Tan Qilin

Publisher Information

Tan Qilin is a software developer located in 四川省, China*. The company is a primary distributor of unwanted software.
Remove Tan Qilin Malware - Powered by Reason Core Security
Authority:
WoSign CA Limited

Valid from:
5/28/2014 7:07:02 AM

Valid to:
5/28/2015 7:07:02 AM

Subject:
CN=Tan Qilin, E=1367024804@qq.com, L=资阳市, S=四川省, C=CN

Issuer:
CN=WoSign Class 2 Code Signing CA, O=WoSign CA Limited, C=CN

Serial number:
07069dfe674402da3b481d6e2ad40fde

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.TanQilin.V, PUP.TanQilin.C, PUP.TanQilin.AA, PUP.TanQilin.U, PUP.TanQilin.F, PUP.Installer.TanQilin.H, PUP.TanQilin.P, PUP.Installer.TanQilin.J, PUP.TanQilin.Installer (M), PUP.TanQilin (M)
96.00%

AVG
Generic, MultiDropper_c
94.00%

ESET NOD32
Win32/RSoftware (variant), Win32/Induc
82.00%

Baidu Antivirus
Trojan.Win32.RSoftware, PUA.Win32.RSoftware, Adware.Win32.ZnPlayer
78.00%

VIPRE Antivirus
Trojan.Win32.Generic.pak!cobra, Threat.4150696
60.00%

Dr.Web
Adware.InstallCore.353, Adware.Plugin.313, Trojan.Pup.13, Win32.Induc, Adware.InstallCore.457, Trojan.Pup.12, Adware.InstallCore.466
54.00%

McAfee
Artemis!1582C3D1ED8D, Artemis!804331C1FC9D, Artemis!8790B4B083F9, Artemis!6F08A27AC942, Artemis!BDEE610366B0, Artemis!FA6299068226, Artemis!A58BF47C8017, Artemis!F61359C37A0A, Artemis!CFF588910879, Artemis!37C648C6CAA9, Artemis!C1D9B04E1216, Artemis!114A969341EC, Artemis!31838F532B2D, Artemis!7502E0A8BF28, Artemis!60FD5B5DC54D, Artemis!4D254647BF9A, Artemis!909333D9EBEF
54.00%

McAfee Web Gateway
Artemis!1582C3D1ED8D, Artemis!6F08A27AC942, Artemis!BDEE610366B0, Artemis!FA6299068226, Artemis!F61359C37A0A, Artemis!Virus
50.00%

avast!
Win32:Adware-gen [Adw], Win32:Malware-gen, Win32:Induc
44.00%

IKARUS anti.virus
PUA.RSoftware, Virus.Win32.Induc
42.00%

1 / 68      (Adware)
mydll.dll  (261e8d2d1ef2f8abb76f49ab407776c0)

1 / 68      (Adware)
my_tv.exe  (b6145c2692f23e40ebce40e5b499304a)

1 / 68      (Adware)
SetupTV.dll (SetupDll by Microsoft)  (4ae67988dc170861d03858ef84158081)

4 / 68      (Adware)
helper20141213194025.exe  (95e7eb14e813943e92c92b560ee2a49b)

5 / 68      (Adware)

10 / 68    (Adware)
SetupDesk.dll (SetupDll by Microsoft)  (909333d9ebef8581ce9f9061272997db)

10 / 68    (Adware)
SetupDesk.dll (SetupDll by Microsoft)  (4d254647bf9a612f6aff5431d1aabe9a)

4 / 68      (Adware)
jl.exe  (e04844d7e574e540489cf9730ec857c4)

6 / 68      (Adware)
SetupTV.dll (SetupDll by Microsoft)  (48cc473b3d0aa44c10e9b31fcc0a11c7)

13 / 68    (Adware)
147_199_6_.exe  (60fd5b5dc54d116dd5502878f81c74c0)

7 / 68      (Adware)
_80_1028_.exe  (7502e0a8bf2872ece490e531025d6e93)

10 / 68    (Adware)
SetupDesk.dll (SetupDll by Microsoft)  (31838f532b2d8cc6047e763a4e6e8288)

9 / 68      (Adware)
��ʒ��ӱ�ʋ���4882_199_6_.exe  (036437f0a4434dd4d58e1b02348c17f2)

21 / 68    (Adware)
g(_h5304_198_6_.exe  (428afd3eb4c2563a4717dbb42c7273a6)

10 / 68    (Adware)
SetupDesk.dll (SetupDll by Microsoft)  (eb6313ba9c995c93cd677388b4e98849)

