xtab.exe

Giner Tech Inc

The application xtab.exe by Giner Tech Inc has been detected as adware by 36 anti-malware scanners. This particular feature is designed to hijack the browser in an attempt to prevent other resources from modify the browser's search and home pages.
Publisher:
XTab  (signed by Giner Tech Inc)

Product:
XTab

Version:
4.0.2.2072

MD5:
648b5639759202c572f11301218768e0

SHA-1:
d5c63e1672c503c8af5a28a6e77a79eb75142875

SHA-256:
9d43dbed0905d135846e81dc2f630e34a5bc4fb2e0a415602b16b30e7a8f8b4b

Scanner detections:
36 / 68

Status:
Adware

Analysis date:
11/1/2024 2:31:11 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.SearchProtect.W
355

Agnitum Outpost
Riskware.Agent
7.1.1

AhnLab V3 Security
PUP/Win32.SearchProtect
2015.05.06

Avira AntiVirus
PUA/SearchProtect.Gen
3.6.1.96

avast!
Win32:Patched-JI
160214-0

AVG
Win32/Slugin.A
2015.0.4522

Baidu Antivirus
PUA.Win32.TNT2
4.0.3.16215

Bitdefender
Adware.SearchProtect.W
1.0.20.230

Bkav FE
W32.HfsAdware
1.3.0.6379

Clam AntiVirus
Win.Adware.SupTab
0.98/20437

Comodo Security
ApplicUnwnt.Win32.SearchProtect.~A
22018

Dr.Web
Adware.Mutabaha.333, Win32.Wplugin.1
9.0.1.05190

Emsisoft Anti-Malware
Adware.SearchProtect.W
8.16.02.15.12

ESET NOD32
Win32/Agent.NAG virus
7.0.302.0

Fortinet FortiGate
Adware/SearchProtect
2/15/2016

F-Prot
W32/Slugin.B
4.6.5.141

F-Secure
Adware.SearchProtect.W
11.2016-15-02_2

G Data
Adware.SearchProtect
16.2.25

K7 AntiVirus
Unwanted-Program
13.203.15815

Kaspersky
Virus.Win32.Slugin
15.0.0.562

Malwarebytes
PUP.Optional.BrowserWatch
v2016.02.15.12

McAfee
Program.Artemis!41BC6E58B277
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.213.6208.0

MicroWorld eScan
Adware.SearchProtect.W
17.0.0.138

NANO AntiVirus
Riskware.Win32.SearchProtect.dpvtwk
0.30.24.1357

Norman
Win32.SlugIn.A
13.02.2016 01:47:07

nProtect
Adware.SearchProtect.W
15.05.04.01

Panda Antivirus
Trj/Genetic.gen
16.02.15.12

Qihoo 360 Security
HEUR/QVM20.1.Malware.Gen
1.0.0.1015

Quick Heal
PUA.SearchProtect.OD3
2.16.14.00

Reason Heuristics
PUP.Thinknice.GinerTech (M)
16.2.16.5

Sophos
PUA 'SearchProtect' (of type Adware)
5.14

Trend Micro House Call
ADW_ELEX
7.2.46

Trend Micro
ADW_ELEX
10.465.15

Vba32 AntiVirus
AdWare.SearchProtect
3.12.26.3

VIPRE Antivirus
Threat.4314870
47028

File size:
2.5 MB (2,630,235 bytes)

Copyright:
copyroght (c) 2011-2014 XTab system

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Documents and Settings\{user}\Local settings\temp\{random}.tmp\8c5f5d2f5f05452a87b4692aef025d56\xtab.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
4/20/2015 2:43:22 AM

Valid to:
12/2/2015 4:23:38 AM

Subject:
CN=Giner Tech Inc, O=Giner Tech Inc, L=Wilmington, S=Delaware, C=US

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112186B135D0152CD8EA8D04B67D2A0CCF34

File PE Metadata
Compilation timestamp:
3/22/2010 7:59:20 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:zXlpEAz9DGIhZnRUdeXQod/t/EOG8bTWvWpOUblUQuRFiI0y:z1aAz9DGIvRUcXQod96CWyJWzR0IX

Entry address:
0x114A

Entry point:
60, E8, 00, 00, 00, 00, 5B, 81, EB, D0, 48, 00, 10, 83, EC, 74, 8B, EC, 8B, 83, AB, 4B, 00, 10, 89, 45, 00, 8B, 83, B3, 4B, 00, 10, 03, 45, 00, 89, 45, 2C, 8B, 83, B7, 4B, 00, 10, 03, 45, 00, 89, 45, 30, C7, 45, 14, 00, 00, 00, 00, C7, 45, 18, 00, 00, 00, 00, C7, 45, 1C, 00, 00, 00, 00, 8B, 45, 14, FF, 45, 14, 66, 33, C9, 8A, 8C, 03, FF, 4B, 00, 10, 84, C9, 74, 7A, 8B, 45, 1C, 66, 01, 4D, 1C, 03, C3, 05, 13, 4C, 00, 10, 50, 8B, 45, 2C, FF, 10, 85, C0, 0F, 84, 5E, 02, 00, 00, 89, 45, 10, 8B, 45, 1C, 03, C3...
 
[+]

Packer / compiler:
ASPack v1.08.04

Code size:
62 KB (63,488 bytes)

Remove xtab.exe - Powered by Reason Core Security