ffmpeg.exe threat report

MD5 f7af7e85a4ae2416ea7e6f6df93bb663
Latest seen 2023-08-10 23:43:36 (2 years ago)
First seen 2017-05-21 04:03:36 (8 years ago)
Size 27 MB

This report summarizes the file identity, detection status, publisher metadata, observed locations, and technical indicators for ffmpeg.exe. ThreatInfo currently classifies this sample as Adware.Gen.

GridinSoft Anti-Malware detection

GridinSoft already detects this file

The latest ThreatInfo record shows ffmpeg.exe detected as Adware.Gen. You can download GridinSoft Anti-Malware to scan the system and remove this detection if the file is present on your device.

Detection name
Adware.Gen
Last analysis
2023-08-10 23:43:36 (2 years ago)
File hash
f7af7e85a4ae2416ea7e6f6df93bb663
Download Anti-Malware

ffmpeg.exe is a Windows file recorded in the ThreatInfo database. The current detection status is Adware.Gen, based on the latest analysis from 2023-08-10 23:43:36 (2 years ago).

If ffmpeg.exe appears on your computer unexpectedly, treat it as suspicious. Check its location, digital signature, and recent system changes before allowing it to run. A full anti-malware scan is recommended when this file is detected as Adware.Gen.

MD5: f7af7e85a4ae2416ea7e6f6df93bb663
Size: 27 MB
First Published: 2017-05-21 04:03:36 (8 years ago)
Latest Published: 2023-08-10 23:43:36 (2 years ago)
Status: Adware.Gen (on last analysis)
Analysis Date: 2023-08-10 23:43:36 (2 years ago)
ffmpeg.exe detection screenshot

The screenshot is a visual record of a GridinSoft Anti-Malware detection for this sample. Use the hash and metadata above as the primary identifiers when comparing the file on your system.

%localappdata%\free youtube downloader
%programfiles%\free youtube downloader
%localappdata%
%programfiles%
%profile%\stok\local settings\application data
%profile%\ropriƩtaire\local settings\application data
%programfiles%
%localappdata%
%localappdata%
%localappdata%

ThreatInfo has observed ffmpeg.exe in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

10.1%
8.5%
7.1%
6.0%
6.0%
4.1%
3.3%
3.0%
2.7%
2.7%
2.7%
2.5%
2.5%
2.2%
1.9%
1.9%
1.9%
1.6%
1.6%
1.6%
1.4%
1.4%
1.4%
1.1%
1.1%
1.1%
0.8%
0.8%
0.8%
0.8%
0.8%
0.8%
0.8%
0.8%
0.5%
0.5%
0.5%
0.5%
0.5%
0.5%
0.5%
0.5%
0.5%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%

The strongest geographic signal for this file is Hong Kong with 10.1% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 10 52.3%
Windows 7 37.0%
Windows 8.1 7.0%
Windows 8 2.4%
Windows XP 0.8%
Windows Vista 0.5%

The most common operating system signal for ffmpeg.exe is Windows 10 with 52.3% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

ffmpeg.exe is identified as pe for 32 systems. The subsystem is Windows CUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Windows CUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x000014e0

PE Sections:

Name Size of data MD5
.text 21411328 997017c924fe556e5508b8d60a8eee5d
.rotext 112128 d9a47088afe4f0f57da29f18103edc73
.data 293888 6c9c5423691cf95ce7799bb80d4c794a
.rdata 6614528 8835d14b4057bacd9a6c3f93e4989ea9
.rodata 43520 ba26d94e112091b8d9b42a4377622358
.bss 0 00000000000000000000000000000000
.idata 14336 f00972e708dc61e972fb412b7fb8cbc7
.CRT 512 0dc1a858778a93a54445dcc7c4ac4815
.tls 512 baa5c9b725e3bad647e802aa076f9f6c

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information: