setup.exe

Tuguu Israel Ltd

The Tuguu download and install manager uses the DomalIQ installer to bundle additional adware offers such as toolbars and browser extensions during the setup process. This software distributes modified installers which are not the same as the original distributed by the author. The application setup.exe by Tuguu Israel has been detected as adware by 31 anti-malware scanners. The program is a setup application that uses the TUGUU DomaIQ Setup installer. During install, it bundles potentially unwanted software on a user's computer at the same time without adequate consent.
Publisher:
Tuguu Israel Ltd  (signed and verified)

MD5:
5397dc4f4a992649efa1a096ee78d927

SHA-1:
2474e9a0f98da788fd7436791ac53bee15548281

SHA-256:
c1c2d28b6412bab762023e6b9491156447171e8337a28ab264e92e5512b2ca5c

Scanner detections:
31 / 68

Status:
Adware

Explanation:
The software bundles potentially unwanted offers during setup including toolbars and adware.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/26/2024 12:25:02 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.11004281
918

Agnitum Outpost
PUA.DomaIQ
7.1.1

AhnLab V3 Security
PUP/Win32.DomaIQ
14.07.31

Avira AntiVirus
APPL/DomaIQ.AUP
7.11.138.122

avast!
Win32:DomaIQ-BD [PUP]
2014.9-140731

AVG
Skodna.Bundle_r.T
2015.0.3396

Bitdefender
Trojan.Generic.11004281
1.0.20.1060

Clam AntiVirus
Win.Adware.Domaiq-44
0.98/19168

Comodo Security
Application.Win32.DomaIQ.X
17979

Dr.Web
Adware.Downware.2011
9.0.1.0212

Emsisoft Anti-Malware
Trojan.Generic.11004281
8.14.07.31.12

ESET NOD32
Win32/DomaIQ.AY.gen (variant)
8.9579

F-Prot
W32/A-0cef6ee3
v6.4.7.1.166

F-Secure
Trojan.Generic.11004281
11.2014-31-07_5

G Data
Trojan.Generic.11004281
14.7.24

herdProtect (fuzzy)
2014.9.10.16

IKARUS anti.virus
PUA.MSIL.DomaIQ
t3scan.1.6.1.0

K7 AntiVirus
Trojan
13.176.11524

Kaspersky
not-a-virus:AdWare.MSIL.DomaIQ
14.0.0.3477

Malwarebytes
PUP.Optional.BundleInstaller.A
v2014.07.31.12

McAfee
RDN/Generic.bfr!gd
5600.7052

MicroWorld eScan
Trojan.Generic.11004281
15.0.0.636

NANO AntiVirus
Riskware.Win32.DomaIQ.cspmgz
0.28.0.58491

nProtect
Trojan-Clicker/W32.Agent.465472
14.07.31.01

Panda Antivirus
PUP/MultiToolbar.A
14.07.31.12

Quick Heal
Adware.Domal.A5
7.14.12.00

Reason Heuristics
PUP.Installer.TuguuIsrael.F
14.8.7.22

Rising Antivirus
PE:PUF.DomaIQ!1.9DE0
23.00.65.14729

Sophos
Generic PUA EB
4.98

Vba32 AntiVirus
BScope.Downware.DomaIQ
3.12.24.3

VIPRE Antivirus
Trojan.Win32.Generic
27676

File size:
454.6 KB (465,472 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
TUGUU DomaIQ Setup

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
6/11/2013 9:00:00 PM

Valid to:
8/20/2014 9:00:00 AM

Subject:
CN=Tuguu Israel Ltd, O=Tuguu Israel Ltd, L=RAMAT GAN, C=IL

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
06FD356584CBF71B04A7AFE790A2329F

File PE Metadata
Compilation timestamp:
1/17/2014 3:50:27 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:xvaqS4IR/kviXzd45seH6zdi69hxMwjPVl0x55TurrU41APIJgU6Xozwdab0BXl3:8/kviXzdcH6N9h/Vl45aPU4EEkdBbTj

Entry address:
0xC4D7

Entry point:
E8, 10, 56, 00, 00, E9, 78, FE, FF, FF, 6A, 0C, 68, 60, 21, 42, 00, E8, 6F, 09, 00, 00, 83, 65, E4, 00, 8B, 75, 08, 3B, 35, 60, 88, 42, 00, 77, 22, 6A, 04, E8, FB, 57, 00, 00, 59, 83, 65, FC, 00, 56, E8, 02, 60, 00, 00, 59, 89, 45, E4, C7, 45, FC, FE, FF, FF, FF, E8, 09, 00, 00, 00, 8B, 45, E4, E8, 7B, 09, 00, 00, C3, 6A, 04, E8, F6, 56, 00, 00, 59, C3, 8B, FF, 55, 8B, EC, 56, 8B, 75, 08, 83, FE, E0, 0F, 87, A1, 00, 00, 00, 53, 57, 8B, 3D, 70, D0, 41, 00, 83, 3D, 14, 84, 42, 00, 00, 75, 18, E8, 18, 49, 00...
 
[+]

Code size:
110.5 KB (113,152 bytes)

Remove setup.exe - Powered by Reason Core Security