setup_1265.exe

Optimizer Pro v3.2

PC Utilities Software Limited

Part of the Optimizer Pro / Driver 'PC optimizer' product lines marketed by Adsology and distributed through various bundled software (PPI and commission) channels. The application setup_1265.exe, “Optimizer Pro – Clean up your PC” by PC Utilities Software Limited has been detected as a potentially unwanted program by 18 anti-malware scanners. Also know as BrowserDefender, this bundled service will prevent various web browser toolbars and extensions from running as well as block changes to the search page and provider.
Publisher:
PCUtilities Software Limited  (signed by PC Utilities Software Limited)

Product:
Optimizer Pro v3.2

Description:
Optimizer Pro – Clean up your PC

Version:
3.3.1.7

MD5:
159ecb028de6d6df9181363040ec1bef

SHA-1:
e19eb4b0a53acf17b770783cc269ce259ef5fe29

SHA-256:
49557c65c2eeb322bfb35a64bfd8cd09dc8beef63e0eea49d65945e815ef55e4

Scanner detections:
18 / 68

Status:
Potentially unwanted

Explanation:
Installed with the Optimizer Pro software which is bundled by 3rd-party monetization programs.

Analysis date:
5/3/2024 8:30:41 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Trojan.Inject
7.1.1

Avira AntiVirus
TR/Bprotector.1969704
7.11.217.14

avast!
PUP-gen [PUP]
2014.9-150313

AVG
Generic
2016.0.3171

Dr.Web
Threat.Undefined
9.0.1.072

ESET NOD32
Generik.ENIMIUX trojan
7.0.302.0

Fortinet FortiGate
W32/Inject.UMUB!tr
3/13/2015

G Data
Win32.Application.OptimizerPro
15.3.25

herdProtect (fuzzy)
2015.6.19.17

K7 AntiVirus
Adware
13.200.15259

Kaspersky
Trojan.Win32.Inject
14.0.0.2352

Malwarebytes
PUP.Optional.OptimizerPR0
v2015.03.13.12

McAfee
Artemis!83104CC0EBA4
5600.6827

Panda Antivirus
Trj/Genetic.gen
15.06.19.05

Qihoo 360 Security
Win32/Trojan.Multi.daf
1.0.0.1015

Reason Heuristics
PUP.Installer.PC Utilities
15.3.13.11

VIPRE Antivirus
Threat.4150696
37788

Zillya! Antivirus
Trojan.Inject.Win32.159775
2.0.0.2097

File size:
7 MB (7,346,640 bytes)

Product version:
3.3.1.7

Copyright:
PCUtilities Software Limited

Original file name:
OptimizerPR0

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\ProgramData\{522c304f-64b0-531a-522c-c304f64bc13d}\setup_1265.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
11/20/2014 6:00:00 PM

Valid to:
11/21/2015 5:59:59 PM

Subject:
CN=PC Utilities Software Limited, O=PC Utilities Software Limited, STREET=78 York Street, L=London, PostalCode=W1H 1DP, C=GB

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00F10854548D47F74C920D7091D9057D6E

File PE Metadata
Compilation timestamp:
3/4/2015 7:39:40 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
196608:q0ZoF2s4hOn80p14Zu5rFRrErO34UrUPT4ARHvW0cEe:q0ZA2C8U4Zud934g2PwEe

Entry address:
0xA193

Entry point:
E8, 97, 76, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, 85, C0, 74, 12, 83, E8, 08, 81, 38, DD, DD, 00, 00, 75, 07, 50, E8, 28, ED, FF, FF, 59, 5D, C3, 8B, FF, 55, 8B, EC, 83, EC, 10, A1, F0, 36, 43, 00, 33, C5, 89, 45, FC, 8B, 55, 18, 53, 33, DB, 56, 57, 3B, D3, 7E, 1F, 8B, 45, 14, 8B, CA, 49, 38, 18, 74, 08, 40, 3B, CB, 75, F6, 83, C9, FF, 8B, C2, 2B, C1, 48, 3B, C2, 7D, 01, 40, 89, 45, 18, 89, 5D, F8, 39, 5D, 24, 75, 0B, 8B, 45, 08, 8B, 00, 8B, 40, 04, 89, 45, 24, 8B, 35, 40, A1, 42, 00...
 
[+]

Entropy:
7.9798  (probably packed)

Code size:
163 KB (166,912 bytes)

Remove setup_1265.exe - Powered by Reason Core Security