setup.exe

Tuguu Israel Ltd

The Tuguu download and install manager uses the DomalIQ installer to bundle additional adware offers such as toolbars and browser extensions during the setup process. This software distributes modified installers which are not the same as the original distributed by the author. The application setup.exe by Tuguu Israel has been detected as adware by 8 anti-malware scanners. The program is a setup application that uses the TUGUU DomaIQ Setup installer.
Publisher:
Tuguu Israel Ltd  (signed and verified)

MD5:
95674d06755027aca9f1679544d4d517

SHA-1:
1fe67490f595df7fc892ba4e741036b2ddf0c6fa

SHA-256:
b06a0a3665ede8007006aae6ac8c92dc90865b3d933d6c075c5e03ad7730cd83

Scanner detections:
8 / 68

Status:
Adware

Explanation:
The software bundles potentially unwanted offers during setup including toolbars and adware.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
4/19/2024 2:19:36 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:DomaIQ-CM [PUP]
140813-1

AVG
Adware Skodna.Generic_r.HZ
2014.0.3986

Clam AntiVirus
Win.Adware.Domaiq-47
0.98/19300

Dr.Web
Trojan.PayInt.9
9.0.1.05190

ESET NOD32
MSIL/DomaIQ.N potentially unwanted application
7.0.302.0

Kaspersky
not-a-virus:AdWare.MSIL.DomaIQ
15.0.0.494

Reason Heuristics
PUP.Installer.TuguuIsrael.I
14.8.22.21

VIPRE Antivirus
Threat.4783262
32210

File size:
459 KB (470,032 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
TUGUU DomaIQ Setup

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
6/11/2013 5:00:00 PM

Valid to:
8/20/2014 5:00:00 AM

Subject:
CN=Tuguu Israel Ltd, O=Tuguu Israel Ltd, L=RAMAT GAN, C=IL

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
06FD356584CBF71B04A7AFE790A2329F

File PE Metadata
Compilation timestamp:
12/27/2013 5:55:46 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:YRnMgvVPOf0ZRfGM65Tzh3WEg8YSqcf2h3gLUawo1XeiWMmbAgUjYLx:AOfsRfV65fg8pfORawo05JU8x

Entry address:
0xD182

Entry point:
E8, C4, 63, 00, 00, E9, 78, FE, FF, FF, 6A, 0C, 68, 38, 43, 42, 00, E8, C4, 04, 00, 00, 83, 65, E4, 00, 8B, 75, 08, 3B, 35, 58, A8, 42, 00, 77, 22, 6A, 04, E8, AF, 65, 00, 00, 59, 83, 65, FC, 00, 56, E8, B6, 6D, 00, 00, 59, 89, 45, E4, C7, 45, FC, FE, FF, FF, FF, E8, 09, 00, 00, 00, 8B, 45, E4, E8, D0, 04, 00, 00, C3, 6A, 04, E8, AA, 64, 00, 00, 59, C3, 8B, FF, 55, 8B, EC, 56, 8B, 75, 08, 83, FE, E0, 0F, 87, A1, 00, 00, 00, 53, 57, 8B, 3D, 70, F0, 41, 00, 83, 3D, 1C, A5, 42, 00, 00, 75, 18, E8, 6A, 5C, 00...
 
[+]

Entropy:
7.4213

Code size:
119.5 KB (122,368 bytes)

Remove setup.exe - Powered by Reason Core Security