Home Possibly Unwanted Program SupTab

SupTab

Posted: January 24, 2014

Threat Metric

Ranking: 1,392
Threat Level: 1/10
Infected PCs: 749,050
First Seen: January 24, 2014
Last Seen: March 10, 2025
OS(es) Affected: Windows


SupTab is a browser add-on that loads advertisements, hence its classification as adware. Adware like SupTab does not include intentionally threatening attack functions of threatening software, but its advertisements may expose you to online security risks or cause your browser to perform sub-optimally. Although SupTab is not classified as a virus, Trojan or any other form of threat, removing SupTab with the help of reputable anti-adware products may be in your best interest.

SupTab: Just a Tab of Advertisements to Take with Your Web-Browsing

SupTab is a browser add-on that malware experts only have verified for the Internet Explorer browser, with a high rate of installation in modern editions of Windows (Windows 7 and Windows 8). Combined with its dearth of website marketing or other promotional materials, SupTab also fails to load a visible interface that would identify its presence within IE. Nonetheless, current versions of SupTab add-ons are configured to launch with that browser automatically, allowing SupTab to modify your browser experience at will.

SupTab's preferences for the latter include displaying unwanted advertising content, which SupTab may load as pop-up windows, interstitial advertisement pages or links injected into other pages. SupTab's advertisements may have unintended side effects on Internet Explorer, such as slowing its loading times or causing other performance issues that prevent you from browsing websites with ideal quality. However, SupTab isn't a threat and should not, in most cases, be classified as a Trojan or other type of threatening software by PC security products.

Ending Internet Explorer's Unnecessary Exploration of New Advertisements

SupTab may not be a threat, but contains all the elements of an adware program that has no intentions of providing beneficial functions to its user, and malware researchers heavily advise removing SupTab from any browser that SupTab modifies. To guarantee the deletion of SupTab and other unwanted programs that lack clear uninstallation methods or visible controls, using traditional anti-adware tools and comprehensive file-scanning software should guarantee the total removal of this BHO and its advertisements as much as possible. For additional certainty, you may wish to conduct scans from Safe Mode and avoid using your Web browser until the scanning process is complete.

Although SupTab is a Browser Helper Object with only advertising as its primary side effect, threatening BHOs also exist. Both types of BHOs may be distributed by the same hoaxes, including bundles and mislabeled file downloads circulated throughout software piracy sources. However, user misbehavior isn't always at fault; malware researchers also recommend blocking scripts that could install SupTab or threats automatically, even if all you've done is visit a hacked website.

Aliases

Adware.Mutabaha.107 [DrWeb]Generic PUA IJ [Sophos]Artemis [McAfee-GW-Edition]Win32:SupTab-G [Adw] [Avast]Artemis!C30458159AED [McAfee]Generic Suspicious [Panda]GrayWare[AdWare:not-a-virus]/Win32.SearchProtect [Antiy-AVL]not-a-virus:AdWare.Win32.SearchProtect.ky [Kaspersky]WS.Reputation.1 [Symantec]PUP/Win32.SearchProtect [AhnLab-V3]Win32.Application.SubTab.E [GData]ZhangLing.AA0 [AVG]Zhang.59F [AVG]Zhang.EF9 [AVG]Adware/Win32.Agent [AhnLab-V3]
More aliases (142)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



