extractnow.exe

ExtractNow

Nathan Moinvaziri

This file is installed with the program ExtractNow.
Publisher:
Nathan Moinvaziri  (signed and verified)

Product:
ExtractNow

Version:
4,7,2,0

MD5:
fe2702f1983c3cbb644f223c46b38807

SHA-1:
237bad796f130b44a7848c941b25049e1e34e249

SHA-256:
68b9f3bd7f39224f9aaafbda913987610c13ca14eb8a9713a60a49befcb9d04e

Scanner detections:
9 / 68

Status:
Clean  (9 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/24/2024 8:09:52 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Toolbar.Babylon
7.1.1

Dr.Web
Adware.Babylon.15
9.0.1.041

ESET NOD32
Win32/Toolbar.Babylon (variant)
9.10636

Malwarebytes
v2015.02.10.06

McAfee
Artemis!CB1EA741201D
5600.6859

NANO AntiVirus
Riskware.Win32.Babylon.dagvqp
0.28.6.62995

Quick Heal
(Suspicious) - DNAScan
2.15.12.00

Trend Micro House Call
HV_ZYX_.65EA3D67
7.2.41

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.24.3

File size:
329.4 KB (337,304 bytes)

Product version:
4,7,2,0

Copyright:
Copyright (C) Nathan Moinvaziri 2012

Original file name:
extractnow.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\extractnow\extractnow.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
1/29/2012 1:00:00 AM

Valid to:
1/29/2013 12:59:59 AM

Subject:
CN=Nathan Moinvaziri, OU=Individual Developer, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=No Organization Affiliation, L=Phoenix, S=Arizona, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2635C1001419277F2FF117789D4E891B

File PE Metadata
Compilation timestamp:
8/27/2012 3:50:36 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:PKoKn1sRLpvpcqAmNkz0NfI6ynBVy1VE8BRnn1ZK+QidPHlVzEoS1P:CkRLpWqBNlNgtBeV9z1ZlQid/lSoS5

Entry address:
0x14C050

Entry point:
60, BE, 00, 60, 50, 00, 8D, BE, 00, B0, EF, FF, 57, 89, E5, 8D, 9C, 24, 80, C1, FF, FF, 31, C0, 50, 39, DC, 75, FB, 46, 46, 53, 68, 8D, A9, 14, 00, 57, 83, C3, 04, 53, 68, 3F, 60, 04, 00, 56, 83, C3, 04, 53, 50, C7, 03, 03, 00, 02, 00, 90, 90, 90, 90, 90, 55, 57, 56, 53, 83, EC, 7C, 8B, 94, 24, 90, 00, 00, 00, C7, 44, 24, 74, 00, 00, 00, 00, C6, 44, 24, 73, 00, 8B, AC, 24, 9C, 00, 00, 00, 8D, 42, 04, 89, 44, 24, 78, B8, 01, 00, 00, 00, 0F, B6, 4A, 02, 89, C3, D3, E3, 89, D9, 49, 89, 4C, 24, 6C, 0F, B6, 4A...
 
[+]

Code size:
284 KB (290,816 bytes)

The file extractnow.exe has been discovered within the following program.

ExtractNow  by Nathan Moinvaziri
Some versions use the OpenCandy software library to bundle potentially unwanted software offers during installation.
www.extractnow.com
28% remove it
 
Powered by Should I Remove It?

Scan extractnow.exe - Powered by Reason Core Security