vafplayer.exe

Tuguu S.L.

The Tuguu download and install manager uses the DomalIQ installer to bundle additional adware offers such as toolbars and browser extensions during the setup process. This software distributes modified installers which are not the same as the original distributed by the author. The application vafplayer.exe by Tuguu S.L has been detected as adware by 5 anti-malware scanners. The program is a setup application that uses the TUGUU DomaIQ Setup installer. It is also typically executed from the user's temporary directory.
Publisher:
Tuguu S.L.  (signed and verified)

MD5:
d3a06d509737458b9ed62c91486e8a52

SHA-1:
fc65f878c4bbb1061f2a418f1b1bc2c50abe31b4

SHA-256:
ae1d226c1f11ee25dd71640c0ac96f1cee66c30a4395adbbb6bdfb1d06fb39d0

Scanner detections:
5 / 68

Status:
Adware

Explanation:
Bundles third-party components such as adware in the installer.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/8/2024 8:04:08 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:DomaIQ-BQ [PUP]
2014.9-140714

Panda Antivirus
PUP/MultiToolbar.A
14.07.14.07

Reason Heuristics
PUP.TuguuSL.J
14.8.7.18

VIPRE Antivirus
DomaIQ
29512

File size:
4 MB (4,148,928 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
TUGUU DomaIQ Setup (using Nullsoft Install System)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\software\vafplayer.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
1/14/2014 4:00:00 AM

Valid to:
1/22/2015 4:00:00 PM

Subject:
CN=Tuguu S.L., O=Tuguu S.L., L=Adeje, S=Santa Cruz de Tenerife, C=ES

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
099FA0FF5AB358109F600F1A845EEE88

File PE Metadata
Compilation timestamp:
12/6/2009 2:50:46 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:AEZbUHqKIuR6tgTbVF5DZ3HUzBTjBeJXn:DZbUHqGQC1kVo

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Entropy:
7.8090

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

Remove vafplayer.exe - Powered by Reason Core Security