player_setup.exe

Tuguu S.L.

The Tuguu download and install manager uses the DomalIQ installer to bundle additional adware offers such as toolbars and browser extensions during the setup process. This software distributes modified installers which are not the same as the original distributed by the author. The application player_setup.exe by Tuguu S.L has been detected as adware by 12 anti-malware scanners. The program is a setup application that uses the TUGUU DomaIQ Setup installer. The file has been seen being downloaded from dlp.ooopsvideo.com and multiple other hosts.
Publisher:
Tuguu S.L.  (signed and verified)

MD5:
044db2b16f9f251fc5347559864e760e

SHA-1:
5817fd1702969bbc33ee0803de4427757ad77aae

SHA-256:
c9a9dfbfa9ca687a58bd07fee5b43bc25b7ba9ffb86cc78fd228c42264dc5f80

Scanner detections:
12 / 68

Status:
Adware

Explanation:
Uses the InstallIQ download installer to bundle various adware offers.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
11/23/2024 2:34:20 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
APPL/DomaIQ.Gen7
7.11.173.218

AVG
Generic
2015.0.3343

Dr.Web
Adware.W3i.28
9.0.1.05190

ESET NOD32
Win32/DomaIQ.X potentially unwanted application
7.0.302.0

K7 AntiVirus
Unwanted-Program
13.183.13451

Malwarebytes
PUP.Optional.MSILLauncher
v2014.09.22.07

McAfee
Artemis!079F1F89836E
5600.6999

Panda Antivirus
PUP/MultiToolbar.A
14.09.22.07

Qihoo 360 Security
HEUR/Malware.QVM03.Gen
1.0.0.1015

Reason Heuristics
PUP.Installer.TuguuSL.M
14.9.22.18

Sophos
DomainIQ pay-per install
4.98

VIPRE Antivirus
Threat.4783235
32938

File size:
372.4 KB (381,344 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
TUGUU DomaIQ Setup (using Nullsoft Install System)

Common path:
C:\users\{user}\downloads\player_setup.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
5/14/2013 2:00:00 AM

Valid to:
7/18/2014 2:00:00 PM

Subject:
CN=Tuguu S.L., OU=U B76539535, O=Tuguu S.L., L=Adeje, S=Santa Cruz de Tenerife, C=ES

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
08EC69B75B2FE31EC2C53E0E441AC0E1

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:41 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:DQqKZuu/h5ICs1OxINRj9jSdPxWgR193uwun8dfxxHgDVq49vAvhkZz:ouu/QCs1zNRjsTWu93JLffQq+vcez

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 3F, 42, 00, E8, F1, 2B, 00, 00, A3, 84, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 36, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

The file player_setup.exe has been seen being distributed by the following 4 URLs.

Remove player_setup.exe - Powered by Reason Core Security