Zhang Ling

Publisher Information

Zhang Ling is a software publisher located in 北京市, China*. The company is a primary distributor of unwanted software. Thre are 4 additional code signing certificates issued to this publisher.
Authority:
WoSign CA Limited

Valid from:
9/23/2014 8:39:35 PM

Valid to:
6/23/2015 8:39:35 PM

Subject:
CN=Zhang Ling, E=chloezhangling@gmail.com, L=北京市, S=北京市, C=CN

Issuer:
CN=WoSign Class 2 Code Signing CA, O=WoSign CA Limited, C=CN

Serial number:
4bd6cd01962107d32d308240da61e020

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.ZhangLing.Q, PUP.BHO.ZhangLing.G, PUP.ZhangLing.E, PUP.Service.ZhangLing.N, PUP.ZhangLing.N, PUP.ZhangLing.P, PUP.ZhangLing.W, PUP.ELEX.ZhangLing (M), PUP.ELEX (M)
100.00%

Avira AntiVirus
APPL/SubTab.spe, TR/Trash.Gen
70.59%

Baidu Antivirus
Adware.Win64.Agent, Adware.Win32.Agent, Adware.Win32.Thinknice, Adware.Win64.Thinknice, Adware.Win32.ELEX
58.82%

Malwarebytes
PUP.Optional.SupTab.A, PUP.Optional.IePluginService.A, PUP.Optional.Skytech.A, PUP.Optional.IEPluginService.A
47.06%

VIPRE Antivirus
Threat.4788726, Threat.4729122, Trojan.Win32.Generic, Threat.4758034, Backdoor.Win32.Bifrose.fsi
41.18%

ESET NOD32
Win64/Thinknice.E potentially unwanted application, Win32/ELEX.AV potentially unwanted application, Win32/Thinknice.E potentially unwanted application
41.18%

G Data
Adware.Generic.1094524, Win32.Application.SubTab, Adware.Agent.OFO, Adware.Agent.OML, Win64.Application.SearchProtect.AF
35.29%

AhnLab V3 Security
PUP/Win32.SearchProtect, Adware/Win32.Agent, Win32/Kashu.E, PUP/Win32.Helper
29.41%

Kaspersky
not-a-virus:AdWare.Win64.Agent, Packed.Win32.Krap, not-a-virus:AdWare.Win32.Agent
23.53%

Emsisoft Anti-Malware
Adware.Generic.1094524, Adware.Agent.OFO, Adware.Agent.OML
23.53%

1 / 68      (Adware)
tmp000000111b30bb0d6ef042a7  (7fdba266ae63ab5d5c661d72643a4b08)

1 / 68      (Adware)
RSHP.exe (RSHP IePlugin control by Skytech Co.)  (e5478f4d339e5175829bb4454488ec64)

1 / 68      (Adware)
hpui.exe  (b798466763aa2da09f9863e265d906e0)

1 / 68      (Adware)
bhoenabler.exe  (228a33de36e3dc20fb72a2abe288c125)

1 / 68      (Adware)
suptab_v5.8.8.865_noblank.exe (Suptab)  (eae2f9d7c49331ad28051b68b98ed910)

3 / 68      (Adware)
bhoenabler.exe  (c4a52f32ccbc6c7670c98f65cd208904)

25 / 68    (Adware)
suptab_v5.8.8.865_noblank.exe (Suptab)  (e6b1e1bc352ba71298ae10d2958b9d50)

7 / 68      (Adware)
searchprotect64.dll (2.0.1.739 by Skytech Co.)  (7a252797d38b4d7566ede126048ad87e)

5 / 68      (Adware)
searchprotect32.dll (2.0.1.739 by Skytech Co.)  (6361a4ca8ae094b4e60c0ca45b798485)

3 / 68      (Adware)
RSHP.exe (RSHP IePlugin control by Skytech Co.)  (79c8a5854cf1b373933f0bcf64e94e72)

10 / 68    (Adware)
dpinterface64.dll (Skytech by Skytech Co.)  (e3bed5dde302d0879257bc03b24efb3e)

12 / 68    (Adware)
dpinterface32.dll (Skytech by Skytech Co.)  (1df8eb8e0f03fc1e74131635c037b256)

15 / 68    (Adware)

18 / 68    (Adware)
hpui.exe  (77d51aa2603179c7fca7911b89932dba)

24 / 68    (Adware)
suptab.dll (SupTab by Thinknice Co. Limited)  (3a012718ba5315abd1b7a371d1b53b70)

10 / 68    (Adware)
windowssupportdll32.dll  (958560d0fbbe09c1dd7d3d648464f9ba)

18 / 68    (Adware)
windowssupportdll64.dll  (d5b9c9335f6bbdef0b9828fdafe96e8b)

The certificates below are also signed by Zhang Ling.

44C9FA07E0C36E90C219294D56307B89  (Sep 15, 2014 to Jul 15, 2015)

64AA90E4D11751F466378DD4391C2CAB  (Nov 24, 2014 to Jun 24, 2015)

33D813964B450F4902EA98231C8EF97E  (Aug 20, 2014 to Jun 20, 2015)

07DAC38DB37E09DF8C8634065592DFE3  (Jun 06, 2014 to Jun 06, 2015)

* Note, the details and description above are based on the code signing digital signature issued to Zhang Ling by WoSign CA Limited on September 23, 2014 with the serial number '4bd6cd01962107d32d308240da61e020'.