PCOptimizerPro.exe

PCOptimizerPro

Xportsoft Technologies

The application PCOptimizerPro.exe, “TWEAK REPAIR ENHANCE & PROTECT” by Xportsoft Technologies has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. While running, it connects to the Internet address rs59.steeprockinc.com on port 80 using the HTTP protocol.
Publisher:
Tweaking Tools Inc  (signed by Xportsoft Technologies)

Product:
PCOptimizerPro

Description:
TWEAK REPAIR ENHANCE & PROTECT

Version:
6, 1, 0, 4

MD5:
255202427b5c1abd39e7c3c57e69237a

SHA-1:
c2ee0dd3dccc3b0c24b6983c4d8142abd84a65b3

SHA-256:
1337a5b28cbe4813c47b39056a51697b30662c4ebd5bfd3be6626b80b73edee1

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/15/2024 11:53:23 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Reason Heuristics
Win64.Generic
17.2.21.16

File size:
10 MB (10,450,832 bytes)

Product version:
6, 1, 0, 4

Copyright:
(c) Tweaking Tools Inc. All rights reserved.

Original file name:
PCOptimizerPro.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States d'America)

Digital Signature
Authority:
The USERTRUST Network

Valid from:
10/21/2010 2:00:00 AM

Valid to:
10/22/2011 1:59:59 AM

Subject:
CN=Xportsoft Technologies, O=Xportsoft Technologies, STREET="Office NO 12-13, Chhabra Complex", STREET=Mahesh Nagar, L=Ambala Cantt, S=Haryana, PostalCode=133001, C=IN

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
56FBF8A7717FD9CBB90C753FF0F4E25F

File PE Metadata
Compilation timestamp:
12/20/2010 11:13:49 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0xE9E38

Entry point:
48, 83, EC, 28, E8, BF, 8D, 00, 00, 48, 83, C4, 28, E9, 16, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 66, 66, 0F, 1F, 84, 00, 00, 00, 00, 00, 48, 3B, 0D, 59, A4, 13, 00, 75, 11, 48, C1, C1, 10, 66, F7, C1, FF, FF, 75, 02, F3, C3, 48, C1, C9, 10, E9, 35, 8E, 00, 00, CC, 48, 89, 5C, 24, 08, 48, 89, 74, 24, 10, 57, 48, 83, EC, 30, 49, 8B, D9, 49, 8B, F0, 48, 8B, FA, 4D, 85, C9, 75, 04, 33, C0, EB, 66, 48, 85, C9, 75, 25, E8, C9, 33, 00, 00, BB, 16, 00, 00, 00, 48, 83, 64, 24, 20, 00, 45, 33...
 
[+]

Code size:
1.6 MB (1,708,032 bytes)

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to rs59.steeprockinc.com  (69.20.11.235:80)

Remove PCOptimizerPro.exe - Powered by Reason Core Security