Tuto4PC.com

Publisher Information

Tuto4PC.com is a software developer located in Paris, Ile-De-France in France*. The company is a primary distributor of unwanted software. Tuto4PC creates video tutorials in Spanish of common popular software products but wraps the installer with potentailly unwanted adware including web browser extensions, toolbars and utilities. Thre are 4 additional code signing certificates issued to this publisher.
Remove Tuto4PC.com Malware - Powered by Reason Core Security
Authority:
GlobalSign nv-sa

Valid from:
11/5/2013 5:27:40 PM

Valid to:
11/6/2014 5:27:40 PM

Subject:
E=contact@tuto4pc.com, CN=Tuto4PC.com, O=Tuto4PC.com, L=Paris, S=Ile-De-France, C=FR

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121dd93f3ac652f954c795b593955887e31

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Eorezo.Tuto4PC.Bundler (M), PUP.Eorezo.Tuto4PC (M)
100.00%

avast!
Win32:Adware-ASG [PUP]
58.00%

Dr.Web
Adware.Downware.3239
58.00%

AVG
Generic, Generic5, MalSign.Generic
58.00%

VIPRE Antivirus
Trojan.Win32.Generic, Tuto4PC, Threat.4150696, Threat.4895339
54.00%

Sophos
EoRezo Adware, PUA 'EoRezo Adware' (of type Adware)
54.00%

K7 AntiVirus
Adware
52.00%

K7 Gateway Antivirus
Adware
52.00%

Baidu Antivirus
Adware.Win32.Eorezo, Adware.Win32.EoRezo, Trojan.Win32.EoRezo, Trojan.Win32.StartPage, Adware.Win32.Tuto4PC
48.00%

McAfee Web Gateway
Artemis, Artemis!7B1B3FDB4E8F, Artemis!EB5749A541DC, Artemis!B8BFC6A74DA2, BehavesLike.Win32.Obfuscated.gc, RDN/Generic PUP.x!cqt
40.00%

1 / 68      (Adware)
mbot_in_26.exe  (271e62aa512bfb1931100a97d883658d)

1 / 68      (Adware)
gentlemjmbot_ibr.exe  (7bedb98c6a8e30e90233f75ee76e8fd2)

14 / 68    (Adware)
majfstfr.exe (FreeSoftToday)  (d7298c9267d91fb35f5d6c2555f4a367)

29 / 68    (Adware)
package_bueno_installer_multilang.exe (Bueno by Tuto4pc)  (b3f644e8c8c7d263cbb4337393bd55d0)

28 / 68    (Adware)
majfst_gentlemg.exe (m_gentle by FST)  (4ea09b8e9acd72c73daf7006f3b6f3fe)

1 / 68      (Adware)
fst-clinstaller.exe  (71e6109b69d1e1c85305c2582181928e)

17 / 68    (Adware)
majmbot_gentlefr.exe (MyBestOffersToday)  (18ac76c8e255533726ee9103b0ebd6c6)

12 / 68    (Adware)

30 / 68    (Adware)

1 / 68      (Adware)
gentlemjmbot_ifr.exe  (eeba255a270932a8c0c76836b78ff51e)

15 / 68    (Adware)

28 / 68    (Adware)
package_block_installer_multilang.exe (Block by Software)  (ade94ea5fa437c31c5e7376929eb412e)

32 / 68    (Adware)
majfst_gentlegb.exe (m_gentle by FST)  (61e36dfd3def18b248e527e87817747d)

17 / 68    (Adware)
majfst_gentlefr.exe (m_gentle by FST)  (b5ead065728754f7be4cadffa63a5a57)

1 / 68      (Adware)
upfst_br_361.exe  (e51ec36762a96eeffb930c531f5d322e)

1 / 68      (Adware)
freesofttoday_widget.exe  (f229441f027eed4a300125fe6d30c744)

1 / 68      (Adware)
upfst_br_369.exe  (c7eb3b3b74ab01ec1c5ec71a45bfec86)

11 / 68    (Adware)

1 / 68      (Adware)
mbot_it_27.exe  (4ba7c00b6ea213448f1c4e46ebd0f00c)

34 / 68    (Adware)

11 / 68    (Adware)

32 / 68    (Adware)

29 / 68    (Adware)

11 / 68    (Adware)

28 / 68    (Adware)
package_block_installer_multilang.exe (Block by Software)  (73d85c3627d59c1684308cd7e6258bb7)

11 / 68    (Adware)

27 / 68    (Adware)
majmbot_gentlebr.exe (MyBestOffersToday)  (d7787e09258702992c094cf15f4e6257)

10 / 68    (Adware)

10 / 68    (Adware)

12 / 68    (Adware)

 
Latest 30 of 6,071 files

Top-level domains owned by Tuto4PC.com.

The certificates below are also signed by Tuto4PC.com.

0080441F3BE38CD527  (Feb 19, 2015 to Feb 19, 2016)

00849AA7E7D18F1566  (Dec 23, 2014 to Dec 23, 2015)

11214E18677190942D49073E30C52D17C351  (Oct 27, 2014 to Dec 07, 2015)

11217A044D9875AB5200314888C39C5486EF  (Oct 27, 2011 to Oct 27, 2013)

The following publishers (by Authenticode signature organization name) are related.

Remove Tuto4PC.com Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to Tuto4PC.com by GlobalSign nv-sa on November 05, 2013 with the serial number '1121dd93f3ac652f954c795b593955887e31'.