Yuanyuan Mei

Publisher Information

Yuanyuan Mei is a software publisher located in Beijing, China*. A majority of the programs developed by the company can be classified as adware or other potentially unwanted programs. Thre are 25 additional code signing certificates issued to this publisher.
Authority:
thawte, Inc.

Valid from:
1/22/2017 1:00:00 AM

Valid to:
4/21/2017 1:59:59 AM

Subject:
CN=Yuanyuan Mei, OU=Individual Developer, O=No Organization Affiliation, L=Beijing, S=Beijing, C=CN

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
045d57d63e13775c8f812e1864797f5a

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Elex (M)
100.00%

1 / 68      (PUP)
damu_ay.exe  (c3af3772eb34b7c0d308d1ced70eb852)

1 / 68      (PUP)
fss_zt.exe  (42dee4489242234367081bf86fa2dbd1)

1 / 68      (PUP)
3rpl4pdld.exe  (02b33bfea674c2eff6e4b92ff8696e24)

1 / 68      (PUP)
adv_288.exe  (54da71a74c21e1aba0b916fa54767813)

1 / 68      (PUP)
rnmpls555.exe  (4d36b9a0cb7e407ff39d20bf93bd37da)

1 / 68      (PUP)
dam_ay.exe  (1f4706b09d947a202f1fcd1c936bf6a8)

1 / 68      (PUP)
tlq8yk5mr.exe  (d0e1fafb3b3b9e239b8644be74a02349)

1 / 68      (PUP)
dam_ay.exe  (31902593053b6f8d9c81afb79446630a)

1 / 68      (PUP)
setup.exe  (e169965c8241b457e475298616d18ed0)

1 / 68      (PUP)
lyi_my.exe  (fd60f93e4a50999388ec339e87a046e0)

1 / 68      (PUP)
3gs_lj.exe  (c6755d7ffab91dcaf931bbe38a1b9a06)

1 / 68      (PUP)
ic-0.0f6308f49a36b4.exe  (4281c68db27e512533f350538e2aaee2)

1 / 68      (PUP)
lyi_my.exe  (96a6025badb51bea34b80a1200a3c55c)

1 / 68      (PUP)
dam_ay.exe  (34666b1ae0b5ee37fd1214fe09d77500)

1 / 68      (PUP)
ggww72on1.exe  (6d67082a7c7bdf68c93c3791d4d02551)

1 / 68      (PUP)
c36c.tmp  (a930570ee911fe684549c88b11e8cf1a)

1 / 68      (PUP)
setup.exe  (0a0b9274fc1f1222e0db88f88ca07c7a)

1 / 68      (PUP)
adv_288.exe  (1f61448b2e497eb5ebe8d215c8bac9b7)

1 / 68      (PUP)
trotux.exe  (b9471204ea8e41475c3bc50dbca770b5)

1 / 68      (PUP)
trotux.exe  (3ffd37de246bdc74d16599a2f23dcdd0)

1 / 68      (PUP)
setup.exe  (51f54ec74748e484558b1e616172f391)

1 / 68      (PUP)
yomz.exe  (b97ada22174e0b3197419d03b331e591)

1 / 68      (PUP)
ic-0.72a3862c016948.exe  (368dca2142e8734b8b348a7f5a60ef48)

1 / 68      (PUP)
lyi_my.exe  (0372f3507df5b9891286a500877b3075)

1 / 68      (PUP)
22c4.tmp  (c978741193ea18e4677e3e48aba38875)

1 / 68      (PUP)
setup.exe  (d4fceab303e2dca1520fe1d2394d6a64)

1 / 68      (PUP)
djlyylawn.exe  (34f022a64fcbf9f221be90428af5b3c5)

1 / 68      (PUP)
ic-0.3a2246bbf36d54.exe  (a17b68a88109229f35b555f8d00a34fa)

1 / 68      (PUP)
3gs_lj.exe  (14db55552dfab3e0b7bca5f1842fe3e4)

1 / 68      (PUP)
1346.tmp  (8b05f8ae5c74055b4dfaef0b1cea53d6)

 
Latest 30 of 45 files

Downloads URLs for files signed by Yuanyuan Mei.

1 / 68      (PUP)
http://dgkytklfjrqkb.cloudfront.net/.../yomz.exe  (b97ada22174e0b3197419d03b331e591)

1 / 68      (PUP)
http://dgkytklfjrqkb.cloudfront.net/.../yomz.exe  (d0e1fafb3b3b9e239b8644be74a02349)

1 / 68      (PUP)
http://d3g1g0k0wwnjag.cloudfront.net/.../3gs_lj.exe  (5fccbf7d7a6c0dab520c2ca62fed2512)

The certificates below are also signed by Yuanyuan Mei.

1E8CBE561541A195413040AFD65F878D  (Jan 06, 2017 to Apr 21, 2017)

6DA39476057154CF6769846DB47C8306  (Aug 26, 2016 to Apr 21, 2017)

648588429AF2C580751BE41E22947AC1  (Aug 24, 2016 to Apr 21, 2017)

7D92FB84FC4339F548AEAF1B0A921F9B  (Aug 18, 2016 to Apr 21, 2017)

19908A5548B59CE82F392297F289696B  (Aug 11, 2016 to Apr 21, 2017)

128A1FE0064E80F84A2197C8F0D07D76  (Jan 24, 2017 to Apr 21, 2017)

7D1B8EB8054873A3D1BACD4595433E06  (Jan 13, 2017 to Apr 21, 2017)

6C5D7A45FC4FE4003F40D7B13C3AA377  (Aug 12, 2016 to Apr 21, 2017)

4B77E45E6EE2D3592CB495A496A5B5CA  (Jan 19, 2017 to Apr 21, 2017)

17C2F6A2F1252BE7B7D77EB4E7424661  (Aug 15, 2016 to Apr 21, 2017)

10 of 25 code signing certificates issued

* Note, the details and description above are based on the code signing digital signature issued to Yuanyuan Mei by thawte, Inc. on January 22, 2017 with the serial number '045d57d63e13775c8f812e1864797f5a'.