Fuyuan Zhou

Publisher Information

Fuyuan Zhou is a software developer located in Jilin, China*. The company is a primary distributor of unwanted software. Thre are 20 additional code signing certificates issued to this publisher.
Authority:
DigiCert Inc

Valid from:
1/15/2015 1:00:00 AM

Valid to:
1/20/2016 1:00:00 PM

Subject:
CN=Fuyuan Zhou, O=Fuyuan Zhou, L=Jilin, S=Jilin, C=CN

Issuer:
CN=DigiCert SHA2 Assured ID Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0b378a1487e66949a44c8cae23820481

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.FuyuanZhou, Threat.FuyuanZhou, PUP.FuyuanZhou (M), PUP.FuyuanZh (M), PUP (M)
100.00%

Sophos
Elex, PUA 'Elex' (of type Adware)
46.43%

G Data
Gen:Application.Elex, Win32.Application.Limo
46.43%

K7 AntiVirus
Unwanted-Program
32.14%

ESET NOD32
Win32/LiMo (variant), Win32/LiMo.C potentially unwanted (variant), Win32/ELEX.BG potentially unwanted
32.14%

Baidu Antivirus
PUA.Win32.LiMo, PUA.Win32.Mystartsearch, PUA.Win32.ELEX
32.14%

Trend Micro House Call
Suspicious_GEN.F47V0119, Suspicious_GEN.F47V0122, Suspicious_GEN.F47V0123, Suspicious_GEN.F47V0204, Suspicious_GEN.F47V0128
25.00%

Dr.Web
Adware.Mutabaha.98, Adware.Mutabaha.220, Adware.Mutabaha.258
21.43%

McAfee
Artemis!B8C5A70B4877, Artemis!7E1C97945F58, Artemis!CDE952D9C0A5, Artemis!A5CC02F58104, Artemis!1DB7AFB19D75
17.86%

Malwarebytes
PUP.Optional.MyStartSearch.A, PUP.Optional.KeyFind.A, PUP.Optional.DoSearch.A
17.86%

1 / 68      (Adware)
pjr_webssearches.exe (2455_pjr_webssearches by SysTools)  (736f5d6522dd57f24791ee618cfcbcaa)

1 / 68      (Adware)
wpc_mystartsearch.exe (2644_wpc_mystartsearch by TabMain)  (3eb7ca28186f3fd0433e745cca432ce9)

1 / 68      (Adware)
wpc_mystartsearch.exe (2644_wpc_mystartsearch by TabMain)  (fabc024a412c9a5fec4e0bf4e0410481)

1 / 68      (Adware)
wpc_mystartsearch.exe (2644_wpc_mystartsearch by TabMain)  (35bef48197b19a57b23e732e6ebebcab)

1 / 68      (Adware)
scl_key-find.exe (2704_scl_key-find by NaNi)  (08694904b4ebccbaf428e41d974e5241)

1 / 68      (Adware)
0ab16rn0.exe (2528_obw_omiga-plus by SysTools)  (945479db29da0822ac4fca3ee8931168)

1 / 68      (Adware)
pjr_webssearches.exe (2655_pjr_webssearches by NaNi)  (e457b35f8941d87f3bc26db89e3469a1)

1 / 68      (Adware)
izctaxao.tnx.exe (2379_irs_webssearches by NaNi)  (dfd8807db16ac46b420dc4334fdac2af)

1 / 68      (Adware)
scl_webssearches.exe (2322_scl_webssearches by NaNi)  (2d5a2b7923ea728c4b25431d003cc01e)

13 / 68    (Adware)

14 / 68    (Adware)

12 / 68    (Adware)
scl_webssearches.exe (2581_scl_webssearches by SysTools)  (55b55930e30e910b336b768d99e52ee5)

12 / 68    (Adware)

3 / 68      (Adware)
pjr_key-find.exe (2702_pjr_key-find by TabMain)  (047a698ef918bd5e9c9672825b2d04cc)

7 / 68      (Adware)
scl_webssearches.exe  (60c97c053cd69e54222aeed1f0b3b13f)

1 / 68      (Adware)
pjr_webssearches.exe (2660_pjr_webssearches by TabMain)  (1e89680db204c8591d81edd4f4461bf1)

5 / 68      (Adware)
0agrj1.exe (2691_obw_omniboxes by TabMain)  (c7e9d79dc366517fbdf3dc3f25583351)

1 / 68      (Adware)
0ab16rn1.exe (2656_obw_omiga-plus by TabMain)  (5bbc1fdfe5b530b9b8f57ed6b675b8df)

2 / 68      (Adware)
wpc_mystartsearch.exe (2644_wpc_mystartsearch by TabMain)  (0dda4ecb3b7cbbad43a6f0b8737b9ba5)

8 / 68      (Adware)
obw_omiga-plus.exe (2528_obw_omiga-plus by SysTools)  (1db7afb19d7553abbe9efc3025276c7a)

12 / 68    (Adware)
wpc_mystartsearch.exe (2417_wpc_mystartsearch by One Syn)  (87e3cb1edb40d233aa7af2d3b9642a69)

8 / 68      (Adware)

6 / 68      (Adware)

8 / 68      (Adware)

5 / 68      (Adware)
pjr_webssearches.exe (2455_pjr_webssearches by SysTools)  (2da9ef8ef1eaa32a033851432191dba2)

7 / 68      (Adware)
0ab15rn2.exe (2465_obw_webssearches by SysTools)  (7e1c97945f583890a9312253e3619459)

8 / 68      (Adware)
0ab10rn2.exe (2528_obw_omiga-plus by SysTools)  (b8c5a70b4877902bcc3a1c298b1c0e4a)

12 / 68    (Adware)
wpc_mystartsearch.exe (2417_wpc_mystartsearch by One Syn)  (bc45329a2b86c08a8c8af73621206b26)

Downloads URLs for files signed by Fuyuan Zhou.

