InbToolN.EXE

InbToolN

nbiz Ltd.

The application InbToolN.EXE by nbiz has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘InbToolN’. This file is typically installed with the program InbToolN by NBIZ.
Publisher:
NBIZ Corp.  (signed by nbiz Ltd.)

Product:
InbToolN

Version:
1, 0, 0, 1

MD5:
9de8a914dba23b0bbfa970fed9e9ba63

SHA-1:
6b4a0e809a339996e9d005fbfaa7c31c589ca6f2

SHA-256:
d5df70094f40dc525326b3b540a2be09d7ac04df015c985741c91868c8762607

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/26/2024 6:16:30 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.1.10.5

File size:
63 KB (64,560 bytes)

Product version:
1, 0, 0, 1

Copyright:
(c) NBIZ. All rights reserved.

Original file name:
InbToolN.EXE

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\inbtooln\inbtooln.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
2/25/2013 9:00:00 AM

Valid to:
4/27/2015 8:59:59 AM

Subject:
CN=nbiz Ltd., O=nbiz Ltd., L=Gangnam-gu, S=Seoul, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
4169B218A122412E6D5CC3230C1EC9C2

File PE Metadata
Compilation timestamp:
4/25/2014 11:14:13 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x22920

Entry point:
60, BE, 00, 70, 41, 00, 8D, BE, 00, A0, FE, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, EF, 75, 09, 8B, 1E, 83, EE, FC, 11, DB, 73, E4, 31, C9, 83, E8, 03, 72, 0D, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 74, 89, C5, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, 75, 20, 41, 01, DB, 75...
 
[+]

Entropy:
7.7757

Packer / compiler:
UPX 2.90LZMA

Code size:
48 KB (49,152 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
InbToolN

Command:
C:\Program Files\inbtooln\inbtooln.exe


The file InbToolN.EXE has been discovered within the following program.

InbToolN  by NBIZ
About 8% of users remove it
 
Powered by Should I Remove It?

Remove InbToolN.EXE - Powered by Reason Core Security