free-opener.exe

Tuguu S.L.

The Tuguu download and install manager uses the DomalIQ installer to bundle additional adware offers such as toolbars and browser extensions during the setup process. This software distributes modified installers which are not the same as the original distributed by the author. The application free-opener.exe by Tuguu S.L has been detected as adware by 13 anti-malware scanners. The program is a setup application that uses the TUGUU DomaIQ Setup installer. During install, it bundles potentially unwanted software on a user's computer at the same time without adequate consent.
Publisher:
Tuguu S.L.  (signed and verified)

MD5:
7ec3c77a4f3ac97746a6b22f1ab7ae56

SHA-1:
b844338f7033573f2b74ee3e26e9fe07758b2cf0

SHA-256:
272f4a79e5685789eea5f2578fc00f88f7ee9692fa5d723c67d8d71ab4816c7b

Scanner detections:
13 / 68

Status:
Adware

Explanation:
May bundle additional potentially unwanted software such as adware during setup.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/24/2024 6:25:02 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.DomaIQ
7.1.1

Avira AntiVirus
APPL/DomaIQ.Gen
7.11.150.22

avast!
DomaIQ-CC [PUP]
140516-1

AVG
DomaIQ
2015.0.3472

ESET NOD32
Win32/DomaIQ.BF (variant)
8.9811

K7 AntiVirus
Unwanted-Program
13.177.12109

Kaspersky
not-a-virus:AdWare.MSIL.DomaIQ
14.0.0.3855

Malwarebytes
PUP.Optional.BundleInstaller.A
v2014.05.17.01

McAfee
PUP-FJP!4377306C677D
5600.7128

Panda Antivirus
PUP/MultiToolbar.A
14.05.17.01

Reason Heuristics
PUP.TuguuSL.L
14.8.7.18

Sophos
Generic PUA PH
4.98

VIPRE Antivirus
DomaIQ
29290

File size:
479.1 KB (490,616 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
TUGUU DomaIQ Setup

Common path:
C:\users\{user}\downloads\free-opener.exe

Digital Signature
Signed by:

Authority:
Starfield Technologies, Inc.

Valid from:
12/9/2013 6:56:54 AM

Valid to:
12/9/2014 6:56:54 AM

Subject:
CN=Tuguu S.L., O=Tuguu S.L., L=Adeje, S=Santa Cruz de Tenerife, C=ES

Issuer:
SERIALNUMBER=10688435, CN=Starfield Secure Certification Authority, OU=http://certificates.starfieldtech.com/repository, O="Starfield Technologies, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
4B49CE87BAE8BE

File PE Metadata
Compilation timestamp:
5/15/2014 2:57:10 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:GgM+lFy9XBu5gmEBipkz+Jix8NB40poIZ2ix0LzjYfbdBcpvhYcH:GqFytBu5kiplJiGDIix4zjNpvNH

Entry address:
0x4E24

Entry point:
E8, 2F, 34, 00, 00, E9, 39, FE, FF, FF, 55, 8B, EC, 83, 7D, 08, 00, 74, 2D, FF, 75, 08, 6A, 00, FF, 35, 58, 03, 43, 00, FF, 15, 6C, D0, 41, 00, 85, C0, 75, 18, 56, E8, 20, 13, 00, 00, 8B, F0, FF, 15, 50, D0, 41, 00, 50, E8, 6B, 13, 00, 00, 59, 89, 06, 5E, 5D, C3, 55, 8B, EC, 56, 8B, 75, 0C, 57, 33, FF, 85, F6, 74, 1B, 6A, E0, 33, D2, 58, F7, F6, 3B, 45, 10, 73, 0F, E8, ED, 12, 00, 00, C7, 00, 0C, 00, 00, 00, 33, C0, EB, 3C, 0F, AF, 75, 10, 53, 8B, 5D, 08, 85, DB, 74, 09, 53, E8, 16, 1B, 00, 00, 59, 8B, F8...
 
[+]

Entropy:
6.6055

Code size:
109 KB (111,616 bytes)

The file free-opener.exe has been seen being distributed by the following URL.

Remove free-opener.exe - Powered by Reason Core Security