Ff file
Author: s | 2025-04-23
.FF is Call of Duty 4 Fast File. Learn what an FF file is, how to open an FF file or how to convert an FF file and view a list of programs that open them.
FF file extension - What is FF file? How to open FF files?
ProgramAdvertiso GmbHThe installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application picasa.exe, “program Setup ” by Advertiso GmbH has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The file has been seen being downloaded from tmpfile1338.s3.amazonaws.com.Description:program Setup MD5:93ecc2348a05ac7831fa83e06ac5c000SHA-1:e8ed86350ac7fa4a86169614c5f4c2643eda3597SHA-256:3562dcdd949664ea091625970e9d3bcb7db0e5dbca70e2503fa9a43bb54fa4d2Scanner detections:1 / 68Note:Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.Description:This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.Analysis date:3/23/2025 5:03:13 AM UTC (today)Scan engineDetectionEngine versionReason HeuristicsPUP.installCore.Advertiso.Installer (M)16.2.21.6File size:961.4 KB (984,504 bytes)File type:Executable application (Win32 EXE)Bundler/Installer:installCore (using Inno Setup)Language:Language NeutralCommon path:C:\users\{user}\downloads\picasa.exeAuthority:GlobalSign nv-saValid from:12/30/2015 12:45:26 PMValid to:12/30/2016 12:45:26 PMSubject:CN=Advertiso GmbH, O=Advertiso GmbH, L=Hamburg, S=Hamburg, C=DEIssuer:CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BESerial number:112153241712D48BF879DC1FEB639FA4305CCompilation timestamp:6/20/1992 12:22:17 AMCTPH (ssdeep):24576:zmp9L9rRD8jHd2H1u/8VjDBzlkv3nFfcFh+C:zc9BRIbUg/8VjNGdcSCEntry point:55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, BF, A9, FF, FF, E8, 5E, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...[+]Packer / compiler:Inno Setup v5.x - Installer MakerCode size:37 KB (37,888 bytes)The file picasa.exe has been seen being distributed by the following URL.
.FF - How to open FF file? FF File Extension - FileInfo
SILICOM INTERNET, S.L.The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application winzip-18.0.exe by SILICOM INTERNET, S.L has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The file has been seen being downloaded from installers.toggle.com.File name:winzip-18.0.exeMD5:1f7b1f27da00523710b5b2661bcf12e0SHA-1:3b07be8967d23211a1f7f14963fbe28e9801e06eSHA-256:3314083817a1ac612cf23f9cb8e29c9db719f712e18e19a111c94269941c2a63Scanner detections:1 / 68Note:Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.Description:This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.Analysis date:3/25/2025 6:10:30 PM UTC (today)Scan engineDetectionEngine versionReason HeuristicsPUP.installCore (M)16.8.10.11File size:674 KB (690,176 bytes)File type:Executable application (Win32 EXE)Bundler/Installer:installCore (using Inno Setup)Common path:C:\users\{user}\downloads\winzip-18.0.exeValid from:10/25/2013 8:00:00 AMValid to:10/29/2014 8:00:00 PMSubject:CN="SILICOM INTERNET, S.L.", O="SILICOM INTERNET, S.L.", L=Villaviciosa de Odon, C=ESIssuer:CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=USSerial number:06C80396B3808BBD5B05A86D48465401Compilation timestamp:6/20/1992 6:22:17 AMCTPH (ssdeep):12288:25vpejiheiYGVpJDgAEcGtKXxzz8enXwjexqg84UvcKqzlt6NcIo:25v0VRUJUAh6KxnFAj4qg8rvMzlPIoEntry point:55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...[+]Packer / compiler:Inno Setup v5.x - Installer MakerCode size:37 KB (37,888 bytes)The file winzip-18.0.exe has been seen being distributed by the following URL.FF File: How to open FF file (and what it is)
