utility.exe

NightWish Center (Bright Circle Investments Ltd)

This adware is a web browser extension that will inject advertising in the browser in the form of unwanted banners and text-links which may link to malware sites and install unwanted software. The application utility.exe by NightWish Center (Bright Circle Investments) has been detected as adware by 12 anti-malware scanners. This is a setup program which is used to install the application. This file is typically installed with the program Crossbrowse by CLARALABSOFTWARE which is a potentially unwanted software program. It is distributed as part of the Brightcircle group of browser-extensions.
Publisher:

Version:
104.0.0.0

MD5:
abdb9fdccfb34599a0cd03df0946a749

SHA-1:
a5ff3aaadae589a8b17c92d5f4044437ecbfedc3

SHA-256:
cd14517e5107d95acfebfc94637a91761f7b6bbbaa1f2524dce3d1ddf1bd8a8d

Scanner detections:
12 / 68

Status:
Adware

Explanation:
May modify the web browser's settings including changing the homepage and search provider in addition to delivering ads (by injecting banner and text-links directly in the webpage). Distributed through the Brightcircle investments brand.

Analysis date:
4/17/2025 11:44:09 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.CrossRider
2015.04.07

avast!
Win32:Malware-gen
2014.9-150407

AVG
Win32/DH{gRITfWUDICIlV04A}
2016.0.3147

Baidu Antivirus
Adware.Win32.CrossAd
4.0.3.1547

ESET NOD32
Win32/Toolbar.CrossRider.CH potentially unwanted (variant)
9.11434

herdProtect (fuzzy)
2015.7.10.9

Kaspersky
HEUR:Trojan-Downloader.Win32.Generic
14.0.0.2230

McAfee
Trojan.Artemis!3B26BBAA2D47
5600.6709

Reason Heuristics
Adware.BrightCircle.NightWishCenterBrightCircleInvestments
15.4.11.23

Sophos
Generic PUA GG
4.98

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.3

VIPRE Antivirus
Threat.4789396
38950

File size:
1.7 MB (1,819,104 bytes)

Product version:
104.0.0.0

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\crossbrowse\crossbrowse\application\utility.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
12/15/2014 10:00:00 PM

Valid to:
12/16/2015 9:59:59 PM

Subject:
CN=NightWish Center (Bright Circle Investments Ltd), O=NightWish Center (Bright Circle Investments Ltd), STREET=Athinodorou 3, STREET=Dasoupoli Strovolos, L=Nicosia, S=Nicosia, PostalCode=2025, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00B30349E6AD66949988B51360F031BFB4

File PE Metadata
Compilation timestamp:
3/25/2015 2:19:54 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
49152:jd9zuD1k9KOEBGlW5SeYyBoaTXpSkLQF7Jz4nmeXt0:59W1xIW59YyBodl

Entry address:
0x119810

Entry point:
E8, D2, 10, 01, 00, E9, 7F, FE, FF, FF, CC, CC, CC, CC, CC, CC, 57, 56, 8B, 74, 24, 10, 8B, 4C, 24, 14, 8B, 7C, 24, 0C, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, 68, 03, 00, 00, 0F, BA, 25, A4, 6D, 5A, 00, 01, 73, 07, F3, A4, E9, 17, 03, 00, 00, 81, F9, 80, 00, 00, 00, 0F, 82, CE, 01, 00, 00, 8B, C7, 33, C6, A9, 0F, 00, 00, 00, 75, 0E, 0F, BA, 25, 48, AE, 59, 00, 01, 0F, 82, DA, 04, 00, 00, 0F, BA, 25, A4, 6D, 5A, 00, 00, 0F, 83, A7, 01, 00, 00, F7, C7, 03, 00, 00, 00, 0F, 85, B8, 01, 00, 00...
 
[+]

Code size:
1.3 MB (1,317,888 bytes)

The file utility.exe has been discovered within the following program.

Crossbrowse  by CLARALABSOFTWARE
87% remove it
 
Powered by Should I Remove It?

The file utility.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to unallocated.barefruit.co.uk  (92.242.140.20:80)

TCP (HTTP):
Connects to hwcdn.net  (69.16.175.10:80)

Remove utility.exe - Powered by Reason Core Security