setup.exe

Tuguu S.L.U.

The Tuguu download and install manager uses the DomalIQ installer to bundle additional adware offers such as toolbars and browser extensions during the setup process. This software distributes modified installers which are not the same as the original distributed by the author. The application setup.exe by Tuguu S.L.U has been detected as adware by 22 anti-malware scanners. The program is a setup application that uses the TUGUU DomaIQ Setup installer. During install, it bundles potentially unwanted software on a user's computer at the same time without adequate consent.
Publisher:
Tuguu S.L.U.  (signed and verified)

MD5:
2c3c8363c50750016baf41728b017f95

SHA-1:
0c706066fdead881c96980d9fe57282a4db02dea

SHA-256:
a5f402dd572b11fe66290094f9602229b0c866ab965756620a1ea0301a1ffaf6

Scanner detections:
22 / 68

Status:
Adware

Explanation:
Uses the DomainIQ download manager to bundle additional potentially unwanted software without adequate consent.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/25/2024 6:48:13 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.DomaIQ
7.1.1

AhnLab V3 Security
PUP/Win32.DomaIQ
14.04.19

Avira AntiVirus
APPL/DomaIQ.Gen2
7.11.138.124

AVG
Skodna.Generic_r
2015.0.3500

Comodo Security
Application.Win32.Agent.D
17980

Dr.Web
Adware.Downware.1823
9.0.1.0109

ESET NOD32
Win32/DomaIQ.AS (variant)
8.9579

F-Prot
W32/DomaIQ.B.gen
v6.4.7.1.166

F-Secure
Adware:W32/DomaIQ
11.2014-19-04_7

G Data
Win32.Adware.Aquiempi
14.4.24

K7 AntiVirus
Unwanted-Program
13.176.11806

Kaspersky
not-a-virus:AdWare.MSIL.DomaIQ
14.0.0.3995

Malwarebytes
PUP.Optional.BundleInstaller.A
v2014.04.19.01

McAfee
Adware-DomaIQ!0F919AA50162
5600.7156

NANO AntiVirus
Riskware.Win32.Downware.csceqm
0.28.0.58491

Panda Antivirus
PUP/MultiToolbar.A
14.04.19.01

Quick Heal
Adware.Domal.A5
4.14.12.00

Reason Heuristics
PUP.Installer.TuguuSLU.F
14.8.7.18

Rising Antivirus
PE:PUF.DomaIQ!1.9EEB
23.00.65.14417

Sophos
DomainIQ pay-per install
4.98

Vba32 AntiVirus
BScope.Downware.DomaIQ
3.12.24.3

VIPRE Antivirus
Trojan.Win32.Generic
27680

File size:
460.5 KB (471,520 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
TUGUU DomaIQ Setup

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
8/27/2013 8:00:00 PM

Valid to:
8/27/2014 7:59:59 PM

Subject:
CN=Tuguu S.L.U., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Tuguu S.L.U., L=Adeje, S=SANTA CRUZ DE TENERIFE, C=ES

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
21FCDE5EAE401DF690786A73C48E74F8

File PE Metadata
Compilation timestamp:
12/21/2013 1:20:11 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:bPgm1w+oJ1dlGpz42w+mBSiNX+bVlzdLQjMyyFu/3LiwoRVVdnDd965AFYV:UF1zG4Gi+7dLGxmI2RVVFDd96v

Entry address:
0xD685

Entry point:
E8, 34, 63, 00, 00, E9, 78, FE, FF, FF, 6A, 0C, 68, B8, 53, 42, 00, E8, 2D, 04, 00, 00, 83, 65, E4, 00, 8B, 75, 08, 3B, 35, 50, B8, 42, 00, 77, 22, 6A, 04, E8, 1F, 65, 00, 00, 59, 83, 65, FC, 00, 56, E8, 26, 6D, 00, 00, 59, 89, 45, E4, C7, 45, FC, FE, FF, FF, FF, E8, 09, 00, 00, 00, 8B, 45, E4, E8, 39, 04, 00, 00, C3, 6A, 04, E8, 1A, 64, 00, 00, 59, C3, 8B, FF, 55, 8B, EC, 56, 8B, 75, 08, 83, FE, E0, 0F, 87, A1, 00, 00, 00, 53, 57, 8B, 3D, 70, 00, 42, 00, 83, 3D, 14, B5, 42, 00, 00, 75, 18, E8, DA, 5B, 00...
 
[+]

Entropy:
7.4164

Code size:
121 KB (123,904 bytes)

Remove setup.exe - Powered by Reason Core Security