Kernel Exchange EDB ViewerLepide Software Private LimitedThe program is a setup application that uses the Inno Setup installer. The file has been seen being downloaded from www.nucleustechnologies.com and multiple other hosts.File name:kernelexchangeedbviewer.exePublisher:Lepide Software Private Limited (signed by Lepide Software Private Limited)Product:Kernel Exchange EDB Viewer Description:Kernel Exchange EDB Viewer Setup MD5:98ec4fc8ef228d6f240c270026fa65faSHA-1:e4e2f53195cb9ca6cbabbd2fbe0b8695e387ea8aSHA-256:465bc1041ee2c5082f2e26a38b1b61c587423b4d2f032b5be38ce7d574ade3edScanner detections:0 / 68Status:Clean (as of last analysis)Analysis date:3/24/2025 9:54:52 PM UTC (today)File size:13 MB (13,598,568 bytes)Copyright:Copyright © 2015 Lepide Software Private Limited. All rights reserved. File type:Executable application (Win32 EXE)Language:Language NeutralCommon path:C:\users\{user}\downloads\kernelexchangeedbviewer.exeAuthority:GlobalSign nv-saValid from:4/22/2015 8:37:46 AMValid to:4/22/2018 8:37:46 AMSubject:CN=Lepide Software Private Limited, O=Lepide Software Private Limited, STREET="B-57, Sector 57", L=Noida, S=Uttar Pradesh, C=IN, OID.1.3.6.1.4.1.311.60.2.1.2=Delhi, OID.1.3.6.1.4.1.311.60.2.1.3=IN, SERIALNUMBER=U74899DL2005PTC143584, OID.2.5.4.15=Private OrganizationIssuer:CN=GlobalSign Extended Validation CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BESerial number:112123367A63FFD214397D34199FF4D6A7C6Compilation timestamp:6/19/1992 3:22:17 PMCTPH (ssdeep):196608:P1vTAGASTEKFdFd+dYNLs8rwAKkKkQXGHgpZJXyfWoglAr5HwNavVyenq5QPN:5TAGVFyKDwAnXHgLRyuoglwO+VlPNEntry point:55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...[+]Packer / compiler:Inno Setup v5.x - Installer MakerCode size:39.5 KB (40,448 bytes)The file kernelexchangeedbviewer.exe has been seen being distributed by the following 3 URLs.. .FF is Call of Duty 4 Fast File. Learn what an FF file is, how to open an FF file or how to convert an FF file and view a list of programs that open them. Related FF File Extensions Tools. FF default file extension is .FF and other similer related extensions and their tools are:FF File Extension - What is a ff file and how do I open a ff file
VNC ServerRealVNC LtdThe program is a setup application that uses the Inno Setup installer. The file has been seen being downloaded from dl.cdn.chip.de and multiple other hosts.File name:vnc-5.3.1-windows.exePublisher:RealVNC Ltd (signed by RealVNC Ltd)MD5:4526ef41405dd4ac4a7ab97e8b77f106SHA-1:3aed2f22ea607a118ecc8db4cd2044ff08056e07SHA-256:4ea5a5f24ba30c6ba3ab3f2fc02bb802ab55b15b614d495b3b4fbebc61f4fc86Scanner detections:0 / 68Status:Clean (as of last analysis)Analysis date:3/12/2025 8:25:32 AM UTC (today)File size:17.6 MB (18,406,960 bytes)Copyright:Copyright © 2002-2016 RealVNC Ltd. File type:Executable application (Win32 EXE)Language:Language NeutralCommon path:C:\users\{user}\downloads\vnc-5.3.1-windows.exeValid from:8/5/2015 1:00:00 AMValid to:10/4/2018 12:59:59 AMSubject:CN=RealVNC Ltd, O=RealVNC Ltd, L=Cambridge, S=Cambridgeshire, C=GBIssuer:CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=USSerial number:2EB260DBC51427A731CD2519701AE3C0Compilation timestamp:6/19/1992 11:22:17 PMCTPH (ssdeep):393216:g+mmoiGdtL9EWtB31C/4ke1daLz8Y6EW/061VuR+uT8tc69854ayD1tL:g/mm9EWtBlM4ke7szz6Ts6Lfuu854a+LEntry point:55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, E8, CD, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, E8, CD...[+]Packer / compiler:Inno Setup v5.x - Installer MakerCode size:37 KB (37,888 bytes)The file vnc-5.3.1-windows.exe has been seen being distributed by the following 15 URLs.FF File Extension - What is it? How to open an FF file?
