OOO Lega Media

Publisher Information

OOO Lega Media is a software publisher located in Saint-Petersburg, Russia*. The company is a primary distributor of unwanted software. There is one additional code signing certificate issued to this publisher.
Remove OOO Lega Media Malware - Powered by Reason Core Security
Authority:
VeriSign, Inc.

Valid from:
4/17/2014 3:00:00 AM

Valid to:
6/16/2017 2:59:59 AM

Subject:
CN=OOO Lega Media, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=OOO Lega Media, L=Saint-Petersburg, S=Saint-Petersburg, C=RU

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
50bbbbfd1dc0231ca78ae1e5f30e0e41

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.OOOLegaMedia.M, PUP.OOOLegaMedia.H, PUP.Startup.OOOLegaMedia.J, PUP.Installer.OOOLegaMedia.J, PUP.OOOLegaMedia.G, PUP.Installer.OOOLegaMedia.P, PUP.OOOLegaMedia.Installer (M)
96.30%

Dr.Web
Adware.Downware.2095, Trojan.Packed.28981
18.52%

ESET NOD32
Win32/bmMedia, Win32/bmMedia (variant), Win32/bmMedia.BY (variant)
11.11%

Avira AntiVirus
APPL/Downloader.Gen9, APPL/BmMedia.E.1
11.11%

Baidu Antivirus
PUA.Win32.bmMedia
7.41%

Trend Micro House Call
Suspicious_GEN.F47V1105, Suspici.6C64B4AC
7.41%

ByteHero BDV
Trojan.Malware.Obscu.Gen.002
3.70%

avast!
Win32:Adware-gen [Adw]
3.70%

VIPRE Antivirus
Threat.4150696
3.70%

K7 Gateway Antivirus
Trojan
3.70%

1 / 68      (Adware)
downloadsetup_s.exe  (01ced69fa0727c4dcbb3508c25eb0218)

1 / 68      (Adware)
downloadsetup_s.exe  (873c12905d326fd8ad57c787d11d70ac)

1 / 68      (Adware)
downloadsetup_s.exe  (ae74dc03c001c8b92d4e3672293bc45a)

1 / 68      (Adware)
downloadsetup_s.exe  (c1cfa16920450117d59125f0a84e977a)

1 / 68      (Adware)
downloadsetup_s.exe  (37cb21cf7c100421fce8c0415ad5f3ab)

1 / 68      (Adware)
downloadsetup_s.exe  (e1ac42b527a3929dfbbcc42dd7342225)

6 / 68      (Adware)
bmasetup.exe  (a4b18d49a8c14a980582f0ff096aa99c)

4 / 68      (Adware)
bmasetup.exe  (3f9f1e9b55251f9cfa6c0a93d3345951)

16 / 68    (Adware)
update.exe (by OOO Lega Media)  (a4f333ee650bd94add8185df5eebe8b7)

4 / 68      (Adware)
update.exe (by OOO Lega Media)  (ee84938d72ef7af71987f09cb5dc2fb1)

1 / 68      (Adware)
dumper.exe  (db197e3d9d801255c1d534977f07349e)

1 / 68      (Adware)
bitmaster.bin  (06a79e03b8c47f79f6c4b40ba97a42fe)

1 / 68      (Adware)
bitmaster.exe  (eabeaf763ad5e03a6c18b2e89d7559bf)

1 / 68      (Adware)
bitmaster.bin  (bf19da3b21f96de50042622215b4acc0)

1 / 68      (Adware)
dumper.exe  (990dd431c08f1eb5702bafb71006c073)

2 / 68      (Adware)
bitmaster.exe  (350f1bd0e1894dfea651d13e09e3b602)

1 / 68      (Adware)
update.exe  (a6b7ee286f693b500f93ca2d8d968261)

2 / 68      (Adware)
bmsetup.exe  (df06e05fbffbb7b92a44e4adb362c7e6)

1 / 68      (Adware)
downloadsetup_s.exe  (eef7ffce0c97cb82065085b859ca4500)

1 / 68      (Adware)
downloadsetup_s.exe  (7ee5f2ffd212dd56cacd6165e909e025)

1 / 68      (Adware)
downloadsetup_s.exe  (40066213568bcdd030b9a28297e0636d)

1 / 68      (Adware)
dumper.exe  (8e0da0681aae1c5f7b9414bb88f91ac6)

1 / 68      (Adware)
wdmasetup.exe  (b700e212b7719e06b30151ced5d96b6d)

1 / 68      (Adware)
bitmaster.exe  (d00bbfe42798d8f6564a943510722e8b)

1 / 68      (Adware)
browser.dll  (900c99a831d804d8b70f222a96ed7140)

1 / 68      (Adware)
torrent.dll  (8131e8d120aea16d9cf2588bcc015e29)

1 / 68      (Adware)
bitmaster.bin  (8ff3ce1244fc78a22fb278149a15efdb)

Downloads URLs for files signed by OOO Lega Media.

The following websites host and distribute files published by OOO Lega Media.

The following certificate is also signed by OOO Lega Media.

207A06BD655445095B358B2C5124046E  (May 01, 2013 to May 02, 2014)

The following publishers (by Authenticode signature organization name) are related.

Remove OOO Lega Media Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to OOO Lega Media by VeriSign, Inc. on April 17, 2014 with the serial number '50bbbbfd1dc0231ca78ae1e5f30e0e41'.