Utatity virus: what it is and how to remove it
Utatity (alternative name Utatity not Utility) is the name of an adware-type application developed by Software Informer in 2016. Since it's release, many people expressed concern on various forums about the legitimacy of the tool and its actual purpose.
Facts checked October 6, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
A scan of the PC is a quick way to confirm that nothing installed is behind the search.safefinder.com redirects.
Do it yourself · free Remove Utatity virus yourself 4 steps, about 12 minutes, no software needed.
Start the steps
Utatity virus: summary
| Detection names | No Microsoft detection name is known |
|---|---|
| Distribution | Not recorded in the old report |
| Damage | Not recorded in the old report |
| Name | Utatity virus |
| Type | Adware extension |
| Symptoms | Redirects to an unknown domain |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 6 more facts
| Evidence | 6 write-ups by security sites; details still limited |
|---|---|
| Domains | search.safefinder.com |
| Ads shown as | Redirects through ad pages |
| Browsers | Chrome, Edge and Firefox |
| First seen | 3 June 2020 |
| Facts checked | 6 October 2026 |
Is Utatity virus dangerous?
From our report of Jun 2020 · not reviewed since
Utatity - an adware-type application that generates intrusive ads and actively promotes PUPs
Utatity (alternative name Utatity not Utility) is the name of an adware-type application developed by Software Informer in 2016.
Since it's release, many people expressed concern on various forums about the legitimacy of the tool and its actual purpose. Although the program has a direct download website, it's not introduced in a proper way, except a download link provided and a bunch of recommended installers, including UltimateZip 2007, CompanyLogoDesigner, Magic-i, Sleepy Sound, Convertdoconline, and others.
According to experts, this application belongs to the group of Potentially Unwanted Programs (PUPs) and adware. The grounds of the classification are the following:
In fact, the Utatity virus is the most common reference to this application because typically it settles down on machines without asking for the user's permission explicitly and starts running a suspicious utatity.exe file in Task Manager.
Besides, people claim that the emergence of this tool among Apps and Programs folder triggered a massive flow of popups marked as "Utatity ads." In most of the cases, these ads promote unknown applications, software downloads, or commercial content that is prepared on the bases of people's web browsing history.
Utatity virus is an invasive software that computer users often find on their computers without even downloading it. After a silent infiltration of the system via freeware bundles, the virus modifies Windows Registry and may possibly add several browser extensions to web browsers to change your homepage (most likely to search.safefinder.com, which produces a lot of sponsored search results) and become able to display intrusive advertisements using your web browsers.
The performance of this application may be highly disruptive as it may send pop-up ads, banners (injected into websites that you visit), interstitial ads, and similar content massively. Some of the ads may be marked as Utatity ads or have no label at all.
Nevertheless, they can easily be distinguished from the others as they tend to be more aggressive, i.e. cover the page completely or do not contain a close button. Moreover, most of them promote potentially unwanted programs, such as SearchYA.
Those who have the Utatity app installed on the machine should understand that none of the displayed ads originate from the websites accessed intentionally. These ads are generated by third-party advertising servers that are used for increasing pay-per-click revenue.
In general, Utatity adware is a potentially unwanted program (PUP) , which aims to make a profit by flooding your computer with third-party ads. It's affiliate put much effort to make the adds appealing, thus increasing the chances that the visitor will click in them. Unfortunately, pay-per-click type revenue is not the sole purpose of this tool.
Utatity virus is also used for promoting other unwanted applications, most of which fall for the category of potentially unwanted programs (PUPs) and adware. It may regularly reroute web browser to the utatity.software.informer.com or other misleading download sites to make you install other intrusive programs. Therefore, it's advisable to get rid of this application ASAP.
On top of the pile of problems it causes, we can add another intolerable feature. It appears that Utatity redirect virus collects various information regarding your browsing habits and stores it on its servers.
Later on, it uses such data for market research and also looks at this information to select targeted ads for you. Although this annoying program cannot collect personally-identifiable data, it can harvest IP address, your geolocation details, search queries, browsing history data, information about browser type and OS version you use.
Thus, to recover your PC and protect privacy, we strongly recommend you to remove Utatity virus from your machine. You can use a professional anti-malware application for that or follow the step-by-step tutorial that will explain how to get rid of it manually.
Upon Utatity removal, use or similar repair utility to revert the changes within Windows Registry and other locations. Recovery of the system is not a must, though it's highly advisable because unwanted programs insert multiple files and eventually cache the machine.
- The application is distributed bundled with freeware;
- Typically, it's a pre-selected additional option disguised under Express installation option;
- Upon infiltration, it rewrites default settings of the browser and injects extensions powered by Utatity Software Informer;
- It generates intrusive ads and triggers the browser's redirects to irrelevant websites;
- It may take advantage of cookies and web beacons to harvest browsing histories.