Brorsoft Blu-ray RipperKUNSHAN MOYEA SOFTWARE CO.,LTDThe program is a setup application that uses the Inno Setup installer. The file has been seen being downloaded from www.ngmco.net.File name:blurayripper_setup.exePublisher:Brorsoft Studio (signed by KUNSHAN MOYEA SOFTWARE CO.,LTD)Product:Brorsoft Blu-ray Ripper Description:Brorsoft Blu-ray Ripper Setup MD5:a8599aa3ab5171d42ce884a195de2170SHA-1:5b24df40b4fd86fe277677b93775bd792535278cSHA-256:f1aa3b275d5e82518abdf5e5b798ddd53baab52d36b8d58b9901017c6c5ae850Scanner detections:0 / 68Status:Clean (as of last analysis)Analysis date:3/12/2025 9:28:58 AM UTC (today)File size:31.3 MB (32,853,784 bytes)Copyright:Copyright 2007-2015 Brorsoft Studio. File type:Executable application (Win32 EXE)Language:Language NeutralAuthority:GlobalSign nv-saValid from:8/14/2013 10:20:30 AMValid to:9/13/2016 10:20:30 AMSubject:CN="KUNSHAN MOYEA SOFTWARE CO.,LTD", OU=Development Department, O="KUNSHAN MOYEA SOFTWARE CO.,LTD", L=苏州, S=江苏, C=CNIssuer:CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BESerial number:1121DA118EF25661C0EC6A5FF5D6F8F5F191Compilation timestamp:6/20/1992 12:22:17 AMCTPH (ssdeep):786432:qNKmanWjEn650UsJi8q1/AjQulpIPLAI2jD3B7BmjYV/DM6/0:qkWjE6mUsM1/Ajv62jDRV10Entry point:55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, BF, A9, FF, FF, E8, 5E, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...[+]Packer / compiler:Inno Setup v5.x - Installer MakerCode size:37 KB (37,888 bytes)The file blurayripper_setup.exe has been seen being distributed by the following URL.How To Open File With FF Extension? - File Extension .FF
ISO2DiscTop Password Software,Inc.The program is a setup application that uses the Inno Setup installer. The file has been seen being downloaded from lon-01.lo4d.com and multiple other hosts.File name:iso2discsetup.exePublisher:Top Password Software, Inc. (signed by Top Password Software,Inc.)Description:ISO2Disc Setup MD5:f61b5c9617fc964585a715bdb625e799SHA-1:5d9c32a61684edfa477ba9d65c9502d68bc2b472SHA-256:ae7a10745fb9f14f08f7329ea00d4249ae96250314568b26c94cf730265340a6Scanner detections:0 / 68Status:Clean (as of last analysis)Analysis date:3/22/2025 9:14:29 AM UTC (today)File size:1.7 MB (1,744,192 bytes)File type:Executable application (Win32 EXE)Language:Language NeutralCommon path:C:\users\{user}\downloads\programs\iso2discsetup.exeValid from:10/22/2014 6:00:00 PMValid to:10/22/2016 5:59:59 PMSubject:CN="Top Password Software,Inc.", OU=IT Dept, O="Top Password Software,Inc.", L=FOSHAN, S=GUANGDONG, C=CNIssuer:CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=USSerial number:598CE18C3C88CE74F048B202DF641614Compilation timestamp:6/19/1992 4:22:17 PMCTPH (ssdeep):49152:A93g+tCGYCjF5aYLnuxb/R/Uu7pATAN6Sni:KPtLRgwuxjlnprchEntry point:55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...[+]Packer / compiler:Inno Setup v5.x - Installer MakerCode size:39.5 KB (40,448 bytes)The file iso2discsetup.exe has been seen being distributed by the following 15 URLs.Properties of FF Files and How to Open a File with .ff Extension
