Home Possibly Unwanted Program SupTab

SupTab

Posted: January 24, 2014

Threat Metric

Ranking: 988
Threat Level: 1/10
Infected PCs: 743,657
First Seen: January 24, 2014
Last Seen: October 17, 2023
OS(es) Affected: Windows


SupTab is a browser add-on that loads advertisements, hence its classification as adware. Adware like SupTab does not include intentionally threatening attack functions of threatening software, but its advertisements may expose you to online security risks or cause your browser to perform sub-optimally. Although SupTab is not classified as a virus, Trojan or any other form of threat, removing SupTab with the help of reputable anti-adware products may be in your best interest.

SupTab: Just a Tab of Advertisements to Take with Your Web-Browsing

SupTab is a browser add-on that malware experts only have verified for the Internet Explorer browser, with a high rate of installation in modern editions of Windows (Windows 7 and Windows 8). Combined with its dearth of website marketing or other promotional materials, SupTab also fails to load a visible interface that would identify its presence within IE. Nonetheless, current versions of SupTab add-ons are configured to launch with that browser automatically, allowing SupTab to modify your browser experience at will.

SupTab's preferences for the latter include displaying unwanted advertising content, which SupTab may load as pop-up windows, interstitial advertisement pages or links injected into other pages. SupTab's advertisements may have unintended side effects on Internet Explorer, such as slowing its loading times or causing other performance issues that prevent you from browsing websites with ideal quality. However, SupTab isn't a threat and should not, in most cases, be classified as a Trojan or other type of threatening software by PC security products.

Ending Internet Explorer's Unnecessary Exploration of New Advertisements

SupTab may not be a threat, but contains all the elements of an adware program that has no intentions of providing beneficial functions to its user, and malware researchers heavily advise removing SupTab from any browser that SupTab modifies. To guarantee the deletion of SupTab and other unwanted programs that lack clear uninstallation methods or visible controls, using traditional anti-adware tools and comprehensive file-scanning software should guarantee the total removal of this BHO and its advertisements as much as possible. For additional certainty, you may wish to conduct scans from Safe Mode and avoid using your Web browser until the scanning process is complete.

Although SupTab is a Browser Helper Object with only advertising as its primary side effect, threatening BHOs also exist. Both types of BHOs may be distributed by the same hoaxes, including bundles and mislabeled file downloads circulated throughout software piracy sources. However, user misbehavior isn't always at fault; malware researchers also recommend blocking scripts that could install SupTab or threats automatically, even if all you've done is visit a hacked website.

