utiltrolatunt.exe

trolatunt

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The application utiltrolatunt.exe by trolatunt has been detected as adware by 5 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “Update trolatunt”. This file is typically installed with the program trolatunt by Yontoo Technology, Inc. which is a potentially unwanted software program. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
trolatunt  (signed and verified)

Version:
1.0.5291.31824

MD5:
1aa60ad2cc82bd4c728f04528e203ace

SHA-1:
a311de37291580c767ffde1fd054fd1f05f86aab

SHA-256:
f935075b4d0194313e430f94ce51620b505295460404a7f022e53c58701d6741

Scanner detections:
5 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
6/4/2026 1:38:09 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Trolatunt
2015.0.3430

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.14628

ESET NOD32
Win32/BrowseFox (variant)
8.10012

Malwarebytes
PUP.Optional.Trolatunt.A
v2014.06.28.03

Reason Heuristics
PUP.trolatunt.N
14.6.28.3

File size:
311.3 KB (318,752 bytes)

Product version:
1.0.5291.31824

Original file name:
trolatunt.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\trolatunt\bin\utiltrolatunt.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
8/21/2013 2:00:00 AM

Valid to:
8/21/2015 1:59:59 AM

Subject:
CN=trolatunt, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=trolatunt, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
16E5B55BC9746E627E43F6A38DDE3E80

File PE Metadata
Compilation timestamp:
6/27/2014 8:41:03 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:j/HBn8l+kr8JNRkXqABW4iGCWwbLrLlvTubZyQ9Z:j/HBY+pJNrAwXrLJXQ

Entry address:
0x4D8CE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
302.5 KB (309,760 bytes)

Service
Display name:
Update trolatunt

Type:
Win32OwnProcess


The file utiltrolatunt.exe has been discovered within the following programs.

trolatunt  by Yontoo Technology, Inc.
This adware software (a branded version of the morphing Yontoo adware browser addon) injects itself into the user's web browser (IE, Chrome and Firefox) and will display out-of context advertising on web sites that are not associated with Yontoo or its affiliate partners.
trolatunt.co/support
83% remove it
 
Powered by Should I Remove It?

Remove utiltrolatunt.exe - Powered by Reason Core Security