Daanav Mouse Cursor ChangerMS Daanav SoftwaresThe program is a setup application that uses the Inno Setup installer. The file has been seen being downloaded from files.downloadnow.com.File name:cursorchangersetup.exePublisher:Daanav Softwares (signed by MS Daanav Softwares)Product:Daanav Mouse Cursor Changer MD5:f5012e13ce01a73964083a5b5cb761e1SHA-1:d9baa3c1d602efbd27fc50b7ebdb479fa7f94024SHA-256:a789a0f13b60368323ac917ca614e1d4c29cc106f12597fe9b95b1ab6a86d23aScanner detections:0 / 68Status:Clean (as of last analysis)Analysis date:3/13/2025 12:56:05 AM UTC (today)File size:4.3 MB (4,560,384 bytes)File type:Executable application (Win32 EXE)Language:Language NeutralCommon path:C:\users\{user}\downloads\cursorchangersetup.exeAuthority:Starfield Technologies, Inc.Valid from:4/7/2013 9:25:30 AMValid to:11/27/2013 3:49:57 AMSubject:CN=MS Daanav Softwares, O=MS Daanav Softwares, L=Panaji, S=Goa, C=INIssuer:SERIALNUMBER=10688435, CN=Starfield Secure Certification Authority, OU= O="Starfield Technologies, Inc.", L=Scottsdale, S=Arizona, C=USSerial number:4F1A36201A07F5Compilation timestamp:6/19/1992 11:22:17 PMCTPH (ssdeep):98304:GI7l7O+TN8FMzBhGP9IqF2MvjX85C5B8RJVbBCtvMvdxXn:x7BTN8FyBhrMvYkgPVbktvMv7nEntry point:55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, BF, A9, FF, FF, E8, 5E, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...[+]Packer / compiler:Inno Setup v5.x - Installer MakerCode size:37 KB (37,888 bytes)The file cursorchangersetup.exe has been seen being distributed by the following URL.. .FF is Call of Duty 4 Fast File. Learn what an FF file is, how to open an FF file or how to convert an FF file and view a list of programs that open them.
Open the .FF file - .FF file extension and applications that support
– If the entry is a folder, pass it back into the recursive function itself.METHOD 2) GLOB2A) BASIC GLOB2a-glob.php// (A) GET FILES/FOLDERS$all = glob("YOUR/FOLDER/*");// $all = glob("YOUR/FOLDER/*.{jpg,jpeg,webp,png,gif}", GLOB_BRACE);$eol = PHP_EOL; // (B) LOOP THROUGH ALLforeach ($all as $ff) { if (is_file($ff)) { echo "{$ff} - file {$eol}"; } if (is_dir($ff)) { echo "{$ff} - folder {$eol}"; }}Now, scandir() will fetch everything. If you only need certain file types – glob() is the best option.2B) GLOB READ SUB-FOLDERS2b-glob.php// (A) RECURSIVE GLOBfunction rglob ($dir, $ext="*") { // (A1) GET FILES $eol = PHP_EOL; foreach (glob("$dir$ext", GLOB_BRACE) as $ff) { if (is_file($ff)) { echo "{$ff} - file {$eol}"; } } // (A2) GET FOLDERS foreach (glob("$dir*", GLOB_ONLYDIR | GLOB_MARK) as $ff) { echo "{$ff} - folder {$eol}"; rglob($ff, $ext); }} // (B) GO!rglob("YOUR/FOLDER/");// rglob("YOUR/FOLDER/", "*.{jpg,jpeg,webp,png,gif}");A “recursive glob” is slightly more roundabout, but basically – Get the files first, then recursive “dig” into the folder.METHOD 3) OPENDIR3A) BASIC OPENDIR3a-opendir.phpThe above methods will “fetch everything into an array”. Some of you sharp code ninjas should have already caught the potential problem – What if there are thousands of files in the folder? This will run into performance and memory issues. So instead of “getting everything at once”, opendir() and readdir() will read “entry by entry”.3B) OPENDIR READ SUB-FOLDERS3a-opendir.phpWell, this should not be a surprise by now. Create a recursive function to open and read sub-folders.METHOD 4) DIRECTORY ITERATOR4A) BASIC ITERATOR4a-iterator.phpisDot()) { continue; } if ($ff->isFile()) { echo "{$ff->getFilename()} - file {$eol}"; } if ($ff->isDir()) { echo "{$ff->getFilename()} - folder {$eol}"; }}Lastly, here is the “alternative” way to read a folder entry by entry – Using a DirectoryIterator.4B) ITERATOR READ SUB-FOLDERS4b-iterator.phpisDot()) { continue; } if ($ff->isFile()) { echo "{$ff->getFilename()} - file {$eol}"; } if ($ff->isDir()) { echo "{$ff->getFilename()} - folder {$eol}"; riterate("{$dir}{$ff->getFilename()}/"); } }} // (B)FF File What is .ff file and how to open it? - Amazing
