AtuZi

AtuZi

Known Adware

by Yontoo Technology, Inc.

What is AtuZi?

AtuZi is software application developed by Yontoo Technology, Inc.. It is most commonly found on computers running Windows 7 with nearly 64.12% of installations running this operating system. AtuZi's installer is typically 1.00 MB in size and installs around 12 files. The most common release is 2014.07.31.142942 with 1.59% of all installations currently using this version.

AtuZi is most popular in the United States with 26.73% of installations residing in this country.

About AtuZi?

AtuZi is a web browser advertisement injection extension designed to deliver ads to users while they browse online. These ads can take the form of banners (both static and videos) and context-hyper links. Typically bundled with 3rd party download managers, the program may include a number of additional offers, many of which are potentially unwanted programs (PUPs). The ads delivered by AtuZi are injected onto web pages at the software's discretion, extending beyond those affiliated with the software or its affiliates. The program also periodically connects to remote servers in order to download new ad feeds and reports back the domains and URLs visited by the user, as well as the links and advertisements clicked on while browsing the web.

Multiple virus scanners have detected malware in AtuZi.

updateAtuZi.exe (MD5: 623a76a8ee26ea6ba4a9ea9998575b67) has been flagged by 41 scanners:
Scanner Software Result
Lavasoft Ad-Aware Adware.SwiftBrowse.CO
Agnitum Outpost PUA.Kranet!
AhnLab-V3 PUP/Win32.BrowseFox
Antiy-AVL GrayWare[AdWare:not-a-virus,HEUR]/MSIL.Kranet
avast! Win32:BrowseFox-AF [PUP]
AVG Generic.095
Avira ADWARE/BrowseFox.Gen7
AVware Yontoo (fs)
Baidu-International Adware.Win32.BrowseFox.bG
Bitdefender Adware.SwiftBrowse.CO
CAT-QuickHeal AdWare.MSIL.r3 (Not a Virus)
Comodo Security UnclassifiedMalware
Dr.Web Trojan.BPlug.198
Emsisoft Anti-Malware Adware.SwiftBrowse.CO (B)
ESET-NOD32 a variant of Win32/BrowseFox.H
Fortinet FortiGate Adware/Kranet
F-Secure Adware.SwiftBrowse.CO
G Data Adware.SwiftBrowse.CO
K7 AntiVirus Unwanted-Program ( 004a8e8b1 )
K7GW Unwanted-Program ( 004a8e8b1 )
Kaspersky not-a-virus:HEUR:AdWare.MSIL.Kranet.heur
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.AtuZi.A
McAfee BrowseFox.c
McAfee-GW-Edition BrowseFox.c
MicroWorld-eScan Adware.SwiftBrowse.CO
NANO AntiVirus Riskware.Win32.BPlug.degvlq
nProtect Adware.SwiftBrowse.CO
Panda Antivirus Trj/Chgt.D
Qihoo-360 Win32/Virus.Adware.e4c
Sophos Browse Fox
Symantec Trojan.Gen
Tencent Win32.Trojan.Falsesign.Wlpi
Trend Micro TROJ_GEN.R0C1C0EKB14
TrendMicro-HouseCall TROJ_GEN.R0C1C0EKB14
VIPRE Antivirus Yontoo (fs)
Avira AntiVir APPL/BrowseFox.Gen2
Clam AntiVirus Win.Adware.Agent-7283
Jiangmin Adware/Agent.joq
SUPERAntiSpyware Adware.BrowseFox/Variant
Zillya Adware.Agent.Win32.9429
1EEA867E-C3C6-4C52-A91E-FD7E398E4E42.dll (MD5: ebeedf55b3c4c61c4c190a27eeafca18) has been flagged by 35 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.BHO.Agent.4
Agnitum Outpost PUA.Agent!
AhnLab-V3 Adware/Win32.Agent
Avira AntiVir APPL/BrowseFox.Gen2
Antiy-AVL GrayWare[AdWare:not-a-virus]/Win32.Agent
AVG BrowseFox.F
Baidu-International Adware.Win32.BrowseFox.BF
Bitdefender Gen:Variant.Adware.BHO.Agent.4
CAT-QuickHeal AdWare.Agent.r5 (Not a Virus)
Clam AntiVirus Win.Adware.Agent-7283
Comodo Security Application.Win32.Altbrowse.AK
Dr.Web Trojan.BPlug.31
Emsisoft Anti-Malware Gen:Variant.Adware.BHO.Agent.4 (B)
ESET-NOD32 a variant of Win32/BrowseFox.F
Fortinet FortiGate Adware/Agent
F-Secure Gen:Variant.Adware.BHO.Agent.4
G Data Gen:Variant.Adware.BHO.Agent.4
Jiangmin Adware/Agent.joq
K7 AntiVirus Unwanted-Program ( 00454f261 )
K7GW Unwanted-Program ( 00454f261 )
Kaspersky not-a-virus:AdWare.Win32.Agent.ahbx
Kingsoft AntiVirus Win32.Troj.Agent.ah.(kcloud)
Malwarebytes PUP.Optional.AtuZi.A
McAfee Artemis!EBEEDF55B3C4
McAfee-GW-Edition Artemis!EBEEDF55B3C4
MicroWorld-eScan Gen:Variant.Adware.BHO.Agent.4
NANO AntiVirus Riskware.Win32.Agent.czmzab
Panda Antivirus Trj/CI.A
Qihoo-360 Win32/Trojan.Adware.dbc
Sophos Browse Fox
SUPERAntiSpyware Adware.BrowseFox/Variant
Symantec Adware.Adpopup
TrendMicro-HouseCall Suspicious_GEN.F47V0616
VIPRE Antivirus Yontoo (fs)
Zillya Adware.Agent.Win32.9429
139E58AB-5590-44B8-AFB3-0DDBBC0CB66F.dll (MD5: 40194c1100fe6bb64355708c76f17b3e) has been flagged by 44 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.BHO.Agent.4
Agnitum Outpost PUA.Agent!
AhnLab-V3 Adware/Win32.Agent
Avira AntiVir APPL/BrowseFox.Gen2
Antiy-AVL GrayWare[AdWare:not-a-virus]/Win32.Agent
AVG BrowseFox.F
AVware Yontoo (fs)
Baidu-International Adware.Win32.BrowseFox.BF
Bitdefender Gen:Variant.Adware.BHO.Agent.4
CAT-QuickHeal AdWare.Agent.r5 (Not a Virus)
Clam AntiVirus Win.Adware.Agent-7283
Comodo Security Application.Win32.Altbrowse.AK
Dr.Web Trojan.BPlug.31
Emsisoft Anti-Malware Gen:Variant.Adware.BHO.Agent.4 (B)
ESET-NOD32 a variant of Win32/BrowseFox.F
Fortinet FortiGate Adware/Agent
F-Prot W32/BadBHO.AW.gen!Eldorado
F-Secure Gen:Variant.Adware.BHO.Agent.4
G Data Gen:Variant.Adware.BHO.Agent.4
Jiangmin Adware/Agent.joq
K7 AntiVirus Unwanted-Program ( 00454f261 )
K7GW Trojan ( 020000001 )
Kaspersky not-a-virus:AdWare.Win32.Agent.ahbx
Kingsoft AntiVirus Win32.Troj.Agent.ah.(kcloud)
Malwarebytes PUP.Optional.AtuZi.A
McAfee Artemis!40194C1100FE
MicroWorld-eScan Gen:Variant.Adware.BHO.Agent.4
NANO AntiVirus Riskware.Win32.Agent.czmzab
nProtect Trojan-Clicker/W32.Agent.249624.B
Panda Antivirus Trj/CI.A
Qihoo-360 Win32/Trojan.Adware.dbc
Rising Antivirus PE:Trojan.Win32.Generic.16D9E744!383379268
Sophos Browse Fox
SUPERAntiSpyware Adware.BrowseFox/Variant
Symantec Adware.Adpopup
TrendMicro-HouseCall Suspicious_GEN.F47V0610
Vba32 AntiVirus AdWare.Agent
VIPRE Antivirus Yontoo (fs)
avast! Win32:BrowseFox-AF [PUP]
Avira ADWARE/BrowseFox.Gen7
McAfee-GW-Edition BrowseFox.c
Tencent Win32.Trojan.Falsesign.Wlpi
Trend Micro TROJ_GEN.R0C1C0EKB14
Zillya Adware.Agent.Win32.9429

