Threat Scorecard

Ranking: 1,633
Threat Level: 10 % (Normal)
Infected Computers: 319,110
First Seen: January 24, 2014
Last Seen: July 16, 2024
OS(es) Affected: Windows

SupTab is a suspicious application, involved in various adware activities. HpUI.exe is the main executable file running the SupTab program. The developers of SupTab advertise it as a tool that will improve your browsing experience. In fact, this is a Potentially Unwanted Program that may not be as a valuable addition to your system as its authors claim. One of the first symptoms that should make you doubt the legitimacy of this program is that HpUI.exe probably just "appeared’ on your system. The applications run by this executable file, may become annoying to you by consistently showing advertisements to sponsored websites. Although at first sight this program doesn't seem to be very threatening, it is the additional programs, coming along SupTab that pose a greater risk.

How is SupTab Distributed?

SupTab has an official Web page but rarely do users download the program from there. It usually installs into their system in the form of a bundle. This is a very common distribution method for Potentially Unwanted Programs. There are many paid computer programs over the Internet, but sometimes people decide to avoid paying and download a free software. Usually, these freeware programs are not only less efficient than their paid rivals, but come along with some additional applications. As a typical Potentially Unwanted Program, SupTab may use certain ways of distribution, such as rogue Flash or Java update pages or fake video codecs, ‘required’ to watch videos online.
If you cannot recall intentionally installing the SupTab, most likely it relied on one of these methods.

What Makes SupTab a Potentially Unwanted Program?

HpUI.exe is the driving file for SupTab (also known as Lightning new tab) or Search Protect. These applications are promoted on many websites as helpful extensions for Internet Explorer, which means that at the moment they are not applicable to other Web browsers such as Google Chrome or Mozilla Firefox. They may be known by other names as well but eventually it is the same program. In case you can find HpUI.exe on your system, but there is no sign of SupTab, Lightning new tab or Search Protect, you certainly have another program, related to them.

HpUI.exe and SupTab are not classified as threatening. They may have annoying results, but the consequences from them will not be devastating to the system. Any program you have on your computer uses the system resources, so you may find your PC slower than usual, and there are even reports of system crashes. However, the real problem is that they often come bundled with other programs that may turn out to be harmful. One of these additional programs is a browser hijacker that often leads to which should always be taken seriously. Awesomehp browser hijacker may collect browsing information, redirect you to suspicious sites and slow down your browsing speed. Your homepage may be modified. will certainly use different methods to avoid detecting and removing. This browser hijacker may add an extension with the name IETabPage Class, which in turn will be very difficult to remove because the Internet Explorer settings are already modified.

Another threat that may appear as a result of HpUI.exe is the browser hijacker. It is operated by a Chinese company and promotes all kinds of junkware, in the meantime modifying and slowing your browser. There are several other hijackers, associated with HpUI.exe as well. Considering this, you can look at the process HpUI.exe as a sign of a threat currently present in your system.

What can You do Against HpUI.exe?

To avoid downloading HpUI.exe and installing any of the programs it manages, computer security experts advise to be extremely careful when you search a software over the Internet. Take your time to check the legitimacy of the sites you intend to download from. Always read every page of the installation process to see if there is some additional software along your desired one. If you find any, uncheck it and safely continue the installation process.

If you already have SupTab or HpUI.exe present in your system, it is of crucial importance to remove it as soon as possible. However, you cannot remove HpUI.exe without taking actions against the applications that are run by it - like SupTab and Search Protect. They must all be removed simultaneously and completely. This is why the best option is to use a special anti-malware program that will be capable of quickly and efficiently removing SupTab or HpUI.exe and all files and programs associated with it. Also, when the special anti-malware program performs a full system scan, you will see whether there are other threats. Moreover, you will be safeguarded in the future from other Potentially Unwanted Programs and other threats.


15 security vendors flagged this file as malicious.

Anti-Virus Software Detection
DrWeb Adware.Mutabaha.107
Sophos Generic PUA IJ
McAfee-GW-Edition Artemis
Avast Win32:SupTab-G [Adw]
McAfee Artemis!C30458159AED
Panda Generic Suspicious
Antiy-AVL GrayWare[AdWare:not-a-virus]/Win32.SearchProtect
Symantec WS.Reputation.1
AhnLab-V3 PUP/Win32.SearchProtect
GData Win32.Application.SubTab.E
AVG ZhangLing.AA0
AVG Zhang.59F
AVG Zhang.EF9
AhnLab-V3 Adware/Win32.Agent

File System Details

SupTab may create the following file(s):
# File Name MD5 Detections
1. CmdShell.exe 0de6521016cae929552dd557979e196c 150
2. CmdShell.exe 0959284c7bb4425a85b8ceb45b51c92c 83
3. ProtectService.exe d0a4fd099b7ee90b302be9d1a13a2ebd 72
4. A0074028.exe b76756198468fdc616b3ebafd5268496 64
5. CmdShell.exe 687063ab8200e3206f6209174354fa69 58
6. cmdshell.exe 9da2bcf2842bb444e5dd761286266e2b 31
7. CmdShell.exe 6a129df750b69b6fa3e6c76ec3dcee40 31
8. CmdShell.exe.vir d1574c7af2815098274d3777cfe9657e 25
9. cmdshell.exe 1fd08d79bf5412f2f2aca7cd6b6b6496 17
10. CmdShell.exe.vir 4405aafb968c7ac90fde9488b318588a 14
11. CmdShell.exe.vir d880e2453990a2ff2a22c89fd91a20c3 12
12. cmdshell.exe b32b956c618cf003fcd97c8345e69360 10
13. ProtectService.exe 3cbf283133cf0047fcde8f22dc27f212 5
14. ProtectService.exe af41bb878802ad244c9096e93315554b 4
15. ProtectService.exe 71dfbcb1f387f42ec07c2f605a3e5ef0 4
16. ProtectService.exe 9619e5f1b2981b8f1ad7b78055d348c6 3
17. ProtectService.exe 0c6b72be41e925b639a429e3c6217ec7 3
18. ProtectService.exe 3cd62e517219b78de1554eff7d2e7d05 2
19. ProtectService.exe a67518b300fe8de6a07a379117771d84 2
20. ProtectService.exe 65770bc9f631284927bc4892b3448a0b 2
21. ProtectService.exe 2d7303aebcf74acb327fef72160a857e 2
22. ProtectService.exe 8ae74e868949ff7d9c9de38eda88fc64 2
23. ProtectService.exe 0752f2dd679df0573774aa2105da9ca8 2
24. cmdshell.exe 8882ba96ef0a3597421e664df0806048 1
25. cmdshell.exe f942761b4ceb7054d5e262cb6b0d051e 1
26. HPNotify.exe 1c3a4b9ff103460544c8ae04fabe22b1 1
More files

Registry Details

SupTab may create the following registry entry or registry entries:
Software\Microsoft\Internet Explorer\Approved Extensions\{1F91A9A1-01BA-4C81-863D-3BA0751E1419}
Software\Microsoft\Internet Explorer\Approved Extensions\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Software\Microsoft\Internet Explorer\Approved Extensions\{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F}
SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{1F91A9A1-01BA-4c81-863D-3BA0751E1419}
SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{1F91A9A1-01BA-4c81-863D-3BA0751E1419}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F}


SupTab may create the following directory or directories:

%ALLUSERSPROFILE%\Application Data\IePluginService
%ALLUSERSPROFILE%\Application Data\IePluginServices


