mapssetup.exe

Maps Toolbar Powered by Inbox

Xacti

The application mapssetup.exe, “Maps Toolbar Powered by Inbox Setup ” by Xacti has been detected as a potentially unwanted program by 18 anti-malware scanners. The program is a setup application that uses the Inno Setup installer. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent.
Publisher:
Xacti, LLC   (signed by Xacti)

Product:
Maps Toolbar Powered by Inbox

Description:
Maps Toolbar Powered by Inbox Setup

Version:
2.0.1.110

MD5:
d4468c17424b9d1ddced7da01d59b244

SHA-1:
1d933add81614156d353dcb314e99c03f24fcbcc

SHA-256:
957a1c8839b91179bbc667e34cea3eee911a5877994b325dd24b265ccdf56f63

Scanner detections:
18 / 68

Status:
Potentially unwanted

Analysis date:
4/24/2024 3:47:00 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.Toolbar
2015.04.25

Avira AntiVirus
TR/Dropper.Gen
7.11.30.172

Baidu Antivirus
PUA.Win32.Crawler
4.0.3.16215

Bkav FE
W32.HfsAdware
1.3.0.6379

Clam AntiVirus
Win.Adware.PCFixSpeed
0.98/21411

Comodo Security
Application.Win32.Inbox.E
19589

Dr.Web
Adware.Downware.9458
9.0.1.046

ESET NOD32
Win32/Toolbar.Crawler.B potentially unwanted application
10.7.0.302.0

F-Secure
Riskware.Application.Bundler.SoftPulse
11.2016-15-02_2

G Data
Win32.Application.ToolbarCrawler
16.2.25

IKARUS anti.virus
PUA.Toolbar
t3scan.1.6.1.0

K7 AntiVirus
Unwanted-Program
13.183.13451

Malwarebytes
PUP.Optional.ToolBarInstaller
v2016.02.15.07

McAfee
Artemis!18B57715C148
5600.6488

NANO AntiVirus
Riskware.Win32.Toolbar.dqlgsc
0.30.20.1219

Reason Heuristics
Win32.Generic
16.2.15.19

Sophos
Generic PUA BM
4.98

VIPRE Antivirus
Threat.4150696
32210

File size:
2.3 MB (2,453,248 bytes)

Product version:
2.0.1.110

Copyright:
copyright © Inbox.com

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Common path:
C:\users\{user}\downloads\mapssetup.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
8/29/2013 2:00:00 AM

Valid to:
9/19/2015 1:59:59 AM

Subject:
CN=Xacti, O=Xacti, L=Boca Raton, S=Florida, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
723180E2A807DDA0F77264108931DA53

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:HEmlxJuogE6iuhpsM4ec+qq9jA9PDn3+hb+uWc3U4R/VS1ebA5rOYiZnk:Hn1giepsMV/jwShb+43UsVUebSivZnk

Entry address:
0xC1C0

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, C8, C0, 40, 00, E8, 60, 86, FF, FF, 33, C0, 55, 68, 85, C8, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 41, C8, 40, 00, 64, FF, 32, 64, 89, 22, A1, 60, E6, 40, 00, E8, 5E, FD, FF, FF, E8, C9, F8, FF, FF, 8D, 55, EC, 33, C0, E8, 93, CA, FF, FF, 8B, 55, EC, B8, 8C, F0, 40, 00, E8, 0A, 77, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 8C, F0, 40, 00, B2, 01...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
46.5 KB (47,616 bytes)

Remove mapssetup.exe - Powered by Reason Core Security