Aliases

Adware.Mutabaha.107 [DrWeb]Generic PUA IJ [Sophos]Artemis [McAfee-GW-Edition]Win32:SupTab-G [Adw] [Avast]Artemis!C30458159AED [McAfee]Generic Suspicious [Panda]GrayWare[AdWare:not-a-virus]/Win32.SearchProtect [Antiy-AVL]not-a-virus:AdWare.Win32.SearchProtect.ky [Kaspersky]WS.Reputation.1 [Symantec]PUP/Win32.SearchProtect [AhnLab-V3]Win32.Application.SubTab.E [GData]ZhangLing.AA0 [AVG]Zhang.59F [AVG]Zhang.EF9 [AVG]Adware/Win32.Agent [AhnLab-V3]
More aliases (142)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Program Files\MiniLite\ProtectService.exe File name: ProtectService.exe
Size: 132.76 KB (132768 bytes)
MD5: d0a4fd099b7ee90b302be9d1a13a2ebd
Detection count: 169
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files\MiniLite\ProtectService.exe
Group: Malware file
Last Updated: August 5, 2021
C:\System Volume Information\SystemRestore\FRStaging\Program Files (x86)\MiuiTab\CmdShell.exe File name: CmdShell.exe
Size: 31.92 KB (31928 bytes)
MD5: 687063ab8200e3206f6209174354fa69
Detection count: 136
File type: Executable File
Mime Type: unknown/exe
Path: C:\System Volume Information\SystemRestore\FRStaging\Program Files (x86)\MiuiTab\CmdShell.exe
Group: Malware file
Last Updated: November 3, 2022
%PROGRAMFILES%\XTab\cmdshell.exe File name: cmdshell.exe
Size: 29.31 KB (29312 bytes)
MD5: f942761b4ceb7054d5e262cb6b0d051e
Detection count: 93
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\XTab
Group: Malware file
Last Updated: March 25, 2016
%PROGRAMFILES%\XTab\HPNotify.exe File name: HPNotify.exe
Size: 674.43 KB (674432 bytes)
MD5: 1c3a4b9ff103460544c8ae04fabe22b1
Detection count: 91
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\XTab
Group: Malware file
Last Updated: March 25, 2016
C:\Program Files\MiuiTab\CmdShell.exe File name: CmdShell.exe
Size: 31.92 KB (31928 bytes)
MD5: 6a129df750b69b6fa3e6c76ec3dcee40
Detection count: 73
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files\MiuiTab\CmdShell.exe
Group: Malware file
Last Updated: February 27, 2023
C:\Program Files\MiuiTab\cmdshell.exe File name: cmdshell.exe
Size: 29.31 KB (29312 bytes)
MD5: 9da2bcf2842bb444e5dd761286266e2b
Detection count: 66
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files\MiuiTab\cmdshell.exe
Group: Malware file
Last Updated: May 23, 2022
%SYSTEMDRIVE%\AdwCleaner\Quarantine\C\Program Files (x86)\miuitab\CmdShell.exe.vir File name: CmdShell.exe.vir
Size: 29.31 KB (29312 bytes)
MD5: d1574c7af2815098274d3777cfe9657e
Detection count: 59
Mime Type: unknown/vir
Path: %SYSTEMDRIVE%\AdwCleaner\Quarantine\C\Program Files (x86)\miuitab\CmdShell.exe.vir
Group: Malware file
Last Updated: August 13, 2021
C:\Program Files\MiuiTab\cmdshell.exe File name: cmdshell.exe
Size: 29.31 KB (29312 bytes)
MD5: 1fd08d79bf5412f2f2aca7cd6b6b6496
Detection count: 40
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files\MiuiTab\cmdshell.exe
Group: Malware file
Last Updated: November 21, 2021
%PROGRAMFILES%\XTab\cmdshell.exe File name: cmdshell.exe
Size: 29.28 KB (29280 bytes)
MD5: 8882ba96ef0a3597421e664df0806048
Detection count: 33
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\XTab
Group: Malware file
Last Updated: March 25, 2016
C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTab\CmdShell.exe.vir File name: CmdShell.exe.vir
Size: 29.31 KB (29312 bytes)
MD5: d880e2453990a2ff2a22c89fd91a20c3
Detection count: 28
Mime Type: unknown/vir
Path: C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTab\CmdShell.exe.vir
Group: Malware file
Last Updated: June 28, 2022
%PROGRAMFILES%\MiuiTab\ProtectService.exe File name: ProtectService.exe
Size: 119.8 KB (119808 bytes)
MD5: 3cbf283133cf0047fcde8f22dc27f212
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\MiuiTab
Group: Malware file
Last Updated: March 23, 2016
%PROGRAMFILES%\MiuiTab\ProtectService.exe File name: ProtectService.exe
Size: 119.8 KB (119808 bytes)
MD5: af41bb878802ad244c9096e93315554b
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\MiuiTab
Group: Malware file
Last Updated: March 23, 2016
%PROGRAMFILES%\MiuiTab\ProtectService.exe File name: ProtectService.exe
Size: 119.8 KB (119808 bytes)
MD5: 71dfbcb1f387f42ec07c2f605a3e5ef0
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\MiuiTab
Group: Malware file
Last Updated: March 25, 2016
%PROGRAMFILES%\XTab\ProtectService.exe File name: ProtectService.exe
Size: 153.6 KB (153600 bytes)
MD5: 9619e5f1b2981b8f1ad7b78055d348c6
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\XTab
Group: Malware file
Last Updated: March 25, 2016
%PROGRAMFILES%\XTab\ProtectService.exe File name: ProtectService.exe
Size: 153.6 KB (153600 bytes)
MD5: 0c6b72be41e925b639a429e3c6217ec7
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\XTab
Group: Malware file
Last Updated: March 25, 2016
%PROGRAMFILES(x86)%\XTab\ProtectService.exe File name: ProtectService.exe
Size: 153.6 KB (153600 bytes)
MD5: 3cd62e517219b78de1554eff7d2e7d05
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\XTab
Group: Malware file
Last Updated: March 25, 2016
%PROGRAMFILES%\MiniLite\ProtectService.exe File name: ProtectService.exe
Size: 127.48 KB (127488 bytes)
MD5: a67518b300fe8de6a07a379117771d84
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\MiniLite
Group: Malware file
Last Updated: March 25, 2016
%PROGRAMFILES%\MiuiTab\ProtectService.exe File name: ProtectService.exe
Size: 119.8 KB (119808 bytes)
MD5: 65770bc9f631284927bc4892b3448a0b
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\MiuiTab
Group: Malware file
Last Updated: March 25, 2016
%PROGRAMFILES%\MiuiTab\ProtectService.exe File name: ProtectService.exe
Size: 119.8 KB (119808 bytes)
MD5: 2d7303aebcf74acb327fef72160a857e
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\MiuiTab
Group: Malware file
Last Updated: March 25, 2016
%PROGRAMFILES%\MiuiTab\ProtectService.exe File name: ProtectService.exe
Size: 119.8 KB (119808 bytes)
MD5: 8ae74e868949ff7d9c9de38eda88fc64
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\MiuiTab
Group: Malware file
Last Updated: March 25, 2016
%PROGRAMFILES%\MiuiTab\ProtectService.exe File name: ProtectService.exe
Size: 119.8 KB (119808 bytes)
MD5: 0752f2dd679df0573774aa2105da9ca8
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\MiuiTab
Group: Malware file
Last Updated: March 25, 2016

