Should I block it?
90% of PCs block this file from running.
Possible reason:
Multiple malware detections
 
 
 Additional versions
Additional versions
| 2, 0, 0, 171 | 12.50% |  | 
| 2, 0, 0, 69 | 25.00% |  | 
| 2, 0, 0, 23 | 25.00% |  | 
| 2, 0, 0, 23 | 12.50% |  | 
| 2, 0, 0, 2 | 25.00% |  | 
 
Relationships
Parent process
Child processes
Related files
|  PE file structure
 | Show functions | 
Import table
advapi32.dll
CryptHashData, CryptAcquireContextW
dnsapi.dll
DnsFree, DnsQuery_W
htmlayout.dll
HTMLayoutSetCallback, ValueStringData
kernel32.dll
GetVersion, ResetEvent, GetModuleFileNameW, GetModuleHandleA, LoadLibraryA, LocalAlloc, LocalFree, GetModuleFileNameA, ExitProcess, QueryPerformanceCounter
ole32.dll
CoCreateInstance, CoInitializeEx
shell32.dll
Shell_NotifyIconW, ShellExecuteW
shlwapi.dll
SHSetValueA, SHDeleteValueW
user32.dll
GetSystemMetrics, DefWindowProcW
wininet.dll
HttpOpenRequestW, InternetCloseHandle
 
     
    
        GoforFiles.exe
GoforFiles Application by Righway Technologies (Signed)
| Version: | 2, 0, 0, 23 | 
| MD5: | defd411295765cb39285d2dd5b264f78 | 
| SHA1: | 82b8a4569936ce9270f46fa3494ba7c5f7f0dccf | 
| SHA256: | fd8c9eeda1fb0efe26ca233e0f1523b13486f8ac2ad16a6d5028fce6ba873809 | 
Warning 4 antivirus scanners has detected malware.
Overview
goforfiles.exe is malware that executes as a process with the local user's privileges usually within the context of Windows Explorer. It has been configured with a firewall exception which allows both inbound and outbound network communication without being blocked. It is installed with a couple of know programs including GoforFiles published by Righway Technologies, Inc, GoforFiles from Righway Technologies, Inc and GoforFiles by Righway Technologies, Inc. The file is digitally signed by Righway Technologies which was issued by the COMODO CA Limited certificate authority (CA).
 Details
Details
| File name: | goforfiles.exe | 
| Publisher: | http://goforfiles.com/ | 
| Product name: | GoforFiles Application | 
| Typical file path: | C:\Program Files\goforfiles\goforfiles.exe | 
| File version: | 2, 0, 0, 23 | 
| Product version: | 2,0,0,0 | 
| Size: | 882.58 KB (903,760 bytes) | 
| Build date: | 5/28/2013 5:35 AM | 
| Certificate | 
| Issued to: | Righway Technologies | 
| Authority (CA): | COMODO CA Limited | 
| Effective date: | Tuesday, August 21, 2012 | 
| Expiration date: | Saturday, August 22, 2015 | 
| Digital DNA | 
| PE subsystem: | Windows GUI | 
| File packed: | No | 
| .NET CLR: | No | 
More details
 Programs
Programs
The following programs will install this file
|  | Righway Technologies, Inc |  | 
GoforFiles bundles various adware toolbars including the Delta Search Toolbar (an adware toolbar that modifies the user's web browser home page, search settings and other settings).
 
 Behaviors
Behaviors
Windows firewall allowed program
Exceptions allow programs to access to the Internet through an outbound connections
- Firewall exception for 'C:\Program Files\GoforFiles\GoforFiles.exe'
Network connections
Access through an approved Windows firewall exception
[TCP] 184.75.220.90:80
 Malware detections
Malware detections
Based on 40+ industry antivirus scanners, 4 of them detected the following malware.
| Antivirus engine | Engine version | Detection | 
| Bkav Security | 1.3.0.4246 | W32.HfsAuto.Fef5 | 
| ESET NOD32 | 7.8813 | a variant of Win32/YourFileDownloader.B | 
| Kingsoft | 2013.4.9.267 | Win32.Troj.Generic.a.(kcloud) | 
| VIPRE Antivirus | 21568 | ExpressFiles Installer (fs) | 
 Resource utilization
Resource utilization
(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
| CPU | 
| Total CPU: | 0.00116397% |  | 
| Kernel CPU: | 0.00052849% |  | 
| User CPU: | 0.00063548% |  | 
| Kernel CPU time: | 338,995,532 ms/min |  | 
| CPU cycles: | 12,177,996/sec |  | 
| Context switches: | 13/sec |  | 
| Memory | 
| Private memory: | 20.81 MB |  | 
| Private (maximum): | 30.1 MB |  | 
| Private (minimum): | 22.3 MB |  | 
| Non-paged memory: | 20.81 MB |  | 
| Virtual memory: | 138.35 MB |  | 
| Virtual memory (peak): | 150.94 MB |  | 
| Working set: | 28.36 MB |  | 
| Working set (peak): | 31.75 MB |  | 
| Page faults: | 2,188,230/min |  | 
| I/O | 
| I/O read transfer: | 1.49 MB/sec |  | 
| I/O read operations: | 59/sec |  | 
| I/O write transfer: | 117.38 KB/sec |  | 
| I/O write operations: | 59/sec |  | 
| I/O other transfer: | 1.56 KB/sec |  | 
| I/O other operations: | 190/sec |  | 
| Resource allocations | 
| Threads: | 14 |  | 
| Handles: | 279 |  | 
| GUI GDI count: | 168 |  | 
| GUI GDI peak: | 169 |  | 
| GUI USER count: | 15 |  | 
| GUI USER peak: | 22 |  | 
 
 Process properties
Process properties
 Distribution by Windows OS
Distribution by Windows OS
| OS version | distribution | 
| Windows 7 Home Premium | 25.00% |  | 
| Windows 8.1 Pro Preview | 12.50% |  | 
| Windows Vista Home Premium | 12.50% |  | 
| Windows 7 Enterprise | 12.50% |  | 
| Windows 7 Ultimate N | 12.50% |  | 
| Windows 7 Ultimate | 12.50% |  | 
| Microsoft Windows XP | 12.50% |  | 
 Distribution by country
Distribution by country
United States installs about 50.00% of GoforFiles Application.
 Distribution by PC manufacturer
Distribution by PC manufacturer
| PC Manufacturer | distribution | 
| Acer | 33.33% |  | 
| Sony | 33.33% |  | 
| Hewlett-Packard | 33.33% |  |