utiltrolatunt.exe

trolatunt

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The application utiltrolatunt.exe by trolatunt has been detected as adware by 6 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “Update trolatunt”. This file is typically installed with the program trolatunt by Yontoo Technology, Inc. which is a potentially unwanted software program. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
trolatunt  (signed and verified)

Version:
1.0.5317.14778

MD5:
407df338e62061384f7a9c1f929e2817

SHA-1:
5793bc03df663323a73fbbcb2822bb46fff4326a

SHA-256:
b2fdccc5a3e5fcfeb1860bb50126befb01fe9d0898ff333623c8e065673e279d

Scanner detections:
6 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/26/2024 12:22:00 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Trolatunt
2015.0.3404

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.14724

ESET NOD32
Win32/BrowseFox.H potentially unwanted application
7.0.302.0

IKARUS anti.virus
PUA.BrowseFox
t3scan.1.6.1.0

Malwarebytes
PUP.Optional.Trolatunt.A
v2014.07.24.12

Reason Heuristics
PUP.Service.trolatunt.N
14.7.24.0

File size:
314.3 KB (321,824 bytes)

Product version:
1.0.5317.14778

Original file name:
trolatunt.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\trolatunt\bin\utiltrolatunt.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
8/21/2013 3:00:00 AM

Valid to:
8/21/2015 2:59:59 AM

Subject:
CN=trolatunt, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=trolatunt, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
16E5B55BC9746E627E43F6A38DDE3E80

File PE Metadata
Compilation timestamp:
7/23/2014 12:12:51 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:lSGBn8mOU7KzfJxkcwi8/cfEd3AMs7PL0aCGgMupbxyj:lSGBrONzfJ6ERxYaCDHy

Entry address:
0x4E59E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 02, 00, 10, 00, 00, 00, 20, 00, 00, 80, 18, 00, 00, 00, D8, 02...
 
[+]

Entropy:
6.0979

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
305.5 KB (312,832 bytes)

Service
Display name:
Update trolatunt

Type:
Win32OwnProcess


The file utiltrolatunt.exe has been discovered within the following programs.

trolatunt  by Yontoo Technology, Inc.
This adware software (a branded version of the morphing Yontoo adware browser addon) injects itself into the user's web browser (IE, Chrome and Firefox) and will display out-of context advertising on web sites that are not associated with Yontoo or its affiliate partners.
trolatunt.co/support
83% remove it
 
Powered by Should I Remove It?

Remove utiltrolatunt.exe - Powered by Reason Core Security