utilatuzi.exe

AtuZi

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The application utilatuzi.exe by AtuZi has been detected as adware by 14 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “Update AtuZi”. Additionally, the file is typically installed by a number of programs including AtuZi by Yontoo Technology, Inc. and Buzzdock by Alactro LLC, both potentially unwanted software. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
AtuZi  (signed and verified)

Version:
1.0.5354.10863

MD5:
7728fe9e11f1783da855d91a7bd04718

SHA-1:
34d9482ab5aa7afc247e12b90d58eb8b83a7cc58

SHA-256:
5ff4e5d5dc3a527295e7dc8b5834a56cc0a0c6a187aeb0c251b3e49f337b7aa7

Scanner detections:
14 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/26/2024 3:26:44 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
APPL/BrowseFox.Gen
7.11.170.24

avast!
Win32:BrowseFox-AF [PUP]
2014.9-140829

AVG
Generic
2015.0.3367

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.14829

Dr.Web
Trojan.BPlug.198
9.0.1.0241

ESET NOD32
Win32/BrowseFox (variant)
8.10337

F-Prot
W32/A-db42cb3b
v6.4.7.1.166

IKARUS anti.virus
PUA.BrowseFox
t3scan.1.7.5.0

Kaspersky
not-a-virus:HEUR:AdWare.MSIL.Kranet
14.0.0.3331

Malwarebytes
PUP.Optional.AtuZi.A
v2014.08.29.07

McAfee
Artemis!7728FE9E11F1
5600.7023

Reason Heuristics
PUP.AtuZi.J
14.8.29.19

Sophos
Browse Fox
4.98

VIPRE Antivirus
Yontoo
32658

File size:
315.8 KB (323,352 bytes)

Product version:
1.0.5354.10863

Original file name:
AtuZi.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\atuzi\bin\utilatuzi.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
4/17/2014 2:00:00 AM

Valid to:
4/18/2015 1:59:59 AM

Subject:
CN=AtuZi, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=AtuZi, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1095EBEC0EFD96E9E4C801DCA0909C26

File PE Metadata
Compilation timestamp:
8/29/2014 9:02:21 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:DffAzZ5HsFAfcP2P7DKld7oVPRN5wxItcVyXbUZbL:DffUlsnvx9kQ1L

Entry address:
0x4EB9E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 02, 00, 10, 00, 00, 00, 20, 00, 00, 80, 18, 00, 00, 00, C8, 02...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
307 KB (314,368 bytes)

Service
Display name:
Update AtuZi

Type:
Win32OwnProcess


The file utilatuzi.exe has been discovered within the following programs.

AtuZi  by Yontoo Technology, Inc.
AtuZi is an web browser advertisement injection extension that is designed with the core purpose of delivering ads to the user's web browser. Ads are in the form of banners (both static and videos) as well as context-hyper links.
a-tu-zi.com/support
80% remove it
Buzzdock  by Alactro LLC
This is a web browser extension that injects advertising. From the EULA: "Buzzdock is free to download and use. Buzzdock is supported by advertising, and users will see additional ads on websites where Buzzdock features operate.
www.buzzdock.com/faq-support
79% remove it
 
Powered by Should I Remove It?

Remove utilatuzi.exe - Powered by Reason Core Security