customizablesetup.exe

Toolbar Powered by Inbox

Xacti

The application customizablesetup.exe, “Toolbar Powered by Inbox Setup ” by Xacti has been detected as a potentially unwanted program by 20 anti-malware scanners. The program is a setup application that uses the Inno Setup installer. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. The file has been seen being downloaded from www2.inbox.com.
Publisher:
Xacti, LLC   (signed by Xacti)

Product:
Toolbar Powered by Inbox

Description:
Toolbar Powered by Inbox Setup

Version:
2.0.1.135

MD5:
48d32fe08aceb4d1aaa21bf19077d3f6

SHA-1:
a13172391d169b2d955a49b5f97d072850efc067

SHA-256:
9011ca3ab8fd04d7e1f97ab5d7efb783d391c0f1feaab5c72cc42ad59e1e35c3

Scanner detections:
20 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 2:36:15 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Toolbar.Inbox.B
354

Avira AntiVirus
TR/Rogue.2959928
7.11.192.162

Bitdefender
Trojan.Generic.11869740
1.0.20.230

Bkav FE
W32.HfsAdware
1.3.0.6379

Clam AntiVirus
Win.Adware.PCFixSpeed
0.98/19586

Comodo Security
Application.Win32.Inbox.E
19152

Dr.Web
Adware.Downware.9458
9.0.1.046

Emsisoft Anti-Malware
Adware.Toolbar.Inbox
8.16.02.15.04

ESET NOD32
Win32/Toolbar.Crawler.B potentially unwanted application
10.7.0.302.0

F-Secure
Riskware.Dropped:Application.Bundler.Outbrowse
11.2016-15-02_2

G Data
Win32.Application.ToolbarCrawler
16.2.25

IKARUS anti.virus
PUA.Toolbar
t3scan.1.6.1.0

K7 AntiVirus
Unwanted-Program
13.183.13417

Malwarebytes
PUP.Optional.ToolBarInstaller
v2016.02.15.04

MicroWorld eScan
Trojan.Generic.11869740
17.0.0.138

NANO AntiVirus
Riskware.Win32.Toolbar.dqlgsf
0.30.24.1357

Norman
Adware.Toolbar.Inbox.B
11.20160215

nProtect
Adware.Toolbar.Inbox.B
14.11.04.01

Reason Heuristics
Win32.Generic
16.2.15.16

VIPRE Antivirus
Threat.4150696
32210

File size:
3.2 MB (3,366,896 bytes)

Product version:
2.0.1.135

Copyright:
copyright © Inbox.com

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\customizablesetup.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
8/29/2013 7:00:00 AM

Valid to:
9/19/2015 6:59:59 AM

Subject:
CN=Xacti, O=Xacti, L=Boca Raton, S=Florida, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
723180E2A807DDA0F77264108931DA53

File PE Metadata
Compilation timestamp:
6/20/1992 5:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:unJInGnteTbY5M1LNBQu/1pOG9MFGebSivZnh:qaJBxWRce2U7

Entry address:
0xC1C0

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, C8, C0, 40, 00, E8, 60, 86, FF, FF, 33, C0, 55, 68, 85, C8, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 41, C8, 40, 00, 64, FF, 32, 64, 89, 22, A1, 60, E6, 40, 00, E8, 5E, FD, FF, FF, E8, C9, F8, FF, FF, 8D, 55, EC, 33, C0, E8, 93, CA, FF, FF, 8B, 55, EC, B8, 8C, F0, 40, 00, E8, 0A, 77, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 8C, F0, 40, 00, B2, 01...
 
[+]

Entropy:
7.9965

Developed / compiled with:
Microsoft Visual C++

Code size:
46.5 KB (47,616 bytes)

The file customizablesetup.exe has been seen being distributed by the following URL.

Remove customizablesetup.exe - Powered by Reason Core Security