Virtual TimeClock Pro ClientRedcort Software, Inc.The program is a setup application that uses the Inno Setup installer. The file has been seen being downloaded from www.redcort.com.File name:pro user client.exePublisher:Redcort Software Inc. (signed by Redcort Software, Inc.)Product:Virtual TimeClock Pro Client Description:Virtual TimeClock Installer MD5:285e48166e113ce3175118830cb551b6SHA-1:5643a5f4512540070bf4e59e9c1d1c027cb4b7ceSHA-256:9c2f8bcc2f6c9e4fef3a7539ca6308ff1f4c4b95507a06e5e086fd2f54a4a79eScanner detections:0 / 68Status:Clean (as of last analysis)Analysis date:3/26/2025 3:38:57 AM UTC (today)File size:7.5 MB (7,853,848 bytes)Copyright:Trademark & Copyright 2015 Redcort Software Inc. All Rights Reserved. File type:Executable application (Win32 EXE)Language:Language NeutralAuthority:COMODO CA LimitedValid from:7/25/2012 7:00:00 PMValid to:7/26/2015 6:59:59 PMSubject:CN="Redcort Software, Inc.", O="Redcort Software, Inc.", STREET="323 W. Cromwell Ave. #101", L=Fresno, S=CA, PostalCode=93711, C=USIssuer:CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GBSerial number:008E18961DD53B3E9527B1E09EDEB3DA50Compilation timestamp:6/19/1992 5:22:17 PMCTPH (ssdeep):196608:NgRGyr+wVuBbNwXM2IaimfuJ5n3fjRsj+mDUqzKm4Do3L:Or+IKbG16XzmI24Do3Entry point:55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, E8, CD, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, E8, CD...[+]Packer / compiler:Inno Setup v5.x - Installer MakerCode size:37 KB (37,888 bytes)The file pro user client.exe has been seen being distributed by the following URL.. .FF is Call of Duty 4 Fast File. Learn what an FF file is, how to open an FF file or how to convert an FF file and view a list of programs that open them. Related FF File Extensions Tools. FF default file extension is .FF and other similer related extensions and their tools are:The FF-Files - Sherdog.com
Installer applicationdobreprogramy sp. z o.o.The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application argente-registry-cleaner-33517-dp.exe, “Installer application Setup ” by dobreprogramy sp. z o.o has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The file has been seen being downloaded from www.tagvaultsclean.com.File name:argente-registry-cleaner-33517-dp.exePublisher:Installer Soft Program (signed by dobreprogramy sp. z o.o.)Product:Installer application Description:Installer application Setup MD5:7fc47ecf3d5afe0b84b54d9c01741dcfSHA-1:29633c7ff82ea18b6e546bce71845c8fe66d9c59SHA-256:12d873f490bff521b8df25cc30c61c77c44c46f204e18e39a80567ee27aee32eScanner detections:1 / 68Note:Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.Description:This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.Analysis date:3/25/2025 6:21:54 PM UTC (today)Scan engineDetectionEngine versionReason HeuristicsPUP.installCore.dobrepro.Installer (M)16.5.15.23File size:939.6 KB (962,128 bytes)File type:Executable application (Win32 EXE)Bundler/Installer:installCore (using Inno Setup)Common path:C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\argente-registry-cleaner-33517-dp.exeAuthority:GlobalSign nv-saValid from:2/13/2015 5:34:27 PMValid to:2/14/2016 5:34:27 PMSubject:CN=dobreprogramy sp. z o.o., O=dobreprogramy sp. z o.o., L=Wroclaw, C=PLIssuer:CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BESerial number:1121B4F3A4313F8A58B614202F80129EBC93Compilation timestamp:6/20/1992 12:22:17 AMCTPH (ssdeep):24576:SK0MnOP4OXqwVfMacL/BLLpQ/VWVSiPmBuJFTs9QOY4I:S1mOuacL/VLh/PmBuDTslEEntry point:55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2,Comments
