
A Revoked 2014 Certificate Still Signs the Same Adware Family
Four binaries in an Optimizer Pro/SpeedingUpMyPC installer chain all carry the identical expired-and-revoked 'PC Utilities Software Limited' Authenticode signature. The certificate died in 2015, yet it still rides across the installer, its setup-extraction copy, and two helper DLLs — a decade-old trust-abuse technique that keeps working on some scanners and users alike.
Four binaries tied to a Windows "PC optimization" installer chain — an EXE, its setup-extraction temp copy, and two helper DLLs — all carry the identical code-signing leaf certificate issued to "PC Utilities Software Limited," serial 00 CF 20 ED FB 9E 9D 56 F4 29 A4 4E 79 C3 46 58 05. That certificate expired in mid-2015 and its chain is now uniformly flagged as either time-invalid or explicitly revoked, yet the signature block is still stamped across every member of the set.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read