tugs_ar_qone8.exe

Skytouch Technology Co., Limited

The application tugs_ar_qone8.exe by Skytouch Technology Co., Limited has been detected as adware by 34 anti-malware scanners. It is also typically executed from the user's temporary directory.
Publisher:
Skytouch Technology Co., Limited  (signed and verified)

Version:
2.0.2.2666

MD5:
21a59f3cd8ba8fc49f1f6c6efef027b8

SHA-1:
d5bc0d823ac782c0efe549ace78b8fdb4ab54801

SHA-256:
210ce58cbbafc406262455882356d048a78c345bff2108cef2ef060f23e6a727

Scanner detections:
34 / 68

Status:
Adware

Analysis date:
4/25/2024 5:09:01 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.9818630
1135

Agnitum Outpost
Trojan.DL.Fyli
7.1.1

Avira AntiVirus
TR/Wysotot.Gen
7.11.119.84

avast!
Win32:Adware-BEC [Adw]
2014.9-131226

AVG
Win32/DH
2014.0.3613

Bitdefender
Trojan.Generic.9818630
1.0.20.1800

Bkav FE
W32.Clod2ef.Trojan
1.3.0.4613

Comodo Security
TrojWare.Win32.StartPage.~CJAB
17425

Dr.Web
Adware.Mutabaha.38
9.0.1.0360

Emsisoft Anti-Malware
Gen:Variant.Application.ExqPage
8.14.01.05.03

ESET NOD32
Win32/ELEX (variant)
7.9162

Fortinet FortiGate
W32/StartPage.CJAB!tr
12/26/2013

F-Prot
W32/Backdoor2.HTEG
v6.4.7.1.166

F-Secure
Trojan.Generic.9818630
11.2013-26-12_5

G Data
Trojan.Generic.9818630
13.12.22

IKARUS anti.virus
Trojan.Win32.StartPage
t3scan.2.2.29

K7 AntiVirus
Unwanted-Program
13.174.10484

Kaspersky
Trojan.Win32.StartPage
14.0.0.4560

Malwarebytes
PUP.Optional.Elex.A
v2013.12.26.10

McAfee
RDN/Downloader.a!og
5600.7269

Microsoft Security Essentials
TrojanDownloader:Win32/Wysotot.A
1.163.1557.0

MicroWorld eScan
Trojan.Generic.9818630
14.0.0.1080

NANO AntiVirus
Trojan.Win32.StartPage.ckbxqj
0.28.0.56692

Norman
Suspicious_Gen4.FFFFA
11.20140105

nProtect
Trojan/W32.Agent.702616
13.12.11.03

Panda Antivirus
Trj/Elex.A
13.12.26.10

Quick Heal
TrojanDownloader.Wysotot.A5
12.13.12.00

Reason Heuristics
PUP.SkytouchTechnologyCoLimited.N
14.3.20.14

Sophos
Elex
4.95

SUPERAntiSpyware
Trojan.Agent/Gen-ELEX
10883

Total Defense
Win32/Wysotot.XRMbSHD
37.0.10641

Trend Micro House Call
TROJ_SPNR.0BJQ13
7.2.360

Trend Micro
TROJ_SPNR.0BJQ13
10.465.26

VIPRE Antivirus
Trojan.Win32.Generic
24274

File size:
686.1 KB (702,616 bytes)

Product version:
2.0.2.2666

Copyright:
Copyright (C) 2013

Original file name:
iXB.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\97fa165c5f484b18a65b6064c9683345\software\tugs_ar_qone8.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
7/8/2013 10:29:59 AM

Valid to:
7/9/2014 10:29:59 AM

Subject:
CN="Skytouch Technology Co., Limited", O="Skytouch Technology Co., Limited", L=HongKong, S=HongKong, C=HK

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11216078022FA91C0EB61326E0E8FDBE9C30

File PE Metadata
Compilation timestamp:
10/22/2013 12:18:54 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:kmEBTASggJMutz4hDhFEouFeED0NO3yEU8m/udmipauZZZZ37nvEo8uICH8WQpXF:4BTNJMuJ0NovlbSWcXPQg/ooo3/VMIyH

Entry address:
0x54FD7

Entry point:
E8, 20, F4, 00, 00, E9, 39, FE, FF, FF, 55, 8B, EC, 56, 57, 8B, 7D, 08, 85, FF, 74, 13, 8B, 4D, 0C, 85, C9, 74, 0C, 8B, 55, 10, 85, D2, 75, 1A, 33, C0, 66, 89, 07, E8, 2C, 8C, 00, 00, 6A, 16, 5E, 89, 30, E8, 80, 5A, 00, 00, 8B, C6, 5F, 5E, 5D, C3, 8B, F7, 66, 83, 3E, 00, 74, 06, 83, C6, 02, 49, 75, F4, 85, C9, 74, D4, 2B, F2, 0F, B7, 02, 66, 89, 04, 16, 8D, 52, 02, 66, 85, C0, 74, 03, 49, 75, EE, 33, C0, 85, C9, 75, D0, 66, 89, 07, E8, E8, 8B, 00, 00, 6A, 22, EB, BA, 55, 8B, EC, 51, 33, C0, 89, 45, FC, 39...
 
[+]

Code size:
515 KB (527,360 bytes)

Remove tugs_ar_qone8.exe - Powered by Reason Core Security