From our report of Jun 2020 · not reviewed since
PUPs do not require users' permission for the installation explicitly
If you haven't installed a particular application, it means that your PC lacks protection and you are not well-informed about spyware/malware distribution methods.
PUPs (adware, browser hijacker, and similar) are usually circulating on the Internet as freeware components.
Useful-looking download managers, converters, or players spread on third-party download sites tend to contain at least two or three additional installers. Each of them can be seen and deselected; however, most people are not determined to spend more time on freeware installation and opt for Express installation option, which does not disclose pre-selected components. The installation of unwanted tools is granted by default just by clicking the Next button.
If you wish to go around shady software marketing techniques, rely on Custom/Advanced settings , which will let you choose to install or not to install suggested additional third-party software. In other words, you need to decompose software bundles via Advanced or Custom settings if you do not want to install junkware into your computer system without realizing it.

From our report of Jun 2020 · not reviewed since
More from our earlier report on Utatity virus
- PUP or adware, which may have traits of a browser hijacker
- To promote suspicious third-party software (PUPs and malware mainly)
- The presence of this adware may manifest with "Ads by Utatity" or similar intrusive browser-based content.
- It may also enable an extension that replaces the start page and search provider to Safe Finder.
- We strongly recommend using an automated software utility to get rid of this malware.
- Eliminating it manually may be difficult due to multiplicity of related files and processes
Check your browser and PC
- Address:
search.safefinder.com
How to remove Utatity virus
How to remove the Utatity virus extension
Do the browser steps in every browser and profile on the PC, then check Windows for the program that installed the extension.
Step 1: Remove extensions you did not add
Utatity virus often works through an extension, so go through the extension list of each browser:
chrome://extensionsedge://extensions- Extensions and themes in Firefox
Switch suspicious extensions off one at a time and reload the page where the problem shows, then remove the one that stops it, and any other you did not add.
Remember the other browsers and profiles on the PC. If Remove is missing or greyed out, a policy forces the extension, which the policy step deals with. Windows 11 and Windows 10 show the same pages.

Chrome on Windows 11: More > Extensions > Manage extensions. Full procedure with screenshots: Remove a browser extension
Step 2: Uninstall programs you did not mean to install
Open Settings > Apps > Installed apps in Windows 11, or Settings > Apps > Apps & features in Windows 10, and sort the list by install date. Look at what appeared around the day the problem started and uninstall every program you do not recognise or did not choose.
Free converters, PDF and video tools, "system optimizers" and unknown browsers are the usual carriers of Utatity virus. If a name is unclear, search for it before you remove it, so you do not uninstall a driver or a Windows component.
Full procedure with screenshots: Uninstall a program or app in Windows On uGetFix
Step 3: Reset the browser
Finish the browser part with a reset, which puts the search engine, start page, new tab page and site permissions back to their defaults and switches extensions off. Chrome: Settings > Reset settings > Restore settings to their original defaults.
Edge: Settings > Reset settings. Firefox: Help > More troubleshooting information > Refresh Firefox, which also removes its extensions. Your bookmarks and saved passwords are kept, and the menus are the same on Windows 11 and Windows 10.

Chrome on Windows 11: Settings > Reset settings. Full procedure with screenshots: Reset a browser and fix a hijacked search engine
Step 4: Scan the PC, then run the offline scan
Open Windows Security > Virus & threat protection > Scan options, run a Full scan and remove everything it finds. Then select Microsoft Defender Antivirus (offline scan) and click Scan now: the PC restarts and scans before Windows loads, which finds files that hide while Windows runs.
Save your work first, because the offline scan takes about 15 minutes. Both scans are built into Windows 11 and Windows 10, and a second scanner from another vendor is a useful extra opinion.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Instructions for each browser and system
The detailed steps for every browser and system this guide covers. Open the one you use.
Uninstall from Windows
You will find UTATITY in the Add/Remove Programs panel (look at instructions how to open it below). This infection typically displays two stars - ** in the Publisher field. Uninstall it, and also uninstall SafeFinder and all suspicious programs that were installed around the same time when these two programs entered your system. You might encounter issues when trying to uninstall Utatity. In such case, do the following: Find these keys: Be careful. You will need to alter Windows Registry. In Windows search, type regedit and launch the identically named program that will appear in search results. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall; HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall; Export the list and save it, for example, on Desktop. Open it with Notepad and search for keyword DisplayVersion and delete all suspicious-looking entries that have 1.00.00 version or Utatity name. Read the information carefully - you should find the directory where these files/programs are located. Go there and delete them. NOTE. If you do not understand these instructions, better do not try to carry them out. Simply employ a powerful spyware removal tool and delete UTATITY automatically.
Uninstall from Windows 10/8:
- Type Control Panel into the Windows search box and open the result.
- Under Programs, select Uninstall a program.