6 / 68      (Adware)
SetupTV.dll (SetupDll by Microsoft)  (9b1e0a45270a629629252770db43524e)

6 / 68      (Adware)
SetupTV.dll (SetupDll by Microsoft)  (a0b8ac536e2f813ef8d8f3c9a9b06156)

20 / 68    (Adware)
_119_1032_.exe  (0e7bfd9d303a5cb10a23ccba69ef63b7)

20 / 68    (Adware)
_119_1032_.exe  (a60f16a3d871a3aa8249ce01448e7a40)

10 / 68    (Adware)
SetupDesk.dll (SetupDll by Microsoft)  (876dafe48ce721fef2a0080476a24436)

6 / 68      (Adware)
SetupTV.dll (SetupDll by Microsoft)  (41985a22ae020d291c29a2f80a043e2b)

22 / 68    (Adware)
_80_1160_.exe  (61cf03d0e1cf101178173937f5a62cf7)

12 / 68    (Adware)
SetupTV.dll (SetupDll by Microsoft)  (114a969341ec5f9aae5648cac43141c8)

27 / 68    (Adware)
-------a_8_10 04_.exe  (a055411d60744a50787ac7a3b86a692a)

10 / 68    (Adware)
SetupDesk.dll (SetupDll by Microsoft)  (b02f63a1d76140109898c3f0c027187c)

25 / 68    (Adware)
vipe.exe  (37c648c6caa9884f7f50b602e8be8c85)

11 / 68    (Adware)
SetupDll.dll (SetupDll by Microsoft)  (cff588910879a733e97699201ea3d635)

8 / 68      (Adware)
SetupTV.dll (SetupDll by Microsoft)  (965cd239e4a93a8e5bf6ef411665d60b)

 
Latest 30 of 51 files

Downloads URLs for files signed by Tan Qilin.

7 / 68      (Adware)

13 / 68    (Adware)
http://ww.zuowangzhanla.com/down/.../_178_1_.exe  (60fd5b5dc54d116dd5502878f81c74c0)

13 / 68    (Adware)
http://ww.zuowangzhanla.com/down/.../_186_5293_.exe  (60fd5b5dc54d116dd5502878f81c74c0)

7 / 68      (Adware)
http://ww.zuowangzhanla.com/down/.../2086_111_8_.exe  (7502e0a8bf2872ece490e531025d6e93)

13 / 68    (Adware)
http://zm.shzgjx88.com/down/.../ G(>h_166_901_.exe  (60fd5b5dc54d116dd5502878f81c74c0)

7 / 68      (Adware)
http://zn.tybests.com/down/.../ G(>h_116_901_.exe  (7502e0a8bf2872ece490e531025d6e93)

13 / 68    (Adware)
http://zm.shzgjx88.com/down/.../147_199_6_.exe  (60fd5b5dc54d116dd5502878f81c74c0)

7 / 68      (Adware)
http://gg.hongyuetextile.com/down/.../_80_1028_.exe  (7502e0a8bf2872ece490e531025d6e93)

5 / 68      (Adware)
http://zm.shzgjx88.com/down/.../ G(>h4792_199_8_.exe  (edff2f35f8beb2134e4fd9dee62fd50e)

20 / 68    (Adware)
http://zn.tybests.com/down/.../_119_1032_.exe  (0e7bfd9d303a5cb10a23ccba69ef63b7)

20 / 68    (Adware)
http://zn.tybests.com/down/.../_119_1032_.exe  (a60f16a3d871a3aa8249ce01448e7a40)

5 / 68      (Adware)
http://zm.shzgjx88.com/down/.../ g(>h9976_199_8_.exe  (edff2f35f8beb2134e4fd9dee62fd50e)

22 / 68    (Adware)
http://zn.tybests.com/down/.../_80_1160_.exe  (61cf03d0e1cf101178173937f5a62cf7)

13 / 68    (Adware)
http://zm.shzgjx88.com/down/.../ G(?>h9976_199_8_.exe  (c1d9b04e12160b097e5cfa6a4faa130d)

13 / 68    (Adware)

11 / 68    (Adware)
http://zm.shzgjx88.com/down/.../??????_137_1008_.exe  (f61359c37a0a084af96e535e7b2e53eb)

14 / 68    (Adware)
http://zn.tybests.com/down/.../pplayer_64_2331_.exe  (803420b5028a9f286b41c029f78bc24a)

The following websites host and distribute files published by Tan Qilin.

Remove Tan Qilin Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to Tan Qilin by WoSign CA Limited on May 28, 2014 with the serial number '07069dfe674402da3b481d6e2ad40fde'.