7 / 68      (Adware)
http://www.girlyangshijian.com/.../scl_webssearches.exe  (60c97c053cd69e54222aeed1f0b3b13f)

7 / 68      (Adware)
http://www.girlwurina.com/.../obw_webssearches.exe  (7e1c97945f583890a9312253e3619459)

5 / 68      (Adware)
http://113.171.224.166/.../obw_omniboxes.exe  (c7e9d79dc366517fbdf3dc3f25583351)

12 / 68    (Adware)
http://www.girlyangshijian.com/.../con_mystartsearch.exe  (26ced154f8b6c706d81d5724292e22a3)

1 / 68      (Adware)
http://www.girlwurina.com/.../scl_webssearches.exe  (2d5a2b7923ea728c4b25431d003cc01e)

12 / 68    (Adware)
http://www.girlyangshijian.com/.../scl_webssearches.exe  (55b55930e30e910b336b768d99e52ee5)

3 / 68      (Adware)
http://d2drfrdurj6mvo.cloudfront.net/.../pjr_key-find.exe  (047a698ef918bd5e9c9672825b2d04cc)

12 / 68    (Adware)
http://www.girlwurina.com/.../wpc_mystartsearch.exe  (87e3cb1edb40d233aa7af2d3b9642a69)

2 / 68      (Adware)
http://www.girlyangshijian.com/.../wpc_mystartsearch.exe  (0dda4ecb3b7cbbad43a6f0b8737b9ba5)

5 / 68      (Adware)
http://www.girlyangshijian.com/.../pjr_webssearches.exe  (2da9ef8ef1eaa32a033851432191dba2)

1 / 68      (Adware)
http://www.girlyangshijian.com/.../obw_omiga-plus.exe  (5bbc1fdfe5b530b9b8f57ed6b675b8df)

5 / 68      (Adware)
http://www.girlyangshijian.com/.../obw_omniboxes.exe  (c7e9d79dc366517fbdf3dc3f25583351)

6 / 68      (Adware)
http://www.girlwurina.com/.../wpc_mystartsearch.exe  (918671639add6f64a95ed2c4426bac9a)

5 / 68      (Adware)
http://www.girlwurina.com/.../pjr_webssearches.exe  (2da9ef8ef1eaa32a033851432191dba2)

1 / 68      (Adware)
http://www.girlyangshijian.com/.../pjr_webssearches.exe  (1e89680db204c8591d81edd4f4461bf1)

8 / 68      (Adware)
http://www.girlyangshijian.com/.../obw_omiga-plus.exe  (1db7afb19d7553abbe9efc3025276c7a)

8 / 68      (Adware)
http://www.girlwurina.com/.../obw_omiga-plus.exe  (b8c5a70b4877902bcc3a1c298b1c0e4a)

12 / 68    (Adware)
http://www.girlwurina.com/.../wpc_mystartsearch.exe  (bc45329a2b86c08a8c8af73621206b26)

5 / 68      (Adware)

2 / 68      (Adware)

12 / 68    (Adware)
http://www.girlyangshijian.com/.../wpc_mystartsearch.exe  (87e3cb1edb40d233aa7af2d3b9642a69)

The following websites host and distribute files published by Fuyuan Zhou.

The certificates below are also signed by Fuyuan Zhou.

0633AA0281655507B43A43C58AC87E24  (Aug 25, 2016 to Jun 22, 2017)

2D0CB6E3DC3A12D7CBCD35A38BE4422E  (Aug 04, 2016 to Jun 22, 2017)

0974CC6B92609F4843A5406187BEF59D  (Jul 28, 2016 to Jun 22, 2017)

10BAEFFAE92E787F9C63D3CE7A487E6F  (Jun 21, 2016 to Jun 22, 2017)

46001FFDEB7F044C0D53B13CFF5C98A6  (Jul 06, 2016 to Jun 22, 2017)

77D22DAACE96DBDBC4E25EEF00C3F1D4  (Aug 24, 2016 to Jun 22, 2017)

21E4E205D19BCF68E4675D7F8F39A764  (Jul 10, 2016 to Jun 21, 2017)

27E9D420E262B14FD8289B7C0BB6D41F  (Jul 31, 2016 to Jun 21, 2017)

31813BE26CE4CFCD461FED27AC9B5D68  (Aug 10, 2016 to Jun 21, 2017)

4A7ABA23225E999B2DA6A856853C0E31  (Jun 30, 2016 to Jun 21, 2017)

10 of 20 code signing certificates issued

The following publishers (by Authenticode signature organization name) are related.

* Note, the details and description above are based on the code signing digital signature issued to Fuyuan Zhou by DigiCert Inc on January 15, 2015 with the serial number '0b378a1487e66949a44c8cae23820481'.