Uninstall from Windows 7/XP:
- Click on Windows Start > Control Panel (Windows XP users should click on Add/Remove Programs).
- In Control Panel, select Programs > Uninstall a program.

Remove the unwanted program:
- In the Programs and Features window, look for any recently installed suspicious entries, select them, and click Uninstall.
- If User Account Control appears, click Yes to confirm, then complete the removal.

Remove from Google Chrome
In Chrome, delete all questionable extensions and reset homepage/search engine parameters if they have been modified by SafeFinder or another potentially unwanted program.
Delete malicious extensions from Google Chrome:
- Open Google Chrome, click on the Menu (three vertical dots at the top-right corner) and select More tools > Extensions.
- In the newly opened window, you will see all the installed extensions. Uninstall all suspicious extensions related to the unwanted program by clicking Remove.

Clear cache and web data from Chrome:
- Click on Menu and pick Settings.
- Under Privacy and security, select Clear browsing data.
- Select Browsing history, Cookies and other site data, as well as Cached images and files.
- Click Clear data.

Change your homepage:
- Click menu and choose Settings.
- Look for a suspicious site in the On startup section.
- Click on Open a specific or set of pages and click on three dots to find the Remove option.
Reset Google Chrome:
If the previous methods did not help you, reset Google Chrome to eliminate all the unwanted components:
- Click on Menu and select Settings.
- In the Settings, scroll down and click Advanced.
- Scroll down and locate Reset and clean up section.
- Now click Restore settings to their original defaults.
- Confirm with Reset settings.

Remove from Microsoft Edge
Delete unwanted extensions from MS Edge:
- Select Menu (three horizontal dots at the top-right of the browser window) and pick Extensions.
- From the list, pick the extension and click on the Gear icon.
- Click Remove.

Clear cookies and other browser data:
- Click on the Menu (three horizontal dots at the top-right of the browser window) and select Settings > Privacy, search, and services..
- Under Clear browsing data, pick Choose what to clear.
- Select Cookies and other site data and Cached images and files. (apart from passwords, although you might want to include Media licenses as well, if applicable) and click on Clear.

Restore new tab and homepage settings:
- Click the menu icon and choose Settings.
- Then find On startup section.
- Click Remove next to any suspicious startup page.
Reset MS Edge if the above steps did not work:
- Press on Ctrl + Shift + Esc to open Task Manager.
- Click on More details arrow at the bottom of the window.
- Select Details tab.
- Now scroll down and locate every entry with Microsoft Edge name in it. Right-click on each of them and select End Task to stop MS Edge from running.

Delete extensions from MS Edge (Chromium):
- Open Edge and click select Settings > Extensions.
- Delete unwanted extensions by clicking Remove.

Clear cache and site data:
- Click on Menu and go to Settings.
- Select Privacy, search and services.
- Under Clear browsing data, pick Choose what to clear.
- Under Time range, pick All time.
- Select Clear now.

Reset Chromium-based MS Edge:
- Click on Menu and select Settings.
- On the left side, pick Reset settings.
- Select Restore settings to their default values.
- Confirm with Reset.
- This will disable extensions and reset startup pages but will not delete bookmarks, saved passwords, or browsing history.

Remove from Mozilla Firefox (FF)
Remove dangerous extensions:
- Open Mozilla Firefox browser and click on the Menu (three horizontal lines at the top-right of the window).
- Select Add-ons.
- In here, select the unwanted extension and click Remove.

Reset the homepage:
- Click three horizontal lines at the top right corner to open the menu.
- Choose Settings.
- Under Home, set your preferred homepage and new tab settings.
Clear cookies and site data:
- Click Menu and pick Settings.
- Go to Privacy & Security section.
- Scroll down to locate Cookies and Site Data.
- Click on Clear Data...
- Select Cookies and Site Data and Temporary cached files and pages, then click Clear.

