File name:

PCOptimizerProInstaller.exe

Full analysis: https://app.any.run/tasks/a365e9c9-10dc-4ef5-9395-e5714aada32e
Verdict: Malicious activity
Analysis date: July 29, 2019, 22:20:57
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
installer
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

18B260587BA339E9C7C7A5391F8E1EA1

SHA1:

CDC5712885EF58CD571D4CC83A19586FC9C4F8ED

SHA256:

5FDA13B6AFE0FA71A5F742ECE8AA2C74B3E2DE4E08010456BE25E1D4E0AE2DC1

SSDEEP:

98304:LCvKD6VKSC7gVzQ3v5O8yKBahT9em2n8OtiCV6FQFFmzNDxtzxbBaPphYgBWRKC4:LCvq2RSwp3hTYm3uhF4ftzwdWRKr

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • PCOptimizerProInstaller.exe (PID: 3008)
      • PCOptimizerProSetup_STD.exe (PID: 3920)
      • regsvr32.exe (PID: 2916)
    • Application was dropped or rewritten from another process

      • PCOptimizerProSetup_STD.exe (PID: 3920)
      • StartApps.exe (PID: 2836)
      • PCOptimizerPro.exe (PID: 4020)
    • Registers / Runs the DLL via REGSVR32.EXE

      • PCOptimizerProSetup_STD.exe (PID: 3920)
    • Changes settings of System certificates

      • PCOptimizerProSetup_STD.exe (PID: 3920)
    • Loads the Task Scheduler DLL interface

      • PCOptimizerPro.exe (PID: 4020)
    • Changes the autorun value in the registry

      • PCOptimizerPro.exe (PID: 4020)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • PCOptimizerProInstaller.exe (PID: 3008)
      • PCOptimizerPro.exe (PID: 4020)
      • PCOptimizerProSetup_STD.exe (PID: 3920)
    • Creates files in the user directory

      • PCOptimizerProSetup_STD.exe (PID: 3920)
    • Creates COM task schedule object

      • regsvr32.exe (PID: 2916)
    • Creates files in the program directory

      • PCOptimizerProSetup_STD.exe (PID: 3920)
      • PCOptimizerPro.exe (PID: 4020)
    • Adds / modifies Windows certificates

      • PCOptimizerProSetup_STD.exe (PID: 3920)
    • Creates a software uninstall entry

      • PCOptimizerProSetup_STD.exe (PID: 3920)
    • Creates files in the Windows directory

      • PCOptimizerPro.exe (PID: 4020)
    • Uses RUNDLL32.EXE to load library

      • PCOptimizerPro.exe (PID: 4020)
    • Searches for installed software

      • PCOptimizerPro.exe (PID: 4020)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | NSIS - Nullsoft Scriptable Install System (94.8)
.exe | Win32 Executable MS Visual C++ (generic) (3.4)
.dll | Win32 Dynamic Link Library (generic) (0.7)
.exe | Win32 Executable (generic) (0.5)
.exe | Generic Win/DOS Executable (0.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2009:12:05 23:50:46+01:00
PEType: PE32
LinkerVersion: 6
CodeSize: 23552
InitializedDataSize: 119808
UninitializedDataSize: 1024
EntryPoint: 0x323c
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 8.1.1.5
ProductVersionNumber: 8.1.1.5
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Windows, Latin1
Comments: PC Optimizer Pro Nothing optimize your PC better for more details visit http://www.pcoptmizerpro.com
CompanyName: Xportsoft.com
FileDescription: PC Optimizer Pro
FileVersion: 8.1.1.5
InternalName: PC Optimizer Pro Nothing optimize your PC better
LegalCopyright: (c) Xportsoft Technologies. All rights reserved.
LegalTrademarks: Xportsoft Technoliges Pvt.. Ltd.
OriginalFileName: PC Optimizer Pro
ProductName: PC Optimizer Pro
ProductVersion: 8.1.1.5

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 05-Dec-2009 22:50:46
Detected languages:
  • English - United States
Comments: PC Optimizer Pro Nothing optimize your PC better for more details visit http://www.pcoptmizerpro.com
CompanyName: Xportsoft.com
FileDescription: PC Optimizer Pro
FileVersion: 8.1.1.5
InternalName: PC Optimizer Pro Nothing optimize your PC better
LegalCopyright: (c) Xportsoft Technologies. All rights reserved.
LegalTrademarks: Xportsoft Technoliges Pvt.. Ltd.
OriginalFilename: PC Optimizer Pro
ProductName: PC Optimizer Pro
ProductVersion: 8.1.1.5

