Trojan

TrojanDownloader:Win32/Tugspay.A removal instruction

Malware Removal

The TrojanDownloader:Win32/Tugspay.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Tugspay.A virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Spanish (Modern)
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Detects Bochs through the presence of a registry key
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine TrojanDownloader:Win32/Tugspay.A?


File Info:

name: E209B8FD7E55C58C14AA.mlw
path: /opt/CAPEv2/storage/binaries/a88ab4947974f6e52761c042319bdbe9f3fff5821193a9c1a30b2db0475bd317
crc32: 9F972F3E
md5: e209b8fd7e55c58c14aa3c8e139e2ee0
sha1: 168721d39f73090d17e029770ca5469d3a993a8f
sha256: a88ab4947974f6e52761c042319bdbe9f3fff5821193a9c1a30b2db0475bd317
sha512: 9af69f3d595bf1c7e9ebf2ac70d2b958ce326164228c0a6692c7612f15d9d462672b5778a12e17fadfcc2dac5bdce984de7ef84712dd331417ec4197d5ef31a8
ssdeep: 6144:mlL7anD8b/2lQbZtUaQ9e0CjGO5951fWjjkcwZEV1lJwjV:ySnD8rAe0CjGA9fWXkclV1lJIV
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T146D4D01273D0C137C45A267B8461CB70AB76F5A95B139B8F2ACD81BC5F257D09A3238B
sha3_384: 844369fabbd6c08672f95bdc84f6185a13c63816d04c6d34aae9c796160a3a02d5c001d3c73fea0966c74c4df5a16164
ep_bytes: e8fc1e0000e979feffff8bff558bec5d
timestamp: 2014-04-11 11:55:38

Version Info:

0: [No Data]

TrojanDownloader:Win32/Tugspay.A also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Application.Bundler.DomaIQ.21
FireEyeGeneric.mg.e209b8fd7e55c58c
CAT-QuickHealAdware.DomaIQ.BT5
SkyhighBehavesLike.Win32.Generic.jm
ALYacGen:Variant.Application.Bundler.DomaIQ.21
MalwarebytesPUP.Optional.DomaIQ.DDS
ZillyaAdware.DomaIQ.Win32.222
SangforTrojan.Win32.Save.a
K7AntiVirusUnwanted-Program ( 00575d1c1 )
AlibabaAdWare:Win32/DomaIQ.14ef70d4
K7GWUnwanted-Program ( 00575d1c1 )
VirITAdware.Win32.DomaIQ.CI
SymantecPUA.MyPCBackup
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/DomaIQ.BB potentially unwanted
APEXMalicious
ClamAVWin.Adware.Domaiq-1
Kasperskynot-a-virus:AdWare.MSIL.DomaIQ.clem
BitDefenderGen:Variant.Application.Bundler.DomaIQ.21
NANO-AntivirusRiskware.Win32.Adw.daqhbe
SUPERAntiSpywarePUP.DomaIQ/Variant
AvastWin32:DomaIQ-CC [PUP]
TencentAdware.Win32.Lollipop.f
SophosDomaIQ pay-per install (PUA)
BaiduWin32.Adware.DomnIQ.b
F-SecurePotentialRisk.PUA/DomaIQ.Gen
DrWebTrojan.Domaiq.190
VIPREGen:Variant.Application.Bundler.DomaIQ.21
Trapminemalicious.high.ml.score
EmsisoftApplication.Downloader (A)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.1XF8QMW
WebrootPua.Adware.Gen
GoogleDetected
AviraPUA/DomaIQ.Gen
VaristW32/DomaIQ.C.gen!Eldorado
Antiy-AVLGrayWare[AdWare]/MSIL.DomaIQ
XcitiumApplication.Win32.DomaIQ.PUP@58rjby
ArcabitTrojan.Application.Bundler.DomaIQ.21
ZoneAlarmnot-a-virus:AdWare.MSIL.DomaIQ.clem
MicrosoftTrojanDownloader:Win32/Tugspay.A
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.DomaIQ.R105451
Acronissuspicious
McAfeePUP-RGTK
MAXmalware (ai score=99)
VBA32BScope.Adware.MSIL.DomaIQ
Cylanceunsafe
PandaPUP/MultiToolbar.A
RisingDownloader.Tugspay!1.A14B (CLASSIC)
YandexPUA.DomaIQ!xJMT9j8mluU
Ikarusnot-a-virus:AdWare.MSIL.DomaIQ
MaxSecureAdware.WIN32.Lollipop.brsc_220671
FortinetRiskware/DomaIQ.BB
AVGWin32:DomaIQ-CC [PUP]
DeepInstinctMALICIOUS

How to remove TrojanDownloader:Win32/Tugspay.A?

TrojanDownloader:Win32/Tugspay.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment