mixiyd.exe

MixiBar

The application mixiyd.exe has been detected as a potentially unwanted program by 17 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. This will display context specific advertisements in the browser as well as attempt to modify the browser's search provider. The file has been seen being downloaded from cdn.file2desktop.com.
Publisher:
MixiBar

Product:
MixiBar

Version:
MixiBar

MD5:
4dcfd1caefcc51e8586ec7ed340625d6

SHA-1:
02c8fd262823f1d56b892921dd81facb692eb2c4

SHA-256:
0a98dfb6af100b59ea5617b959d5f3ac55a60a34b4ecfec3055d08fa7e56dab8

Scanner detections:
17 / 68

Status:
Potentially unwanted

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Analysis date:
4/19/2024 6:41:58 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Toolbar.Babylon
7.1.1

avast!
NSIS:Adware-KR [PUP]
2014.9-140309

Baidu Antivirus
Adware.Win32.Toolbar
4.0.3.1439

Bkav FE
W32.Clodb1e.Trojan
1.3.0.4959

Dr.Web
Adware.Downware.2082
9.0.1.068

ESET NOD32
Win32/OutBrowse
8.9490

Fortinet FortiGate
Riskware/Toolbar
3/9/2014

K7 AntiVirus
Trojan
13.176.11311

Kaspersky
not-a-virus:WebToolbar.Win32.Toolbar
14.0.0.4198

Malwarebytes
v2014.03.09.08

McAfee
Artemis!4DCFD1CAEFCC
5600.7197

NANO AntiVirus
Trojan.Win32.Babylon.cdsyuj
0.28.0.58101

Qihoo 360 Security
Win32/Virus.WebToolbar.0c6
1.0.0.1015

Rising Antivirus
PE:Malware.XPACK/RDM!5.1
23.00.65.14307

Sophos
Generic PUA AC
4.98

Trend Micro House Call
TROJ_GEN.R0CBH07L713
7.2.68

VIPRE Antivirus
Trojan.Win32.Generic
27000

File size:
844.7 KB (864,998 bytes)

Copyright:
© MixiBar

Trademarks:
MixiBar

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\mixiyd.exe

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:+U//rgCDUMXJ+za8bYoChSA3XzbVlyz8b9N+d:XrgCyLbYPhV3DbE4+d

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9786

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file mixiyd.exe has been seen being distributed by the following URL.

Remove mixiyd.exe - Powered by Reason Core Security