vlc media player 64 bit - chip-installer.exe

OCSClient

CHIP Digital GmbH

The application vlc media player 64 bit - chip-installer.exe, “CHIP Secured Installer” by CHIP Digital GmbH has been detected as a potentially unwanted program by 18 anti-malware scanners. The program is a setup application that uses the Covus installer. With this installer, users are expecting to download the VideoLAN VLC media player but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
CHIP Digital GmbH  (signed and verified)

Product:
OCSClient

Description:
CHIP Secured Installer

Version:
7.00

MD5:
f253e4fedff01e45643e3cc62d8814fb

SHA-1:
a590643d925d1b53dfa7b5b16162149a672f836c

SHA-256:
1d7d43648aa5e30f7c21054e5905b51061028d7acd502611b772f36b784690dd

Scanner detections:
18 / 68

Status:
Potentially unwanted

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
5/10/2024 12:27:59 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.11671772
355

Agnitum Outpost
Riskware.Agent
7.1.1

Avira AntiVirus
APPL/Downloader.Gen
7.11.175.174

avast!
PUP-gen [PUP]
2014.9-160215

Bkav FE
W32.HfsAdware
1.3.0.6379

Dr.Web
Adware.Downware.3982
9.0.1.046

ESET NOD32
Win32/DownloadSponsor.A potentially unwanted application
10.7.0.302.0

F-Prot
W32/A-4024500f
v6.4.7.1.166

F-Secure
Trojan.Generic.11671772
11.2016-15-02_2

K7 AntiVirus
Unwanted-Program
13.183.13535

McAfee
Artemis!AC5B9B93E630
5600.6489

MicroWorld eScan
Trojan.Generic.11671772
17.0.0.138

NANO AntiVirus
Trojan.Win32.DownloadSponsor.didyel
0.28.6.62995

Norman
DownloadSponsor.M
11.20160215

Panda Antivirus
Trj/Genetic.gen
16.02.15.09

Reason Heuristics
PUP.ChipDigital.Bundler.Covus.Installer.Meta (M)
16.2.15.9

Rising Antivirus
PE:Malware.XPACK-HIE/Heur!1.9C48
23.00.65.16213

Sophos
Generic PUA JJ
4.98

File size:
938.8 KB (961,360 bytes)

Product version:
7.00

Copyright:
Copyright © 2014 Chip Digital GmbH

Original file name:
ocsclient.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Covus

Language:
German (Germany)

Common path:
C:\users\{user}\downloads\vlc media player 64 bit - chip-installer.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
2/25/2014 1:00:00 AM

Valid to:
2/26/2015 12:59:59 AM

Subject:
CN=CHIP Digital GmbH, O=CHIP Digital GmbH, L=Muenchen, S=Bayern, C=DE

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
0D160B8252A4F0A16FE1255FA0A22E2B

File PE Metadata
Compilation timestamp:
6/11/2014 1:47:08 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:X7lw1DxJIe5Qtn3WWbqYb71nZKce03J/Y0XHkKiL7VpoZAI8BKfqnQkIlMdv76Dm:X7m1D8e4ngceQ8Nmn6+rysgpnnc0

Entry address:
0x1684

Entry point:
68, 74, F6, 40, 00, E8, EE, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 90, D9, 08, B9, C3, 1B, 17, 42, BC, 98, BA, 2C, 1A, 1F, 11, D2, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 4F, 43, 53, 43, 6C, 69, 65, 6E, 74, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, FF, CC, 31, 00, 03, 45, 27, 9D, 52, 33, 22, 89, 4C, 85, D8, D8, 25, C5, 86, 63, C3, 48, 93, C2, 28, 03, E5, 8E, 4E, 88, BD, 98, B2, D1, 95, 3A, 6F, 3A, 4F, AD, 33, 99, 66, CF, 11, B7, 0C, 00...
 
[+]

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
100 KB (102,400 bytes)

Remove vlc media player 64 bit - chip-installer.exe - Powered by Reason Core Security