updateatuzi.exe

AtuZi

Part of the Yontoo web browser plugin (delivers advertisements to the web browser in the form of injected banners, text-links, popups, etc.) the updater mechanism for AtuZi will automatically keep the extension patched by downloaded new functionality which is auto-enabled by default. The application updateatuzi.exe by AtuZi has been detected as adware by 8 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “Update AtuZi”. This file is typically installed with the program AtuZi by Yontoo Technology, Inc. which is a potentially unwanted software program. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
AtuZi  (signed and verified)

Version:
1.0.5317.20831

MD5:
8f5aa838fb2e99f35a94d5f42dc57c5d

SHA-1:
04334cd571e5d0dbaffd32cc2dbe889899dd4df5

SHA-256:
a7c1a2b79f32d84c84f8b702c5896031f493d2de0a3231743450a534ee2a472d

Scanner detections:
8 / 68

Status:
Adware

Explanation:
Part of the Yontoo adware web browser extension update process.

Analysis date:
4/26/2024 4:29:53 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Generic
2015.0.3404

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.14723

ESET NOD32
Win32/BrowseFox.H potentially unwanted application
7.0.302.0

IKARUS anti.virus
PUA.BrowseFox
t3scan.1.6.1.0

Malwarebytes
PUP.Optional.AtuZi.A
v2014.07.23.10

Reason Heuristics
Adware.Yontoo.AtuZi.L
14.7.23.21

Sophos
Browse Fox
4.98

VIPRE Antivirus
Threat.4741131
31208

File size:
314.3 KB (321,816 bytes)

Product version:
1.0.5317.20831

Original file name:
AtuZi.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\atuzi\updateatuzi.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
4/17/2014 2:00:00 AM

Valid to:
4/18/2015 1:59:59 AM

Subject:
CN=AtuZi, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=AtuZi, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1095EBEC0EFD96E9E4C801DCA0909C26

File PE Metadata
Compilation timestamp:
7/23/2014 2:34:37 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:lRFBn8Ek5h+P3VkvOcrGDq1lntMs7THWx86FpbWAwIq:lRFBdkyP3nqxt+YzIq

Entry address:
0x4E596

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 02, 00, 10, 00, 00, 00, 20, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
305.5 KB (312,832 bytes)

Service
Display name:
Update AtuZi

Type:
Win32OwnProcess


The file updateatuzi.exe has been discovered within the following program.

AtuZi  by Yontoo Technology, Inc.
AtuZi is an web browser advertisement injection extension that is designed with the core purpose of delivering ads to the user's web browser. Ads are in the form of banners (both static and videos) as well as context-hyper links.
a-tu-zi.com/support
80% remove it
 
Powered by Should I Remove It?

Remove updateatuzi.exe - Powered by Reason Core Security