updateatuzi.exe

AtuZi

Part of the Yontoo web browser plugin (delivers advertisements to the web browser in the form of injected banners, text-links, popups, etc.) the updater mechanism for AtuZi will automatically keep the extension patched by downloaded new functionality which is auto-enabled by default. The application updateatuzi.exe by AtuZi has been detected as adware by 6 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “Update AtuZi”. This file is typically installed with the program AtuZi by Yontoo Technology, Inc. which is a potentially unwanted software program. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Remove updateatuzi.exe - Powered by Reason Core Security
Publisher:
AtuZi  (signed and verified)

Version:
1.0.5273.23275

MD5:
04b2b305d92d95451228fec0d83ca325

SHA-1:
41bfcaf0dfa5dd0888d5527becd87e834e4925b7

SHA-256:
2b111acd175269201981e278c2f2d16e32c24e0d3d3a7f21ba6a033300baed0b

Scanner detections:
6 / 68

Status:
Adware

Explanation:
Part of the Yontoo adware web browser extension update process.

Analysis date:
12/5/2016 3:30:22 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Generic
2015.0.3448

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.14610

ESET NOD32
Win32/BrowseFox (variant)
8.9920

Malwarebytes
PUP.Optional.AtuZi.A
v2014.06.10.11

Reason Heuristics
Adware.Yontoo.Service.L
14.7.7.15

VIPRE Antivirus
Yontoo
30142

Remove updateatuzi.exe - Powered by Reason Core Security
File size:
310.3 KB (317,720 bytes)

Product version:
1.0.5273.23275

Original file name:
AtuZi.exe

File type:
Executable application (Win32 EXE)

Language:
Turkish (Turkey)

Common path:
C:\Program Files\atuzi\updateatuzi.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
4/17/2014 3:00:00 AM

Valid to:
4/18/2015 2:59:59 AM

Subject:
CN=AtuZi, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=AtuZi, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1095EBEC0EFD96E9E4C801DCA0909C26

File PE Metadata
Compilation timestamp:
6/9/2014 4:56:05 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:J0Bn87bD6J/fTudG1AkZwurpPWZopG8U1WkubLO/:J0BqbDqfTudG16JoWD/

Entry address:
0x4D5BA

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 02, 00, 10, 00, 00, 00, 20, 00, 00, 80, 18, 00, 00, 00, C8, 02, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 01, 00, 01, 00, 00, 00, 38, 00, 00, 80, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
301.5 KB (308,736 bytes)

Service
Display name:
Update AtuZi

Type:
Win32OwnProcess


The file updateatuzi.exe has been discovered within the following program.

AtuZi  by Yontoo Technology, Inc.
AtuZi is an web browser advertisement injection extension that is designed with the core purpose of delivering ads to the user's web browser. Ads are in the form of banners (both static and videos) as well as context-hyper links.
a-tu-zi.com/support
80% remove it
 
Powered by Should I Remove It?

Remove updateatuzi.exe - Powered by Reason Core Security