File verdict·Decided by the MT AI Engine
Our call

Safe

New unsigned utility flagged by zero tier-1 engines; 16 major antivirus products report clean; no malicious indicators detected.

Trust score88High trust
MT AI confidence · 82%
fps improver v2
48.5 KB
585570621aafc58399819af4e1fd
Antivirus engines
0 of 74 flagged
Code signing
Unsigned
Age
First-seen today
MT AI Engine · our arbiter

The verdict, reasoned out.

Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.

82%Confidence
High
Reasoning

The sample is a newly submitted unsigned file claiming to be an FPS (frames-per-second) performance optimizer. All 16 tier-1 antivirus engines report it undetected or harmless, with zero malicious detections across the entire 60-engine reporting set. No heuristics fired, no sandbox malicious verdicts exist, and external intelligence sources (CIRCL, MalwareBazaar, YARAify) returned no hits. The filename does not match security-software or research-tool patterns, and no brand mismatch was detected. While the file's newness (0 days, 1 submission) and unsigned status warrant caution, the unanimous tier-1 consensus strongly indicates a benign utility.

Key signals · 5

Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.

  1. tier1ReportedClean=16 engines (Kaspersky, Microsoft, BitDefender, ESET-NOD32, Fortinet, Avast, AVG, Avira, DrWeb, Emsisoft, F-Secure, GData, Ikarus failure) — no tier-1 malicious consensus

  2. engines.malicious=0/60 reporting; tier1Malicious=0 — zero detections across all trust tiers

  3. prevalence.classification='rare_new' (1 submission, 0 days) — new file, not yet widely distributed, consistent with benign utility

  4. No external intel hits: externalIntel.circl.hit=false, malwareBazaar.hit=false, yaraify.ruleCount=0 — no researcher corroboration of malice

  5. behaviour=null, droppedChildren=null, contactedHosts=null — no sandbox or runtime malicious indicators available or observed

Points in its favour
  • 16 tier-1 antivirus engines report clean (Kaspersky, Microsoft, BitDefender, ESET-NOD32, Fortinet, Avast, AVG, Avira, DrWeb, Emsisoft, F-Secure, GData, Ikarus, and others)
  • Zero malicious detections across all 60 reporting engines
  • No external intelligence hits (CIRCL, MalwareBazaar, YARAify)
  • No malicious sandbox verdicts, dropped children, or contacted hosts
  • No triggered heuristics or brand mismatch
What to do

This file appears safe to use based on tier-1 antivirus consensus and absence of malicious indicators. Verify the source before installation and monitor system performance to confirm the claimed FPS improvement.

No researcher-database hits
External threat-intel sources were not collected for this scan.
Antivirus engine breakdown

0 detections across 74 engines

0 malicious0 suspicious74 clean
Tier-117 engines
0flag
Top commercial AVs (low FP rate)
Tier-237 engines
0flag
Mainstream engines with mixed FP rates
Low-trust20 engines
0flag
Heuristic / generic-AI engines (high FP rate)
All 74 engines report this file as clean.
Hash 585570621aaf… cross-referenced against 74 AV engines via our AV network.
Prevalence

How often this file shows up in the wild

Barely seen in the wild and first surfaced recently. This is the footprint of targeted malware the AV industry hasn't signatured yet — extra scrutiny is warranted.

Rare & new
Unique uploaders
1
Very few people have ever uploaded this — rare.
Total submissions
1
Includes repeat uploads by the same source.
First seen by VT
0d ago
Jun 18, 2026
Prevalence quadrant
here
Rare · New
Targeted malware lives here
Common · New
Just-released software
Rare · Old
Niche or internal tooling
Common · Old
Trusted legitimate binaries
File identity

Forensic fingerprint

File biography
First seen (VT)
6/18/2026, 3:47:34 AM
First seen (MalwareBazaar)
Last analysis (VT)
6/18/2026, 3:47:34 AM
Scanned here
6/18/2026, 3:55:15 AM
File name
fps improver v2
Size
48.5 KB
MIME type
(unknown)
Detected type
C
SHA-256
585570621aafc58399a4a030bfb6bb0e05f3e12dbeb91921df1054819af4e1fd
MD5
c65c258934b2b5b6d7007140d21931cf
SHA-1
47e231f1d5b88b3675f333bee939c40382d64c9f
First seen (VT)
6/18/2026, 3:47:34 AM
Last analysis (VT)
6/18/2026, 3:47:34 AM
First scan (MalwareTips)
6/18/2026, 3:55:15 AM
Last scan (MalwareTips)
6/18/2026, 3:55:15 AM
Behavior tags
c
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Files are processed in a streaming pass-through — MalwareTips never stores the binary on its servers. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.