Liyan Liu

Publisher Information

Liyan Liu is a software developer located in Wenzhou, Zhejiang in China*. The company is a primary distributor of unwanted software. Thre are 2 additional code signing certificates issued to this publisher.
Authority:
DigiCert Inc

Valid from:
7/22/2014 2:00:00 AM

Valid to:
7/27/2015 2:00:00 PM

Subject:
CN=Liyan Liu, O=Liyan Liu, L=Wenzhou, S=Zhejiang, C=CN

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
06a374858107d7f624d3cc328c92248a

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.LiyanLiu.O, PUP.LiyanLiu.CC, PUP.LiyanLiu.X, PUP.Service.LiyanLiu.N, PUP.BHO.LiyanLiu.G, PUP.LiyanLiu.BB, PUP.LiyanLiu.J, PUP.LiyanLiu.K, PUP.LiyanLiu.N, PUP.LiyanLiu.E, PUP.LiyanLiu.P, PUP.LiyanLiu.Q, PUP.ELEX.LiyanLiu (M), PUP.ELEX (M)
100.00%

Baidu Antivirus
Adware.Win32.ELEX
48.00%

VIPRE Antivirus
Elex Installer, Trojan.Win32.Generic, Threat.4788726
46.00%

AVG
Generic
44.00%

McAfee
Artemis!2B06B857ED00, Artemis!7B2461778723, Downloader-FAGU!D9583555C063, Downloader-FAGU!E16272CC2C38, Downloader-FAGU!45F81EBA9094, Downloader-FAGU!11D757A71C82, Artemis!969DAC15F48B, Artemis!F798DCBC5BAE
40.00%

Malwarebytes
PUP.Optional.SearchHijacker.A, PUP.Optional.IePluginService.A, PUP.Optional.SupTab.A, PUP.Optional.Skytech.A, PUP.Optional.IEPluginService.A
38.00%

avast!
Win32:Malware-gen, Win32:SupTab-C [Adw], Win32:SupTab-G [Adw], Win32:Adware-CDI [PUP], Win32:SaliCode, Win32:SupTab-D [Adw]
34.00%

AhnLab V3 Security
PUP/Win32.Amonetiz, PUP/Win32.Downloader, PUP/Win32.Helper, Adware/Win32.Agent, Win32/Kashu.E, PUP/Win32.SearchProtect
26.00%

Agnitum Outpost
Riskware.Agent, PUA.Agent, Trojan.Click, PUA.Mutabaha
26.00%

Dr.Web
Adware.Mutabaha.67, Trojan.Click3.9479, Trojan.Click3.8536, Adware.Mutabaha.85, Trojan.StartPage1.6314, Adware.Mutabaha.89
26.00%

1 / 68      (Adware)
smt_istartsurf.exe (1046_smt_istartsurf by File Syn)  (6f68c9f9f771fbe98cc0fda27a86bf03)

1 / 68      (Adware)
adv_46.exe (1079_step_istartsurf by File Syn)  (a9ba8fc8eb94da0d887394ceb8e9e533)

1 / 68      (Adware)
lly_webssearches.exe (1191_tugs_webssearches by File Syn)  (7a1486cff1eb363dd19954265725f53d)

1 / 68      (Adware)

1 / 68      (Adware)
scl_webssearches.exe (1295_scl_webssearches by File Syn)  (380f781d75c8b7e8415de2f4eabfe043)

1 / 68      (Adware)
smt_istart123.exe (1047_smt_istart123 by File Syn)  (8176f1007bdf9c0cf024a73cf43efbcc)

1 / 68      (Adware)

1 / 68      (Adware)
sien_istartsurf.exe (1095_sien_istartsurf by File Syn)  (3786b239470643a914df9f017819d6f1)

1 / 68      (Adware)
toolbar429826494.exe (1046_smt_istartsurf by File Syn)  (dc5cb29afbaff73972e6d2e03a0b1f12)

1 / 68      (Adware)

1 / 68      (Adware)
wpc_webssearches.exe (1171_wpc_webssearches by File Syn)  (621ec4323552d98e1554bdcf12523d24)

1 / 68      (Adware)
mx6sslfdl9.exe (1211_exp_webssearches by File Syn)  (511080fe67f10e05c8b92e237692feac)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
mind_webssearches (1060_mind_webssearches by File Syn)  (94d48d621264ca1c0ad849fa2495df33)

1 / 68      (Adware)
suptab_v5.8.8.1580_noblank_amy.exe  (525e6dc8d9112f0174a6a7deafb4daf3)

1 / 68      (Adware)
istart123.exe (1107_ymb_istart123 by File Syn)  (71198a90118384b17a90d87819a0a2b0)

1 / 68      (Adware)
bdo_istartsurf.exe (1229_bdo_istartsurf by File Syn)  (480846de4067feb61b6e6fde5730cf32)

1 / 68      (Adware)
310714_a5.exe (1183_pcm_webssearches by File Syn)  (592803c481bc0b8d1c412cdeb704f521)

1 / 68      (Adware)
unte256.tmp.exe (1086_epom3_istartsurf by File Syn)  (9ef039e932bc43ef5a483871cf309e4c)

1 / 68      (Adware)
unt3bf5.tmp.exe (1084_epom1_istartsurf by File Syn)  (544a7f810d1a5efba4af4028a2b440c2)

1 / 68      (Adware)

1 / 68      (Adware)
quick start.exe (1063_xpo_istart123 by File Syn)  (ffc12ea7e96a07112bc2fe9fa7d5f8e8)

1 / 68      (Adware)
smt_istartsurf.exe (1046_smt_istartsurf by File Syn)  (2f7476657c9025b191cdc483edf1d51c)

13 / 68    (Adware)

2 / 68      (Adware)

20 / 68    (Adware)
aug12_v9.exe (1188_cor_v9 by File Syn)  (b5969a24ab573ab1539e6fa73d52b3d7)

14 / 68    (Adware)
aug12_sweet-page.exe (1187_cor_sweet-page by File Syn)  (f798dcbc5bae9b404b888fe5a4502f8e)

1 / 68      (Adware)
uni_istartsurf.exe (1091_uni_istartsurf by File Syn)  (e47a2f22bc01fb9dd3c223715d0e105b)

12 / 68    (Adware)
wpc_istart123.exe (1226_wpc_istart123 by File Syn)  (969dac15f48b3e3e1945aab4cfe0085d)

 
Latest 30 of 108 files

The certificates below are also signed by Liyan Liu.

5E0B6377F33581B2B9F8E9C1C0BAB247  (Jan 25, 2016 to Jan 25, 2017)

02CA146AED05062A5F6C4AC5628BBC00  (Jul 21, 2014 to Jul 27, 2015)

The following publishers (by Authenticode signature organization name) are related.

* Note, the details and description above are based on the code signing digital signature issued to Liyan Liu by DigiCert Inc on July 22, 2014 with the serial number '06a374858107d7f624d3cc328c92248a'.