Threat Database Browser Hijackers DefaultTab-Search Results

DefaultTab-Search Results

By CagedTech in Browser Hijackers

Threat Scorecard

Ranking: 5,161
Threat Level: 50 % (Medium)
Infected Computers: 170,983
First Seen: March 4, 2013
Last Seen: May 9, 2025
OS(es) Affected: Windows

Aliases

6 security vendors flagged this file as malicious.

Anti-Virus Software Detection
AVG Generic5.AXOX
Comodo ApplicUnwnt
AVG Searchres.2F5
McAfee Artemis!E8BC5FD5F80C
DrWeb Adware.Toolbar.239
McAfee Artemis!5F593CAC9F67

File System Details

DefaultTab-Search Results may create the following file(s):
# File Name MD5 Detections
1. temp.dat 7307ffae447bf45c01af9a7ead0e9d43 26,635
2. DefaultTabSearch.exe.vir 2d7c1661961ce19085b6a968b1b293d4 5,062
3. DTReg.exe ff9e721d98bc7cf94c283c9d4836c9df 4,608
4. DTChk.exe e8bc5fd5f80cdb59429cd0ce8e91d41a 3,528
5. DefaultTabUninstaller.exe b01a4f484f4879f07ee086a37812a960 2,382
6. DefaultTabBHO.dll 4b1858d4620a29d822abc80a5088d51e 1,695
7. DefaultTabHost.exe f3985d54a726af27019c5b14e94c2d62 1,370
8. defaulttabsearch.exe 6239dd7975e92941241cabb704248a19 763
9. A0116343.dll f19f3f866f08b34c8673255d73d513a3 750
10. uninstalldt.exe 1613ea0c778e9445237c774ee2f32d24 302
11. uninstalldt.exe.vir cf5b2ce169cc6761e80089bc849dae8a 228
12. A0118888.dll 94b6531c6ce4584579c42664c4a98f1a 212
13. DefaultTabStart.exe f18ecac51f9b4504c3d1ce10b09e6486 184
14. vqsdyeai.dll e9750bbde8ef179fab78e74201d19770 41
15. DTChrome.exe 6a79268ced5f8545e0205077b39b4489 34
16. RelatedLinksBHO.dll 2993d192b9d115e4b715836ea576b59f 33
17. idqbe32.dll 585a980f6bb1718fa43217f762b203a2 31
18. pguweoyd.dll 3be6a04df5b29814ada7f030cbcddcd2 21
19. DefaultTabSetup.exe ac04843865032d4d1a258ed1774de8cb 19
20. A0119762.exe e2610dc22de4b215f7a84d4be7e11589 18
21. xgzjtimx.dll 0465119fd5c2d6086bca2787f13ffe9e 12
22. rrfbdzio.dll 7c265b2c21fcdc986b5329ad069055d5 10
23. DefaultTab.crx 0fdecf833d96310b1b5650de60a8d97c 9
24. DTUpdate.exe 911e4382189b121c459325f05ed9218c 9
25. DatamngrCoordinator.exe c3c8797e5ee2ed85e0dba33b8a891ba1 5
26. R001.exe 744e70443bdf26713cfa1d24e32aca92 4
27. R002.exe 644b1ec961307113ce2d9a39e02d66f7 4
28. addon@defaulttab.com.xpi ae04d944084bd34f9ab112297a9d8ce6 0
More files

Registry Details

DefaultTab-Search Results may create the following registry entry or registry entries:
CLSID
{1F8EDE97-36D5-422A-B8F0-9406E2D87C60}
{38495740-0035-4471-851E-F5BBB86AB085}
{72D89EBF-0C5D-4190-91FD-398E45F1D007}
{7F6AFBF1-E065-4627-A2FD-810366367D01}
{A1E28287-1A31-4b0f-8D05-AA8C465D3C5A}
{BE89FFB3-7F9C-4A16-B475-98B195A06628}
{FEB62B15-CC00-4736-AAEC-BA046C9DFF73}
Regexp file mask
%PUBLIC%\Util\DTChk.exe
%Temp%\DefaultTabSetup[RANDOM CHARACTERS].exe
Software\AppDataLow\Software\DefaultTab
SOFTWARE\Classes\AppID\DefaultTabBHO.DLL
SOFTWARE\Classes\DefaultTabBHO.DefaultTabBrowser
SOFTWARE\Classes\DefaultTabBHO.DefaultTabBrowser.1
SOFTWARE\Classes\DefaultTabBHO.DefaultTabBrowserActiveX
SOFTWARE\Classes\DefaultTabBHO.DefaultTabBrowserActiveX.1
SOFTWARE\Classes\Wow6432Node\AppID\DefaultTabBHO.DLL
Software\Default Tab
SOFTWARE\Google\Chrome\NativeMessagingHosts\default_tab_host
Software\Microsoft\Internet Explorer\Approved Extensions\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration{7F6AFBF1-E065-4627-A2FD-810366367D01}
Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration{A1E28287-1A31-4B0F-8D05-AA8C465D3C5A}
Software\Microsoft\Internet Explorer\Protect Approved Extensions\{7F6AFBF1-E065-4627-A2FD-810366367D01}
SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Default2Check
SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\DefaultCheck
SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\DefaultReg
Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F6AFBF1-E065-4627-A2FD-810366367D01}
SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A1E28287-1A31-4B0F-8D05-AA8C465D3C5A}
Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{A1E28287-1A31-4B0F-8D05-AA8C465D3C5A}
SOFTWARE\Wow6432Node\Classes\AppID\DefaultTabBHO.DLL
SOFTWARE\Wow6432Node\Default Tab
SOFTWARE\Wow6432Node\DefaultTab
SOFTWARE\Wow6432Node\Google\Chrome\NativeMessagingHosts\default_tab_host
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2D33ED6-EBBD-467C-BF6F-F175D9B51363}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BAD84EE2-624D-4e7c-A8BB-41EFD720FD77}
SOFTWARE\Wow6432Node\Microsoft\Tracing\DefaultTabSearch_RASAPI32
SOFTWARE\Wow6432Node\Microsoft\Tracing\DefaultTabSearch_RASMANCS
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7F6AFBF1-E065-4627-A2FD-810366367D01}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A1E28287-1A31-4B0F-8D05-AA8C465D3C5A}
SYSTEM\ControlSet001\services\DefaultTabSearch
SYSTEM\ControlSet001\services\DefaultTabUpdate
SYSTEM\ControlSet002\services\DefaultTabSearch
SYSTEM\ControlSet002\services\DefaultTabUpdate
SYSTEM\CurrentControlSet\services\DefaultTabSearch
SYSTEM\CurrentControlSet\services\DefaultTabUpdate

Directories

DefaultTab-Search Results may create the following directory or directories:

%APPDATA%\DefaultTab
%PROGRAMFILES%\DefaultTab
%PROGRAMFILES(x86)%\DefaultTab
%TMP%\installdt.tmp
%WINDIR%\system32\config\systemprofile\AppData\Roaming\defaulttab

URLs

DefaultTab-Search Results may call the following URLs:

https://www.mysearchresults.com/search?

Trending

Most Viewed

Loading...