defaulttabsetup.exe

Search Results, LLC

The application defaulttabsetup.exe by Search Results has been detected as adware by 11 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from cdn1.mysearchresults.com.
Publisher:
Search Results, LLC  (signed and verified)

Description:
SetupInstall.exe

Version:
2.4.0.0

MD5:
a183b57c702238cfb904f10d84170b61

SHA-1:
1175cb50faa16696f4e414b90a9477e2ee143049

SHA-256:
6f3f31178e0fd03a5215e156c3aefa6b313ed54c2a9bf19652e6607e7b1e0b6c

Scanner detections:
11 / 68

Status:
Adware

Analysis date:
5/16/2024 3:55:27 PM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
W32.Clod091.Trojan
1.3.0.4613

Boost by Reason
Optional.SearchResults.P
188838

Dr.Web
Adware.Plugin.48
9.0.1.015

ESET NOD32
Win32/Toolbar.DefaultTab (variant)
8.9190

K7 AntiVirus
Unwanted-Program
13.174.10656

Malwarebytes
PUP.Optional.DefaultTab.A
v2014.01.15.03

McAfee
Artemis!B2D361D6CCFC
5600.6995

NANO AntiVirus
Trojan.Win32.Plugin.crfhgu
0.28.0.57029

Reason Heuristics
PUP.Installer.SearchResults.P
14.8.7.17

Sophos
Generic PUA BM
4.96

Trend Micro House Call
TROJ_GEN.F47V1222
7.2.15

File size:
3.2 MB (3,319,424 bytes)

Product version:
2.4.0.0

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\defaulttabsetup.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
4/24/2012 8:00:00 PM

Valid to:
4/25/2014 7:59:59 PM

Subject:
CN="Search Results, LLC", O="Search Results, LLC", STREET="2751 Hennepin Ave S #252", L=Minneapolis, S=MN, PostalCode=55405, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00B6815DF3B6D64839E008D65B53EF0170

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:M9c5OsKF20oH24EeFKnAF1X4stCH0nP80LdqrTcLFyGeK33YIWwjbDxlycTSwKte:Ma5OsKs0oWleFd4soaP1dVs1K33zPDb9

Entry address:
0x4BB001

Entry point:
60, E8, 03, 00, 00, 00, E9, EB, 04, 5D, 45, 55, C3, E8, 01, 00, 00, 00, EB, 5D, BB, ED, FF, FF, FF, 03, DD, 81, EB, 00, B0, 4B, 00, 83, BD, 88, 04, 00, 00, 00, 89, 9D, 88, 04, 00, 00, 0F, 85, CB, 03, 00, 00, 8D, 85, 94, 04, 00, 00, 50, FF, 95, A9, 0F, 00, 00, 89, 85, 8C, 04, 00, 00, 8B, F0, 8D, 7D, 51, 57, 56, FF, 95, A5, 0F, 00, 00, AB, B0, 00, AE, 75, FD, 38, 07, 75, EE, 8D, 45, 7A, FF, E0, 56, 69, 72, 74, 75, 61, 6C, 41, 6C, 6C, 6F, 63, 00, 56, 69, 72, 74, 75, 61, 6C, 46, 72, 65, 65, 00, 56, 69, 72, 74...
 
[+]

Packer / compiler:
ASPack v2.12

Code size:
1.4 MB (1,500,672 bytes)

The file defaulttabsetup.exe has been seen being distributed by the following URL.

Remove defaulttabsetup.exe - Powered by Reason Core Security