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{1F91A9A1-01BA-4c81-863D-3BA0751E1419}{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F}{7D3C47ED-E0BE-4940-9DDA-A7A097AEBD88}{917CAAE9-DD47-4025-936E-1414F07DF5B8}{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}HKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\Approved Extensions\{1F91A9A1-01BA-4C81-863D-3BA0751E1419}Software\Microsoft\Internet Explorer\Approved Extensions\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}Software\Microsoft\Internet Explorer\Approved Extensions\{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F}SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{1F91A9A1-01BA-4c81-863D-3BA0751E1419}SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}SOFTWARE\Mozilla\Firefox\Extensions\fftoolbar2014@etech.comSOFTWARE\SupDpSoftware\SupHpUISoftSOFTWARE\supTabSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{1F91A9A1-01BA-4c81-863D-3BA0751E1419}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}SOFTWARE\Wow6432Node\Mozilla\Firefox\Extensions\fftoolbar2014@etech.comSOFTWARE\Wow6432Node\SupDpSOFTWARE\Wow6432Node\supTabSYSTEM\ControlSet001\services\eventlog\Application\IePluginServiceSYSTEM\ControlSet001\services\eventlog\Application\IePluginServicesSYSTEM\ControlSet001\services\IePluginServiceSYSTEM\ControlSet001\services\IePluginServicesSYSTEM\ControlSet002\services\eventlog\Application\IePluginServiceSYSTEM\ControlSet002\services\eventlog\Application\IePluginServicesSYSTEM\ControlSet002\services\IePluginServiceSYSTEM\ControlSet002\services\IePluginServicesSYSTEM\CurrentControlSet\services\eventlog\Application\IePluginServiceSYSTEM\CurrentControlSet\services\eventlog\Application\IePluginServicesSYSTEM\CurrentControlSet\services\IePluginServiceSYSTEM\CurrentControlSet\services\IePluginServicesHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}IePluginsSupTabXTab

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Application Data\IePluginService%ALLUSERSPROFILE%\Application Data\IePluginServices%ALLUSERSPROFILE%\IePluginService%ALLUSERSPROFILE%\IePluginServices%APPDATA%\SupTab%APPDATA%\{37E99E86-D615-4B08-937F-F8F935C455F3}_ANZHUANG\{2E089831-61B1-4CF2-8553-300574316F09}_DIYIGE%PROGRAMFILES%\MiniLite%PROGRAMFILES%\MiuiTab%PROGRAMFILES%\STab%PROGRAMFILES%\SupTab%PROGRAMFILES%\XTab%PROGRAMFILES(x86)%\MiniLite%PROGRAMFILES(x86)%\MiuiTab%PROGRAMFILES(x86)%\STab%PROGRAMFILES(x86)%\SupTab%PROGRAMFILES(x86)%\XTab%UserProfile%\SupTab
Loading...