dffsetup-d3dx9_39.exe

Dll-Files Fixer

Dll-Files.com

The application dffsetup-d3dx9_39.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from download.dll-files.com.
Publisher:
Dll-Files.com

Product:
Dll-Files Fixer

Version:
Dll-Files Fixer

MD5:
1cbafaa0b5528baeeac53d8d6dde823c

SHA-1:
56a6fb244646ac69619516d5f14b802167052cb0

SHA-256:
18b07ad49094848c67c36448a7e9e7e036e222760965ddcee33a6752a7f41140

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 9:47:32 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.DllFiles.Optional.Installer.Meta (L)
16.1.21.6

File size:
5.2 MB (5,473,352 bytes)

Product version:
3.2.90

Copyright:
© Dll-Files.com

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\dffsetup-d3dx9_39.exe

File PE Metadata
Compilation timestamp:
7/9/2014 2:58:13 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:FZk549KKdbLjR/tFDPXHRTW0xEVWGscb2JjyGbwiVBzTCdVxMO6FEt1O7O:4QKKdLRFFDP3l8VdscbsgiVNTgVxT6hO

Entry address:
0x113BC

Entry point:
EB, 03, 80, F9, DE, 42, 0F, AF, CF, 3B, ED, 75, 02, 87, F7, 42, 0F, C8, E8, 06, 00, 00, 00, 0F, CD, 8A, FE, 3B, FD, 20, F2, 81, FD, 21, 4C, 00, 00, 74, 0C, 81, E8, 02, 85, 81, 98, FE, C4, F6, DC, 84, E8, 69, F2, E8, 8C, E2, D1, 2A, C5, 0F, CF, 51, 76, 02, F7, D6, 5E, 69, F8, 32, 70, B5, D4, F6, C0, A3, 8D, 1E, 0F, AF, F5, 81, FB, 0B, 76, 00, 00, 72, 06, 69, C3, BE, 41, 56, 25, 84, CD, F6, C3, C3, 8D, 2D, B5, 0F, 00, 00, BA, E1, FF, E2, 9E, 81, F5, B5, 0F, 00, 00, F7, C1, E1, B0, F6, E1, 33, EB, 81, FA, F9...
 
[+]

Entropy:
7.8746  (probably packed)

Code size:
63.5 KB (65,024 bytes)

The file dffsetup-d3dx9_39.exe has been seen being distributed by the following URL.

Remove dffsetup-d3dx9_39.exe - Powered by Reason Core Security