Reset Mozilla Firefox
If clearing the browser as explained above did not help, reset Mozilla Firefox:
- Open Mozilla Firefox browser and click the Menu.
- Go to Help and then choose Troubleshooting Information.

- Under Give Firefox a tune up section, click on Refresh Firefox...
- Once the pop-up shows up, confirm the action by pressing on Refresh Firefox.

Delete from Safari
Remove dangerous extensions:
- Open Safari, click Safari in the menu at the top-left of the screen, and select Preferences.
- Go to the Extensions tab, look for any suspicious entries, and click Uninstall to remove them.

Clear history and website data:
- Click Safari in the menu and pick Clear History.
- Set Clear to all history and confirm with Clear History.

Reset Safari:
- Click Safari in the menu and select Preferences > Advanced.
- Enable Show Develop menu in menu bar.
- From the menu bar, click Develop and select Empty Caches.

Delete from macOS
Remove the unwanted application:
- From the menu bar, select Go > Applications.
- In the Applications folder, look for any suspicious entries, then drag them to Trash (or right-click and pick Move to Trash).

Delete leftover files and folders:
- Select Go > Go to Folder.
- Enter /Library/Application Support and remove any suspicious folders related to the unwanted program.
- Repeat the same check in the /Library/LaunchAgents and /Library/LaunchDaemons folders, deleting any suspicious entries.

- Finally, empty the Trash to permanently remove the leftovers.
Reset Internet Explorer
Remove dangerous add-ons:
- Open Internet Explorer, click on the Gear icon (IE menu) on the top-right corner of the browser
- Pick Manage Add-ons.
- You will see a Manage Add-ons window. Here, look for suspicious plugins. Click on these entries and select Disable.

Change your homepage if it was altered:
- Open IE and click on the Gear icon.
- Select Internet Options.
- In the General tab, delete the Home page address and replace it by your preferred one (for example, Google.com).
- Click Apply and then select OK.

Delete temporary files:
- Press on the Gear icon and select Internet Options.
- Under Browsing history, click Delete...
- Select relevant fields and press Delete.

Reset Internet Explorer:
- Click on Gear icon > Internet options and select Advanced tab.
- Select Reset.
- In the new window, check Delete personal settings and select Reset.

