| N/A | |
| PE32 executable (GUI) Intel 80386, for MS Windows | 322568 |
| N/A | |
| 2b63b8a1bd8ccd4dbcccc11af5f8248a | |
| 017f784f6abe4068a897b4acab42e93cbad7128d | |
| f763472482859d4252475e42fdbecb20dbd3a844fa0904b38f6302e24af60f7e | |
| N/A | |
| N/A | |
| N/A | |
| N/A | |
| PE32 | |
| TSULoader | |
| {5A3ED548-5AC8-4F2A-B164-A8296A502D8E} | |
| {E3B3B09C-CF46-4E42-ACA9-87643850926A} | |
| N/A | |
| WinNT (x86) Unicode Lib Rel | |
| 315 kB | |
| Intel 386 or later, and compatibles | |
| TSULoader.exe | |
| Win32 | |
| N/A | |
| 7680 | |
| 4.0 | |
| 0x14db | |
| 0x003f | |
| 8.0 | |
| N/A | |
| N/A | |
| N/A | |
| 309760 | |
| N/A | |
| N/A | |
| 1.0.0.3 | |
| N/A | |
| TopApp soft | |
| TopApp soft | |
| application/octet-stream | |
| N/A | |
| Unicode | |
| Neutral | |
| 2014.5.26.2303 | |
| Win32 EXE | |
| N/A | |
| N/A | |
| N/A | |
| Windows GUI | |
| N/A | |
| Executable application | |
| 6.0 | |
| Special build | |
| 4.0 | |
| /x | |
| Source: |

| AVG | Generic.373 |
| Agnitum | Trojan.AntiFW! |
| AhnLab-V3 | PUP/Win32.TSULoader |
| AntiVir | Adware/InstallRex.G |
| Antiy-AVL | RiskWare[Downloader:not-a-virus,HEUR]/Win32.AdLoad |
| Avast | Win32:InstalleRex-BW [PUP] |
| Baidu-International | Adware.Win32.InstalleRex.bM |
| Bkav | HW32.CDB.3100 |
| CAT-QuickHeal | Trojan.AntiFW.A5 |
| Comodo | Application.Win32.InstalleRex.KG |
| DrWeb | Trojan.WebPick.2579 |
| ESET-NOD32 | Win32/InstalleRex.M |
| Kaspersky | Trojan.Win32.AntiFW.b |
| Kingsoft | Win32.Troj.AntiFW.b.(kcloud) |
| Malwarebytes | PUP.Optional.InstalleRex |
| McAfee | PUP-FHQ!2B63B8A1BD8C |
| McAfee-GW-Edition | PUP-FHQ!2B63B8A1BD8C |
| NANO-Antivirus | Riskware.Win32.InfoLeak.cvgqot |
| Panda | PUP/TSUploader |
| Qihoo-360 | Malware.QVM20.Gen |
| Rising | PE:Trojan.AntiFW!6.17F7 |
| Sophos | InstallRex |
| VBA32 | Downware.TSU |
| VIPRE | Trojan.Win32.Generic!BT |