Trojan

What is “TrojanDownloader:Win32/Tugspay.A”?

Malware Removal

The TrojanDownloader:Win32/Tugspay.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Tugspay.A virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Spanish (Modern)
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine TrojanDownloader:Win32/Tugspay.A?


File Info:

name: AB6456C32F726F7A02EF.mlw
path: /opt/CAPEv2/storage/binaries/b1f1798b2d139d9471ac67d8d3f187e08197e6edef93acdfe0d5eeac57ec97f2
crc32: C0BB1363
md5: ab6456c32f726f7a02effa8a1b1f8b60
sha1: b20624280c95f82559e5aec8c668b4b0117da386
sha256: b1f1798b2d139d9471ac67d8d3f187e08197e6edef93acdfe0d5eeac57ec97f2
sha512: ff9a887d55fc956ee27ab29a9e2e70eb1bfd551213f9a52cff5057d6a21b96273bd8809461e4860ac7dc46e03f383bfffa9f30eec409ce2275b19eacd83982fa
ssdeep: 6144:YLkL+jocfjGNouUGCDPJolfCf/EO0ksQyXYf4+UYPskubZmYaQAYl:YwL+ccfjTuUGCDholyb0YHUnT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T110949D153294C933CA6E4FB9902186A087B9A357564BF78F2DC965FC1EA5390E7032CB
sha3_384: c665660ea65504c338171325405186caa249ee10ad6e32318f4337c7623d3f729a8aca682699a3787ba34cbc748c531f
ep_bytes: e853240000e979feffff8bff558bec5d
timestamp: 2014-04-09 16:31:45

Version Info:

0: [No Data]

TrojanDownloader:Win32/Tugspay.A also known as:

BkavW32.AIDetectMalware
LionicAdware.MSIL.DomaIQ.lWWy
tehtrisGeneric.Malware
DrWebTrojan.Packed.26446
MicroWorld-eScanApplication.Bundler.DomaIQ.Q
CAT-QuickHealAdware.DomaIQ.BT5
SkyhighBehavesLike.Win32.Generic.gh
McAfeeCryptDomaIQ
Cylanceunsafe
ZillyaAdware.DomaIQ.Win32.207
SangforTrojan.Win32.Save.a
K7AntiVirusUnwanted-Program ( 00575d1c1 )
AlibabaAdWare:Win32/DomaIQ.0a5667a3
K7GWUnwanted-Program ( 00575d1c1 )
Cybereasonmalicious.32f726
VirITAdware.Win32.DomaIQ_r.H
SymantecTrojan.ADH.2
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/DomaIQ.BB potentially unwanted
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R002C0CBG24
ClamAVWin.Adware.Domaiq-1
Kasperskynot-a-virus:HEUR:AdWare.MSIL.DomaIQ.gen
BitDefenderApplication.Bundler.DomaIQ.Q
NANO-AntivirusRiskware.Win32.Lollipop.cykrpe
SUPERAntiSpywarePUP.DomaIQ/Variant
AvastWin32:DomaIQ-CC [PUP]
TencentAdware.Win32.Lollipop.f
EmsisoftApplication.Downloader (A)
F-SecurePotentialRisk.PUA/DomaIQ.Gen
BaiduWin32.Adware.DomnIQ.b
VIPREApplication.Bundler.DomaIQ.Q
TrendMicroTROJ_GEN.R002C0CBG24
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.ab6456c32f726f7a
SophosDomaIQ pay-per install (PUA)
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=100)
JiangminPack.Mal.AntiVM
GoogleDetected
AviraPUA/DomaIQ.Gen
VaristW32/A-5724c4f6!Eldorado
Antiy-AVLGrayWare[AdWare]/MSIL.DomaIQ
MicrosoftTrojanDownloader:Win32/Tugspay.A
XcitiumApplication.Win32.DomaIQ.PUP@58rjby
ArcabitApplication.Bundler.DomaIQ.Q
ViRobotAdware.Domaiq.441736.J
ZoneAlarmnot-a-virus:HEUR:AdWare.MSIL.DomaIQ.gen
GDataWin32.Trojan.PSE.10PH8RR
AhnLab-V3PUP/Win32.DomaIQ.R105267
Acronissuspicious
VBA32BScope.Adware.MSIL.DomaIQ
ALYacApplication.Bundler.DomaIQ.Q
MalwarebytesPUP.Optional.DomaIQ.DDS
PandaPUP/MultiToolbar.A
RisingDownloader.Tugspay!1.A14B (CLASSIC)
YandexPUA.DomaIQ!0T6K0AUV7sY
IkarusRootkit
MaxSecureAdware.WIN32.Lollipop.brsc_220668
FortinetAdware/MSIL_DomaIQ
AVGWin32:DomaIQ-CC [PUP]
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_100% (W)
alibabacloudTrojan:Win/Tugspay.BCD(dyn)

How to remove TrojanDownloader:Win32/Tugspay.A?

TrojanDownloader:Win32/Tugspay.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment