avg antivirus.exe

Tuguu S.L.

The Tuguu download and install manager uses the DomalIQ installer to bundle additional adware offers such as toolbars and browser extensions during the setup process. This software distributes modified installers which are not the same as the original distributed by the author. The application avg antivirus.exe by Tuguu S.L has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the TUGUU DomaIQ Setup installer.
Publisher:
Tuguu S.L.  (signed and verified)

MD5:
d63ddc1889d1476439f0cdf2760e5870

SHA-1:
2368384206fcaad02e6db2f41573c1386def92dc

SHA-256:
800d005dcdee3e8b1d1298434a2d7d63991ea3c2aa3b2382c8b3051a892407ff

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Bundles third-party components such as adware in the installer.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/26/2024 11:24:22 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Tuguu.Bundler (M)
16.2.5.12

File size:
550.7 KB (563,888 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
TUGUU DomaIQ Setup

Common path:
C:\users\{user}\downloads\avg antivirus.exe

Digital Signature
Signed by:

Authority:
Starfield Technologies, Inc.

Valid from:
12/9/2013 2:56:54 PM

Valid to:
12/9/2014 2:56:54 PM

Subject:
CN=Tuguu S.L., O=Tuguu S.L., L=Adeje, S=Santa Cruz de Tenerife, C=ES

Issuer:
SERIALNUMBER=10688435, CN=Starfield Secure Certification Authority, OU=http://certificates.starfieldtech.com/repository, O="Starfield Technologies, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
4B49CE87BAE8BE

File PE Metadata
Compilation timestamp:
3/28/2014 10:10:27 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:0sWPjZjMU4p+P2DSZ21TbYFfzEp8gw28WV2Gd4+Sn6U8QHYrT1WYXS:0NtjMU3Wa65bwWjAiQHAT1BS

Entry address:
0x3C66

Entry point:
E8, 37, 2C, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 83, 7D, 08, 00, 74, 2D, FF, 75, 08, 6A, 00, FF, 35, BC, 74, 41, 00, FF, 15, 6C, B0, 40, 00, 85, C0, 75, 18, 56, E8, 4B, 0C, 00, 00, 8B, F0, FF, 15, 50, B0, 40, 00, 50, E8, 50, 0C, 00, 00, 59, 89, 06, 5E, 5D, C3, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 54, 24, 0C, 8B, 4C, 24, 04, 85, D2, 74, 7F, 0F, B6, 44, 24, 08, 0F, BA, 25, 88, 71, 41, 00, 01, 73, 0D, 8B, 4C, 24, 0C, 57, 8B, 7C, 24, 08, F3, AA, EB, 5D, 8B, 54, 24, 0C, 81, FA, 80, 00, 00, 00, 7C, 0E, 0F, BA...
 
[+]

Entropy:
5.6681

Code size:
40 KB (40,960 bytes)

Remove avg antivirus.exe - Powered by Reason Core Security