itunes.exe

Lunacom Interactive Ltd

This is the Tuguu DomaIQ download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application itunes.exe by Lunacom Interactive has been detected as adware by 32 anti-malware scanners. The program is a setup application that uses the TUGUU DomaIQ Setup installer. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. With this installer, users are expecting to download Apple's iTunes but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
Lunacom Interactive Ltd  (signed and verified)

MD5:
37c9e348db0f5e418371dc92c1918701

SHA-1:
a0eecd9131f0c8b317124e4f8f6a1f313369e5ee

SHA-256:
00b9c3c9ec6ce0a9fc77b6947b8f73f2a76caf54e6bb397f922f1fc5e12677af

Scanner detections:
32 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/25/2024 5:06:35 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Bundler.DomaIQ.Q
849

Agnitum Outpost
PUA.DomaIQ
7.1.1

AhnLab V3 Security
PUP/Win32.DomaIQ
2014.10.09

Avira AntiVirus
APPL/DomaIQ.Gen
7.11.177.102

avast!
PUP-gen [PUP]
141003-0

AVG
Adware Skodna.Bundle_r.O
2014.0.4037

Bitdefender
Application.Bundler.DomaIQ.Q
1.0.20.1410

Clam AntiVirus
Win.Trojan.Domaiq-5
0.98/19488

Comodo Security
Application.Win32.DomaIQ.JIK
19745

Dr.Web
Adware.Downware.1636
9.0.1.05190

ESET NOD32
Win32/DomaIQ.AK potentially unwanted application
7.0.302.0

F-Prot
W32/A-f735a5e0
v6.4.7.1.166

F-Secure
Application.Bundler.DomaIQ
11.2014-09-10_5

G Data
Application.Bundler.DomaIQ
14.10.24

IKARUS anti.virus
Trojan.SuspectCRC
t3scan.1.7.8.0

K7 AntiVirus
Unwanted-Program
13.183.13619

Kaspersky
not-a-virus:AdWare.Win32.DomaIQ
15.0.0.494

Malwarebytes
Trojan.Dropper.FJ
v2014.10.09.04

McAfee
CryptDomaIQ
5600.6983

MicroWorld eScan
Application.Bundler.DomaIQ.Q
15.0.0.846

NANO AntiVirus
Trojan.Win32.Downware.cqrlin
0.28.2.62483

Norman
DomaIQ.CERT
11.20141009

nProtect
Trojan-Clicker/W32.DomaIQ.555800
14.10.08.01

Panda Antivirus
PUP/MultiToolbar.A
14.10.09.04

Quick Heal
Adware.DomaIQ.BT5
10.14.14.00

Reason Heuristics
PUP.LunacomInteractive.G
14.10.9.4

Rising Antivirus
PE:Trojan.Win32.Generic.16AE6527!380527911
23.00.65.141007

Sophos
Mal/Generic-S
4.98

Total Defense
Win32/DomainIQ.bFNVOa
37.0.11216

Vba32 AntiVirus
BScope.Downware.DomaIQ
3.12.26.3

VIPRE Antivirus
Threat.4783235
33706

Zillya! Antivirus
Adware.DomaIQ.Win32.183
2.0.0.1948

File size:
542.8 KB (555,800 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
TUGUU DomaIQ Setup

Common path:
C:\users\{user}\downloads\itunes.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
10/5/2013 5:00:00 PM

Valid to:
12/5/2014 3:59:59 PM

Subject:
CN=Lunacom Interactive Ltd, OU="Raul Valenberg 6, ", OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Lunacom Interactive Ltd, L=Tel Aviv-Jaffa, S=Israel, C=IL

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
15E496383F5A0396A7AD86D85850D5BB

File PE Metadata
Compilation timestamp:
11/6/2013 3:51:17 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:nMR+5Y8feGk8zju34KptplPujwlxMIS1JM/4:nFfeyj2LRplqIEn

Entry address:
0xD6B6

Entry point:
E8, 2E, 71, 00, 00, E9, 78, FE, FF, FF, 6A, 0C, 68, 78, 36, 42, 00, E8, 0C, 21, 00, 00, 83, 65, E4, 00, 8B, 75, 08, 3B, 35, 90, B8, 42, 00, 77, 22, 6A, 04, E8, 19, 73, 00, 00, 59, 83, 65, FC, 00, 56, E8, 20, 7B, 00, 00, 59, 89, 45, E4, C7, 45, FC, FE, FF, FF, FF, E8, 09, 00, 00, 00, 8B, 45, E4, E8, 18, 21, 00, 00, C3, 6A, 04, E8, 14, 72, 00, 00, 59, C3, 8B, FF, 55, 8B, EC, 56, 8B, 75, 08, 83, FE, E0, 0F, 87, A1, 00, 00, 00, 53, 57, 8B, 3D, A8, E0, 41, 00, 83, 3D, 3C, A5, 42, 00, 00, 75, 18, E8, E0, 68, 00...
 
[+]

Entropy:
7.3926

Code size:
113.5 KB (116,224 bytes)

The file itunes.exe has been seen being distributed by the following URL.

Remove itunes.exe - Powered by Reason Core Security