Trojan

TrojanDownloader:Win32/Tugspay.A removal

Malware Removal

The TrojanDownloader:Win32/Tugspay.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Tugspay.A virus can do?

  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • .NET file is packed/obfuscated with Confuser
  • Authenticode signature is invalid

How to determine TrojanDownloader:Win32/Tugspay.A?


File Info:

name: 2916D37F340484950BEA.mlw
path: /opt/CAPEv2/storage/binaries/412b2c8e76b4a59950036775b06afa12fc5ef04c982f3791e35203b9ce616aee
crc32: D159EE75
md5: 2916d37f340484950bea6befe209ef30
sha1: 14dc5fb142c70ec46188c2dd3172a77899e23cbe
sha256: 412b2c8e76b4a59950036775b06afa12fc5ef04c982f3791e35203b9ce616aee
sha512: 397bbe45253ab19cb4745119e6f1d3bd9d78068b703ef4fe565c502b38a79b990177866824e997fa1c8401cc6ef9d52234ca5e0f7d75a8395c2cd9bce678effa
ssdeep: 3072:EQoRVFM1I6vv4/9jQr9FbIsSguKGEqVDR+kQ2iOo6bbsKVjAB28WQvtqAqTJYY3L:EQoR/M+634/ZaKszyR8Qbti28W/JY0L
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T106545B5DB3949E03FA6F0EFA815213B193B08747AA8BF3865CC97CE928E574025075DB
sha3_384: 97d515d21459c76c9be3f474b5ba8a564c40b1988701226759ed93098beef0a5c78974d745d5723f5350ab869439ec9b
ep_bytes: ff250020400000000000000000000000
timestamp: 2014-03-06 15:21:01

Version Info:

Translation: 0x0000 0x04b0
FileDescription: ProcessMon
FileVersion: 4.0.8.01
InternalName: rSetp.dll
LegalCopyright:
OriginalFilename: rSetp.dll
ProductVersion: 4.0.8.01
Assembly Version: 4.0.8.1

TrojanDownloader:Win32/Tugspay.A also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanApplication.Bundler.DomaIQ.Q
CAT-QuickHealPUA.Tuguusl3.Gen
SkyhighBehavesLike.Win32.AdwareDoma.dh
McAfeePUP-FJP
Cylanceunsafe
ZillyaAdware.Lollipop.Win32.395
SangforSuspicious.Win32.Save.a
CrowdStrikewin/grayware_confidence_100% (D)
AlibabaAdWare:MSIL/DomaIQ.dfe255f5
ArcabitApplication.Bundler.DomaIQ.Q
VirITAdware.Win32.DomaIQ.AP
SymantecSecurityRisk.gen1
ESET-NOD32a variant of MSIL/DomaIQ.X potentially unwanted
CynetMalicious (score: 100)
ClamAVWin.Adware.Domaiq-1
Kasperskynot-a-virus:AdWare.Win32.Lollipop.qp
BitDefenderApplication.Bundler.DomaIQ.Q
NANO-AntivirusTrojan.Win32.DomaIQ.cwydit
SUPERAntiSpywarePUP.DomaIQ/Variant
AvastWin32:Adware-gen [Adw]
TencentAdware.Win32.Lollipop.f
EmsisoftApplication.Bundler.DomaIQ.Q (B)
BaiduWin32.Adware.DomnIQ.b
F-SecurePotentialRisk.PUA/DomaIQ.Gen
VIPREApplication.Bundler.DomaIQ.Q
SophosDomaIQ pay-per install (PUA)
IkarusPUA.Bundler.DomaIQ
JiangminAdWare/MSIL.pp
WebrootPua.Tuguu.Gen
VaristW32/DomaIQ.E.gen!Eldorado
AviraPUA/DomaIQ.Gen
Antiy-AVLGrayWare[AdWare]/Win32.Lollipop.qp
XcitiumMalware@#1dbek6yz0adj1
MicrosoftTrojanDownloader:Win32/Tugspay.A
ZoneAlarmnot-a-virus:AdWare.Win32.Lollipop.qp
GDataApplication.Bundler.DomaIQ.Q
GoogleDetected
AhnLab-V3PUP/Win32.DomaIQ.R106285
VBA32TScope.Trojan.MSIL
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/CI.A
RisingDownloader.Tugspay!1.A14B (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecurenot-a-virus:.Adware.DomaIQ.annu
FortinetAdware/Lollipop
AVGWin32:Adware-gen [Adw]
DeepInstinctMALICIOUS

How to remove TrojanDownloader:Win32/Tugspay.A?

TrojanDownloader:Win32/Tugspay.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment