utils.exe

The application utils.exe has been detected as adware by 12 anti-malware scanners. The program is a setup application that uses the Nullsoft Install System installer, however the file is not signed with an authenticode signature from a trusted source. This file is typically installed with the program Browser+ Apps+ by Gogo Network Club which is a potentially unwanted software program. It is built using the Crossrider cross-browser extension platform. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider.
Version:
1.35.9.16

MD5:
2b4b4adf55acfe05d35b157b1b51c957

SHA-1:
002376537e5f51a38c2d558f168ca1d30e9c98f3

SHA-256:
b78edfeabe3cd91088d6daace97455d45367a9609a6e92cb3f9379a6da1a99e1

Scanner detections:
12 / 68

Status:
Adware

Explanation:
This is part of the Crossrider Internet browser extension framework which may modify the user's web browser settings including changing the home and search pages.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application.

Analysis date:
4/26/2024 6:52:22 PM UTC  (today)

Scan engine
Detection
Engine version

AegisLab AV Signature
AdWare.NSIS.Indirect
2.1.4+

Agnitum Outpost
Riskware.VMDetector
7.1.1

Baidu Antivirus
PUA.Win32.VMDetector
4.0.3.141022

Bkav FE
HW32.Packed
1.3.0.4959

Dr.Web
infected with Trojan.Crossrider.33333
9.0.1.05190

ESET NOD32
Win32/Packed.VMDetector
8.10604

G Data
NSIS.Adware.Crossrider
14.10.24

IKARUS anti.virus
AdWare.CrossRider
t3scan.1.7.8.0

Malwarebytes
v2014.10.22.02

NANO AntiVirus
Trojan.Win32.Crossrider.dgtvxk
0.28.2.62841

Reason Heuristics
PUP.Crossrider.F
14.10.22.14

Vba32 AntiVirus
Trojan.GoogUpdate
3.12.26.3

File size:
2.4 MB (2,518,787 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Language:
English (United States)

Common path:
C:\Program Files\browser+ apps+\utils.exe

File PE Metadata
Compilation timestamp:
12/4/2012 5:25:02 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
49152:4ZZ6n4ZM1vN0wga9HHjNslycS1WFdOGnj6AMa++EXJjf:NlvNmazPcSW6eE5jf

Entry address:
0x4323

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, C3, 44, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, C4, 44, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, C4, 44, 00, 56, A3, 40, 3B, 44, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8D, 3B, 00, 00, A3, 9C, 3B, 44, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 01, B3, 40, 00, FF, 15, AC, C4, 44, 00, 83, EC, 14, C7, 44, 24, 04, 02, B3, 40, 00, C7...
 
[+]

Entropy:
7.9882  (probably packed)

Code size:
34.5 KB (35,328 bytes)

The file utils.exe has been discovered within the following program.

Browser+ Apps+  by Gogo Network Club
browser+ apps+ is a potentially unwanted adware program that injects ads into the user's browser. This includes inserting into web pages or displaying ads over parts of existing web page advertisements, banners, coupons or text links that would not otherwise appear.
84% remove it
 
Powered by Should I Remove It?

Remove utils.exe - Powered by Reason Core Security