optimizerpro.exe

Optimizer Pro v3.2

PC Utilities Software Limited

Part of the Optimizer Pro / Driver 'PC optimizer' product lines marketed by Adsology and distributed through various bundled software (PPI and commission) channels. The application optimizerpro.exe, “Optimizer Pro – Clean up your PC” by PC Utilities Software Limited has been detected as a potentially unwanted program by 38 anti-malware scanners. This is a setup program which is used to install the application. Also know as BrowserDefender, this bundled service will prevent various web browser toolbars and extensions from running as well as block changes to the search page and provider.
Publisher:
PCUtilities Software Limited  (signed by PC Utilities Software Limited)

Product:
Optimizer Pro v3.2

Description:
Optimizer Pro – Clean up your PC

Version:
3.3.1.7

MD5:
1db72cd09ec266ff9f8e94d4ef48b46b

SHA-1:
d9917ce96238b44837c7a03d1d76d72e32415bfa

SHA-256:
b51ac92ce16b3eda98003ef4cbf0ebe3703165824e8634eb04426ef383c89c7d

Scanner detections:
38 / 68

Status:
Potentially unwanted

Explanation:
Installed with the Optimizer Pro software which is bundled by 3rd-party monetization programs.

Analysis date:
12/25/2024 2:00:33 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.12849989
362

Agnitum Outpost
Trojan.Inject
7.1.1

AhnLab V3 Security
PUP/Win32.OptimizerPro
2015.04.16

Avira AntiVirus
TR/Bprotector.1969704
7.11.217.14

avast!
PUP-gen [PUP]
2014.9-160208

AVG
Win32/DH{gRKBE4EOICIlABM1gQw}
2017.0.2840

Baidu Antivirus
PUA.Win32.Rezimitpo
4.0.3.1628

Bitdefender
Gen:Variant.Zusy.133230
1.0.20.195

Bkav FE
W32.HfsAdware
1.3.0.6379

Clam AntiVirus
Win.Trojan.Inject-10791
0.98/21511

Comodo Security
Application.Win32.OptimizerPro.FY
21267

Dr.Web
Threat.Undefined
9.0.1.039

Emsisoft Anti-Malware
Gen:Variant.Zusy.133230
8.16.02.08.09

ESET NOD32
Win32/Adware.SpeedingUpMyPC.AB application
10.7.0.302.0

Fortinet FortiGate
W32/Inject.UMUB!tr
2/8/2016

F-Prot
W32/OptimizerPro.H.gen
v6.4.7.1.166

F-Secure
Trojan.Generic.12850669
11.2016-08-02_2

G Data
Win32.Application.OptimizerPro
16.2.25

IKARUS anti.virus
PUA.SpeedingUpMyPC
t3scan.1.8.6.0

K7 AntiVirus
Riskware
13.1915124

Kaspersky
Trojan.Win32.Inject
14.0.0.693

Malwarebytes
PUP.Optional.OptimizerPR0
v2016.02.08.09

McAfee
Artemis!83104CC0EBA4
5600.6496

MicroWorld eScan
Trojan.Generic.12850669
17.0.0.117

NANO AntiVirus
Trojan.Win32.Inject.dprbqo
0.30.16.1110

nProtect
Trojan.GenericKD.2203974
15.03.27.01

Panda Antivirus
Trj/Genetic.gen
16.02.08.09

Qihoo 360 Security
Win32/Trojan.Multi.daf
1.0.0.1015

Quick Heal
PUA.OptimizerPro.A9
2.16.14.00

Reason Heuristics
PUP.PC Utilities.PCUtilities (M)
16.2.8.9

Rising Antivirus
PE:Trojan.Win32.SpeedingUpMyPC.a!1075357520
23.00.65.16206

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
TROJ_GEN.R08NC0OC615
7.2.39

Trend Micro
TROJ_GEN.F0C2C00D315
10.465.08

Vba32 AntiVirus
Trojan.Inject
3.12.26.3

VIPRE Antivirus
Threat.4150696
37788

ViRobot
Trojan.Win32.S.Agent.7346640.A[h]
2014.3.20.0

Zillya! Antivirus
Trojan.Inject.Win32.159090
2.0.0.2088

File size:
7 MB (7,339,984 bytes)

Product version:
3.3.1.7

Copyright:
PCUtilities Software Limited

Original file name:
OptimizerPR0

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\ProgramData\{8faca589-fa22-1bb3-8fac-ca589fa29627}\optimizerpro.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
11/20/2014 6:00:00 PM

Valid to:
11/21/2015 5:59:59 PM

Subject:
CN=PC Utilities Software Limited, O=PC Utilities Software Limited, STREET=78 York Street, L=London, PostalCode=W1H 1DP, C=GB

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00F10854548D47F74C920D7091D9057D6E

File PE Metadata
Compilation timestamp:
2/25/2015 7:07:30 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
196608:Ux+PjfCEoXj1/2DneuyDr8jsQEzCNOJvlC0FE:UxqYx/2LTyDAjsWOJXFE

Entry address:
0xEAC7

Entry point:
E8, 06, 7A, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, 20, 95, 42, 00, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 5F, 89, 45, FC, 5E, 85, C0, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, 1C, 91, 42, 00, C9, C2, 08, 00, CC, CC, CC, 8B, 4C, 24, 04, F7, C1, 03, 00, 00, 00, 74, 24, 8A, 01, 83, C1, 01, 84, C0, 74, 4E, F7, C1, 03, 00, 00, 00, 75, EF, 05, 00, 00, 00, 00, 8D, A4, 24, 00, 00...
 
[+]

Entropy:
7.9795  (probably packed)

Code size:
160 KB (163,840 bytes)

The file optimizerpro.exe has been seen being distributed by the following URL.

Remove optimizerpro.exe - Powered by Reason Core Security