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x000000D8

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 5
Time date stamp: 05-Dec-2009 22:50:46
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_LINE_NUMS_STRIPPED
  • IMAGE_FILE_LOCAL_SYMS_STRIPPED
  • IMAGE_FILE_RELOCS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x00005A5A
0x00005C00
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.4177
.rdata
0x00007000
0x00001190
0x00001200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.18163
.data
0x00009000
0x0001AF98
0x00000400
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
4.70903
.ndata
0x00024000
0x00008000
0x00000000
IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
0
.rsrc
0x0002C000
0x00000EE8
0x00001000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
4.06995

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.19512
727
UNKNOWN
English - United States
RT_MANIFEST
103
2.16096
20
UNKNOWN
English - United States
RT_GROUP_ICON
105
2.66174
256
UNKNOWN
English - United States
RT_DIALOG
106
2.88094
284
UNKNOWN
English - United States
RT_DIALOG
111
2.48825
96
UNKNOWN
English - United States
RT_DIALOG

Imports

ADVAPI32.dll
COMCTL32.dll
GDI32.dll
KERNEL32.dll
SHELL32.dll
USER32.dll
VERSION.dll
ole32.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
8
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start drop and start pcoptimizerproinstaller.exe pcoptimizerprosetup_std.exe regsvr32.exe startapps.exe no specs pcoptimizerpro.exe rundll32.exe no specs systempropertiescomputername.exe no specs pcoptimizerproinstaller.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
280"C:\Windows\System32\SystemPropertiesComputerName.exe" C:\Windows\System32\SystemPropertiesComputerName.exerundll32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Change Computer Settings
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\systempropertiescomputername.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sysdm.cpl
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
864"C:\Windows\System32\rundll32.exe" shell32.dll,Control_RunDLL SYSDM.CPL,2C:\Windows\System32\rundll32.exePCOptimizerPro.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
2836"C:\Program Files\PC Optimizer Pro\StartApps.exe" "C:\Program Files\PC Optimizer Pro\PCOptimizerPro.exe"C:\Program Files\PC Optimizer Pro\StartApps.exePCOptimizerProSetup_STD.exe
User:
admin
Company:
Xportsoft Technologies
Integrity Level:
HIGH
Description:
Starting up the applicaiton
Exit code:
0
Version:
1.0.0.9
Modules
Images
c:\program files\pc optimizer pro\startapps.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2916regsvr32.exe /s "C:\Program Files\PC Optimizer Pro\PCOptProCtxMenu.dll" C:\Windows\system32\regsvr32.exe
PCOptimizerProSetup_STD.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3008"C:\Users\admin\AppData\Local\Temp\PCOptimizerProInstaller.exe" C:\Users\admin\AppData\Local\Temp\PCOptimizerProInstaller.exe
explorer.exe
User:
admin
Company:
Xportsoft.com
Integrity Level:
HIGH
Description:
PC Optimizer Pro
Exit code:
0
Version:
8.1.1.5
Modules
Images
c:\users\admin\appdata\local\temp\pcoptimizerproinstaller.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
3756"C:\Users\admin\AppData\Local\Temp\PCOptimizerProInstaller.exe" C:\Users\admin\AppData\Local\Temp\PCOptimizerProInstaller.exeexplorer.exe
User:
admin
Company:
Xportsoft.com
Integrity Level:
MEDIUM
Description:
PC Optimizer Pro
Exit code:
3221226540
Version:
8.1.1.5
Modules
Images
c:\users\admin\appdata\local\temp\pcoptimizerproinstaller.exe
c:\systemroot\system32\ntdll.dll
3920C:\Users\admin\AppData\Local\Temp\PCOptimizerProSetup_STD.exeC:\Users\admin\AppData\Local\Temp\PCOptimizerProSetup_STD.exe
PCOptimizerProInstaller.exe
User:
admin
Company:
Xportsoft.com
Integrity Level:
HIGH
Description:
PC Optimizer Pro
Exit code:
0
Version:
8.1.1.5
Modules
Images
c:\users\admin\appdata\local\temp\pcoptimizerprosetup_std.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
4020"C:\Program Files\PC Optimizer Pro\PCOptimizerPro.exe" C:\Program Files\PC Optimizer Pro\PCOptimizerPro.exe
StartApps.exe
User:
admin
Company:
Xportsoft Technologies
Integrity Level:
HIGH
Description:
Nothing optimize your PC better
Exit code:
3221225547
Version:
8, 1, 1, 5
Modules
Images
c:\program files\pc optimizer pro\pcoptimizerpro.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winmm.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
Total events
1 919
Read events
1 570
Write events
344
Delete events
5

