GridinSoft Threat Intelligence

Continuum_OFX_Float.dll threat report

Detected as Trojan.Packed File reputation report
MD5 d8c0df5d09b7a2008575a0bf67794ef6
Latest seen 2026-05-23 17:01:02 (4 days ago)
First seen 2023-09-05 23:21:37 (2 years ago)
Size 11 MB
Publisher Boris FX, Inc.
Product Boris FX(tm)

GridinSoft Anti-Malware detection

Detected by GridinSoft before you download

The current ThreatInfo record shows this exact file hash detected as Trojan.Packed. Download GridinSoft Anti-Malware to scan the device, confirm whether this file is present, and remove the detected object if it is found.

Detection name
Trojan.Packed
Recommended action
Scan and remove
Last analysis
2026-05-23 17:01:02 (4 days ago)
File hash
d8c0df5d09b7a2008575a0bf67794ef6
Download Anti-Malware

Why it matters

Why GridinSoft flags this file

Detection

GridinSoft identifies the sample as Trojan.Packed, part of the Trojan threat category.

Category context

Malware disguised as legitimate software or delivered through deceptive packaging. Related Trojan reports help compare this file with nearby detections, publishers, and hashes.

Timeline

First seen 2023-09-05 23:21:37 (2 years ago); latest analysis 2026-05-23 17:01:02 (4 days ago).

Publisher context

Company metadata: Boris FX, Inc.. Product metadata: Boris FX(tm).

Observed locations

ThreatInfo has seen this file in user or system paths listed below. Unexpected locations increase the need for local verification.

Recommended action

What to do next

  1. Compare the MD5 above with the file found on the device.
  2. Check whether the file appears in the observed locations or under one of the alternate names.
  3. Run GridinSoft Anti-Malware to confirm the detection and remove the file if it is present. Review the Trojan category for related samples and common context.

Continuum_OFX_Float.dll is a Windows file recorded in the ThreatInfo database. It is associated with Boris FX(tm). The reported company name is Boris FX, Inc.. The current detection status is Trojan.Packed, based on the latest analysis from 2026-05-23 17:01:02 (4 days ago). ThreatInfo groups this verdict with Trojan reports for broader family-level investigation.

If Continuum_OFX_Float.dll appears on your computer unexpectedly, treat it as suspicious. Check its location, digital signature, and recent system changes before allowing it to run. A full anti-malware scan is recommended when this file is detected as Trojan.Packed.

Product Name: Boris FX(tm)
Company Name: Boris FX, Inc.
MD5: d8c0df5d09b7a2008575a0bf67794ef6
Size: 11 MB
First Published: 2023-09-05 23:21:37 (2 years ago)
Latest Published: 2026-05-23 17:01:02 (4 days ago)
Status: Trojan.Packed (on last analysis)
Analysis Date: 2026-05-23 17:01:02 (4 days ago)
Continuum_OFX_Float.dll detection screenshot

The screenshot is a visual record of a GridinSoft Anti-Malware detection for this sample. Use the hash and metadata above as the primary identifiers when comparing the file on your system.

%programfiles%\borisfx\continuumofx\15
%sysdrive%\new folder\new folder (2)\wondershare_filmora_11.7.3.814\crack
%localappdata%\wondershare\wondershare filmora
%programfiles%
%sysdrive%\$recycle.bin\s-1-5-21-393099566-2242912797-3845494103-1001
%sysdrive%\util\util2020\wondershare filmora v11.7.3.814 x64\crack
%sysdrive%\school related\o t h e r\new folder\wondershare_filmora_11.7.3.814\crack

ThreatInfo has observed Continuum_OFX_Float.dll in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

Windows 10 100.0%

The most common operating system signal for Continuum_OFX_Float.dll is Windows 10 with 100.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

Continuum_OFX_Float.dll is identified as pe for 64-bit systems. The subsystem is Windows GUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Format pe
Architecture 64-bit
Subsystem Windows GUI
Entry point 0x02117160
Image base 0x0000000180000000

PE Sections:

Sections 14
Raw data 11555491

Section layout highlights raw-size concentration, repeated names, packer markers, and hashes that can be compared across related samples.

5586123 bytes · 48.3% of section data
Large raw data Uncommon name
MD5 84aed23f597f9c5ed8f45156621cbfd1
734437 bytes · 6.4% of section data
Uncommon name
MD5 9f947191a094a5b440bc4ad43a61c5c9
177735 bytes · 1.5% of section data
Uncommon name
MD5 bded1c57a09196e131e654f30788ea2c
259556 bytes · 2.2% of section data
Uncommon name
MD5 f8b2cb6a014f412d7c2fdec9b822bfa0
48593 bytes · 0.4% of section data
Uncommon name
MD5 eaa7fa811c12066e23bbd4ddbb2fa90a
18496 bytes · 0.2% of section data
Uncommon name
MD5 9cc6d70eded223da24b3be04f1953057
18087 bytes · 0.2% of section data
Uncommon name
MD5 ba15004ba0645f9c4fdc04b28323d14c
.exports 1536 bytes · 0.0% of section data
Uncommon name
MD5 7566c22046bb29edb3b0962c06aef83d
.imports 2560 bytes · 0.0% of section data
Uncommon name
MD5 146005d6936e0ef3887482620cb8d0fa
.tls 512 bytes · 0.0% of section data
MD5 f9d4159c742f5c9e87b61a9920b48941
.rsrc 3072 bytes · 0.0% of section data
MD5 ba8a0d61125c2cf8495ec5eca8d6db27
.themida 0 bytes · 0.0% of section data
Uncommon name
MD5 d41d8cd98f00b204e9800998ecf8427e
.boot 4704768 bytes · 40.7% of section data
Uncommon name
MD5 3634f1bf66f622a0adc453f2d17b3bc4
.reloc 16 bytes · 0.0% of section data
MD5 98f409e134ea3b6087948eb444e32ae2

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

Report conclusion

GridinSoft detects this file as Trojan.Packed

This report identifies Continuum_OFX_Float.dll by MD5 d8c0df5d09b7a2008575a0bf67794ef6. It is part of the Trojan report group. If the same file is present on your device, scan the system and remove the detected object after confirming the hash and location.

Download GridinSoft Anti-Malware Scan the device and confirm whether this exact hash is present. Check this hash on VirusTotal

Recommended next steps

  • Compare the local file MD5 with d8c0df5d09b7a2008575a0bf67794ef6.
  • Check the file path, publisher, and signature against the details in this report.
  • Run a GridinSoft scan and remove the object if the same hash is found. Use the Trojan category to compare similar reports.