utils.exe

The application utils.exe has been detected as adware by 6 anti-malware scanners. The program is a setup application that uses the Nullsoft Install System installer, however the file is not signed with an authenticode signature from a trusted source. This file is typically installed with the program HDtubeV1.6 by Robokid Technologies which is a potentially unwanted software program. The installer uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars.
Version:
1.34.7.1

MD5:
ed0de468a61335a563a22f29237241a8

SHA-1:
b94c274a11ef748ee984893423fa9a19ef5fde4a

SHA-256:
28f21a88890bff5fa94909a88ee0f79fb3850e10c23b011f093b042e79c9e4c5

Scanner detections:
6 / 68

Status:
Adware

Explanation:
This is part of the Crossrider Internet browser extension framework which may modify the user's web browser settings including changing the home and search pages.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application.

Analysis date:
4/25/2024 9:55:04 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.Solimba
2014.07.24

Bkav FE
HW32.CDB
1.3.0.4959

Clam AntiVirus
Win.Adware.Agent-6597
0.98/19168

IKARUS anti.virus
PUA.PlusHD
t3scan.1.6.1.0

Malwarebytes
v2014.07.24.01

Reason Heuristics
PUP.Crossrider.F
14.7.23.23

File size:
2.1 MB (2,229,465 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Language:
English (United States)

Common path:
C:\Program Files\hdtubev1.6\utils.exe

File PE Metadata
Compilation timestamp:
12/4/2012 4:55:02 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
49152:HOiRK1mB8k0Ry8eoRkeFX7eRdtO06MY0VQQW+01f/6B+DJT9k2cm:54MCy8XksrCP3DKe01f/6wDJTkm

Entry address:
0x4323

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, C3, 44, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, C4, 44, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, C4, 44, 00, 56, A3, 40, 3B, 44, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8D, 3B, 00, 00, A3, 9C, 3B, 44, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 01, B3, 40, 00, FF, 15, AC, C4, 44, 00, 83, EC, 14, C7, 44, 24, 04, 02, B3, 40, 00, C7...
 
[+]

Entropy:
7.9855  (probably packed)

Code size:
34.5 KB (35,328 bytes)

The file utils.exe has been discovered within the following program.

HDtubeV1.6  by Robokid Technologies
HDTube is an adware web browser application that displays banner ads as well as contextual link ads that are injected in the web page.
crossrider.com
80% remove it
 
Powered by Should I Remove It?

Remove utils.exe - Powered by Reason Core Security