{120b6-74f56c-74f96c}

Excite Find Distant 2008

Excite Find Inc.

The file {120b6-74f56c-74f96c}, “Excite Find Distant” has been detected as a potentially unwanted program by 27 anti-malware scanners.
Publisher:
Excite Find Inc.

Product:
Excite Find® Distant® 2008

Description:
Excite Find Distant

Version:
5.7.83203.3 built by: Three

MD5:
35caf645d5d79755a53bb17787d5000c

SHA-1:
9072ffbc4a8a5471af8c7504faf30bf2cd1fcda0

SHA-256:
975177a0617d44988d1f612cd852524515fce4d15a478aa20c52a3c231fb8ca3

Scanner detections:
27 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 8:19:06 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Symmi.25645
618

Agnitum Outpost
Trojan.Bublik
7.1.1

AhnLab V3 Security
Trojan/Win32.Bublik
2015.05.07

avast!
Win32:Trojan-gen
2014.9-150527

AVG
Win32/Cryptor
2016.0.3096

Baidu Antivirus
Adware.Win32.iBryte
4.0.3.15527

Bitdefender
Gen:Variant.Symmi.25645
1.0.20.735

Comodo Security
UnclassifiedMalware
22028

Emsisoft Anti-Malware
Gen:Variant.Symmi.25645
8.15.05.27.11

ESET NOD32
Win32/Kryptik.BFWS (variant)
9.11590

Fortinet FortiGate
W32/KRYPTIK.PDA!tr
5/27/2015

F-Secure
Gen:Variant.Symmi.25645
11.2015-27-05_4

G Data
Gen:Variant.Symmi.25645
15.5.25

IKARUS anti.virus
Virus.Win32.Cryptor
t3scan.1.8.9.0

K7 AntiVirus
Trojan
13.203.15832

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.1975

McAfee
PWSZbot-FDL!35CAF645D5D7
5600.6752

Microsoft Security Essentials
TrojanSpy:Win32/Shiotob.A
1.1.11602.0

MicroWorld eScan
Gen:Variant.Symmi.25645
16.0.0.441

NANO AntiVirus
Trojan.Win32.Bublik.cjtoud
0.30.24.1357

Norman
Troj_Generic.MYBNZ
11.20150527

Panda Antivirus
Trj/CI.A
15.05.27.11

Qihoo 360 Security
Win32/Trojan.619
1.0.0.1015

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
TROJ_SPNR.11GT13
7.2.147

Trend Micro
TROJ_SPNR.11GT13
10.465.27

VIPRE Antivirus
Trojan.Win32.Generic
40024

File size:
251 KB (257,024 bytes)

Product version:
5.7.83203.3

Copyright:
© 2002 Excite Find Inc. All rights reserved.

Original file name:
Did.exe

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{120b6-74f56c-74f96c}

File PE Metadata
Compilation timestamp:
7/15/2013 6:11:22 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
3072:K+8MZLezsM518NFUSNdQQ61998QL1uxZjfin8vQkvy2ZZNdOr:K+8oaQq18NiQdh6N8uuHjfinYdZZs

Entry address:
0x49A0

Entry point:
6A, 60, 68, 00, D5, 42, 00, E8, 3C, 05, 00, 00, BF, 94, 00, 00, 00, 8B, C7, E8, A8, 29, 00, 00, 89, 65, E8, 8B, F4, 89, 3E, 56, FF, 15, 74, E4, 44, 00, 8B, 4E, 10, 89, 0D, 94, C3, 44, 00, 8B, 46, 04, A3, A0, C3, 44, 00, 8B, 56, 08, 89, 15, A4, C3, 44, 00, 8B, 76, 0C, 81, E6, FF, 7F, 00, 00, 89, 35, 98, C3, 44, 00, 83, F9, 02, 74, 0C, 81, CE, 00, 80, 00, 00, 89, 35, 98, C3, 44, 00, C1, E0, 08, 03, C2, A3, 9C, C3, 44, 00, 33, F6, 56, 8B, 3D, 6C, E4, 44, 00, FF, D7, 66, 81, 38, 4D, 5A, 75, 1F, 8B, 48, 3C, 03...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v7.0

Code size:
83.5 KB (85,504 bytes)

Remove {120b6-74f56c-74f96c} - Powered by Reason Core Security