Trojan

TrojanDownloader:Win32/Tugspay!pz information

Malware Removal

The TrojanDownloader:Win32/Tugspay!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Tugspay!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Spanish (Modern)
  • Authenticode signature is invalid
  • Detects Bochs through the presence of a registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Attempted to write directly to a physical drive
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine TrojanDownloader:Win32/Tugspay!pz?


File Info:

name: C629DE5FDE6EB58FFD55.mlw
path: /opt/CAPEv2/storage/binaries/13899d2755a9749ac36f312a96bc9f4ac30321ba56a9f71ad3489635f9ea2030
crc32: 3735A525
md5: c629de5fde6eb58ffd553e536eaeb2fb
sha1: 7cd2ace2a7b07329245904329b3a11b58d5ad472
sha256: 13899d2755a9749ac36f312a96bc9f4ac30321ba56a9f71ad3489635f9ea2030
sha512: 829ff94ba527da36063b113c722f87c031fd3fa7aa87b77686446120dda95b55e1dadf576951d093689bc762e5d118eb1f6b1fe971e0c10058b46118a4038d0d
ssdeep: 12288:GAOn2vQLFMBqOqb3W0LXxpULy0l4SGGvGGvGGvGGp2wW:GT9eqb3W0LXXLXSGGvGGvGGvGGp2h
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19CE4AD113254C662E07F4FFB90A2511003B4BD278B96F79B2FD976ED1D323815B2A6A3
sha3_384: 02ae5b6d5b5ddbd2c5f33e3d2a7b46467906d42d7773eef0f25b8fba7fc86aff742ef5e7f6d45eb7fc055e4b9b150520
ep_bytes: e8fe3b0000e939feffff558bec837d08
timestamp: 2014-06-03 10:56:34

Version Info:

0: [No Data]

TrojanDownloader:Win32/Tugspay!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Application.Bundler.DomaIQ.21
FireEyeGeneric.mg.c629de5fde6eb58f
CAT-QuickHealAdware.DomaIQ.BT5
SkyhighBehavesLike.Win32.Generic.jh
McAfeePUP-FAO
MalwarebytesPUP.Optional.DomaIQ.DDS
ZillyaAdware.DomaIQ.Win32.315
SangforTrojan.Win32.Save.a
AlibabaMalware:Win32/km_2c9e4.None
K7GWAdware ( 004b9d501 )
K7AntiVirusAdware ( 004b9d501 )
VirITAdware.Win32.DomaIQ.EN
SymantecTrojan.Gen.MBT
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/DomaIQ.BB potentially unwanted
APEXMalicious
AvastWin32:DomaIQ-CC [PUP]
ClamAVWin.Adware.Domaiq-1
Kasperskynot-a-virus:HEUR:AdWare.MSIL.DomaIQ.heur
BitDefenderGen:Variant.Application.Bundler.DomaIQ.21
NANO-AntivirusRiskware.Win32.DomaIQ.dawypj
SUPERAntiSpywarePUP.DomaIQ/Variant
TencentAdware.Win32.Domaiq.16000414
EmsisoftApplication.Downloader (A)
BaiduWin32.Adware.DomnIQ.l
F-SecurePotentialRisk.PUA/DomaIQ.Gen
DrWebTrojan.DownLoader11.26788
VIPREGen:Variant.Application.Bundler.DomaIQ.21
TrendMicroTROJ_GEN.R002C0CAN24
Trapminemalicious.high.ml.score
SophosDomaIQ pay-per install (PUA)
IkarusAdWare.DomaIQ
GDataWin32.Trojan.PSE.1IIEU93
JiangminAdWare/Lollipop.dx
WebrootPua.Downloadmgr
VaristW32/DomaIQ.J.gen!Eldorado
AviraPUA/DomaIQ.Gen
MAXmalware (ai score=100)
Antiy-AVLGrayWare[AdWare]/Win32.Lollipop
XcitiumApplicUnwnt.Win32.DomaIQ.DDF@5b4wjh
ArcabitTrojan.Application.Bundler.DomaIQ.21
ViRobotAdware.Domaiq.669232.I
ZoneAlarmnot-a-virus:HEUR:AdWare.MSIL.DomaIQ.heur
MicrosoftTrojanDownloader:Win32/Tugspay!pz
GoogleDetected
AhnLab-V3PUP/Win32.DomaIQ.R109029
Acronissuspicious
VBA32BScope.Adware.MSIL.DomaIQ
ALYacGen:Variant.Application.Bundler.DomaIQ.21
Cylanceunsafe
PandaPUP/MultiToolbar.A
TrendMicro-HouseCallTROJ_GEN.R002C0CAN24
RisingDownloader.Tugspay!1.A14B (CLASSIC)
YandexPUA.Lollipop!e/iNV639QzQ
SentinelOneStatic AI – Malicious PE
FortinetRiskware/DomaIQ
AVGWin32:DomaIQ-CC [PUP]
DeepInstinctMALICIOUS

How to remove TrojanDownloader:Win32/Tugspay!pz?

TrojanDownloader:Win32/Tugspay!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment