How to Remove “utilman.exe”

What is utilman.exe?

utilman.exe is a legitimate file popularly known as UtilMan EXE. It belongs to Windows Operating System developed by Microsoft Corporation. It is typically located in C:\Windows\System32. Malware programmers create files with virus scripts and name them after utilman.exe with an intention to spread virus on the internet.

Affected Platform: Windows OS

How to check if your computer is infected with utilman.exe malware?

Keep an eye for the following symptoms to see if your PC is infected with utilman.exe malware:

  • Internet connection fluctuates
  • utilman.exe takes too much CPU space
  • PC slows down significantly
  • Browser automatically redirects to some irrelevant websites
  • Unsolicited ads and popups starts appearing
  • Screen freezes constantly

Take the following steps to diagnose your PC for possible utilman.exe malware attack:

Step 1: Download the award-winning Free Internet Security.

Step 2: Installation configuration frames will be displayed. Select the configuration you would like to apply.

Step 3: After network detection is complete, press “Close” button for a scan window.

Step 4: Restart your PC.

Step 5: It will take some time for the Comodo Internet Security to update the antivirus.

Step 6: Proceed with a quick scan that automatically begins after the update.

Step 7: If threats are found during the scanning, you will be prompted with an alert screen.

Step 8: Comodo Antivirus will remove the utilman.exe virus from your computer including all other malwares!

29

Malware Entries

First Seen: 19 January 2011 at 11:34 pm
No. Company File Type SHA1 MD5 Malware
Name
Digitally
Signed
File
Version
Product
Version
Submitted
From
Malware Behavior
1 Microsoft Corporation Executable 9ea032f03ee4647b
44d2e741ce014add
bb3ba574
2b5a3d6758a51cfd
6353de14c429b9e2
Virus.Win32.
Virut.CE
No 6.1.7600.1
6385
(win7_rtm.
090713-125
5)
6.1.7600.1
6385
Australia N/A
2 Microsoft Corporation Executable a2289b26ef5abe4c
bd495c6443b5d291
c15f0b75
78d3f2273d3d175f
ecc6a468b08bbc96
TrojWare.Win
32.Agent.hvc
n
No 6, 1,
2112, 4137
6, 1,
2112, 4137
United States N/A
3 Microsoft Corporation Executable af5d5debe5c2becc
b3010cf468805fab
46b39824
cc4d2d5ab94ccb06
d4b6f257d14fd6b5
Virus.Win32.
Virut.CE
No 5.1.2600.5
512
(xpsp.0804
13-2105)
5.1.2600.5
512
Poland N/A
4 Microsoft Corporation Executable 3ccb54f0389cdb02
434fb94a88ea222d
f6a9efcc
1c424b7de16358d3
e37bfccff49aa1d4
Virus.Win32.
Virut.CE
No 5.1.2600.2
180
(xpsp_sp2_
rtm.040803
-2158)
5.1.2600.2
180
Poland N/A
Display 4 items per page
  • 4 items per page
  • 8 items per page
  • 16 items per page
  • 32 items per page
34

Safe Entries

First Seen: 10 June 2008 at 11:11 am
No. Company File Type SHA1 MD5 Digitally
Signed
File
Version
Product
Version
Submitted
From
1 Microsoft Corporation Executable e96f4e17f8752d5f
5d247dfcbf400a4b
b6ec7888
8a6868cd3093d318
f6a8f78f1b86680e
No 5.1.2600.5
512
(xpsp.0804
13-2105)
5.1.2600.5
512
Netherlands
2 Microsoft Corporation Executable 34e21796d09b631e
5de0dfe6b03ae40a
c2da43bb
970e01c0fd2ea786
69e5995d5ff70f35
No 5.1.2600.2
180
(xpsp_sp2_
rtm.040803
-2158)
5.1.2600.2
180
United States
3 Microsoft Corporation Executable 8f8d0aee344e1524
24143da49ce2c7ba
dabb8f9d
32c5ee55eadfc071
e57851e26ac98477
No 6.1.7600.1
6385
(win7_rtm.
090713-125
5)
6.1.7600.1
6385
Poland
4 Microsoft Corporation Executable 1d80a6a9186228be
9e0f3cd137a20338
b581eba2
7b9602d3475967f1
49c1a2c3e2b75a79
No 6.1.7600.1
6385
(win7_rtm.
090713-125
5)
6.1.7600.1
6385
Internal Submission
Display 4 items per page
  • 4 items per page
  • 8 items per page
  • 16 items per page
  • 32 items per page
 
Exclusive Offer
Get Free Endpoint Protection
Get Advanced
Endpoint
Protection

Award-Winning Security to Protect Your Clients from Cyber Attacks

Comodo Internet Security Pro

Free Antivirus protection from hackers! Get the ultimate Antivirus solution to keep your PC clean and to remove viruses from a slow or infected PC. Improve the PC performance at home or use it on-the-go!

Get Comodo Internet Security Comodo Internet Security