ccleaner - chip-downloader.exe

OCSClient

CHIP Digital GmbH

The application ccleaner - chip-downloader.exe, “CHIP Secured Installer” by CHIP Digital GmbH has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Covus installer. With this installer, users are expecting to download the free Piriform CCleaner but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
CHIP Digital GmbH  (signed and verified)

Product:
OCSClient

Description:
CHIP Secured Installer

Version:
7.00

MD5:
b3930aa602019f662c79fa981c15717e

SHA-1:
fd31dd6947a23972ad47facf468215574a789031

SHA-256:
81f2e69da02c1ddb8db3cbb21eadf7ec5bfdccf2ddc3e85c5cf23dedf4ea4a6e

Scanner detections:
1 / 68

Status:
Potentially unwanted

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/19/2024 10:24:19 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Win32.Generic
16.1.30.10

File size:
600.4 KB (614,792 bytes)

Product version:
7.00

Copyright:
Copyright © 2014 Chip Digital GmbH

Original file name:
ocsclient.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Covus

Language:
English (United States)

Common path:
C:\users\{user}\downloads\ccleaner - chip-downloader.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
1/8/2014 1:00:00 AM

Valid to:
1/9/2015 12:59:59 AM

Subject:
CN=CHIP Digital GmbH, O=CHIP Digital GmbH, STREET=St.-Martin-Str. 66, L=Munich, S=Bavaria, PostalCode=81541, C=DE

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00F0BAAB0E388698D0A2DD8D584AF69876

File PE Metadata
Compilation timestamp:
1/15/2014 3:02:34 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:HKWlw1DxDlASIAfCEv2YUMNJlaJuNlK17Y4c83fhysVufBn597NX2:H7lw1Dx55zfXeYU43fiysgfBnnl2

Entry address:
0x1620

Entry point:
68, 08, F6, 40, 00, E8, EE, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 6C, 51, CB, CF, 4C, 39, 05, 47, 9B, A7, 1A, 8F, 7C, 78, 87, FE, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 2D, 43, 30, 30, 30, 2D, 4F, 43, 53, 43, 6C, 69, 65, 6E, 74, 00, 34, 36, 7D, 23, 32, 2E, 00, 00, 00, 00, FF, CC, 31, 00, 03, 76, 0F, D7, 04, EA, F7, DC, 4B, 85, 6D, 25, A8, 40, C8, C5, 30, F6, 07, 2C, 55, A5, 90, CA, 4A, A7, 78, 6F, 37, 88, E2, A6, 56, 3A, 4F, AD, 33, 99, 66, CF, 11, B7, 0C, 00...
 
[+]

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
96 KB (98,304 bytes)

Remove ccleaner - chip-downloader.exe - Powered by Reason Core Security