lly_mystartsearch.exe

1767_tugs_mystartsearch

Li Mo

The application lly_mystartsearch.exe by Li Mo has been detected as adware by 13 anti-malware scanners. This is a setup program which is used to install the application. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from www.girllumin.com.
Publisher:
One Syn  (signed by Li Mo)

Product:
1767_tugs_mystartsearch

Description:
Syn worker

Version:
6.2.7601.1029

MD5:
e175686597141cc8b4073d83df7886c8

SHA-1:
cb614859bdb8f1fbcfc9c311f7dfd6686d717cb6

SHA-256:
e729f261007ec8ec7ad5fa9c9c24f6b087f9d514a53c5ee59446b59dba020ca3

Scanner detections:
13 / 68

Status:
Adware

Analysis date:
4/18/2025 6:34:01 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Bundler.FT
834

Agnitum Outpost
Riskware.Agent
7.1.1

AhnLab V3 Security
PUP/Win32.SearchHijacker
2014.10.25

AVG
Generic
2015.0.3312

Bitdefender
Application.Bundler.FT
1.0.20.1485

Dr.Web
Adware.Mutabaha.76
9.0.1.05190

ESET NOD32
Win32/LiMo (variant)
8.10615

F-Secure
Application.Bundler.FT
11.2014-24-10_6

G Data
Application.Bundler.FT
14.10.24

Malwarebytes
PUP.Optional.LiMo
v2014.10.24.11

MicroWorld eScan
Application.Bundler.FT
15.0.0.891

NANO AntiVirus
Riskware.Win32.Mutabaha.dgvhdd
0.28.2.62841

Reason Heuristics
PUP.LiMo.R
14.10.24.11

File size:
544.4 KB (557,432 bytes)

Product version:
6.2.7601.1029

Copyright:
One Syn

Original file name:
Worker.exe

File type:
Executable application (Win32 EXE)

Language:
English (Storbritannien)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\lly_mystartsearch.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
8/4/2014 2:00:00 AM

Valid to:
8/12/2015 2:00:00 PM

Subject:
CN=Li Mo, O=Li Mo, L=Guilin, S=Guangxi, C=CN

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0F53999A8B9372F6AAC4844D7A5BE2CE

File PE Metadata
Compilation timestamp:
10/16/2014 9:02:53 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:Af9NClQC13HG3JR9nUAHA860xe0YsTTSZKWhYSJL:AVhtU+Av0TTTuKWhYSN

Entry address:
0x3F6B9

Entry point:
E8, 3D, DD, 00, 00, E9, 7F, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 57, 56, 8B, 74, 24, 10, 8B, 4C, 24, 14, 8B, 7C, 24, 0C, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, 68, 03, 00, 00, 0F, BA, 25, 9C, DE, 47, 00, 01, 73, 07, F3, A4, E9, 17, 03, 00, 00, 81, F9, 80, 00, 00, 00, 0F, 82, CE, 01, 00, 00, 8B, C7, 33, C6, A9, 0F, 00, 00, 00, 75, 0E, 0F, BA, 25, 20, 61, 47, 00, 01, 0F, 82, DA, 04, 00, 00, 0F, BA, 25, 9C, DE, 47, 00, 00, 0F, 83, A7, 01, 00, 00, F7, C7, 03, 00, 00...
 
[+]

Code size:
376.5 KB (385,536 bytes)

The file lly_mystartsearch.exe has been seen being distributed by the following URL.

http://www.girllumin.com/.../lly_mystartsearch.exe

Remove lly_mystartsearch.exe - Powered by Reason Core Security