defaulttabsetup_20130903.exe

DefaultTab

Search Results, LLC

The application defaulttabsetup_20130903.exe, “DefaultTabSetup.exe” by Search Results has been detected as adware by 10 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from cdn1.mysearchresults.com and multiple other hosts.
Publisher:
Search Results  (signed by Search Results, LLC)

Product:
DefaultTab

Description:
DefaultTabSetup.exe

Version:
2.2.18.0

MD5:
b2b114b3abb6969fea3f491e92b3afb2

SHA-1:
798c6c00285c5377341c4eced8d2edf6ffb04860

SHA-256:
61ed9543df6a4b3425990c36ddfc7dccdaa3c99020ae5221b0aa3d03528bd84c

Scanner detections:
10 / 68

Status:
Adware

Analysis date:
11/23/2024 4:08:24 AM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
W32.Clod091.Trojan
1.3.0.4613

Boost by Reason
Trojan.Adw.Installer.SearchResults.Y
2013.9.13.11

Dr.Web
Adware.Plugin.48
9.0.1.0256

ESET NOD32
Win32/Toolbar.DefaultTab (variant)
7.8962

K7 AntiVirus
Unwanted-Program
13.174.10656

Malwarebytes
PUP.Optional.DefaultTab.A
v2013.09.13.11

McAfee
Artemis!B2D361D6CCFC
5600.6995

NANO AntiVirus
Trojan.Win32.Plugin.crfhgu
0.28.0.57029

Reason Heuristics
PUP.Installer.SearchResults.Y
14.8.7.17

Sophos
Generic PUA BM
4.96

File size:
3 MB (3,113,608 bytes)

Product version:
2.2.18.0

Copyright:
Search Results, LLC

Trademarks:
Search Results, LLC

Original file name:
DefaultTabSetup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\defaulttabsetup_20130903.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
4/24/2012 5:00:00 PM

Valid to:
4/25/2014 4:59:59 PM

Subject:
CN="Search Results, LLC", O="Search Results, LLC", STREET="2751 Hennepin Ave S #252", L=Minneapolis, S=MN, PostalCode=55405, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00B6815DF3B6D64839E008D65B53EF0170

File PE Metadata
Compilation timestamp:
6/19/1992 3:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:agjdEC4CMaouPQAXryZP549lLTbMhNam0fa9iAmvwJhQC118GGUE13mkvsQSbx3u:+yrluuneam0fa9iAHhQGGGGUE4hbt5Ru

Entry address:
0x637001

Entry point:
60, E8, 03, 00, 00, 00, E9, EB, 04, 5D, 45, 55, C3, E8, 01, 00, 00, 00, EB, 5D, BB, ED, FF, FF, FF, 03, DD, 81, EB, 00, 70, 63, 00, 83, BD, 88, 04, 00, 00, 00, 89, 9D, 88, 04, 00, 00, 0F, 85, CB, 03, 00, 00, 8D, 85, 94, 04, 00, 00, 50, FF, 95, A9, 0F, 00, 00, 89, 85, 8C, 04, 00, 00, 8B, F0, 8D, 7D, 51, 57, 56, FF, 95, A5, 0F, 00, 00, AB, B0, 00, AE, 75, FD, 38, 07, 75, EE, 8D, 45, 7A, FF, E0, 56, 69, 72, 74, 75, 61, 6C, 41, 6C, 6C, 6F, 63, 00, 56, 69, 72, 74, 75, 61, 6C, 46, 72, 65, 65, 00, 56, 69, 72, 74...
 
[+]

Entropy:
7.9982

Packer / compiler:
ASPack v2.12

Code size:
1.4 MB (1,480,704 bytes)

The file defaulttabsetup_20130903.exe has been seen being distributed by the following 3 URLs.

http://cdn1.mysearchresults.com/DefaultTabSetup.exe

Remove defaulttabsetup_20130903.exe - Powered by Reason Core Security