ffsetup3.3.5.0.exe

Format Factory

chen jun hao

The application ffsetup3.3.5.0.exe, “Format Factory Video/Audio/Picture Converter” by chen jun hao has been detected as a potentially unwanted program by 2 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This version of the installer will bundle the Ask.com Toolbar, a potentially unwanted web browser extension. The file has been seen being downloaded from global-shared-files-l3.softonic.com and multiple other hosts.
Publisher:
Free Time  (signed by chen jun hao)

Product:
Format Factory

Description:
Format Factory Video/Audio/Picture Converter

Version:
3.3.5.0

MD5:
c0be08f0c5b9377b8b656d9f9edadbfd

SHA-1:
a5102072b4d392dd837edb635480d4854c0f74b0

SHA-256:
9ea7a6e661d4e40306e65da06ff729ff26cc39f6573d2477a4670edfa16bc0e8

Scanner detections:
2 / 68

Status:
Potentially unwanted

Explanation:
Bundles that Ask.com toolbar as a third-party offer, a web browser extension that may modify a user's search and home pages.

Analysis date:
11/23/2024 4:44:59 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Bundled.Toolbar.Ask (variant)
8.9911

Reason Heuristics
PUP.Installer.chenjunhao.L
14.7.31.23

File size:
51.2 MB (53,647,808 bytes)

Product version:
3.3.5.0

Copyright:
Format Factory

Trademarks:
Format Factory Application is a trademark of FreeTime

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\ffsetup3.3.5.0.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
6/25/2013 11:09:13 AM

Valid to:
6/25/2016 11:09:13 AM

Subject:
CN=chen jun hao, C=CN

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11215F9DDE67138EA8C52C9F6F1901954DE8

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1572864:NVLBJ9NWINww19kGnYp20eMib28oIb+jAwQ4khp:NVdNVnTnYYzb28Ij4

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file ffsetup3.3.5.0.exe has been seen being distributed by the following 50 URLs.

http://global-shared-files-l3.softonic.com/a51/020/.../file?nvb=20140902191702&nva=20140903071802&token=0e5ae9414566008240f42&id_file=72054&channel=WEB&instance=softonic_en&type=PROGRAM&fdh=yes&SD_used=0&filename=FFSetup3-3-5-0.exe

http://global-shared-files-l3.softonic.com/a51/020/.../file?nvb=20140726183034&nva=20140727063134&token=065b96de3bdd19ad8c99a&id_file=72054&channel=WEB&instance=softonic_en&type=PROGRAM&fdh=yes&SD_used=0&filename=FFSetup3-3-5-0.exe

http://www.softexia.com/?dl_id=20

http://gsf-cf.softonic.com/a51/020/.../file?instance=softonic_br&Expires=1416439739&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=Jf1pTmGZPnF0HNLiJaCknBCtMsB~nGW~vv8~Krv~bLwpCzYeIvCtJo94rG7Vok7R3EbWf14y6eGwicImSwPZCqLUjVIq5fY6~2dLaMuIn8upASmG2NXmDoZ49qkUp0dXv-7zF-VU50ifrA~LvjgYUt0C50nUmLXBGoi9451fPww_&filename=FFSetup3-3-5-0.exe

http://forum.enativ.com/filebase.php?d=1&id=293&f=293&what=s&searchword=?????&page=1

http://global-shared-files-l3.softonic.com/a51/020/.../file?nvb=20140728164950&nva=20140729045050&token=0113397d9b143cb243e13&id_file=72054&channel=WEB&instance=softonic_en&type=PROGRAM&fdh=yes&SD_used=0&filename=FFSetup3-3-5-0.exe

https://docs.google.com/uc?export=download&confirm=0yNZ&id=0B2Qi14KlPWiyNXRIY0c1d1YtbWc

http://dl1.filesoul.com/.../Format-Factory-3-3-5.exe

http://download681.mediafire.com/396n06zl31jg/.../FFSetup3.3.5.0.exe

http://filehippo.com/download/file/.../

http://download1879.mediafire.com/64byu1uzhjlg/.../FFSetup3.3.5.0.exe

http://download2121.mediafire.com/981iy4aasxfg/.../FFSetup3.3.5.0.exe

http://dc356.4shared.com/download/.../FFSetup3350.exe

https://drive.google.com/uc?export=download&confirm=tHPb&id=0B2Z-8E4JRrg6cjhDQWpGcXhYZHc

http://gsf-cf.softonic.com/a51/020/.../file?instance=softonic_br&Expires=1416710544&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=eEg37IY6xVYtY6rodkdU9hp9N~P6THE4fmylVCI77RqH09TkLsbTWZ5F2iojKbe140othOn2mp09VPLNuWljgHFlG~ZxKcQCxqtA0V5YwkIfEG6xzDUZEnWSITIi0aDbmXVsnKR85smfC8cyOopBCgpmDeSounNmKvDUDOcUnBk_&filename=FFSetup3-3-5-0.exe

