WINUTIL3.dll

WINUTIL3

Capital Intellect Inc

The module WINUTIL3.dll by Capital Intellect Inc has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Capital Intellect Inc  (signed and verified)

Product:
WINUTIL3

Description:
WINUTL3

Version:
2005.03.0017

MD5:
8360480cb730cc36604123423ad02fb1

SHA-1:
15e5867ff5635c3d4956951ce4dfa9ac4aa25aee

SHA-256:
4267203f84eea50eafea8ffd0fe3b4d4b7672a0e049a47f485a86f442e39b2a3

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/28/2024 11:14:12 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Win32.Generic
16.6.29.9

File size:
450.1 KB (460,944 bytes)

Product version:
2005.03.0017

Copyright:
Copyright (c) 2002-2005. Capital Intellect Inc. All Rights Reserved.

Trademarks:
Copyright (c) 2002-2005. Capital Intellect Inc. All Rights Reserved.

Original file name:
WINUTIL3.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\windows\syswow64\winutil3.dll

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/9/2005 8:00:00 PM

Valid to:
6/10/2006 7:59:59 PM

Subject:
CN=Capital Intellect Inc, OU=Winferno Software, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Capital Intellect Inc, L=Boston, S=Massachusetts, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
73F02771770397365C7AA841E5C43539

File PE Metadata
Compilation timestamp:
11/7/2005 4:40:36 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:GBawg1D65UdwIxOA49eKtRI/gwZXS9riE7mgZSiaJjTUnHf1hj1+Ega:ug1gqrKtWgpriYfa5A/1hJga

Entry address:
0x6CA0

Entry point:
5A, 68, CC, 0B, 9A, 16, 68, D0, 0B, 9A, 16, 52, E9, E7, FF, FF, FF, 00, 00, 00, 48, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 29, 47, 0E, C0, 33, A4, 9F, 40, 90, C1, 95, 81, 00, 5A, C8, DC, 00, 00, 00, 00, 00, 00, 02, 00, 00, 00, 00, 00, 00, 00, 00, 00, 57, 49, 4E, 55, 54, 49, 4C, 33, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, B0, 00, 00, 00, 90, 00, 00, 00, 00, 00, 00, 00, 02, 00, 00, 00, 1E, 00, 00, 00, D8, A9, 15, E6, AD, 2F, 32, 47, 80, 3C, FF, B2, 1C, A1, EA, EF...
 
[+]

Entropy:
6.1765

Developed / compiled with:
Microsoft Visual Basic v6.0

Code size:
360 KB (368,640 bytes)

Remove WINUTIL3.dll - Powered by Reason Core Security