00000000

TUGUU SL

The Tuguu download and install manager uses the DomalIQ installer to bundle additional adware offers such as toolbars and browser extensions during the setup process. This software distributes modified installers which are not the same as the original distributed by the author. The file 00000000 by TUGUU SL has been detected as adware by 16 anti-malware scanners. The program is a setup application that uses the TUGUU DomaIQ Setup installer.
Publisher:
TUGUU SL  (signed and verified)

MD5:
f906cf67231d2d6be917b3cc335fe3f0

SHA-1:
06212f206572a39937c8a48f1cfa0e84395cd9b3

SHA-256:
687c8b1b4fefcd3b2e5e633b395bbc7b0c75f720b3f891fc7514e3c0cef3970a

Scanner detections:
16 / 68

Status:
Adware

Explanation:
Uses the DomainIQ download manager to bundle additional potentially unwanted software without adequate consent.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/25/2024 1:04:45 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Lollipop
7.1.1

Avira AntiVirus
APPL/DomaIQ.A.10
7.11.141.176

avast!
Win32:DomaIQ-T [PUP]
2014.9-141121

AVG
DomaIQ
2015.0.3283

Comodo Security
Application.Win32.DomaIQ.PUP
18061

Dr.Web
Adware.Downware.2479
9.0.1.0325

ESET NOD32
Win32/DomaIQ.BB (variant)
8.9646

herdProtect (fuzzy)
2014.11.22.3

Kaspersky
not-a-virus:AdWare.Win32.Lollipop
14.0.0.2910

Malwarebytes
PUP.Optional.DomalQ
v2014.11.21.10

McAfee
Adware-DomaIQ!4EA20723FD6C
5600.6939

Panda Antivirus
PUP/MultiToolbar.A
14.11.21.10

Qihoo 360 Security
Malware.QVM06.Gen
1.0.0.1015

Reason Heuristics
PUP.TUGUUSL.I
14.9.17.17

Sophos
DomainIQ pay-per install
4.98

VIPRE Antivirus
DomaIQ
28115

File size:
432 KB (442,368 bytes)

Bundler/Installer:
TUGUU DomaIQ Setup

Common path:
C:\users\{user}\appdata\local\google\chrome\user data\default\file system\001\t\00\00000000

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
5/3/2013 6:24:02 PM

Valid to:
5/3/2014 6:24:02 PM

Subject:
CN=TUGUU SL, O=TUGUU SL, L=Adeje, S=Santa Cruz de Tenerife, C=ES

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2776B257979F9A

File PE Metadata
Compilation timestamp:
4/2/2014 5:05:48 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:OMpLaPZZc6XKADMZ/Mnoo0wToPdL8o/FBohRYSP/6JADD8by0caQifY5:1pA/cgwZ/Moo0wTYoDLSADKG

Entry address:
0x26F0

Entry point:
E8, 23, 2E, 00, 00, E9, 79, FE, FF, FF, 6A, 0C, 68, 40, F2, 41, 00, E8, 06, 01, 00, 00, 8B, 75, 08, 85, F6, 74, 75, 83, 3D, D8, 5F, 42, 00, 03, 75, 43, 6A, 04, E8, 25, 30, 00, 00, 59, 83, 65, FC, 00, 56, E8, 48, 31, 00, 00, 59, 89, 45, E4, 85, C0, 74, 09, 56, 50, E8, 69, 31, 00, 00, 59, 59, C7, 45, FC, FE, FF, FF, FF, E8, 0B, 00, 00, 00, 83, 7D, E4, 00, 75, 37, FF, 75, 08, EB, 0A, 6A, 04, E8, F9, 2E, 00, 00, 59, C3, 56, 6A, 00, FF, 35, 4C, 5A, 42, 00, FF, 15, 64, C0, 41, 00, 85, C0, 75, 16, E8, DD, 0A, 00...
 
[+]

Code size:
108 KB (110,592 bytes)

Remove 00000000 - Powered by Reason Core Security