TabNav

TabNav

Known Generic

by FlowSurf Apps

What is TabNav?

TabNav is software application developed by FlowSurf Apps. It is most commonly found on computers running Windows 7 with nearly 52.00% of installations running this operating system. TabNav's installer is typically 12.00 MB in size and installs around 32 files. The most common release is 3.0.0.4 with 46.00% of all installations currently using this version.

TabNav is most popular in United Kingdom with 20.37% of installations residing in this country.

Multiple virus scanners have detected malware in TabNav.

setupfs_1123.exe (MD5: 369c15bae2ca70bc466fc2a53760fb1a) has been flagged by 28 scanners:
Scanner Software Result
Antiy-AVL Trojan/Win32.SGeneric
avast! Win32:Malware-gen
AVG Generic6
Avira TR/Agent.5442433
AVware Trojan.Win32.Generic!BT
Baidu-International Trojan.NSIS.Adload.AK
Comodo Security ApplicUnwnt
Cyren W32/Trojan.PRUI-3556
Dr.Web Trojan.KillFiles.23205
ESET-NOD32 a variant of Win32/Komodia.A potentially unsafe
IKARUS anti.virus PUA.FlowSurf
K7 AntiVirus Unwanted-Program
K7GW Unwanted-Program ( 004b89781 )
Kaspersky UDS:DangerousObject.Multi.Generic
McAfee Artemis!369C15BAE2CA
McAfee-GW-Edition BehavesLike.Win32.Downloader.tc
NANO AntiVirus Trojan.Win32.KillFiles.dobcbg
Norman Troj_Generic.YLGRY
Qihoo-360 HEUR/QVM42.0.Malware.Gen
Symantec Trojan.Gen
Trend Micro TROJ_GEN.R00UC0OBD15
TrendMicro-HouseCall TROJ_GEN.R00UC0OBD15
VIPRE Antivirus Trojan.Win32.Generic!BT
Bkav FE W32.Clod662.Trojan.1e8e
Rising Antivirus PE:Trojan.Win32.Generic.18D0C1A5!416334245
Agnitum Outpost Riskware.Agent!
Malwarebytes PUP.Optional.Winsock.HijackBoot.A
Total Defense Heur/TrojanHorse.ZCIC!suspicious
abengine.exe (MD5: 50a84b3af5137c7eb5ef0b041865a2fc) has been flagged by 13 scanners:
Scanner Software Result
Agnitum Outpost Riskware.Agent!
Avira ADWARE/Komodia.1332576
AVware Trojan.Win32.Generic!BT
Baidu-International Hacktool.Win32.Komodia.A
ESET-NOD32 a variant of Win32/Komodia.A potentially unsafe
K7 AntiVirus Unwanted-Program ( 004b89781 )
K7GW Unwanted-Program ( 004b89781 )
Malwarebytes PUP.Optional.Winsock.HijackBoot.A
McAfee Artemis!50A84B3AF513
McAfee-GW-Edition Artemis
Symantec Trojan.Gen.2
Total Defense Heur/TrojanHorse.ZCIC!suspicious
VIPRE Antivirus Trojan.Win32.Generic!BT
zufap3002.exe (MD5: 2d30d06469ad27a869d63ecc1d4276f1) has been flagged by 20 scanners:
Scanner Software Result
avast! NSIS:Adware-TD [Adw]
AVware Trojan.Win32.Generic!BT
Baidu-International Adware.Win32.Agent.Elnx
Bkav FE W32.Clod662.Trojan.1e8e
Dr.Web Trojan.DownLoader13.49633
ESET-NOD32 NSIS/TrojanDownloader.Adload.AK
K7 AntiVirus Riskware ( 0040eff71 )
K7GW Riskware ( 0040eff71 )
Kaspersky UDS:DangerousObject.Multi.Generic
McAfee Artemis!2D30D06469AD
McAfee-GW-Edition BehavesLike.Win32.BadFile.qc
NANO AntiVirus Trojan.Nsis.Downloader.duuajo
Qihoo-360 HEUR/QVM42.0.Malware.Gen
Rising Antivirus PE:Trojan.Win32.Generic.18D0C1A5!416334245
Symantec Trojan.Gen.2
VIPRE Antivirus Trojan.Win32.Generic!BT
Agnitum Outpost Riskware.Agent!
Avira ADWARE/Komodia.1332576
Malwarebytes PUP.Optional.Winsock.HijackBoot.A
Total Defense Heur/TrojanHorse.ZCIC!suspicious

Software Behaviors

Services:
  • isj.exe runs as a service named 'Injector Service' (InjectorService) "Injector Service".
  • abengine.exe runs as a service named 'abengine' (abengine) "AbEngine protects your browser".

Startup Entries

Startup tasks:
  • zufap3002.exe is automatically launched at startup through a scheduled task named zufap3002.

Software Details

URL:
https://www.flowsurf.net
Support:
Installation path:
C:\Program Files\tabnav
Uninstaller:
C:\Program Files\TabNav\uninstall.exe
Size:
12.00 MB
Language:
English

TabNav Executable Details

Primary executable:
setupfs_1123.exe
Name:
TabNav
Path:
C:\Program Files\tabnav\setupfs_1123.exe
MD5:
369c15bae2ca70bc466fc2a53760fb1a
SHA-1:
SHA-256:
Files installed by TabNav
File Type Filename MD5
EXE
50a84b3af5137c7eb5ef0b041865a2fc
EXE
19c6af184335f3a00af90e735fd1c965
EXE
a0ef183228acd6ed4b118a59425daded
EXE
2d30d06469ad27a869d63ecc1d4276f1
EXE
0e59eec79047565e420dc532208dbee6
EXE
ee8fa398ec1e6b5245feb1ef35a4e673
EXE
d519e59351f68ba91dc4eb33d224bd92
EXE
5c0d9ffa9814d4c195b507c0e37c6b81
EXE
46e544287bcc982fdca27c1baaef3a16
EXE
79d1e1a8121a09aec8a3aae6149a26ed