Home Malware Programs Adware Adware.Tuto4PC

Adware.Tuto4PC

Posted: November 6, 2013

Threat Metric

Ranking: 2,397
Threat Level: 2/10
Infected PCs: 445,648
First Seen: November 6, 2013
Last Seen: March 10, 2025
OS(es) Affected: Windows

Adware.Tuto4PC is an adware browser add-on marketed by tuto4pc.com, a tutorial website that has been categorized as threatening for its promotion of adware like Adware.Tuto4PC. Because Adware.Tuto4PC's antics may include browser hijacks, displaying advertisements without you asking for it, installing third party software and updating itself automatically, malware researchers consider Adware.Tuto4PC a bit more of a danger to your PC than the typical piece of adware. Deleting Adware.Tuto4PC with any trusted anti-malware program should be the instantaneous response to any Adware.Tuto4PC infection – since Adware.Tuto4PC may be free to install other PC threats with every passing moment that Adware.Tuto4PC has on your computer.

When Tutorials Teach Your Browser How to Misbehave

The tutorial website officially marketing Adware.Tuto4PC is one with a strong history of distributing various types of adware, advertisements, browser hijackers and other content that commonly are associated with minor browser problems. Interestingly enough, the company responsible for Adware.Tuto4PC appears to be doing all of this with the supposed consent of its users, as a quick look at its user policy will inform you that Adware.Tuto4PC has the right to install third party content at will, update itself, hijack your browser and collect non-confidential information, amongst other things. As a general safety tip, malware researchers consider it a good practice to avoid any software with such suspicious user agreements – even if the program doesn't conduct any immediately threatening functions.

Because of Adware.Tuto4PC's ability to install other software automatically, Adware.Tuto4PC also has close associations with other forms of adware, including EoRezo. Symptoms between different payloads related to Adware.Tuto4PC are, of course, flexible, but may involve injected advertisements, pop-ups, homepage hijacks and/or search hijacks to promote advertising content and traffic redirections that are profitable for Adware.Tuto4PC's company. Other problems may arise as Adware.Tuto4PC may install additional software.

Flunking Adware.Tuto4PC out of Your Browser Security Class

Even though all of its functions are outlined in its user agreement and, therefore, technically consensual, Adware.Tuto4PC should be considered a danger to your PC and removed, like all other kinds of threats. Because of the risks of additional PC threats being installed through Adware.Tuto4PC, malware experts suggest scanning your PC with accurate anti-malware products that also can delete any hidden threats, along with removing Adware.Tuto4PC.

As of this article's writing, Adware.Tuto4PC has not been found guilty of using non-consensual means to install itself, despite its functions including almost every invasive act that a low-level PC threat possibly could accomplish. Since the Tuto4pc.com website looks perfectly legitimate unless examined by a third party source that can provide additional information on its business history, Adware.Tuto4PC's mere existence serves as a potent underscoring to malware expert's advice about never installing software without researching its source.

Aliases

Win32:Eorezo-BZ [PUP] [Avast]Adware.Eorezo [Symantec]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



