Trojan

How to remove “TrojanDownloader:Win32/Tugspay!pz”?

Malware Removal

The TrojanDownloader:Win32/Tugspay!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Tugspay!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Spanish (Modern)
  • Authenticode signature is invalid
  • Detects Bochs through the presence of a registry key
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Anomalous binary characteristics

How to determine TrojanDownloader:Win32/Tugspay!pz?


File Info:

name: A79B195B0F0FDEA78262.mlw
path: /opt/CAPEv2/storage/binaries/66db388ccdfd5e59ecf667d741b95996747048d162e856c872fb883dffbab3a5
crc32: 177F2006
md5: a79b195b0f0fdea78262329444e26f50
sha1: 696af641b02f4109ec5e1db52615473adc42c174
sha256: 66db388ccdfd5e59ecf667d741b95996747048d162e856c872fb883dffbab3a5
sha512: a1c12d04f43fa265d144020e1de08de2b77b409a6e32493f1262ff377d15496997b036e28e6717c284e6694f6b99fa75c2445f297db26af033eaf105ebb6d8d0
ssdeep: 6144:OXmiLuncbmmkHCUwDgt/ZSwLM2f3a6xAEg8ovT9ploCe1O6pRbYxvfTHMYA:WmiGmkHC3s3SwLMAvxAQwjJe7SrHI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EFA4AE193794C933D62F4FF6413183A44BB1E2179A4BF78B2DD924F91E983919A072CB
sha3_384: b938eada69c9b3ba2d9e1fbc3088bc8893f3e058fc8cec2ca9f4d07184ba10782a02bd84b1f21671be77a11079043c2c
ep_bytes: e8272e0000e979feffff6a0c6820fa41
timestamp: 2014-04-16 09:37:10

Version Info:

0: [No Data]

TrojanDownloader:Win32/Tugspay!pz also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanApplication.Bundler.DomaIQ.Q
FireEyeGeneric.mg.a79b195b0f0fdea7
CAT-QuickHealAdware.DomaIQ.BT5
SkyhighBehavesLike.Win32.Generic.gh
McAfeeGenericRXAP-LE!A79B195B0F0F
Cylanceunsafe
VIPREApplication.Bundler.DomaIQ.Q
SangforTrojan.Win32.Save.a
CrowdStrikewin/grayware_confidence_100% (D)
AlibabaAdWare:Win32/DomaIQ.9ae2394c
K7GWUnwanted-Program ( 004a8e8a1 )
K7AntiVirusUnwanted-Program ( 004a8e8a1 )
BaiduWin32.Adware.DomnIQ.b
VirITAdware.Win32.DomaIQ_r.J
SymantecPUA.MyPCBackup
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/DomaIQ.BB potentially unwanted
APEXMalicious
ClamAVWin.Adware.Domaiq-1
Kasperskynot-a-virus:AdWare.Win32.Lollipop.agzn
BitDefenderApplication.Bundler.DomaIQ.Q
NANO-AntivirusRiskware.Win32.Lollipop.cxalla
SUPERAntiSpywarePUP.DomaIQ/Variant
AvastWin32:DomaIQ-CC [PUP]
TencentAdware.Win32.Lollipop.f
SophosDomaIQ pay-per install (PUA)
F-SecurePotentialRisk.PUA/DomaIQ.Gen
DrWebTrojan.Domaiq.316
ZillyaAdware.DomaIQ.Win32.229
Trapminemalicious.high.ml.score
EmsisoftApplication.Downloader (A)
IkarusAdWare.DomaIQ
GDataWin32.Trojan.PSE.10PH8RR
JiangminAdWare/MSIL.qw
WebrootPua.Tuguu.Gen
GoogleDetected
AviraPUA/DomaIQ.Gen
VaristW32/A-82f72d20!Eldorado
Antiy-AVLGrayWare[AdWare]/Win32.Lollipop
Kingsoftmalware.kb.a.983
XcitiumApplication.Win32.DomaIQ.PUR@596hhd
ArcabitApplication.Bundler.DomaIQ.Q
ZoneAlarmnot-a-virus:AdWare.Win32.Lollipop.agzn
MicrosoftTrojanDownloader:Win32/Tugspay!pz
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.DomaIQ.R105208
Acronissuspicious
ALYacApplication.Bundler.DomaIQ.Q
MAXmalware (ai score=99)
VBA32BScope.Adware.MSIL.DomaIQ
MalwarebytesGeneric.Malware.AI.DDS
PandaPUP/MultiToolbar.A
RisingDownloader.Tugspay!1.A14B (CLASSIC)
YandexPUA.Lollipop!Tit8xLQr6yg
SentinelOneStatic AI – Malicious PE
MaxSecureAdware.WIN32.Lollipop.brsc_220674
FortinetRiskware/Generic.AC.8EBC9
AVGWin32:DomaIQ-CC [PUP]
DeepInstinctMALICIOUS

How to remove TrojanDownloader:Win32/Tugspay!pz?

TrojanDownloader:Win32/Tugspay!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment