Zhang Ling

Publisher Information

Zhang Ling is a software publisher located in 北京市, China*. The company is a primary distributor of unwanted software. Thre are 4 additional code signing certificates issued to this publisher.
Authority:
WoSign CA Limited

Valid from:
6/6/2014 4:29:18 AM

Valid to:
6/6/2015 4:29:18 AM

Subject:
CN=Zhang Ling, E=chloezhangling@gmail.com, L=北京市, S=北京市, C=CN

Issuer:
CN=WoSign Class 2 Code Signing CA, O=WoSign CA Limited, C=CN

Serial number:
07dac38db37e09df8c8634065592dfe3

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.ZhangLing.L, PUP.BHO.ZhangLing.G, PUP.ZhangLing.Q, PUP.ZhangLing.E, PUP.Service.ZhangLing.N, PUP.ZhangLing.O, PUP.ZhangLing.J, PUP.ZhangLing.N, Common.CRuntimePackaged.PUP.I, PUP.ZhangLing.P, PUP.Installer.ZhangLing.G, PUP.ZhangLing.W, PUP.ZhangLing.K, PUP.ELEX.ZhangLin (M), PUP.ELEX (M)
100.00%

AVG
Zhangling
84.00%

Baidu Antivirus
Adware.Win32.Thinknice, Adware.Win32.SupTab, Adware.Win32.ELEX, Adware.Win64.Thinknice, PUA.Win32.Thinknice, Adware.Win32.Agent
60.00%

VIPRE Antivirus
Threat.4150696, Threat.4120919, Threat.4758034, Backdoor.Win32.Bifrose.fsi, Threat.4788726, Trojan.Win32.Generic
40.00%

Malwarebytes
PUP.Optional.SupTab.A, PUP.Optional.IePluginService.A, PUP.Optional.IEPluginService.A, PUP.Optional.Skytech.A
40.00%

IKARUS anti.virus
PUA.SubTab, Virus.Win32.Virut, PUA.SearchProtect
40.00%

Dr.Web
Trojan.Click3.8536, Win32.Virut.56, Adware.Mutabaha.236, Trojan.Damaged.1, Adware.Mutabaha.50, Trojan.StartPage1.6314
36.00%

ESET NOD32
Win32/Thinknice.B potentially unwanted application, Win32/Thinknice.E potentially unwanted application, Win64/Thinknice.F potentially unwanted application
36.00%

Agnitum Outpost
PUA.Agent, Win32.Virut.Y.Gen, Riskware.Agent
32.00%

Vba32 AntiVirus
AdWare.Agent, Virus.Virut.06
28.00%

1 / 68      (Adware)
suptab_v5.8.8.640.exe  (9376816656c8ae6681456eeb366f96fb)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
dpinterface32.dll (Skytech by Skytech Co.)  (461952dedc771d560d92be79ead55b12)

1 / 68      (Adware)
dpinterface64.dll (Skytech by Skytech Co.)  (ebb00b5d40931939b000509257ba8668)

1 / 68      (Adware)
RSHP.exe (RSHP IePlugin control by Skytech Co.)  (09056245a43f201e8bc84312129e7448)

1 / 68      (Adware)
bhoenabler.exe  (7d1a96d3dd1f5e04629ee8dec238943b)

7 / 68      (Adware)
bhoenabler.exe  (7519dcdfd4c813d7eebbfe05fe53c8c1)

3 / 68      (Adware)
bhoenabler.exe  (873c050ca24bd3d87b93d1da2884f046)

8 / 68      (Adware)
searchprotect64.dll (2.0.1.739 by Skytech Co.)  (e2f8a6cf0c6b51b51d809f7a46640743)

23 / 68    (Adware)
searchprotect32.dll (2.0.1.739 by Skytech Co.)  (d945caaf514ac60a643dae9885ded9fc)

10 / 68    (Adware)
dpinterface64.dll (Skytech by Skytech Co.)  (74059abfb8f84a3398c9e0e751fdbdc5)

12 / 68    (Adware)
dpinterface32.dll (Skytech by Skytech Co.)  (2cc11b8a2d715e333303233267282cb6)

24 / 68    (Adware)
uninstall.exe (TODO: <Product name>)  (4d5469dfea882955730243ae0ab74c3f)

6 / 68      (Adware)
RSHP.exe (RSHP IePlugin control by Skytech Co.)  (ac455b1be98a87b7a5fb8c07f7c8bc26)

3 / 68      (Adware)
suptab_v5.8.8.749_noblank.exe  (938786491250b6c7aa2b0a9570224890)

21 / 68    (Adware)
suptab.dll (SupTab by Thinknice Co. Limited)  (b19adaccaa31f8063a13e1668530f36d)

5 / 68      (Adware)
hpui.exe  (0e4d70657a8757a8cc314ed40d4852eb)

10 / 68    (Adware)
windowssupportdll32.dll  (a8c8852a76fc13c2b0cf54052a784529)

18 / 68    (Adware)
windowssupportdll64.dll  (5b9cb5063908616f92d71374baccaa0d)

26 / 68    (Adware)

2 / 68      (Adware)
bhoenabler.exe  (cd56294d2ea42a47f1193133f6510c74)

3 / 68      (Adware)
suptab_v5.8.8.640.exe  (0abe3c3df43f605eb91fa47610ffc83d)

7 / 68      (Adware)
searchprotect64.dll (2.0.1.613 by Skytech Co.)  (5dea5285dfa62e67fe128acae5cfef63)

3 / 68      (Adware)
searchprotect32.dll (2.0.1.613 by Skytech Co.)  (6e3e1b6ea4426c1fbbc9c64931ca3495)

10 / 68    (Adware)
dpinterface64.dll (Skytech by Skytech Co.)  (e718460227e21231ae206b29c9bb06f9)

12 / 68    (Adware)
dpinterface32.dll (Skytech by Skytech Co.)  (0b8a6e517e9b3b40b700e10d7b823427)

24 / 68    (Adware)
uninstall.exe (TODO: <Product name>)  (b6a45b3af7f3e997fca5fc439a139d57)

16 / 68    (Adware)
suptab.dll (SupTab by Thinknice Co. Limited)  (d17b47bf7ef004f3a7e74dfb3b0aa981)

 
Latest 30 of 72 files

The certificates below are also signed by Zhang Ling.

44C9FA07E0C36E90C219294D56307B89  (Sep 15, 2014 to Jul 15, 2015)

64AA90E4D11751F466378DD4391C2CAB  (Nov 24, 2014 to Jun 24, 2015)

4BD6CD01962107D32D308240DA61E020  (Sep 23, 2014 to Jun 23, 2015)

33D813964B450F4902EA98231C8EF97E  (Aug 20, 2014 to Jun 20, 2015)

* Note, the details and description above are based on the code signing digital signature issued to Zhang Ling by WoSign CA Limited on June 06, 2014 with the serial number '07dac38db37e09df8c8634065592dfe3'.