file.exe File name: file.exe
Size: 629.76 KB (629760 bytes)
MD5: a6ecfd587e050969f9cea8474061c9e2
Detection count: 211
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: January 14, 2021
%SystemDrive%\Documents and Settings\LocalService\Configuraci?n local\Datos de programa\tuto4pc_pl_7\supt4pc_pl_7.exe File name: supt4pc_pl_7.exe
Size: 3.05 MB (3058024 bytes)
MD5: d552e6f84ee42f1a55d749dd70151829
Detection count: 96
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Documents and Settings\LocalService\Configuraci?n local\Datos de programa\tuto4pc_pl_7
Group: Malware file
Last Updated: March 26, 2016
%LOCALAPPDATA%\tuto100_ar_21\upt100_ar_21.exe File name: upt100_ar_21.exe
Size: 3.15 MB (3154416 bytes)
MD5: 491feb87741d3e07daf45bd020f16ccc
Detection count: 95
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\tuto100_ar_21
Group: Malware file
Last Updated: March 19, 2016
%LOCALAPPDATA%\t4pcfr1\supt4pcfr1.exe File name: supt4pcfr1.exe
Size: 3.05 MB (3056488 bytes)
MD5: e459babbc1f578d5cfe936aa1b240d11
Detection count: 71
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\t4pcfr1
Group: Malware file
Last Updated: March 26, 2016
%USERPROFILE%\Ustawienia lokalne\Dane aplikacji\tuto4pc_pl_8\upt4pc_pl_8.exe File name: upt4pc_pl_8.exe
Size: 2.1 MB (2100224 bytes)
MD5: a7aed22856ab621bf6c0ce819b2188f6
Detection count: 62
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Ustawienia lokalne\Dane aplikacji\tuto4pc_pl_8
Group: Malware file
Last Updated: March 19, 2016
%LOCALAPPDATA%\tuto4pc_fr_28\upt4pc_fr_28.exe File name: upt4pc_fr_28.exe
Size: 2.08 MB (2082664 bytes)
MD5: 7c728d16d50b8ad8bac18f3566030600
Detection count: 61
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\tuto4pc_fr_28
Group: Malware file
Last Updated: March 19, 2016
%LOCALAPPDATA%\majtutoriales100_es_17\supmajt100_es_17.exe File name: supmajt100_es_17.exe
Size: 3.05 MB (3059560 bytes)
MD5: 0ecb29b036ea2b33770c887adbbd81bd
Detection count: 54
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\majtutoriales100_es_17
Group: Malware file
Last Updated: March 26, 2016
C:\Program Files\VulkanRT\8CR69UJNG8OZT7F0J04VVILZKBIGEUVB3I0BSKZEY38PBOJS349DVRLZ02V8MCIVNM5KHEI8AZ61J6X62ZNKUSPL7AK0Y12WVMBYS9KYVAC5UTP4EZFWZ7B56TMG4RKI7KG648N2OYYTPU0OVQV9VF6XLG28WE4E038KMS9GMNHAIRPM38VO6LX1OTVXGOFK4U2V\KMfmdS__hl.exe File name: KMfmdS__hl.exe
Size: 540.67 KB (540672 bytes)
MD5: fc8f1fa166aee3f3d3f4871aadf2b09e
Detection count: 52
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files\VulkanRT\8CR69UJNG8OZT7F0J04VVILZKBIGEUVB3I0BSKZEY38PBOJS349DVRLZ02V8MCIVNM5KHEI8AZ61J6X62ZNKUSPL7AK0Y12WVMBYS9KYVAC5UTP4EZFWZ7B56TMG4RKI7KG648N2OYYTPU0OVQV9VF6XLG28WE4E038KMS9GMNHAIRPM38VO6LX1OTVXGOFK4U2V\KMfmdS__hl.exe
Group: Malware file
Last Updated: October 13, 2021
%USERPROFILE%\AppData\Local\t4pc_en_020010044\upt4pc_en_020010044.exe File name: upt4pc_en_020010044.exe
Size: 3.31 MB (3319952 bytes)
MD5: 120282b48e52bd6c6555460dfd9988b3
Detection count: 45
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\AppData\Local\t4pc_en_020010044
Group: Malware file
Last Updated: March 19, 2016
%USERPROFILE%\Impostazioni locali\Dati applicazioni\tuto4pc_it_10\upt4pc_it_10.exe File name: upt4pc_it_10.exe
Size: 3.15 MB (3150848 bytes)
MD5: d032ff791dc9da879daba72c67248d7e
Detection count: 33
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Impostazioni locali\Dati applicazioni\tuto4pc_it_10
Group: Malware file
Last Updated: March 19, 2016
%LOCALAPPDATA%\majtuto4pc_pt_16\supmajt4pc_pt_16.exe File name: supmajt4pc_pt_16.exe
Size: 3.06 MB (3060072 bytes)
MD5: f9d0b41b3a501fbefcf05d62e65b45bd
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\majtuto4pc_pt_16
Group: Malware file
Last Updated: March 26, 2016
%WINDIR%\SysWOW64\config\systemprofile\AppData\Local\tuto4pc_pl_6\supt4pc_pl_6.exe File name: supt4pc_pl_6.exe
Size: 3.05 MB (3057512 bytes)
MD5: 0dc52cc1224c0035a144a36e8b8ca4a8
Detection count: 22
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\SysWOW64\config\systemprofile\AppData\Local\tuto4pc_pl_6
Group: Malware file
Last Updated: March 26, 2016
%LOCALAPPDATA%\stv_fr_4\upstv_fr_4.exe File name: upstv_fr_4.exe
Size: 3.26 MB (3267536 bytes)
MD5: 5e0da44c7dbb4da87815b59790e4f467
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\stv_fr_4
Group: Malware file
Last Updated: March 19, 2016
%APPDATA%\Tutoriales100\Tutoriales100\UpdTralesCoSftnicHP.exe File name: UpdTralesCoSftnicHP.exe
Size: 3.3 MB (3304296 bytes)
MD5: abd8affabe0eebcf0317b9949972f9df
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Tutoriales100\Tutoriales100
Group: Malware file
Last Updated: March 25, 2016
%LOCALAPPDATA%\t4pc_en_3\upt4pc_en_3.exe File name: upt4pc_en_3.exe
Size: 3.26 MB (3268040 bytes)
MD5: 8f868623f43522f35396807f1d503c08
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\t4pc_en_3
Group: Malware file
Last Updated: March 19, 2016
%LOCALAPPDATA%\stv_fr_12\upstv_fr_12.exe File name: upstv_fr_12.exe
Size: 3.26 MB (3267536 bytes)
MD5: 85cd1f9bf35c96ff39eb836a9715d660
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\stv_fr_12
Group: Malware file
Last Updated: March 19, 2016
%LOCALAPPDATA%\t4pc_en_10\upt4pc_en_10.exe File name: upt4pc_en_10.exe
Size: 3.32 MB (3323360 bytes)
MD5: 2220ce637c6319053430b7298c23ae13
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\t4pc_en_10
Group: Malware file
Last Updated: March 19, 2016
%LOCALAPPDATA%\t4pc_en_6\upt4pc_en_6.exe File name: upt4pc_en_6.exe
Size: 3.34 MB (3341280 bytes)
MD5: 54f8d93de7480fa2924733aa01782239
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\t4pc_en_6
Group: Malware file
Last Updated: March 19, 2016
%LOCALAPPDATA%\t4pc_en_7\upt4pc_en_7.exe File name: upt4pc_en_7.exe
Size: 3.35 MB (3354608 bytes)
MD5: ff658901098b2f1356ce0dfafab727cc
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\t4pc_en_7
Group: Malware file
Last Updated: March 19, 2016
%USERPROFILE%\Configuraci?n local\Datos de programa\tutoriales100_mx_3\UpdTuto100SlmbaHP.exe File name: UpdTuto100SlmbaHP.exe
Size: 793.44 KB (793448 bytes)
MD5: 1767fac9cfb195e1e2eb286bc1da4717
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Configuraci?n local\Datos de programa\tutoriales100_mx_3
Group: Malware file
Last Updated: March 19, 2016
%LOCALAPPDATA%\tuto4pc_fr_33\upt4pc_fr_33.exe File name: upt4pc_fr_33.exe
Size: 2.67 MB (2671104 bytes)
MD5: dfda3e8176f378819b5189175840459b
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\tuto4pc_fr_33
Group: Malware file
Last Updated: March 19, 2016
%APPDATA%\Tuto4pc\Tuto4pc\UpdateTuto4PCHP.exe File name: UpdateTuto4PCHP.exe
Size: 990.05 KB (990056 bytes)
MD5: 8f0ff3a1da6322590bdb8075f09e1e0e
Detection count: 3
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Tuto4pc\Tuto4pc
Group: Malware file
Last Updated: March 25, 2016
%USERPROFILE%\Local Settings\Application Data\tuto4pc_in_6\upt4pc_in_6.exe File name: upt4pc_in_6.exe
Size: 2.07 MB (2079744 bytes)
MD5: 14651a9886ec9c1f251f4833e9ad730c
Detection count: 1
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Local Settings\Application Data\tuto4pc_in_6
Group: Malware file
Last Updated: March 19, 2016

