lly_omiga-plus.exe

1768_tugs_omiga-plus

Ma Lin

The application lly_omiga-plus.exe by Ma Lin has been detected as adware by 19 anti-malware scanners. This is a setup program which is used to install the application. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from www.girllumin.com.
Publisher:
One Syn  (signed by Ma Lin)

Product:
1768_tugs_omiga-plus

Description:
Syn worker

Version:
6.2.7601.1029

MD5:
3240e2b55922f65d304f0d26069e06ff

SHA-1:
96ff12dc600f150ab8c30da67795f849cbb6d6da

SHA-256:
277d9b036954cd0ebe851bac736309a8abbad2e8197f2e3020c16eaffe890b6d

Scanner detections:
19 / 68

Status:
Adware

Analysis date:
4/9/2025 6:26:44 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Bundler.FT
633

Agnitum Outpost
Riskware.Agent
7.1.1

AhnLab V3 Security
PUP/Win32.SearchHijacker
2014.10.25

Baidu Antivirus
PUA.Win32.LiMo
4.0.3.15512

Bitdefender
Application.Bundler.FT
1.0.20.660

Dr.Web
Adware.Mutabaha.76
9.0.1.0132

Emsisoft Anti-Malware
Application.Bundler.FT
10.0.0.5366

ESET NOD32
Win32/LiMo (variant)
9.10615

F-Secure
Application.Bundler.FT
11.2015-12-05_3

G Data
Application.Bundler.FT
15.5.24

herdProtect (fuzzy)
2015.8.9.12

Malwarebytes
PUP.Optional.LiMo
v2015.08.09.12

MicroWorld eScan
Application.Bundler.FT
16.0.0.396

NANO AntiVirus
Riskware.Win32.Mutabaha.dgvhdd
0.28.2.62841

Norman
Application.Bundler.FT
03.12.2014 13:20:04

Qihoo 360 Security
Win32/Application.0d6
1.0.0.1015

Reason Heuristics
PUP.MaLin
15.5.12.14

VIPRE Antivirus
Threat.4150696
39486

Zillya! Antivirus
Backdoor.PePatch.Win32.48941
2.0.0.1975

File size:
545.6 KB (558,744 bytes)

Product version:
6.2.7601.1029

Copyright:
One Syn

Original file name:
Worker.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\lly_omiga-plus.exe

Digital Signature
Signed by:

Authority:
WoSign CA Limited

Valid from:
8/20/2014 11:22:46 AM

Valid to:
7/20/2015 11:22:46 AM

Subject:
CN=Ma Lin, E=chloezhangling@163.com, L=北京市, S=北京市, C=CN

Issuer:
CN=WoSign Class 2 Code Signing CA, O=WoSign CA Limited, C=CN

Serial number:
760E23ABF26CF75AE5C944881CCA6DA7

File PE Metadata
Compilation timestamp:
10/16/2014 9:02:53 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:lf9NClQC13HG3JR9nUAHA860xe0YsTTSZKWhtSJL:lVhtU+Av0TTTuKWhtSl

Entry address:
0x3F6B9

Entry point:
E8, 3D, DD, 00, 00, E9, 7F, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 57, 56, 8B, 74, 24, 10, 8B, 4C, 24, 14, 8B, 7C, 24, 0C, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, 68, 03, 00, 00, 0F, BA, 25, 9C, DE, 47, 00, 01, 73, 07, F3, A4, E9, 17, 03, 00, 00, 81, F9, 80, 00, 00, 00, 0F, 82, CE, 01, 00, 00, 8B, C7, 33, C6, A9, 0F, 00, 00, 00, 75, 0E, 0F, BA, 25, 20, 61, 47, 00, 01, 0F, 82, DA, 04, 00, 00, 0F, BA, 25, 9C, DE, 47, 00, 00, 0F, 83, A7, 01, 00, 00, F7, C7, 03, 00, 00...
 
[+]

Code size:
376.5 KB (385,536 bytes)

The file lly_omiga-plus.exe has been seen being distributed by the following URL.

Remove lly_omiga-plus.exe - Powered by Reason Core Security