http://dl1.filesoul.com/.../Format-Factory-3-3-5.exe

http://download2112.mediafire.com/y0sg9uwkbrtg/.../FFSetup3.3.5.0.exe

http://global-shared-files-l3.softonic.com/a51/020/.../file?nvb=20140621140858&nva=20140622020958&token=0f4bc20e4acf92cc55159&id_file=72054&channel=WEB&instance=softonic_en&type=PROGRAM&fdh=yes&SD_used=0&filename=FFSetup3-3-5-0.exe

http://global-shared-files-l3.softonic.com/a51/020/.../file?nvb=20140821062907&nva=20140821183007&token=0b95f6065e6b02bf51cf8&id_file=72054&channel=WEB&instance=softonic_en&type=PROGRAM&fdh=yes&SD_used=0&filename=FFSetup3-3-5-0.exe

http://d.baixakifiles2.com/?ic_user_id=254&data=f/UUlUkRclq9ostSAscryHAof14VmoFVgQp3kiqFmmeRl1gYPFL syLPNDPUcRh4TLy9AnLpLMvYZOtNfkuaBn4WjT/uHls8VPWZuNkUXyh2Iyf6nQIOQShfY Yjg /plom FnnhBcgdCQXtTr5ckv54lb1qSaXAJFygnm5qdh4f1C3t9QXZMegWxkaH3vpv56awK1MvrhCdcUrpZgG9IRWZwm25ioOvBmfTtV63UfHi2al5HcWz/K7LwKIHxpO2m6fW0Wg8mO3cZtPO89h7APB02HlOu2Jmmb 6iwHRskVbgJL8BGNKCeMk3nRXBN8t6Z57jitERjCFXiJcczBuOU6ZvT2PnHdSK6VM4WbFhUDe78nCOx/YICTjXWckj4GR3AEbXTyojlzytapf UTNooo12VL o2ooidrnt/qGd4 KP7viVsGRI/FPh7IErVjH1wIr0h6aCtZ433tjKDYPZVrjUt7JN5QfpS11sQERBLkaNizME42rFKFL MsCB0151cOOq E56YoKWc/K/s1Pq 7mfs7j3s215mHu0s6r61Fg0/e1i2A8vWf w2UFrbKiI3UZ8cbLNQAE9bRJrQbfLgfTV8YRbsa BldRVdB0do4b1vF2a5ILCyu2u lJ2gXo3m8tw9Eq0uw/W6zhcpE5Zmx3ogIvgXxRBY 9l48W5HQexBgOO3EGppecdKKYdsxH4SqKuMOOlww7pab6kLPhdVoqLoLPe6q2z5FrCWqkKtivUJtHVZz9ImT7nhj1z3AyykrPjsn/R WPnSRRv5T0HSG&key=BQ/GUFe4xMWemUH/7gaocPcNvIO5rBEllJOKl4GMieUOwGx1veT4xHAMiwEj T2XHUOAQoVsm5ZDnbP/.../1h5

http://www.afterdawn.com/software/general/.../format_factory?mirror_id=0&version_id=83034&software_id=2243

http://download1106.mediafire.com/l4ffof58w4bg/.../FFSetup3.3.5.0.exe

https://doc-00-7c-docs.googleusercontent.com/docs/securesc/ofkn0qisrtr48nv4ggvcs90ubisposds/qlg8hticc4dtvgprjsojbp90q5gm95g0/1460800800000/01310693624363926097/.../0B4k3R4urGt-nVUJJVmZZSksxSDg?e=download&nonce=6l0fg3m90epjm&user=12155228466282078484&hash=kdqgn3gnojsdhatgo3nio84umk7q3425

&onid=2194&oid=3001-2194_4-10968547&rsid=cbsidownloadcomsite&sl=en&sc=us&pdguid=download:13783603&topicguid=video/converters&topicbrcrm=windows software&pid=13783603&mfgid=10053063&merid=10053063&ctype=dm&cval=CBSI&devicetype=desktop&pguid=c6719b157537632c325b1d01&viewguid=QupU4DkrYDmGHruPGTfqX7vKM-syf6T5H8Gb&destUrl=http://software-files-a.cnet.com/s/software/13/78/36/.../FFSetup3.3.5.0.exe

http://global-shared-files-l3.softonic.com/a51/020/.../file?nvb=20140822002914&nva=20140822123014&token=03d13a39f0188dfa98ad5&id_file=72054&channel=WEB&instance=softonic_en&type=PROGRAM&fdh=yes&SD_used=0&filename=FFSetup3-3-5-0.exe

http://www.filehippo.com/download/file/.../

http://global-shared-files-l3.softonic.com/a51/020/.../file?nvb=20141021090628&nva=20141021210728&token=0a6f8cfb7a1a043b0488d&instance=softonic_en&filename=FFSetup3-3-5-0.exe

http://download2096.mediafire.com/n6o8pmiui4ag/.../FFSetup3.3.5.0.exe

http://download2096.mediafire.com/gwb6btx2ivpg/.../FFSetup3.3.5.0.exe

Latest 30 of 100 download URLs

Remove ffsetup3.3.5.0.exe - Powered by Reason Core Security