Trojan

How to remove “TrojanDownloader:Win32/Tugspay.A”?

Malware Removal

The TrojanDownloader:Win32/Tugspay.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Tugspay.A virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Spanish (Modern)
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Detects Bochs through the presence of a registry key
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine TrojanDownloader:Win32/Tugspay.A?


File Info:

name: 65CE19C622568F2116B7.mlw
path: /opt/CAPEv2/storage/binaries/647db27fb35a3719d47a45b56f200ca8e82b504fd4fc53aff4766becc6018992
crc32: CFCAF5A1
md5: 65ce19c622568f2116b7005881162028
sha1: a59202e33925c026d5fb43ac63b3370f9f9cbf90
sha256: 647db27fb35a3719d47a45b56f200ca8e82b504fd4fc53aff4766becc6018992
sha512: 1b1ac151b0b16543c60aee8e56baa4f380e269e26f898cb8bd2506f6853245721ee2f83486211e9ff9df7200880087274265eeb042fb23255a1ccb12e7d0edbf
ssdeep: 6144:dMcaGLqwiO3S9O02uD2ZhrHNmGgs3W6kQMLnnGmHbxSYKQ:dwGewiOC9FDKhrRgs3W6kznG0kQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T138849D1533D4DA76D96F4EB5808246A097B0D7A3928BF78B2DD878EE4DF038146136CB
sha3_384: ad3fc4da315160c9916aa5869827d4c3f91f08c41c0bc036b219d3e407692e308a065e2f1e1230af09481e8d12d3a2d1
ep_bytes: e862510000e979feffffcccccccccccc
timestamp: 2014-02-27 16:39:37

Version Info:

0: [No Data]

TrojanDownloader:Win32/Tugspay.A also known as:

BkavW32.AIDetectMalware
DrWebTrojan.Domaiq.269
MicroWorld-eScanApplication.Bundler.DomaIQ.C
ClamAVWin.Adware.Domaiq-1
FireEyeGeneric.mg.65ce19c622568f21
CAT-QuickHealAdware.DomaIQ.BT5
SkyhighCryptDomaIQ
McAfeeCryptDomaIQ
MalwarebytesCrypt.Trojan.Malicious.DDS
VIPREApplication.Bundler.DomaIQ.C
SangforTrojan.Win32.Save.a
K7AntiVirusUnwanted-Program ( 00575d1c1 )
AlibabaAdWare:Win32/DomaIQ.643cd4f0
K7GWUnwanted-Program ( 00575d1c1 )
VirITAdware.Win32.DomaIQ.R
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/DomaIQ.BA potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
Kasperskynot-a-virus:HEUR:AdWare.MSIL.Convagent.gen
BitDefenderApplication.Bundler.DomaIQ.C
NANO-AntivirusRiskware.Win32.DomaIQ.cvzhre
SUPERAntiSpywarePUP.Bundler/Variant
AvastWin32:DomaIQ-CC [PUP]
TencentAdware.Win32.Lollipop.f
EmsisoftApplication.Generic (A)
F-SecureAdware:W32/DomaIQ.B
BaiduWin32.Adware.DomnIQ.b
ZillyaAdware.DomaIQ.Win32.166
SophosDomaIQ pay-per install (PUA)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.10PH8RR
JiangminAdWare/MSIL.pw
WebrootPua.Tuguu.Gen
GoogleDetected
AviraPUA/DomaIQ.Gen
MAXmalware (ai score=100)
Antiy-AVLGrayWare[AdWare]/MSIL.DomaIQ
Kingsoftmalware.kb.a.994
XcitiumApplication.Win32.DomaIQ.PUQ@58u63d
ArcabitApplication.Bundler.DomaIQ.C
ZoneAlarmnot-a-virus:HEUR:AdWare.MSIL.Convagent.gen
MicrosoftTrojanDownloader:Win32/Tugspay.A
VaristW32/DomaIQ.C.gen!Eldorado
AhnLab-V3PUP/Win32.DomaIQ.R102667
Acronissuspicious
VBA32Trojan.DomaIQ.28709
ALYacApplication.Bundler.DomaIQ.C
Cylanceunsafe
PandaPUP/MultiToolbar.A
RisingDownloader.Tugspay!1.A14B (CLASSIC)
YandexPUA.DomaIQ!iiHrJicYbnc
IkarusPUA.Bundler.DomaIQ
MaxSecurenot-a-virus:Adware.Lolipop.gen
FortinetW32/Generic.AC.28C338!tr
AVGWin32:DomaIQ-CC [PUP]
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_100% (W)

How to remove TrojanDownloader:Win32/Tugspay.A?

TrojanDownloader:Win32/Tugspay.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment