PUA

PUA:Win32/Tugspay removal tips

Malware Removal

The PUA:Win32/Tugspay is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA:Win32/Tugspay virus can do?

  • Authenticode signature is invalid

How to determine PUA:Win32/Tugspay?


File Info:

name: 1B5B21D356FA178B42CD.mlw
path: /opt/CAPEv2/storage/binaries/e0573cbec218cf92a2b917a93b36d0a7904a1445081df07b5d5c0953a0a1914f
crc32: 25F9D6E1
md5: 1b5b21d356fa178b42cde5fd2431d98d
sha1: c91281ec9866b7d203e4e08b189c4705cebe2ed9
sha256: e0573cbec218cf92a2b917a93b36d0a7904a1445081df07b5d5c0953a0a1914f
sha512: ab8dbd0074b863246b180eeeec0c3eb915648bd41a98868d5703b92a7dff4c220d3734bfa1af0963adcbdf1b970fcf5bdc6f6f472ffbcc7429503b329ba973d0
ssdeep: 12288:AKsGrWwZZS6mO6wbbS+kC7IuLy2HcP1N0Ye4QCxX+mXkh4z1zjKQLFe4ccxpvf4O:pq6mO6sbS+kCcuLy289Q+
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T104B4519C321076EFE85BD97ACEA41C64EA6074A7871BD203A45353ED9D0CAA7CF114E3
sha3_384: 67a48e68fd9508e627fcf6102d624a5a8f51f4f009149f1b3f71777eea80ec5a99144d17429371bf99a6a0ee092a2c7d
ep_bytes: 00000000000000000000000000000000
timestamp: 2014-06-12 13:02:09

Version Info:

0: [No Data]

PUA:Win32/Tugspay also known as:

LionicAdware.MSIL.DomaIQ.2!c
SkyhighArtemis!Trojan
McAfeeArtemis!1B5B21D356FA
Cylanceunsafe
ZillyaAdware.DomaIQ.Win32.3496
SangforTrojan.Win32.Save.a
AlibabaTrojanDownloader:Win32/Tugspay.066f5cbc
CrowdStrikewin/malicious_confidence_60% (D)
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
ClamAVWin.Dropper.Domaiq-9992448-0
Kasperskynot-a-virus:HEUR:AdWare.MSIL.DomaIQ.heur
AvastWin32:Adware-gen [Adw]
TencentMsil.AdWare.Domaiq.Msmw
F-SecureTrojan.TR/Inject.owlpanom
SophosGeneric Reputation PUA (PUA)
IkarusAdWare.DomaIQ
AviraTR/Inject.owlpanom
Antiy-AVLGrayWare[AdWare]/MSIL.DomaIQ
MicrosoftPUA:Win32/Tugspay
ZoneAlarmnot-a-virus:HEUR:AdWare.MSIL.DomaIQ.heur
GoogleDetected
VBA32CIL.HeapOverride.Heur
MalwarebytesPUP.Optional.DomaIQ.DDS
PandaTrj/CI.A
RisingDownloader.Tugspay!1.A14B (CLASSIC)
FortinetAdware/DomaIQ
AVGWin32:Adware-gen [Adw]
DeepInstinctMALICIOUS

How to remove PUA:Win32/Tugspay?

PUA:Win32/Tugspay removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment