updateatuzi.exe

AtuZi

Part of the Yontoo web browser plugin (delivers advertisements to the web browser in the form of injected banners, text-links, popups, etc.) the updater mechanism for AtuZi will automatically keep the extension patched by downloaded new functionality which is auto-enabled by default. The application updateatuzi.exe by AtuZi has been detected as adware by 3 anti-malware scanners. This file is typically installed with the program AtuZi by Yontoo Technology, Inc. which is a potentially unwanted software program. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
AtuZi  (signed and verified)

Version:
1.0.5220.25936

MD5:
6c775ecbb23ca6ac874f3e65c0ea24e4

SHA-1:
33450091633870dfddcb0d463daaf1530a6e2c34

SHA-256:
c31bde355b2635fd1e9164743664b104bf9eec5ebc46ad4773101b87f4dba7ec

Scanner detections:
3 / 68

Status:
Adware

Explanation:
Part of the Yontoo adware web browser extension update process.

Analysis date:
4/24/2024 11:09:12 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Dr.Web
Trojan.BPlug.35
9.0.1.0113

ESET NOD32
Win32/BrowseFox (variant)
8.9710

Reason Heuristics
Adware.Yontoo.AtuZi.L
14.7.7.15

File size:
342.3 KB (350,488 bytes)

Product version:
1.0.5220.25936

Original file name:
AtuZi.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\atuzi\updateatuzi.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
4/17/2014 3:00:00 AM

Valid to:
4/18/2015 2:59:59 AM

Subject:
CN=AtuZi, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=AtuZi, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1095EBEC0EFD96E9E4C801DCA0909C26

File PE Metadata
Compilation timestamp:
4/17/2014 6:24:48 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:657x5C4x/EA65yhKYxcv418WvxeVzN+s+X+vVP5eMbDzj+DgE91fDpd+g2bcobbn:65t5u904KgE917pb2bX51

Entry address:
0x5556E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.0850

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
333.5 KB (341,504 bytes)

The file updateatuzi.exe has been discovered within the following program.

AtuZi  by Yontoo Technology, Inc.
AtuZi is an web browser advertisement injection extension that is designed with the core purpose of delivering ads to the user's web browser. Ads are in the form of banners (both static and videos) as well as context-hyper links.
a-tu-zi.com/support
80% remove it
 
Powered by Should I Remove It?

Remove updateatuzi.exe - Powered by Reason Core Security