firefox - chip-installer.exe

OCSClient

CHIP Digital GmbH

The application firefox - chip-installer.exe, “CHIP Secured Installer” by CHIP Digital GmbH has been detected as a potentially unwanted program by 9 anti-malware scanners. The program is a setup application that uses the Covus installer. The installer is marketed through download protals and search ads as the free Mozilla Firefox web browser but will also install additional software offers which include adware, PUPs and browser toolbars.
Publisher:
CHIP Digital GmbH  (signed and verified)

Product:
OCSClient

Description:
CHIP Secured Installer

Version:
7.00

MD5:
92b765846b888213cdd5fdfa2c92490e

SHA-1:
2616fed6a5d8a7863b48f21300cd546dde2c9427

SHA-256:
161e6b84568a10416df522288aff29e9dbf02d5051b79c89640c3f5928bdac0e

Scanner detections:
9 / 68

Status:
Potentially unwanted

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/19/2024 5:31:57 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Agent
7.1.1

Avira AntiVirus
TR/Dropper.Gen
7.11.30.172

avast!
PUP-gen [PUP]
141214-1

ESET NOD32
Win32/DownloadSponsor.A potentially unwanted application
7.0.302.0

F-Prot
W32/A-59b09341
v6.4.7.1.166

K7 AntiVirus
Unwanted-Program
13.188.14410

McAfee
Artemis!DF1EE5392801
5600.6909

Panda Antivirus
Trj/Genetic.gen
14.12.22.05

Rising Antivirus
PE:Malware.XPACK-HIE/Heur!1.9C48
23.00.65.141220

File size:
806.8 KB (826,192 bytes)

Product version:
7.00

Copyright:
Copyright © 2014 Chip Digital GmbH

Original file name:
ocsclient.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Covus

Language:
German (Germany)

Common path:
C:\users\{user}\downloads\firefox - chip-installer.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
2/25/2014 1:00:00 AM

Valid to:
2/26/2015 12:59:59 AM

Subject:
CN=CHIP Digital GmbH, O=CHIP Digital GmbH, L=Muenchen, S=Bayern, C=DE

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
0D160B8252A4F0A16FE1255FA0A22E2B

File PE Metadata
Compilation timestamp:
7/22/2014 1:41:41 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:sKWlw1DxmCjN6Q1k9Qi23RGHQPcoU/cagPCY6Dz6MnOhdqreL4tze/fZfwTCXki1:s7lw1DxBjc2JU/PO7tfIZi0oq7e74/I

Entry address:
0x1674

Entry point:
68, 64, F6, 40, 00, E8, EE, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 4D, 12, 86, 15, A0, 2F, A2, 42, 9C, 72, AC, 7D, EB, A8, B9, 27, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 4F, 43, 53, 43, 6C, 69, 65, 6E, 74, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, FF, CC, 31, 00, 03, 66, 78, A6, D1, AB, 85, C9, 4A, 97, 80, 2E, 33, DD, C3, DE, 9A, 29, 4F, B1, 98, A2, 0E, 58, 44, 92, DD, D5, 2E, 24, C8, B5, C7, 3A, 4F, AD, 33, 99, 66, CF, 11, B7, 0C, 00...
 
[+]

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
100 KB (102,400 bytes)

Remove firefox - chip-installer.exe - Powered by Reason Core Security