More files

Registry Modifications

The following newly produced Registry Values are:

File name without pathwbn.regiedepub[1].xmlHKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\DOMStorage\regiedepub.comSoftware\Microsoft\Internet Explorer\DOMStorage\wbn.regiedepub.comSoftware\Microsoft\Internet Explorer\LowRegistry\DOMStorage\regiedepub.comSoftware\Microsoft\otutSoftware\Microsoft\TinstallsSoftware\Microsoft\TinstallsSOFTWARE\Microsoft\Tracing\otutnetwork_RASAPI32SOFTWARE\Microsoft\Tracing\otutnetwork_RASMANCSSOFTWARE\Microsoft\Windows\CurrentVersion\Run\sun2SOFTWARE\SUNNYDAYSOFTWARE\TUTO4PCSoftware\Tutorials\updatetutorialeshpSoftware\Tutorials\updatetutorialeshp1Software\Tutorials\updatetutorialeshp2Software\Tutorials\updatetutorialshpSoftware\Tutorials\updvSoftware\TutoTagSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\sun2SOFTWARE\Wow6432Node\SUNNYDAYSOFTWARE\Wow6432Node\TUTO4PC

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\Tuto4PC%ALLUSERSPROFILE%\Start Menu\Programs\Tuto4PC%APPDATA%\Tuto4pc%APPDATA%\Tutoriales100%PROGRAMFILES%\TUTORIALES100%PROGRAMFILES%\Tuto4pc%PROGRAMFILES(x86)%\TUTORIALES100%PROGRAMFILES(x86)%\Tuto4pc%PROGRAMFILES(x86)%\oasi_en_317010107
Loading...