G:\AdwCleaner\Quarantine\C\ProgramData\IePluginServices\PluginService.exe.vir File name: PluginService.exe.vir
Size: 715.65 KB (715656 bytes)
MD5: 5e0c29fcd859ab8d5b1c859f034d8f2f
Detection count: 13,118
Mime Type: unknown/vir
Path: G:\AdwCleaner\Quarantine\C\ProgramData\IePluginServices\PluginService.exe.vir
Group: Malware file
Last Updated: July 16, 2024
C:\ProgramData\IePluginServices\trz2D87.tmp File name: trz2D87.tmp
Size: 3.42 MB (3427208 bytes)
MD5: 0bb615800d2dcadc05f34cd053ace60e
Detection count: 9,097
File type: Temporary File
Mime Type: unknown/tmp
Path: C:\ProgramData\IePluginServices\trz2D87.tmp
Group: Malware file
Last Updated: May 30, 2022
%PROGRAMFILES(x86)%\SupTab\Loader64.exe File name: Loader64.exe
Size: 73.21 KB (73216 bytes)
MD5: 09b9b6c0f8277a86cc8f4d66aeaab762
Detection count: 7,617
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\SupTab\Loader64.exe
Group: Malware file
Last Updated: March 3, 2025
\??\C:\Program Files\SupTab\cfgdrv32.cfg File name: cfgdrv32.cfg
Size: 24.28 KB (24280 bytes)
MD5: ad0d1330d9c9ceacb08069d2e573897d
Detection count: 5,890
Mime Type: unknown/cfg
Path: \??\C:\Program Files\SupTab
Group: Malware file
Last Updated: August 27, 2020
C:\ProgramData\IePluginServices\PLUGINSERVICE.EXE.542ac9e4 File name: PLUGINSERVICE.EXE.542ac9e4
Size: 689.03 KB (689032 bytes)
MD5: 2f0f97174cc76a2153d4ef7dba269c83
Detection count: 4,291
Mime Type: unknown/542ac9e4
Path: C:\ProgramData\IePluginServices\PLUGINSERVICE.EXE.542ac9e4
Group: Malware file
Last Updated: June 22, 2021
%SYSTEMDRIVE%\AdwCleaner\Quarantine\C\Program Files (x86)\XTab\SupTab.dll.vir File name: SupTab.dll.vir
Size: 210.09 KB (210096 bytes)
MD5: fece5b81614bd16ff043051f338183a0
Detection count: 3,253
Mime Type: unknown/vir
Path: %SYSTEMDRIVE%\AdwCleaner\Quarantine\C\Program Files (x86)\XTab\SupTab.dll.vir
Group: Malware file
Last Updated: May 7, 2024
C:\Program Files\SupTab\cfgdrv64.cfg File name: cfgdrv64.cfg
Size: 30.42 KB (30424 bytes)
MD5: d1df98d570b57f932ccb2acdf1c11939
Detection count: 672
Mime Type: unknown/cfg
Path: C:\Program Files\SupTab\cfgdrv64.cfg
Group: Malware file
Last Updated: June 22, 2021
C:\Users\<username>\AppData\Local\Temp\~dlFFB2\~dljyb\tmp\SupTab_v5.8.8.777_noblank.exe File name: SupTab_v5.8.8.777_noblank.exe
Size: 2.64 MB (2643848 bytes)
MD5: f3fb2b89707be53d0ccf4b909c0801b2
Detection count: 550
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\~dlFFB2\~dljyb\tmp\SupTab_v5.8.8.777_noblank.exe
Group: Malware file
Last Updated: January 21, 2024
C:\Users\<username>\AppData\Local\Temp\CD4586F4-6AD1-490c-BFD9-10952EA3ADDE[o]\1.zipDir\tmp\SupTab_ns_v5.8.8.640.exe File name: SupTab_ns_v5.8.8.640.exe
Size: 2.49 MB (2496512 bytes)
MD5: d549db22a9e1aba82a5a647fe32306dc
Detection count: 358
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\CD4586F4-6AD1-490c-BFD9-10952EA3ADDE[o]\1.zipDir\tmp\SupTab_ns_v5.8.8.640.exe
Group: Malware file
Last Updated: January 20, 2023
%PROGRAMFILES%\XTab\SupTab.dll File name: SupTab.dll
Size: 538.25 KB (538256 bytes)
MD5: c30458159aed49894b9a4dccd8697830
Detection count: 244
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\XTab
Group: Malware file
Last Updated: September 14, 2020
C:\Users\<username>\AppData\Local\Temp\~dlA5E5\lxwsh\tmp\XTab_Setup1998.exe File name: XTab_Setup1998.exe
Size: 2.57 MB (2571576 bytes)
MD5: 415d34e187876e93a9959ab04563aa12
Detection count: 98
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\~dlA5E5\lxwsh\tmp\XTab_Setup1998.exe
Group: Malware file
Last Updated: December 14, 2022
%PROGRAMFILES%\XTab\HPNotify.exe File name: HPNotify.exe
Size: 674.43 KB (674432 bytes)
MD5: 1c3a4b9ff103460544c8ae04fabe22b1
Detection count: 91
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\XTab
Group: Malware file
Last Updated: March 25, 2016
C:\Program Files\MiuiTab\CmdShell.exe File name: CmdShell.exe
Size: 31.92 KB (31928 bytes)
MD5: 6a129df750b69b6fa3e6c76ec3dcee40
Detection count: 73
