dfo_setup_xls_.exe

Download File Opener

MS Technology Inc.

The application dfo_setup_xls_.exe by MS Technology has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
DownloadFileOpener.com  (signed by MS Technology Inc.)

Product:
Download File Opener

Version:
3.26.3.100

MD5:
0744fd00ffe58e1d036b5f430e08c860

SHA-1:
29cd1694f6cb497fa47ba276c89f316d4a71925c

SHA-256:
f8b0806b95ec562d7529387742fd1f3fc6f359a8366b14649393675148b8ee60

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
8/12/2025 8:37:52 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.DownloadFileOpener (M)
16.10.24.13

File size:
1.5 MB (1,551,880 bytes)

Product version:
3.26.3.100

Copyright:
(c) DownloadFileOpener.com All rights reserved.

Original file name:
downloadfileopener.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\dfo_setup_xls_.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
12/22/2014 1:00:00 AM

Valid to:
12/22/2016 12:59:59 AM

Subject:
CN=MS Technology Inc., O=MS Technology Inc., STREET=4262 Richfield Terr, L=Victoria, S=BC, PostalCode=V8X 4V3, C=CA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
5BB294E57C9EC3985FB70CFFD8D583C2

File PE Metadata
Compilation timestamp:
6/24/2015 2:34:09 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:dM4LwZv6xX/u3UkGMjAiUoubppByBlFZE9+8:dMzv0X/wGNBTpyzFmX

Entry address:
0x4323C

Entry point:
50, 81, C4, FC, FF, FF, FF, 89, 0C, 24, 52, 81, EC, 04, 00, 00, 00, 89, 1C, 24, 81, EC, 04, 00, 00, 00, 89, 24, 24, 81, EC, 04, 00, 00, 00, 89, 2C, 24, 56, 81, EC, 04, 00, 00, 00, 89, 3C, 24, 81, EC, 04, 00, 00, 00, 89, 2C, 24, 89, E5, 81, C4, E0, FF, FF, FF, E8, 63, DE, FB, FF, C7, 85, FC, FF, FF, FF, F2, C4, F1, 00, 89, 85, F4, FF, FF, FF, 8B, 8D, F4, FF, FF, FF, BB, 00, 00, 00, 00, 81, C1, 60, 97, 0F, 00, 81, EC, 04, 00, 00, 00, 8B, 95, FC, FF, FF, FF, C7, 04, 24, 24, B2, 00, 00, 58, 33, 19, 81, C0, FC...
 
[+]

Code size:
340 KB (348,160 bytes)

Remove dfo_setup_xls_.exe - Powered by Reason Core Security