ProgramAdvertiso GmbHThe installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application picasa.exe, “program Setup ” by Advertiso GmbH has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The file has been seen being downloaded from tmpfile1338.s3.amazonaws.com.Description:program Setup MD5:93ecc2348a05ac7831fa83e06ac5c000SHA-1:e8ed86350ac7fa4a86169614c5f4c2643eda3597SHA-256:3562dcdd949664ea091625970e9d3bcb7db0e5dbca70e2503fa9a43bb54fa4d2Scanner detections:1 / 68Note:Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.Description:This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.Analysis date:3/23/2025 5:03:13 AM UTC (today)Scan engineDetectionEngine versionReason HeuristicsPUP.installCore.Advertiso.Installer (M)16.2.21.6File size:961.4 KB (984,504 bytes)File type:Executable application (Win32 EXE)Bundler/Installer:installCore (using Inno Setup)Language:Language NeutralCommon path:C:\users\{user}\downloads\picasa.exeAuthority:GlobalSign nv-saValid from:12/30/2015 12:45:26 PMValid to:12/30/2016 12:45:26 PMSubject:CN=Advertiso GmbH, O=Advertiso GmbH, L=Hamburg, S=Hamburg, C=DEIssuer:CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BESerial number:112153241712D48BF879DC1FEB639FA4305CCompilation timestamp:6/20/1992 12:22:17 AMCTPH (ssdeep):24576:zmp9L9rRD8jHd2H1u/8VjDBzlkv3nFfcFh+C:zc9BRIbUg/8VjNGdcSCEntry point:55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, BF, A9, FF, FF, E8, 5E, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...[+]Packer / compiler:Inno Setup v5.x - Installer MakerCode size:37 KB (37,888 bytes)The file picasa.exe has been seen being distributed by the following URL.
2025-03-31SILICOM INTERNET, S.L.The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application winzip-18.0.exe by SILICOM INTERNET, S.L has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The file has been seen being downloaded from installers.toggle.com.File name:winzip-18.0.exeMD5:1f7b1f27da00523710b5b2661bcf12e0SHA-1:3b07be8967d23211a1f7f14963fbe28e9801e06eSHA-256:3314083817a1ac612cf23f9cb8e29c9db719f712e18e19a111c94269941c2a63Scanner detections:1 / 68Note:Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.Description:This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.Analysis date:3/25/2025 6:10:30 PM UTC (today)Scan engineDetectionEngine versionReason HeuristicsPUP.installCore (M)16.8.10.11File size:674 KB (690,176 bytes)File type:Executable application (Win32 EXE)Bundler/Installer:installCore (using Inno Setup)Common path:C:\users\{user}\downloads\winzip-18.0.exeValid from:10/25/2013 8:00:00 AMValid to:10/29/2014 8:00:00 PMSubject:CN="SILICOM INTERNET, S.L.", O="SILICOM INTERNET, S.L.", L=Villaviciosa de Odon, C=ESIssuer:CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=USSerial number:06C80396B3808BBD5B05A86D48465401Compilation timestamp:6/20/1992 6:22:17 AMCTPH (ssdeep):12288:25vpejiheiYGVpJDgAEcGtKXxzz8enXwjexqg84UvcKqzlt6NcIo:25v0VRUJUAh6KxnFAj4qg8rvMzlPIoEntry point:55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...[+]Packer / compiler:Inno Setup v5.x - Installer MakerCode size:37 KB (37,888 bytes)The file winzip-18.0.exe has been seen being distributed by the following URL.