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files\MiuiTab\CmdShell.exe
Group: Malware file
Last Updated: February 27, 2023
%SYSTEMDRIVE%\AdwCleaner\Quarantine\C\Program Files (x86)\miuitab\CmdShell.exe.vir File name: CmdShell.exe.vir
Size: 29.31 KB (29312 bytes)
MD5: d1574c7af2815098274d3777cfe9657e
Detection count: 59
Mime Type: unknown/vir
Path: %SYSTEMDRIVE%\AdwCleaner\Quarantine\C\Program Files (x86)\miuitab\CmdShell.exe.vir
Group: Malware file
Last Updated: August 13, 2021
C:\Windows.old.000\Users\<username>\AppData\Local\Temp\158AF40F-387C-4D75-B9F1-9186769876B9mp\tmp\XTab_v4.0.exe File name: XTab_v4.0.exe
Size: 2.41 MB (2415992 bytes)
MD5: ab5ef850169b67afe19637fd7b6ed049
Detection count: 40
File type: Executable File
Mime Type: unknown/exe
Path: C:\Windows.old.000\Users\<username>\AppData\Local\Temp\158AF40F-387C-4D75-B9F1-9186769876B9mp\tmp\XTab_v4.0.exe
Group: Malware file
Last Updated: March 16, 2023
C:\Users\<username>\AppData\Local\Temp\~dlD762\~dljyb\tmp\STab_v4.0.exe File name: STab_v4.0.exe
Size: 2.64 MB (2646016 bytes)
MD5: 684ce32af59ccba1cc2954b5b369e364
Detection count: 33
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\~dlD762\~dljyb\tmp\STab_v4.0.exe
Group: Malware file
Last Updated: September 26, 2022
%TEMP%\16110582\16110582.zipDir\tmp\SupTab_v5.8.8.619.exe File name: SupTab_v5.8.8.619.exe
Size: 2.67 MB (2676616 bytes)
MD5: c8b1b2053e6333ca6e8e15461dbbb30c
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\16110582\16110582.zipDir\tmp
Group: Malware file
Last Updated: April 2, 2016
%TEMP%\7E82590C-48C6-48BD-9DBB-BDCC68C3CBB8[i]\tmp\SupTab_v5.8.8.865_noblank.exe File name: SupTab_v5.8.8.865_noblank.exe
Size: 2.59 MB (2598824 bytes)
MD5: e6b1e1bc352ba71298ae10d2958b9d50
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\7E82590C-48C6-48BD-9DBB-BDCC68C3CBB8[i]\tmp
Group: Malware file
Last Updated: April 2, 2016
%PROGRAMFILES%\MiuiTab\ProtectService.exe File name: ProtectService.exe
Size: 119.8 KB (119808 bytes)
MD5: 71dfbcb1f387f42ec07c2f605a3e5ef0
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\MiuiTab
Group: Malware file
Last Updated: March 25, 2016
%TEMP%\418FDC53-0734-447f-8C1F-81B9497C5431[u]\1.zipDir\tmp\SupTab_v5.8.8.749_noblank.exe File name: SupTab_v5.8.8.749_noblank.exe
Size: 2.52 MB (2526088 bytes)
MD5: 938786491250b6c7aa2b0a9570224890
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\418FDC53-0734-447f-8C1F-81B9497C5431[u]\1.zipDir\tmp
Group: Malware file
Last Updated: April 2, 2016
%TEMP%\7E82590C-48C6-48BD-9DBB-BDCC68C3CBB8[i]\tmp\SupTab_v5.8.8.864_noblank.exe File name: SupTab_v5.8.8.864_noblank.exe
Size: 2.59 MB (2598808 bytes)
MD5: 0b794323677b724a87f5eac14ae998c0
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\7E82590C-48C6-48BD-9DBB-BDCC68C3CBB8[i]\tmp
Group: Malware file
Last Updated: April 2, 2016
%TEMP%\Wtmp1093093\tmp\STab_Down.exe File name: STab_Down.exe
Size: 105.47 KB (105472 bytes)
MD5: 2215dd367287115f6a9f284b1602183c
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\Wtmp1093093\tmp
Group: Malware file
Last Updated: April 2, 2016
%TEMP%\wtmp\A630A478653E485d8B31E589D87F2CD7\XTab.exe File name: XTab.exe
Size: 2.57 MB (2571976 bytes)
MD5: da5ef50c598c700600eea8f470aa5ea7
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\wtmp\A630A478653E485d8B31E589D87F2CD7
Group: Malware file
Last Updated: March 27, 2020
%TEMP%\t7145FFC5-EF2C-4750-9CC6-B934D573F69Bmp\tmp\SupTab_v5.8.8.777_noblank_amy.exe File name: SupTab_v5.8.8.777_noblank_amy.exe
Size: 2.62 MB (2626528 bytes)
MD5: 571fdf3d30fd80191dd511e5116a3c14
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\t7145FFC5-EF2C-4750-9CC6-B934D573F69Bmp\tmp
Group: Malware file
Last Updated: March 14, 2020
%TEMP%\Wtmp552652667\tmp\XTab_Setup1987.exe File name: XTab_Setup1987.exe
Size: 2.57 MB (2572024 bytes)
MD5: 22dc5bc0d2d27d0ad01ac18546fc21b2
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\Wtmp552652667\tmp
Group: Malware file
Last Updated: April 2, 2016