Modification events

(PID) Process:(2916) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{203ABD21-41F1-4F1B-BAE3-D6A89A90D239}
Operation:writeName:
Value:
PCProCtxMenu Class
(PID) Process:(2916) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{203ABD21-41F1-4F1B-BAE3-D6A89A90D239}\InprocServer32
Operation:writeName:
Value:
C:\Program Files\PC Optimizer Pro\PCOptProCtxMenu.dll
(PID) Process:(2916) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{203ABD21-41F1-4F1B-BAE3-D6A89A90D239}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Apartment
(PID) Process:(2916) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\PCProCtxMenu
Operation:writeName:
Value:
{203ABD21-41F1-4F1B-BAE3-D6A89A90D239}
(PID) Process:(2916) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\lnkfile\shellex\ContextMenuHandlers\PCProCtxMenu
Operation:writeName:
Value:
{203ABD21-41F1-4F1B-BAE3-D6A89A90D239}
(PID) Process:(2916) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{203ABD21-41F1-4F1B-BAE3-D6A89A90D239}\InprocServer32
Operation:delete keyName:
Value:
(PID) Process:(2916) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{203ABD21-41F1-4F1B-BAE3-D6A89A90D239}
Operation:delete keyName:
Value:
(PID) Process:(2916) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\PCProCtxMenu
Operation:delete keyName:
Value:
(PID) Process:(2916) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\lnkfile\shellex\ContextMenuHandlers\PCProCtxMenu
Operation:delete keyName:
Value:
(PID) Process:(2916) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{003B9C22-6FE0-4BCA-A73F-9AA99B9BBDAA}\1.0
Operation:writeName:
Value:
PCOptProCtxMenu 1.0 Type Library
Executable files
15
Suspicious files
10
Text files
291
Unknown types
4

Dropped files

PID
Process
Filename
Type
3920PCOptimizerProSetup_STD.exeC:\Users\admin\AppData\Local\Temp\nssE09E.tmp\GetVersion.dllexecutable
MD5:5264F7D6D89D1DC04955CFB391798446
SHA256:7D76C7DD8F7CD5A87E0118DACB434DB3971A049501E22A5F4B947154621AB3D4
3920PCOptimizerProSetup_STD.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Optimizer Pro\PC Optimizer Pro.lnklnk
MD5:
SHA256:
3008PCOptimizerProInstaller.exeC:\Users\admin\AppData\Local\Temp\nsgDE8A.tmp\GetVersion.dllexecutable
MD5:5264F7D6D89D1DC04955CFB391798446
SHA256:7D76C7DD8F7CD5A87E0118DACB434DB3971A049501E22A5F4B947154621AB3D4
3008PCOptimizerProInstaller.exeC:\Users\admin\AppData\Local\Temp\PCOptimizerProSetup_STD.exeexecutable
MD5:7ECCAB7E72A91A90DCCC0CC7D6D09061
SHA256:49C0AA6FDEF05441488EE80F50BEAAB8F55C3C01882CBEA51650F1075ED80C80
3920PCOptimizerProSetup_STD.exeC:\Program Files\PC Optimizer Pro\data.xmlxml
MD5:AC4169805E1CAA0BB68CD6E9F494134F
SHA256:DB58F7626A3E7E32EE0622CFFE522F394971CD2709AA5E87B9B1A8FF12084CA9
3920PCOptimizerProSetup_STD.exeC:\Program Files\PC Optimizer Pro\xmllite.dll
MD5:
SHA256:
3920PCOptimizerProSetup_STD.exeC:\Program Files\PC Optimizer Pro\PCOptimizerPro.exeexecutable
MD5:CBF686BFC49C18F0D7A46AA851FE5A59
SHA256:C1EC9101298F1092064B217ADE5042B71A913F3BA7E4ADC8FB2101873D9DF0DA
3920PCOptimizerProSetup_STD.exeC:\Program Files\PC Optimizer Pro\StartApps.exeexecutable
MD5:2A90679E095F703BA3E19A27995F80AE
SHA256:73EBA3C5F70A11B5C190F10ACBF34269DB07388705D983332C08206F472F1740
3920PCOptimizerProSetup_STD.exeC:\Program Files\PC Optimizer Pro\Languages\DE.xmlxml
MD5:1EBD8CC9732943E9D794CCDB80BFEE75
SHA256:642906467DA21E57419ADF9597477DC4A8E14221274AD286F6497CF34AB2B0CE
3920PCOptimizerProSetup_STD.exeC:\Program Files\PC Optimizer Pro\UpdatesDll_s.dllexecutable
MD5:22F6A47E7F69E582CB0A6CF21392F520
SHA256:CC2129E9E18FABAFDA2988C35421DC45E04644FBE88280EE4CF2A48DEA6A9A14
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
5
DNS requests
2
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3920
PCOptimizerProSetup_STD.exe
GET
302
207.97.224.82:80
http://www.pcoptimizerpro.com/site/admin/instcnt.aspx?bit=32&tid=STD&OS=Windows%207&IP=192.168.100.180&compid=010000003800
US
html
262 b
malicious
4020
PCOptimizerPro.exe
GET
302
207.97.224.82:80
http://www.pcoptimizerpro.com/admin/isrenewed.aspx?bitver=32&h=&uq=5254004A04AF&uq1=5254004A04AF&uq2=18912D000000&tid=STD
US
html
265 b
malicious
3920
PCOptimizerProSetup_STD.exe
GET
200
91.199.212.52:80
http://crt.comodoca.com/COMODORSAAddTrustCA.crt
GB
der
1.37 Kb
whitelisted
4020
PCOptimizerPro.exe
GET
302
207.97.224.82:80
http://www.pcoptimizerpro.com/admin/islivechat.aspx?bit=32&tid=STD&lang=EN
US
html
206 b
malicious
4020
PCOptimizerPro.exe
GET
302
207.97.224.82:80
http://www.pcoptimizerpro.com/admin/showongui.aspx?bit=32&tid=STD&lang=EN
US
html
205 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3920
PCOptimizerProSetup_STD.exe
207.97.224.82:80
www.pcoptimizerpro.com
Rackspace Ltd.
US
suspicious
3920
PCOptimizerProSetup_STD.exe
207.97.224.82:443
www.pcoptimizerpro.com
Rackspace Ltd.
US
suspicious
3920
PCOptimizerProSetup_STD.exe
91.199.212.52:80
crt.comodoca.com
Comodo CA Ltd
GB
suspicious
4020
PCOptimizerPro.exe
207.97.224.82:443
www.pcoptimizerpro.com
Rackspace Ltd.
US
suspicious
4020
PCOptimizerPro.exe
207.97.224.82:80
www.pcoptimizerpro.com
Rackspace Ltd.
US
suspicious