2025-03-25VNC ServerRealVNC LtdThe program is a setup application that uses the Inno Setup installer. The file has been seen being downloaded from dl.cdn.chip.de and multiple other hosts.File name:vnc-5.3.1-windows.exePublisher:RealVNC Ltd (signed by RealVNC Ltd)MD5:4526ef41405dd4ac4a7ab97e8b77f106SHA-1:3aed2f22ea607a118ecc8db4cd2044ff08056e07SHA-256:4ea5a5f24ba30c6ba3ab3f2fc02bb802ab55b15b614d495b3b4fbebc61f4fc86Scanner detections:0 / 68Status:Clean (as of last analysis)Analysis date:3/12/2025 8:25:32 AM UTC (today)File size:17.6 MB (18,406,960 bytes)Copyright:Copyright © 2002-2016 RealVNC Ltd. File type:Executable application (Win32 EXE)Language:Language NeutralCommon path:C:\users\{user}\downloads\vnc-5.3.1-windows.exeValid from:8/5/2015 1:00:00 AMValid to:10/4/2018 12:59:59 AMSubject:CN=RealVNC Ltd, O=RealVNC Ltd, L=Cambridge, S=Cambridgeshire, C=GBIssuer:CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=USSerial number:2EB260DBC51427A731CD2519701AE3C0Compilation timestamp:6/19/1992 11:22:17 PMCTPH (ssdeep):393216:g+mmoiGdtL9EWtB31C/4ke1daLz8Y6EW/061VuR+uT8tc69854ayD1tL:g/mm9EWtBlM4ke7szz6Ts6Lfuu854a+LEntry point:55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, E8, CD, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, E8, CD...[+]Packer / compiler:Inno Setup v5.x - Installer MakerCode size:37 KB (37,888 bytes)The file vnc-5.3.1-windows.exe has been seen being distributed by the following 15 URLs.
2025-04-14Brorsoft Blu-ray RipperKUNSHAN MOYEA SOFTWARE CO.,LTDThe program is a setup application that uses the Inno Setup installer. The file has been seen being downloaded from www.ngmco.net.File name:blurayripper_setup.exePublisher:Brorsoft Studio (signed by KUNSHAN MOYEA SOFTWARE CO.,LTD)Product:Brorsoft Blu-ray Ripper Description:Brorsoft Blu-ray Ripper Setup MD5:a8599aa3ab5171d42ce884a195de2170SHA-1:5b24df40b4fd86fe277677b93775bd792535278cSHA-256:f1aa3b275d5e82518abdf5e5b798ddd53baab52d36b8d58b9901017c6c5ae850Scanner detections:0 / 68Status:Clean (as of last analysis)Analysis date:3/12/2025 9:28:58 AM UTC (today)File size:31.3 MB (32,853,784 bytes)Copyright:Copyright 2007-2015 Brorsoft Studio. File type:Executable application (Win32 EXE)Language:Language NeutralAuthority:GlobalSign nv-saValid from:8/14/2013 10:20:30 AMValid to:9/13/2016 10:20:30 AMSubject:CN="KUNSHAN MOYEA SOFTWARE CO.,LTD", OU=Development Department, O="KUNSHAN MOYEA SOFTWARE CO.,LTD", L=苏州, S=江苏, C=CNIssuer:CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BESerial number:1121DA118EF25661C0EC6A5FF5D6F8F5F191Compilation timestamp:6/20/1992 12:22:17 AMCTPH (ssdeep):786432:qNKmanWjEn650UsJi8q1/AjQulpIPLAI2jD3B7BmjYV/DM6/0:qkWjE6mUsM1/Ajv62jDRV10Entry point:55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, BF, A9, FF, FF, E8, 5E, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...[+]Packer / compiler:Inno Setup v5.x - Installer MakerCode size:37 KB (37,888 bytes)The file blurayripper_setup.exe has been seen being distributed by the following URL.
