parent.txt

tuguu sl

The Tuguu download and install manager uses the DomalIQ installer to bundle additional adware offers such as toolbars and browser extensions during the setup process. This software distributes modified installers which are not the same as the original distributed by the author. The file parent.txt by tuguu sl has been detected as adware by 32 anti-malware scanners. The program is a setup application that uses the TUGUU DomaIQ Setup installer. During install, it bundles potentially unwanted software on a user's computer at the same time without adequate consent.
Publisher:
tuguu sl  (signed and verified)

MD5:
9d25c426884befa76a086ade4cd4f526

SHA-1:
bdbebc6f5ad96ed71c7b671a7d1cedc255018aac

SHA-256:
81be742163369a3c0b68abfe25ba9238e104c932bc70b352419bd0043361208d

Scanner detections:
32 / 68

Status:
Adware

Explanation:
May bundle additional potentially unwanted software such as adware during setup.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/26/2024 5:37:30 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Dropped:Application.Bundler.DomaIQ.Q
6324531

Agnitum Outpost
PUA.DomaIQ
7.1.1

AhnLab V3 Security
PUP/Win32.DomaIQ
2015.03.29

avast!
DomaIQ-BD [PUP]
2014.9-150328

AVG
Adware Skodna.Bundle_r.T
2016.0.3156

Bitdefender
Dropped:Application.Bundler.DomaIQ.Q
1.0.20.435

Bkav FE
W32.HfsAdware
1.3.0.6379

Clam AntiVirus
Win.Adware.Domaiq-206
0.98/21511

Comodo Security
Application.Win32.DomaIQ.STX
21573

Dr.Web
Adware.Downware.2011
9.0.1.087

Emsisoft Anti-Malware
Adware.Generic.677325
8.15.03.28.06

ESET NOD32
Win32/DomaIQ.AY.gen potentially unwanted application
9.7.0.302.0

Fortinet FortiGate
Riskware/Generic.AC.2671323
3/28/2015

F-Prot
W32/A-f735a5e0
v6.4.7.1.166

F-Secure
Adware:W32/DomaIQ
5.13.68

G Data
Dropped:Application.Bundler.DomaIQ
15.3.25

herdProtect (fuzzy)
2015.7.3.7

K7 AntiVirus
Unwanted-Program
13.202.15414

Kaspersky
not-a-virus:AdWare.Win32.Lollipop
14.0.0.2276

Malwarebytes
PUP.Optional.BundleInstaller.A
v2015.03.28.06

McAfee
CryptDomaIQ
5600.6812

MicroWorld eScan
Adware.Generic.677325
16.0.0.261

NANO AntiVirus
Riskware.Win32.DomaIQ.cspmgz
0.30.8.659

Norman
Dropped:Application.Bundler.DomaIQ.Q
03.12.2014 13:20:04

nProtect
Trojan-Clicker/W32.Lollipop.465488
14.10.14.01

Quick Heal
Adware.Domal.A5
3.15.14.00

Reason Heuristics
PUP.Bundler.Tuguu
15.3.28.18

Rising Antivirus
PE:Trojan.Win32.Generic.167FA07B!377462907
23.00.65.15326

Sophos
Generic PUA EB
4.98

Vba32 AntiVirus
BScope.Downware.DomaIQ
3.12.26.3

VIPRE Antivirus
Threat.4783262
33706

Zillya! Antivirus
Adware.DomaIQ.Win32.67
2.0.0.2119

File size:
454 KB (464,944 bytes)

Bundler/Installer:
TUGUU DomaIQ Setup

Common path:
C:\users\{user}\appdata\local\temp\parent.txt

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
6/13/2013 7:06:55 AM

Valid to:
6/13/2014 7:06:55 AM

Subject:
CN=tuguu sl, O=tuguu sl, L=Adeje, S=Santa Cruz de Tenerife, C=ES

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2B632A0CF95E4D

File PE Metadata
Compilation timestamp:
1/17/2014 9:50:27 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:6vaqS4IR/kviXzd45seH6zdi69hxMwjPVl0x55TurrU41APIJgU6Xozwdab0BXl9:5/kviXzdcH6N9h/Vl45aPU4EEkdBb9

Entry address:
0xC4D7

Entry point:
E8, 10, 56, 00, 00, E9, 78, FE, FF, FF, 6A, 0C, 68, 60, 21, 42, 00, E8, 6F, 09, 00, 00, 83, 65, E4, 00, 8B, 75, 08, 3B, 35, 60, 88, 42, 00, 77, 22, 6A, 04, E8, FB, 57, 00, 00, 59, 83, 65, FC, 00, 56, E8, 02, 60, 00, 00, 59, 89, 45, E4, C7, 45, FC, FE, FF, FF, FF, E8, 09, 00, 00, 00, 8B, 45, E4, E8, 7B, 09, 00, 00, C3, 6A, 04, E8, F6, 56, 00, 00, 59, C3, 8B, FF, 55, 8B, EC, 56, 8B, 75, 08, 83, FE, E0, 0F, 87, A1, 00, 00, 00, 53, 57, 8B, 3D, 70, D0, 41, 00, 83, 3D, 14, 84, 42, 00, 00, 75, 18, E8, 18, 49, 00...
 
[+]

Entropy:
7.3711

Code size:
110.5 KB (113,152 bytes)

Remove parent.txt - Powered by Reason Core Security