setup.exe

TUGUU SL

The Tuguu download and install manager uses the DomalIQ installer to bundle additional adware offers such as toolbars and browser extensions during the setup process. This software distributes modified installers which are not the same as the original distributed by the author. The application setup.exe by TUGUU SL has been detected as adware by 23 anti-malware scanners. The program is a setup application that uses the TUGUU DomaIQ Setup installer.
Publisher:
TUGUU SL  (signed and verified)

MD5:
9244b0475a8158127c1bffa5673e664f

SHA-1:
716dc814bd51580eb91ca2ca63b01e5bf513e8b0

SHA-256:
a46dde98920db60bb2794fe5933743717b81117eb7739e12b34b80c322b2dbf7

Scanner detections:
23 / 68

Status:
Adware

Explanation:
Uses the DomainIQ download manager to bundle additional potentially unwanted software without adequate consent.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/26/2024 3:53:56 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.DomaIQ.AN
1018

Agnitum Outpost
PUA.Lollipop
7.1.1

AhnLab V3 Security
PUP/Win32.DomaIQ
14.04.23

Avira AntiVirus
APPL/DomaIQ.Gen
7.11.144.202

avast!
Win32:DomaIQ-T [PUP]
2014.9-140423

AVG
DomaIQ_r.J
2015.0.3496

Bitdefender
Adware.DomaIQ.AN
1.0.20.565

Comodo Security
Application.Win32.DomaIQ.PUR
18152

Dr.Web
Adware.Downware.2759
9.0.1.0113

Emsisoft Anti-Malware
Adware.DomaIQ.AN
8.14.04.23.03

ESET NOD32
Win32/DomaIQ.BB (variant)
8.9709

F-Secure
Adware.DomaIQ.AN
11.2014-23-04_4

G Data
Adware.DomaIQ.AN
14.4.24

K7 AntiVirus
Unwanted-Program
13.176.11847

Kaspersky
not-a-virus:AdWare.Win32.Lollipop
14.0.0.3974

Malwarebytes
PUP.Optional.DomalQ
v2014.04.23.03

McAfee
Artemis!3DABD305A85C
5600.7152

MicroWorld eScan
Adware.DomaIQ.AN
15.0.0.339

nProtect
Adware.DomaIQ.AN
14.04.22.01

Panda Antivirus
PUP/MultiToolbar.A
14.04.23.03

Reason Heuristics
PUP.Installer.TUGUUSL.F
14.8.7.18

Sophos
DomainIQ pay-per install
4.98

VIPRE Antivirus
Trojan.Win32.Generic
28526

File size:
438.4 KB (448,928 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
TUGUU DomaIQ Setup

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\low\content.ie5\{random}\setup.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
5/3/2013 1:24:02 PM

Valid to:
5/3/2014 1:24:02 PM

Subject:
CN=TUGUU SL, O=TUGUU SL, L=Adeje, S=Santa Cruz de Tenerife, C=ES

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2776B257979F9A

File PE Metadata
Compilation timestamp:
4/16/2014 5:37:10 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:OPmiLuncbmmkHCUwDgt/ZSwLM2f3a6xAEg8ovT9ploCe1O6pRbYxvfTEYu:umiGmkHC3s3SwLMAvxAQwjJe7Sru

Entry address:
0x271A

Entry point:
E8, 27, 2E, 00, 00, E9, 79, FE, FF, FF, 6A, 0C, 68, 20, FA, 41, 00, E8, 0C, 01, 00, 00, 8B, 75, 08, 85, F6, 74, 75, 83, 3D, D8, 57, 42, 00, 03, 75, 43, 6A, 04, E8, 29, 30, 00, 00, 59, 83, 65, FC, 00, 56, E8, 4C, 31, 00, 00, 59, 89, 45, E4, 85, C0, 74, 09, 56, 50, E8, 6D, 31, 00, 00, 59, 59, C7, 45, FC, FE, FF, FF, FF, E8, 0B, 00, 00, 00, 83, 7D, E4, 00, 75, 37, FF, 75, 08, EB, 0A, 6A, 04, E8, FD, 2E, 00, 00, 59, C3, 56, 6A, 00, FF, 35, 4C, 52, 42, 00, FF, 15, 64, C0, 41, 00, 85, C0, 75, 16, E8, E3, 0A, 00...
 
[+]

Entropy:
6.7359

Code size:
108 KB (110,592 bytes)

Remove setup.exe - Powered by Reason Core Security