Suining Qixi Advertising Media Co., Ltd.

Publisher Information

Suining Qixi Advertising Media Co., Ltd. is a software publisher located in Suining, Jiangsu in China*. The publisher primarily developes software that can be classified as adware.
Authority:
WoSign CA Limited

Valid from:
4/21/2014 5:14:06 AM

Valid to:
4/23/2017 5:14:06 AM

Subject:
CN="Suining Qixi Advertising Media Co., Ltd.", E=xiguayingyin@gmail.com, O="Suining Qixi Advertising Media Co., Ltd.", L=Suining, S=Jiangsu, C=CN

Issuer:
CN=WoSign Class 3 Code Signing CA, O=WoSign CA Limited, C=CN

Serial number:
6ba70b4380eca6e171fb81a495ec5def

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.SuiningQixiAdvertisingMediaCo.T, PUP.SuiningQixiAdvertisingMediaCo.H, PUP.SuiningQixiAdvertisingMediaCo.F, PUP.Installer.SuiningQixiAdvertisingMediaCo.W, PUP.BHO.SuiningQixiAdvertisingMediaCo.E, PUP.MozillaPlugin.SuiningQixiAdvertisingMediaCo.G, PUP.Startup.SuiningQixiAdvertisingMediaCo, PUP.SuiningQixiAdvertisingMediaCo.Installer (M), PUP.SuiningQixiAdvertisingMediaCo (M)
100.00%

AVG
Suining
85.71%

IKARUS anti.virus
Trojan.Win32.Antavmu, Trojan.ATRAPS
14.29%

VIPRE Antivirus
Threat.4150696, Trojan.Win32.Generic, Threat.4762589
12.24%

Bkav FE
W32.HfsAdware, HW32.Packed
10.20%

McAfee Web Gateway
BehavesLike.Win32.MPlug.bh, BehavesLike.Win32.PWSMmorpg.bh, Artemis
10.20%

Norman
OnLineGames.LWBP
8.16%

Trend Micro House Call
Suspicious_GEN.F47V1107, Suspicious_GEN.F47V1129, Suspicious_GEN.F47V1218, Suspicious_GEN.F47V0129
8.16%

McAfee
Artemis!D2597A28236D, Artemis!8E39BE78CF46, Artemis!A423F430FC7B, Artemis!D0ADEBF748EC
8.16%

Clam AntiVirus
Suspect.Trojan.Generic.FD-4
6.12%

1 / 68      (PUP)
xigua_install.exe  (c099b13be2e362bd905123dd7e18da3a)

1 / 68      (PUP)
xigua_2_12_0_5.exe  (54dd2278d7b102d8791d0b3e9f6cefbd)

1 / 68      (PUP)
xigua_install.exe  (890ff57700d52a2ecc8ddd290a87a37d)

1 / 68      (PUP)
xigua_2_12_0_5.exe  (50411effb69ee418ecdd45dcb7bc3277)

4 / 68      (PUP)
uninstall-1.exe  (41cfd18ddb95cbe4c53e980cb3757881)

7 / 68      (PUP)
xigua_install_2.exe  (d0adebf748ec4c86e8ef4090916c039b)

1 / 68      (PUP)
setup_xiguayingyin.exe  (3c40c8fc022034a388d41ab2adc79a80)

2 / 68      (PUP)
packer.exe  (e082aa74c4e032b6d7718881d1934a79)

3 / 68      (PUP)
xgyingshi.dll  (da2c974eabed13424140f1e90d382f5e)

3 / 68      (PUP)
xgengine.exe  (818dbd7b94962b8d8616cd1307e1d13e)

8 / 68      (PUP)
xigua_install.exe  (a423f430fc7bff64b33f7302a4a7c851)

3 / 68      (PUP)
setup_xigua_install.exe (by xigua.com)  (297050aeb2e485637c6a3c9a9deec389)

2 / 68      (PUP)
xgyingshi.dll  (4d10f441e84c9292966c312c1bce8a57)

2 / 68      (PUP)
xgvr.dll  (98fcaa3c28b67507970c9ced3450b591)

2 / 68      (PUP)
xgtr.exe  (0a2ff422657a05d8ff272c1ff9b450e6)

2 / 68      (PUP)
xgtj.dll  (3153dc8ac9fbd3ca08f05c1d573a4420)

2 / 68      (PUP)
xgpopad.exe  (c74131d631734cbed7c298a1d4757dc3)

2 / 68      (PUP)
xgmy.exe (xgmy)  (1644f85ea66d4ced973440a869e1a4d1)

2 / 68      (PUP)
xgcrash.exe  (a3177a30b4b7f402311dad63ddbe0366)

2 / 68      (PUP)
xgbho.dll  (59f7f8dfea8c12748bec1d582d9cdf45)

2 / 68      (PUP)
xgax.dll  (5c3a06fa55f8f53ca62daa7a9d70b211)

2 / 68      (PUP)
vitable.exe (auto123)  (134b1b081e0e63b659f35d6203be8365)

5 / 68      (PUP)
tourl.exe  (d7ce8f71d5e291b18c6903f75da2fb64)

2 / 68      (PUP)
toolsuite.exe  (e0f89c630984d68d0f129c89fa85abfb)

2 / 68      (PUP)
PNCRT.DLL (RealPlayer/RealServer by Real Networks, Inc)  (5895cbce3ed698f9884460118598d9a7)

2 / 68      (PUP)
packer.exe  (24737dc3b94b5086698acb17a7654ba0)

5 / 68      (PUP)
openurl.exe  (3f605845244fab27233f362779beb7ba)

2 / 68      (PUP)
npreg.dll  (41a65953c60609fc626906f3267ad3ec)

2 / 68      (PUP)
MediaInfo.dll (MediaInfo by MediaArea.net)  (df45271be9f54d799875adbcbd0997a1)

1 / 68      (PUP)
d3dx9_43.dll (Microsoft DirectX for Windows by Microsoft)  (d6ed6d5cd9fe6fa28d88c9542b1de6a2)

 
Latest 30 of 194 files

Downloads URLs for files signed by Suining Qixi Advertising Media Co., Ltd..

10 / 68    (PUP)

10 / 68    (PUP)
http://210.6.198.20/.../xigua_2_12_0_5.exe  (8e39be78cf4661636e6deb350c80243e)

10 / 68    (PUP)
http://s2.xiguaplayer.com/xigua_2_12_0_5.exe  (8e39be78cf4661636e6deb350c80243e)

10 / 68    (PUP)
http://s1.xiguaplayer.com/xigua_Install.exe  (8e39be78cf4661636e6deb350c80243e)

8 / 68      (PUP)
http://s2.xiguaplayer.com/xigua_Install.exe  (a423f430fc7bff64b33f7302a4a7c851)

8 / 68      (PUP)
http://s1.xiguaplayer.com/xigua_Install.exe  (a423f430fc7bff64b33f7302a4a7c851)

12 / 68    (PUP)
http://183.91.33.17/.../xigua_Install.exe  (d2597a28236d80e37ce721f9212fb0c1)

12 / 68    (PUP)
http://s1.xiguaplayer.com/xigua_Install.exe  (d2597a28236d80e37ce721f9212fb0c1)

The following websites host and distribute files published by Suining Qixi Advertising Media Co., Ltd..

* Note, the details and description above are based on the code signing digital signature issued to Suining Qixi Advertising Media Co., Ltd. by WoSign CA Limited on April 21, 2014 with the serial number '6ba70b4380eca6e171fb81a495ec5def'.