Stream videos without limitations, no matter where you are
There are multiple parties that could find out almost anything about you by checking your online activity.
While this is highly unlikely, advertisers and tech companies are constantly tracking you online. The first step to privacy should be a secure browser that focuses on tracker reduction to a minimum.
Even if you employ a secure browser, you will not be able to access websites that are restricted due to local government laws or other reasons. In other words, you may not be able to stream Disney+ or US-based Netflix in some countries. To bypass these restrictions, you can employ a powerful VPN, which provides dedicated servers for torrenting and streaming, not slowing you down in the process.
Data backups are important - recover your lost files
Ransomware is one of the biggest threats to personal data.
Once it is executed on a machine, it launches a sophisticated encryption algorithm that locks all your files, although it does not destroy them. The most common misconception is that anti-malware software can return files to their previous states. This is not true, however, and data remains locked after the malicious payload is deleted.
While regular data backups are the only secure method to recover your files after a ransomware attack, tools such as can also be effective and restore at least some of your lost data.
From our report of Jun 2020 · not reviewed since
Take advantage of the professional anti-malware to remove Utatity adware
As we have previously mentioned, it can be hard to remove Utatity virus manually - you will need to configure some settings in Windows Registry and get rid of the whole PUP bundle simultaneusly.
It lets you delete all critical programs at once, whereas removing PUPs and viruses manually may take a lot more time.
SafeFinder and all suspicious programs that were installed around the same time when these two programs entered your system.
You might encounter issues when trying to uninstall Utatity. In such case, do the following:
NOTE. If you do not understand these instructions, better do not try to carry them out. Simply employ a powerful spyware removal tool and delete UTATITY automatically.
SafeFinder or another potentially unwanted program.
- Find these keys:
- Be careful. You will need to alter Windows Registry. In Windows search, type regedit and launch the identically named program that will appear in search results. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall; HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall;
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall;
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall;
- Export the list and save it, for example, on Desktop. Open it with Notepad and search for keyword DisplayVersion and delete all suspicious-looking entries that have 1.00.00 version or Utatity name. Read the information carefully - you should find the directory where these files/programs are located. Go there and delete them.
Questions about Utatity virus
Why does my browser keep going to search.safefinder.com?
Something is sending it there. On one site only, that site's ads are the cause and leaving the site ends it.
On many different sites, the usual causes are an extension you installed with something else, a site you once allowed to send notifications, or an ad-supported program in Windows that changes how the browser behaves. search.safefinder.com itself is only a stop on the way: it records the visit and forwards you to whatever advertiser pays most.
Check the extensions page, then the list of sites allowed to send notifications, then Installed apps sorted by date. Removing the cause stops the redirects; blocking the domain alone usually does not, because the network moves to a new one.
Did search.safefinder.com install a virus on my PC?
Very unlikely, unless you downloaded and opened something from the pages it led to. Redirect domains such as search.safefinder.com sell your visit to advertisers; they do not need to install anything to make money.
What can be installed is the thing that causes the redirects in the first place, such as an extension or an ad-supported program that came with free software. That is why the checks in this guide look at extensions, notification permissions and Installed apps.
A full scan with Microsoft Defender afterwards gives you a clear answer about the rest of the PC. If the scan is clean and the redirects stop after removing the cause, you are done.
What is Utatity virus?
Utatity virus is an adware extension, a kind of adware. It earns money by showing redirects through ad pages, and each view, click or redirect pays whoever runs it. It is not something people usually choose; it arrives through a free download, a fake button or a misleading prompt.
Utatity virus does not encrypt files or take control of Windows, but its ads are sold to anyone, including scam operators, so they can lead to fake virus warnings and unwanted downloads. The steps in this guide remove it from Windows and from each browser.
Which browsers does Utatity virus affect?
In the cases we checked, Utatity virus showed up in Chrome, Edge and Firefox. That does not rule out others on your PC, since adware installers often target every browser they find, and permissions and extensions sync across computers signed in to the same browser account.
Open each browser you have, go to its extensions page and its notification settings, and remove anything you do not recognise. Profiles count separately: Chrome and Edge can each hold several, and each one needs checking on its own.
Are the pop-ups I see really from Utatity virus?
Compare them with the details in the table above. Utatity virus produces redirects through ad pages, and the clearest sign of it is redirects to search.safefinder.com. Other adware looks similar, so check the name of the sending site at the bottom of a notification, the address in the tab that opened, or the newest entries on the extensions page.
If those match, this guide fits. If you see a different name, the same kind of steps apply, but remove the item you actually find rather than guessing.
Can an adware pop-up infect my PC just by appearing?
No. A pop-up, a notification or a new tab is only a web page or a message. It cannot run programs on Windows by itself, provided the browser and Windows are up to date. Infection needs a step from you:
- running a downloaded file
- installing an extension
- giving a stranger remote access
That is why scam pages work so hard to make you click. Close such pages with the tab's X or by closing the browser, not with buttons inside the page, which may start a download.
Did Utatity virus collect my data?
Adware typically collects what it needs to choose ads:
- the sites you visit
- search terms
- approximate location
- browser and system details
Extensions with permission to read and change data on all websites can technically see everything on those pages, including forms. That is a privacy problem rather than proof of theft.
If you typed card details or passwords while it was active, changing the most important passwords is a reasonable precaution. Clearing cookies after removal ends the tracking sessions it may have started.
I let a "support technician" from an ad connect to my PC. What should I do?
Act quickly but calmly. Disconnect the PC from the internet first, so the connection ends. Uninstall the remote access tool they asked you to install and check Installed apps for anything else added during the call.
Run a Microsoft Defender full scan and offline scan. From another device, change your e-mail and banking passwords and sign out of all sessions.
If you paid by card, bank transfer or gift card, contact your bank or the card issuer immediately, and report the scam to the police. Do not answer if they call back.
My scan found nothing, but the ads continue. Why?
Because the source may not be a file a scanner looks for. Browser notifications are a permission stored in the browser, and many adware extensions are not flagged because they come from an official store.
Some ad-supported programs are only reported if you enable detection of potentially unwanted apps. So a clean scan does not mean the job is done. Check each browser's notification permissions and extension list by hand, and turn on Potentially unwanted app blocking in Windows Security before scanning again.
Will Fortect remove Utatity virus?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For Utatity virus, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- Wikipedia, the free encyclopedia: Pay-per-click (read October 6, 2026)
- How-To Geek: Defend Your Windows PC From Junkware: 5 Lines of Defense (read October 6, 2026)
- Google Chrome Help: Use notifications to get alerts (no longer online) (read October 6, 2026)
- FTC: How to recognize, remove and avoid malware (read October 6, 2026)
- Microsoft Learn: Microsoft Defender Offline (read October 6, 2026)