utils.exe

The application utils.exe has been detected as adware by 14 anti-malware scanners. The program is a setup application that uses the Nullsoft Install System installer, however the file is not signed with an authenticode signature from a trusted source. This file is typically installed with the program Browser+ Apps+ by Gogo Network Club which is a potentially unwanted software program. It is built using the Crossrider cross-browser extension platform. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider.
Version:
1.35.3.9

MD5:
1fd183a7ab5b2de8f6cbacdd6bf14714

SHA-1:
cbe9eaeddfd242483363ac7715da114e577b17f2

SHA-256:
96f7da224e19796e57f7cd78c4cbbc8c6cdb62e689897a0f527af4a3ffdffb57

Scanner detections:
14 / 68

Status:
Adware

Explanation:
This is part of the Crossrider Internet browser extension framework which may modify the user's web browser settings including changing the home and search pages.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application.

Analysis date:
4/19/2024 8:30:40 PM UTC  (today)

Scan engine
Detection
Engine version

AegisLab AV Signature
AdWare.NSIS.Indirect
2.1.4+

avast!
Win32:Malware-gen
2014.9-141019

Baidu Antivirus
PUA.Win32.VMDetector
4.0.3.141019

Bkav FE
HW32.Packed
1.3.0.4959

Dr.Web
infected with Trojan.Crossrider.32316
9.0.1.05190

ESET NOD32
Win32/Packed.VMDetector
8.10587

G Data
NSIS.Adware.Crossrider
14.10.24

IKARUS anti.virus
AdWare.CrossRider
t3scan.1.7.8.0

Malwarebytes
v2014.10.19.05

NANO AntiVirus
Trojan.Win32.Crossrider.dgtfbg
0.28.2.62671

Reason Heuristics
PUP.Crossrider.F
14.10.19.16

Rising Antivirus
PE:Malware.Obscure!1.9C59
23.00.65.141017

Trend Micro House Call
Suspici.389644AA
7.2.292

Vba32 AntiVirus
Trojan.GoogUpdate
3.12.26.3

File size:
2.4 MB (2,560,462 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Language:
English (United States)

Common path:
C:\Program Files\browser+ apps+\utils.exe

File PE Metadata
Compilation timestamp:
12/4/2012 7:55:02 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
49152:J9zhCJlN2b2m12Q2hlHA9lmGv1VT8Cx90JCgH3MZTTywWZEXcu:D+C9eHA7msnmJ9H3cT27u

Entry address:
0x4323

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, C3, 44, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, C4, 44, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, C4, 44, 00, 56, A3, 40, 3B, 44, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8D, 3B, 00, 00, A3, 9C, 3B, 44, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 01, B3, 40, 00, FF, 15, AC, C4, 44, 00, 83, EC, 14, C7, 44, 24, 04, 02, B3, 40, 00, C7...
 
[+]

Entropy:
7.9883  (probably packed)

Code size:
34.5 KB (35,328 bytes)

The file utils.exe has been discovered within the following program.

Browser+ Apps+  by Gogo Network Club
browser+ apps+ is a potentially unwanted adware program that injects ads into the user's browser. This includes inserting into web pages or displaying ads over parts of existing web page advertisements, banners, coupons or text links that would not otherwise appear.
84% remove it
 
Powered by Should I Remove It?

Remove utils.exe - Powered by Reason Core Security