2025-04-17Daanav Mouse Cursor ChangerMS Daanav SoftwaresThe program is a setup application that uses the Inno Setup installer. The file has been seen being downloaded from files.downloadnow.com.File name:cursorchangersetup.exePublisher:Daanav Softwares (signed by MS Daanav Softwares)Product:Daanav Mouse Cursor Changer MD5:f5012e13ce01a73964083a5b5cb761e1SHA-1:d9baa3c1d602efbd27fc50b7ebdb479fa7f94024SHA-256:a789a0f13b60368323ac917ca614e1d4c29cc106f12597fe9b95b1ab6a86d23aScanner detections:0 / 68Status:Clean (as of last analysis)Analysis date:3/13/2025 12:56:05 AM UTC (today)File size:4.3 MB (4,560,384 bytes)File type:Executable application (Win32 EXE)Language:Language NeutralCommon path:C:\users\{user}\downloads\cursorchangersetup.exeAuthority:Starfield Technologies, Inc.Valid from:4/7/2013 9:25:30 AMValid to:11/27/2013 3:49:57 AMSubject:CN=MS Daanav Softwares, O=MS Daanav Softwares, L=Panaji, S=Goa, C=INIssuer:SERIALNUMBER=10688435, CN=Starfield Secure Certification Authority, OU= O="Starfield Technologies, Inc.", L=Scottsdale, S=Arizona, C=USSerial number:4F1A36201A07F5Compilation timestamp:6/19/1992 11:22:17 PMCTPH (ssdeep):98304:GI7l7O+TN8FMzBhGP9IqF2MvjX85C5B8RJVbBCtvMvdxXn:x7BTN8FyBhrMvYkgPVbktvMv7nEntry point:55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, BF, A9, FF, FF, E8, 5E, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...[+]Packer / compiler:Inno Setup v5.x - Installer MakerCode size:37 KB (37,888 bytes)The file cursorchangersetup.exe has been seen being distributed by the following URL.
2025-04-07– If the entry is a folder, pass it back into the recursive function itself.METHOD 2) GLOB2A) BASIC GLOB2a-glob.php// (A) GET FILES/FOLDERS$all = glob("YOUR/FOLDER/*");// $all = glob("YOUR/FOLDER/*.{jpg,jpeg,webp,png,gif}", GLOB_BRACE);$eol = PHP_EOL; // (B) LOOP THROUGH ALLforeach ($all as $ff) { if (is_file($ff)) { echo "{$ff} - file {$eol}"; } if (is_dir($ff)) { echo "{$ff} - folder {$eol}"; }}Now, scandir() will fetch everything. If you only need certain file types – glob() is the best option.2B) GLOB READ SUB-FOLDERS2b-glob.php// (A) RECURSIVE GLOBfunction rglob ($dir, $ext="*") { // (A1) GET FILES $eol = PHP_EOL; foreach (glob("$dir$ext", GLOB_BRACE) as $ff) { if (is_file($ff)) { echo "{$ff} - file {$eol}"; } } // (A2) GET FOLDERS foreach (glob("$dir*", GLOB_ONLYDIR | GLOB_MARK) as $ff) { echo "{$ff} - folder {$eol}"; rglob($ff, $ext); }} // (B) GO!rglob("YOUR/FOLDER/");// rglob("YOUR/FOLDER/", "*.{jpg,jpeg,webp,png,gif}");A “recursive glob” is slightly more roundabout, but basically – Get the files first, then recursive “dig” into the folder.METHOD 3) OPENDIR3A) BASIC OPENDIR3a-opendir.phpThe above methods will “fetch everything into an array”. Some of you sharp code ninjas should have already caught the potential problem – What if there are thousands of files in the folder? This will run into performance and memory issues. So instead of “getting everything at once”, opendir() and readdir() will read “entry by entry”.3B) OPENDIR READ SUB-FOLDERS3a-opendir.phpWell, this should not be a surprise by now. Create a recursive function to open and read sub-folders.METHOD 4) DIRECTORY ITERATOR4A) BASIC ITERATOR4a-iterator.phpisDot()) { continue; } if ($ff->isFile()) { echo "{$ff->getFilename()} - file {$eol}"; } if ($ff->isDir()) { echo "{$ff->getFilename()} - folder {$eol}"; }}Lastly, here is the “alternative” way to read a folder entry by entry – Using a DirectoryIterator.4B) ITERATOR READ SUB-FOLDERS4b-iterator.phpisDot()) { continue; } if ($ff->isFile()) { echo "{$ff->getFilename()} - file {$eol}"; } if ($ff->isDir()) { echo "{$ff->getFilename()} - folder {$eol}"; riterate("{$dir}{$ff->getFilename()}/"); } }} // (B)
2025-03-26