Zugo Ltd

Publisher Information

Zugo Ltd is a software publisher located in St Helier, Jersey in JE*. The company is a primary distributor of unwanted software. Zugo is a web browser monetization platform that co-bundles various search exetensions including the StartNow toolbar. The company provides software bundle opportunities for publishers that install these extensions. Thre are 2 additional code signing certificates issued to this publisher.
Authority:
COMODO CA Limited

Valid from:
1/30/2013 7:00:00 PM

Valid to:
1/31/2016 6:59:59 PM

Subject:
CN=Zugo Ltd, O=Zugo Ltd, STREET=PO Box 36, STREET=1st Floor, STREET=37 Broad St., L=St Helier, S=Jersey, PostalCode=JE4 9NU, C=JE

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00fa860df2ac924fc31176c787706f3824

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Toolbar.Zugo.N, PUP.Zugo.N, PUP.Startup.Zugo.O, PUP.Zugo.I, PUP.Zugo.Installer, PUP.Zugo (M), PUP.Zugo.StartNow.Installer (M), PUP.Zugo.Installer (M)
100.00%

Dr.Web
Adware.Zugo.71, Adware.Zugo.114
26.92%

VIPRE Antivirus
Zugo Ltd
26.92%

Boost by Reason
Optional.Zugo.N
15.38%

NANO AntiVirus
Trojan.Win32.MulDrop3.cojavl, Riskware.Win32.Zugo.dfshvj
11.54%

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
11.54%

ESET NOD32
Win32/Toolbar.Zugo, Win32/Toolbar.Zugo potentially unwanted (variant)
11.54%

Bkav FE
W32.Clod5c4.Trojan, W32.HfsAdware
7.69%

Trend Micro House Call
ADW_INSTALLEREX, TROJ_GEN.F47V0222
7.69%

Rising Antivirus
NS:AdWare.Script.VBS.StartPage.g!1579249, PE:Malware.ArcadeWeb!6.425
7.69%

1 / 68      (Adware)
zplugins.dll  (c831a16f7c8cdff319d2299f92c67836)

1 / 68      (Adware)
zplugins.dll  (a0445442fa8bd66cefaceb9b695f4206)

1 / 68      (Adware)
zplugins.dll  (9e3b9da5a7b640f8e7870f4ec87b6864)

1 / 68      (Adware)
genfix.exe  (ac437f049ef62c6bb69a58570df06d72)

1 / 68      (Adware)
search_protect.exe (StartNow Search Update)  (174c7ce594f051ea1b0735095e93c86c)

1 / 68      (Adware)
zplugins.dll  (3438403cb6e512d8322142fc48279c2d)

1 / 68      (Adware)
zplugins.dll  (caa8a8192ea28e27fb67b3ed4e679d1d)

1 / 68      (Adware)
toolbarupdate.exe (StartNow Toolbar update (Firefox))  (7e09f5adf5c6476babefc1f0b3cbd049)

1 / 68      (Adware)
toolbarupdate.exe  (9825a9516a6c2c133a212e23d45fc648)

1 / 68      (Adware)
zplugins.dll  (f50a9f2e4c786fe1935c5b016904a931)

1 / 68      (Adware)
zplugins.dll  (d4b61e5197ee4983d027e1f63cc09daa)

1 / 68      (Adware)
tmp00000149f44fed09929e11d8  (57139da1b3c30665c7f24a030f2fe096)

1 / 68      (Adware)
startnow-toolbar.exe (StartNow Toolbar by Zugo)  (fec1ba41ca7552259d5fe4bcd6831a5c)

1 / 68      (Adware)
tmp00000056118f7596fe19f828  (f9cfa40dd228a7a239f7222fc873c9a2)

1 / 68      (Adware)
zplugins.dll  (b0340137d4fc336978e5d9dd33948ee1)

1 / 68      (Adware)
zplugins.dll  (67b3edadab82b332b6793da33dd7d371)

5 / 68      (Adware)

1 / 68      (Adware)
zplugins.dll  (6b8f10bb530c05c691a53e0b81a555f4)

1 / 68      (Adware)
zplugins.dll  (738360f4575afe6284038949c4d44f69)

19 / 68    (Adware)
startnow-toolbar.exe (StartNow Toolbar by Zugo)  (ae7544854cf4e27757e0d9ceb4a2aab8)

1 / 68      (Adware)
zplugins.dll  (a0445442fa8bd66cefaceb9b695f4206)

7 / 68      (Adware)
toolbarupdate.exe  (9caeb652d45bee7d3ca9796b987f97fb)

4 / 68      (Adware)
search_protect.exe (StartNow Search Update)  (9fc90fe4883297aed915ce0c411b4156)

5 / 68      (Adware)
toolbarupdate.exe  (65b30940c6f76b234ff2269b0600660d)

4 / 68      (Adware)
toolbarupdate.exe  (28ae3dd3ac533b525a3fcbe4f26fd6f8)

13 / 68    (Adware)
toolbarupdate.exe (StartNow Toolbar update (Firefox))  (e265dd2389058bf99c55d7bcb2fffdb0)

Downloads URLs for files signed by Zugo Ltd.

19 / 68    (Adware)
http://about.startnow.com/.../startnow-toolbar.exe  (ae7544854cf4e27757e0d9ceb4a2aab8)

The following websites host and distribute files published by Zugo Ltd.

The certificates below are also signed by Zugo Ltd.

46241CDE5C7B500B51C5F1328228F2A9  (Jan 27, 2011 to Jan 27, 2013)

00C52FD6F7886644358C539D8FC50BCC93  (Jan 25, 2010 to Jan 26, 2011)

* Note, the details and description above are based on the code signing digital signature issued to Zugo Ltd by COMODO CA Limited on January 30, 2013 with the serial number '00fa860df2ac924fc31176c787706f3824'.