omesuperv.exe

Bebo Media Ltd.

The application omesuperv.exe by Bebo Media has been detected as a potentially unwanted program by 19 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘OMESupervisor’.
Publisher:
Bebo Media Ltd.  (signed and verified)

MD5:
6785b09655b57f93768ec3690e7cc43c

SHA-1:
ab19b928994038ff5300e5c3f7f8010582aabe89

SHA-256:
a622b5d71b106f2719d8f03fa780ff2ef86e0757e284f08a981e17bbbcfeee3d

Scanner detections:
19 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 7:57:53 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.OfferMosquito.A
613

Agnitum Outpost
PUA.Bho
7.1.1

AVG
Generic
2016.0.3091

Bitdefender
Adware.OfferMosquito.A
1.0.20.760

Dr.Web
Adware.Bho.4009
9.0.1.0152

Emsisoft Anti-Malware
Adware.OfferMosquito
8.15.06.01.11

F-Secure
Adware.OfferMosquito.A
11.2015-01-06_2

G Data
Adware.OfferMosquito
15.6.25

K7 AntiVirus
Riskware
13.201.15304

Kaspersky
not-a-virus:AdWare.Win32.Agent
14.0.0.1950

Malwarebytes
PUP.Optional.OfferMosquito.A
v2015.06.01.11

McAfee
Artemis!6785B09655B5
5600.6747

MicroWorld eScan
Adware.OfferMosquito.A
16.0.0.456

NANO AntiVirus
Trojan.Win32.Generic.dbxkgn
0.30.8.659

nProtect
Adware.OfferMosquito.A
15.03.18.01

Reason Heuristics
PUP.Installer.BeboMedia
15.6.1.23

Sophos
Generic PUA GO
4.98

Trend Micro House Call
TROJ_GE.46A4BDB5
7.2.152

VIPRE Antivirus
BeboMedia
38548

File size:
2.1 MB (2,239,264 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\omesuperv.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
10/15/2013 5:20:49 AM

Valid to:
10/16/2014 5:20:49 AM

Subject:
E=office@bebomedia.com, CN=Bebo Media Ltd., O=Bebo Media Ltd., L=Tortola, S=Tortola, C=VG

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121C31FCB2852745C71A0A38B8A13B20EF7

File PE Metadata
Compilation timestamp:
12/5/2009 4:53:24 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:1O0S8OERVUYv3/dfCFzbq5mb/pHVNSIKb6ImzYtpExyQbxqNOS904:1ObaVU9Fz+Mb/J7SIjIwYYxx0N64

Entry address:
0x355E

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, B8, A7, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 80, 40, 00, 53, FF, 15, 88, 82, 40, 00, 6A, 08, A3, 98, 10, 43, 00, E8, D6, 2E, 00, 00, A3, E4, 0F, 43, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, E8, A7, 42, 00, FF, 15, 58, 81, 40, 00, 68, AC, A7, 40, 00, 68, E0, 07, 43, 00, E8, DC, 29, 00, 00, FF, 15, AC, 80, 40, 00, BF, 00, 70, 43, 00, 50, 57, E8, CA, 29, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
25 KB (25,600 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
OMESupervisor

Command:
C:\users\{user}\appdata\local\omesuperv.exe


Remove omesuperv.exe - Powered by Reason Core Security