omg music plus-codedownloader.exe

OMG Music Plus

Bundlore LTD

This is the Bundlore download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application omg music plus-codedownloader.exe, “OMG Music Plus exe” has been detected as adware by 12 anti-malware scanners. The program is a setup application that uses the Bundlore Downloader installer, however the file is not signed with an authenticode signature from a trusted source. This file is typically installed with the program OMG Music Plus by Bundlore LTD which is a potentially unwanted software program. Built using the Crossrider web brower toolkit the CodeDownloader component will automatically connnect to the remote API server and download additional code/components for Bundlore LTD extension/toolbar. The component makes a number of requests to the host app-static.crossrider.com/plugins/.../monetization/monetizationLoader.js.
Publisher:
Bundlore LTD

Product:
OMG Music Plus

Description:
OMG Music Plus exe

Version:
1000.1000.1000.1000

MD5:
cf03ef38079eda787231256ff2017e36

SHA-1:
e6567dcfdef0ebcaeea6c731ccb2828e6a698afe

SHA-256:
a8392c879816482a5937702dcc043fb069986277c9d199b839f8a8cc6dd2d81b

Scanner detections:
12 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application.

Analysis date:
4/29/2024 1:16:59 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Dropper-gen [Drp]
2014.9-140403

AVG
Generic5
2015.0.3516

Baidu Antivirus
Adware.Win32.CrossRider
4.0.3.1443

Dr.Web
Trojan.Crossrider.7193
9.0.1.093

ESET NOD32
Win32/Toolbar.CrossRider.AA (variant)
8.9619

Fortinet FortiGate
Riskware/Toolbar_CrossRider
4/3/2014

Malwarebytes
PUP.Optional.OMGMusicPlus.A
v2014.04.03.08

McAfee
Artemis!CF03EF38079E
5600.7172

Qihoo 360 Security
Win32/Trojan.Dropper.c9f
1.0.0.1015

Reason Heuristics
PUP.Crossrider.Bundlore.DD
14.4.3.8

Trend Micro House Call
TROJ_GEN.F47V0320
7.2.93

VIPRE Antivirus
Crossrider
27910

File size:
554 KB (567,296 bytes)

Product version:
1000.1000.1000.1000

Copyright:
Copyright 2011

Original file name:
OMG Music Plus.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Bundlore Downloader

Language:
English (United States)

Common path:
C:\Program Files\omg music plus\omg music plus-codedownloader.exe

File PE Metadata
Compilation timestamp:
3/16/2014 8:05:27 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:BCZY12cIkx9D1LvhlOardFv3AwGuFYriAFSpTccVe:B8q2cIkx9D1Lvh5rPv6VuTe

Entry address:
0x4DC0F

Entry point:
E8, CD, D4, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 30, 66, 48, 00, E8, FB, 49, 00, 00, E8, 6F, 1D, 00, 00, 0F, B7, F0, 6A, 02, E8, 60, D4, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 8D, 7A, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
435.5 KB (445,952 bytes)

Scheduled Task
Task name:
OMG Music Plus-codedownloader

Trigger:
Logon (Runs on logon)

Action:
omg music plus-codedownloader.exe \reinstallapp \runfrom=task \agentregpath='omg mus


The file omg music plus-codedownloader.exe has been discovered within the following program.

OMG Music Plus  by Bundlore LTD
OMG Music (OMG Ltd.) is a potentially unwanted web browser extension that is ad-supported and will display various popup and banner ads as well as modify the user's web browser search and home page settings.
www.onlinemusicgroove.com
86% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to update.srvstatsdata.com  (69.16.175.42:80)

 
http://update.srvstatsdata.com/installer_updates/005976/update.json

TCP (HTTP):
Connects to stats.srvstatsdata.com  (176.32.99.41:80)

TCP (HTTP):
Connects to app-static.crossrider.com  (69.16.175.10:80)

Remove omg music plus-codedownloader.exe - Powered by Reason Core Security