Software Behaviors

Services:
  • updateAtuZi.exe runs as a service named 'Update AtuZi' (Update AtuZi).

Software Details

URL:
https://a-tu-zi.com/support
Support:
https://mailto:
Installation path:
C:\Program Files\AtuZi
Uninstaller:
C:\Program Files\AtuZi\AtuZiuninstall.exe
Size:
1.00 MB
Language:
English

AtuZi Executable Details

Primary executable:
AtuZibho.dll
Name:
AtuZi
Path:
C:\Program Files\AtuZi\AtuZibho.dll
MD5:
35a7083687ebc71015ef7ec0590091d5
SHA-1:
–
SHA-256:
–
Files installed by AtuZi
File Type Filename MD5
DLL
3288f33be7634c85c251b01d2bab9ea8
EXE
e92604e043f51c604b6d1ac3bcd3a202
EXE
c5bc3d856c77bc50fb4f06591205e1b1
EXE
8d31becb8cb931c69008858a565afb28
EXE
623a76a8ee26ea6ba4a9ea9998575b67
EXE
d6fda19b3f48d59d4421e3323c67bb4e
DLL
35a7083687ebc71015ef7ec0590091d5
DLL
40194c1100fe6bb64355708c76f17b3e
DLL
ebeedf55b3c4c61c4c190a27eeafca18
DLL
ebeedf55b3c4c61c4c190a27eeafca18