QQ started out 17 years ago with the idea to have a messenger for China similar to programs like Skype or ICQ. Since then, the program was developed a lot, and it became the most widespread instant messaging engine. Currently, Tencent QQ has also developed a mobile application transferring its huge user base to mobile devices. It all sounds great until users have reported observing a variant of the program that heavily displays advertisements on the user PCs.
|Type||PUP, Browser Hijacker|
|Short Description||The software changes settings to the user’s web browser may collect user information and installs plugins without notification. Also difficult to erase from the PC.|
|Symptoms||The user may witness his home page changed to qq(.)com and may notice it in Programs and Features in Windows.|
|Distribution Method||Via PUPs, installed by bundling (Browser Hijackers) or by visiting a suspicious third-party site that is advertising it.|
|Detection Tool||Download Malware Removal Tool, to See If Your System Has Been Affected by Tencent QQ|
|User Experience||Join our forum to discuss Tencent QQ.|
Tencent QQ – How Is It Spread
There may be several methods by which Tencent QQ may spread onto your computer. The program may be encountered as a bundled application in case you download applications from third-party websites. Such websites may be of the following character:
- Torrent websites sharing software installers.
- Randomly visited third-party software providing websites found online.
- Websites that are advertised via adware on your computer.
- Sites which are advertised on social media.
- Programs that are shared in p2p sharing software such as DC++, for example.
Imagine the following scenario – you have cleanly reinstalled Windows, and you have to download all of the free programs you have previously used. To do this, you have to search for those programs online one by one. Here is where you may have the bad luck of downloading an app from a software provider that has Tencent QQ included(bundled) in your installer, for example:
And this is not the only way of distribution. Besides it, the application may be automatically downloaded without your permission by other ad-supported programs that have elevated privileges to do it or even malware. Some users have even reported on Reddit forums to get the suspicious ad-supported version of QQ via playing online games, like the Chinese Blade and Soul.
The program can also be found in an international version on websites such as download.com. However we could not manage to download it via this method:
Tencent QQ Ads Variant in Detail
The original version of the program itself has all of the necessary features of a chat software. However, it is all good until one point – the point where it situates approximately 200 MB which is highly untypical for chat engines. To put this in perspective, Skype is ~76 MB in size.
Not only this but when the program was installed, the anti-malware tool installed on the test device immediately detected it as an unknown software:
When we checked for any bundled applications along with QQ in Programs and Features and not to our amazement, we have found that it had a QQ email plugin installed along it:
We were surprised however when after a system restart, we opened Mozilla Firefox only to discover QQ’s plugins spread all over it and there was no notification during install that there will be any:
Just when we thought the nightmare was over, we decided to check Internet Explorer, only to find out that Tencent QQ has modified Registry Entires to set its website qq(.)com as a home page:
The cherry on the cake was when we decided to use the search engine of the software, which redirected us via a new tab to a hoax search engine, called Sogou, which is known in the malware research world as a name copied by several browser hijackers, like the Sogou Browser Hijacker:
This situation is considered to be potentially harmful to the user, due to several different reasons:
- The software may collect user information and share it with third-parties.
- Advertisements may display web links to third-party websites that could either collect information themselves, advertise other PUPs (Potentially Unwanted Programs).
- The user could be redirected to a malicious website that may or may not infects his computer with malware.
Remove Tencent QQ from Your Computer
Uninstalling Tencent may be tricky. When you attempt it, most likely you may be able to uninstall the plugin of Tencent, but you may not eventually be able to uninstall the main software. On attempt to uninstall the program, Tencent displays the following pop-up:
This is why manually removing this software may take some work because it also modifies your web browsers. For maximum effectiveness, we have created the following instructions to help you successfully get rid of it and clean your PC without having to reinstall it.