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{1F91A9A1-01BA-4c81-863D-3BA0751E1419}{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F}{7D3C47ED-E0BE-4940-9DDA-A7A097AEBD88}{917CAAE9-DD47-4025-936E-1414F07DF5B8}{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}HKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\Approved Extensions\{1F91A9A1-01BA-4C81-863D-3BA0751E1419}Software\Microsoft\Internet Explorer\Approved Extensions\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}Software\Microsoft\Internet Explorer\Approved Extensions\{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F}SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{1F91A9A1-01BA-4c81-863D-3BA0751E1419}SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}SOFTWARE\Mozilla\Firefox\Extensions\fftoolbar2014@etech.comSOFTWARE\SupDpSoftware\SupHpUISoftSOFTWARE\supTabSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{1F91A9A1-01BA-4c81-863D-3BA0751E1419}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}SOFTWARE\Wow6432Node\Mozilla\Firefox\Extensions\fftoolbar2014@etech.comSOFTWARE\Wow6432Node\SupDpSOFTWARE\Wow6432Node\supTabSYSTEM\ControlSet001\services\eventlog\Application\IePluginServiceSYSTEM\ControlSet001\services\eventlog\Application\IePluginServicesSYSTEM\ControlSet001\services\IePluginServiceSYSTEM\ControlSet001\services\IePluginServicesSYSTEM\ControlSet002\services\eventlog\Application\IePluginServiceSYSTEM\ControlSet002\services\eventlog\Application\IePluginServicesSYSTEM\ControlSet002\services\IePluginServiceSYSTEM\ControlSet002\services\IePluginServicesSYSTEM\CurrentControlSet\services\eventlog\Application\IePluginServiceSYSTEM\CurrentControlSet\services\eventlog\Application\IePluginServicesSYSTEM\CurrentControlSet\services\IePluginServiceSYSTEM\CurrentControlSet\services\IePluginServicesHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}IePluginsSupTabXTab

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Application Data\IePluginService%ALLUSERSPROFILE%\Application Data\IePluginServices%ALLUSERSPROFILE%\IePluginService%ALLUSERSPROFILE%\IePluginServices%APPDATA%\SupTab%APPDATA%\{37E99E86-D615-4B08-937F-F8F935C455F3}_ANZHUANG\{2E089831-61B1-4CF2-8553-300574316F09}_DIYIGE%PROGRAMFILES%\MiniLite%PROGRAMFILES%\MiuiTab%PROGRAMFILES%\STab%PROGRAMFILES%\SupTab%PROGRAMFILES%\XTab%PROGRAMFILES(x86)%\MiniLite%PROGRAMFILES(x86)%\MiuiTab%PROGRAMFILES(x86)%\STab%PROGRAMFILES(x86)%\SupTab%PROGRAMFILES(x86)%\XTab%UserProfile%\SupTab
Loading...