KB (83,456 bytes)

Scheduled Task
Task name:
Optimizer Pro Schedule

Trigger:
Logon (Runs on logon)


Remove optprolauncher.exe - Powered by Reason Core Security