ffsetup3.6.0.0.exe

Format Factory

chen jun hao

The application ffsetup3.6.0.0.exe, “Format Factory Video/Audio/Picture Converter” by chen jun hao has been detected as a potentially unwanted program by 4 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This file is typically installed with the program Toolwiz Time Freeze 2014 by ToolWiz. The file has been seen being downloaded from www.filehippo.com and multiple other hosts.
Publisher:
Free Time  (signed by chen jun hao)

Product:
Format Factory

Description:
Format Factory Video/Audio/Picture Converter

Version:
3.6.0.0

MD5:
f2b5f6407d105b3d4c05993dbfbe7f11

SHA-1:
c24b236653ccda241077274f5fe0d68908b25eb3

SHA-256:
b34958176f11eed4d277b6ed351e23f5ecaf21fa1461c60fb35ab96ec44e9ef8

Scanner detections:
4 / 68

Status:
Potentially unwanted

Analysis date:
11/23/2024 2:04:15 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Skodna.Generic_c
2016.0.3197

ESET NOD32
Win32/Hao123.A potentially unwanted (variant)
9.11180

Reason Heuristics
PUP.Installer.chenjunhao
15.2.15.19

Vba32 AntiVirus
Signed-Adware.Hao123.BaiduBeijingCo
3.12.26.3

File size:
53 MB (55,605,736 bytes)

Product version:
3.6.0.0

Copyright:
Format Factory

Trademarks:
Format Factory Application is a trademark of FreeTime

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\ffsetup3.6.0.0.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
6/25/2013 11:09:13 AM

Valid to:
6/25/2016 11:09:13 AM

Subject:
CN=chen jun hao, C=CN

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11215F9DDE67138EA8C52C9F6F1901954DE8

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
786432:H67aAZY7mh+qgfASFC/dsxuwyvcNvjni3BgHUgfbO4LSH7rrjxGmKlPd2KL:H67zZSpqwASFC/dVwjiRgHNbcH4nPd2k

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file ffsetup3.6.0.0.exe has been discovered within the following program.

www.Toolwiz.com
About 1% of users remove it
 
Powered by Should I Remove It?

The file ffsetup3.6.0.0.exe has been seen being distributed by the following 50 URLs.

http://www.filehippo.com/download/file/.../

http://filehippo.com/download/file/.../

http://filehippo.com/download/file/.../

http://filehippo.com/download/file/.../

http://dw.html.it/index.php?softname=FFSetup3.6.0.0.exe&code=1425737002&q=ODE3NTd8Zm9ybWF0LWZhY3RvcnktMTI=

http://www.gezginler.net/indir/v/7152/.../

http://www.filehippo.com/download/file/.../

http://www.majorgeeks.com/index.php?ct=files&action=download&PHPSESSID=5qk921clno0o8m9u2uvaor2ei1

http://format-factory.ar.softonic.com/.../3tjQyeLV3cjDp-Hw3sCixsiGa5-flqONoKCfkZc=

http://format-factory.ar.softonic.com/.../3tjQyeLV3cjDp-Hw3sCixsiGa5-flqSKp6WmmpY=

http://filehippo.com/it/download/file/.../

http://fs32.filehippo.com/6073/.../FFSetup3.6.0.0.exe

http://format-factory.ar.softonic.com/.../3tjQyeLV3cjDp-Hw3sCixsiGa5-flqWLpqOflJg=

http://format-factory.he.softonic.com/.../3tjQyeLV3cjDp-Hw3sCixsiGa5-flqOMp6Whkpk=

http://filehippo.com/download/file/.../

http://moywot.ru/.../FormatFactory_Rus_Setup.exe

http://filehippo.com/download/file/.../

http://filehippo.com/download/file/.../

http://www.quetelecharger.com/.../561a332c.dl

https://docs.google.com/uc?export=download&confirm=V4al&id=0B_fCq6PbiCFzTHpoaTRIeWJGWEk

https://www.kaldata.com/modules.php?modid=1&action=download&id=1397

http://format-factory.he.softonic.com/.../3tjQyeLV3cjDp-Hw3sCixsiGa5-flqSPnqWglpc=

http://www.ex.ua/.../154770038

http://fs37.filehippo.com/2205/.../FFSetup3.6.0.0.exe

http://format-factory.he.softonic.com/.../3tjQyeLV3cjDp-Hw3sCixsiGa5-flqOJpaOjkps=

http://format-factory.th.softonic.com/.../3tjQyeLV3cjDp-Hw3sCixsiGa5-flqWHoqOimJs=

http://format-factory.th.softonic.com/.../3tjQyeLV3cjDp-Hw3sCixsiGa5-flqWHpJ6gl5g=

http://filehippo.com/download/file/.../

http://dl1.filesoul.com/.../Format-Factory-3-6-0.exe

https://archive.org/download/.../Format factory 3-6-0.exe

Latest 30 of 104 download URLs

Remove ffsetup3.6.0.0.exe - Powered by Reason Core Security