DNS requests

Domain
IP
Reputation
www.pcoptimizerpro.com
  • 207.97.224.82
malicious
crt.comodoca.com
  • 91.199.212.52
whitelisted

Threats

PID
Process
Class
Message
3920
PCOptimizerProSetup_STD.exe
A Network Trojan was detected
ET USER_AGENTS Suspicious User Agent (Microsoft Internet Explorer)
4020
PCOptimizerPro.exe
A Network Trojan was detected
ET USER_AGENTS Suspicious User Agent (Microsoft Internet Explorer)
Process
Message
regsvr32.exe
HKCR { NoRemove CLSID { ForceRemove {203ABD21-41F1-4F1B-BAE3-D6A89A90D239} = s 'PCProCtxMenu Class' { InprocServer32 = s 'C:\Program Files\PC Optimizer Pro\PCOptProCtxMenu.dll' { val ThreadingModel = s 'Apartment' } } } NoRemove * { NoRemove ShellEx { NoRemove ContextMenuHandlers { ForceRemove PCProCtxMenu = s '{203ABD21-41F1-4F1B-BAE3-D6A89A90D239}' } } } NoRemove lnkfile { NoRemove ShellEx { NoRemove ContextMenuHandlers { ForceRemove PCProCtxMenu = s '{203ABD21-41F1-4F1B-BAE3-D6A89A90D239}' } } } }
regsvr32.exe
HKCR { NoRemove CLSID { ForceRemove {203ABD21-41F1-4F1B-BAE3-D6A89A90D239} = s 'PCProCtxMenu Class' { InprocServer32 = s 'C:\Program Files\PC Optimizer Pro\PCOptProCtxMenu.dll' { val ThreadingModel = s 'Apartment' } } } NoRemove * { NoRemove ShellEx { NoRemove ContextMenuHandlers { ForceRemove PCProCtxMenu = s '{203ABD21-41F1-4F1B-BAE3-D6A89A90D239}' } } } NoRemove lnkfile { NoRemove ShellEx { NoRemove ContextMenuHandlers { ForceRemove PCProCtxMenu = s '{203ABD21-41F1-4F1B-BAE3-D6A89A90D239}' } } } }
PCOptimizerProSetup_STD.exe
strData:1572012987
PCOptimizerProSetup_STD.exe
Initial:5qlbH5bYal
PCOptimizerProSetup_STD.exe
Target:1Og62
PCOptimizerProSetup_STD.exe
Target:5qlbH5bYal1Og62
PCOptimizerPro.exe
:N Need Help? Dial Toll Free: 1-866-364-6553:
PCOptimizerPro.exe
20180830
PCOptimizerPro.exe
20190323
PCOptimizerPro.exe
20180828