chrome_update.exe

The application chrome_update.exe has been detected as a potentially unwanted program by 3 anti-malware scanners. The program is a setup application that uses the AirInstaller Download Manager installer, however the file is not signed with an authenticode signature from a trusted source. The installer is marketed through download protals and search ads as Google's Chrome web browser but will also install additional software offers which include adware, PUPs and browser toolbars. The file has been seen being downloaded from fixflashplayer.info.
MD5:
bd8d81a7d1da9849da71afa59c2381b4

SHA-1:
f07db70ba78f07f83cb5fd595e24b63674cfa506

SHA-256:
a234daca0608dc30c3346cfcc577056c9edc346e6432ddee29a86c9a91a97837

Scanner detections:
3 / 68

Status:
Potentially unwanted

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
12/26/2024 3:23:18 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Adware-CAH [PUP]
151217-3

Reason Heuristics
PUP.Win.Reputation
15.12.13.21

Sophos
PUA 'AirInstaller'
5.22

File size:
815.9 KB (835,496 bytes)

File type:
Executable application (Win16 EXE)

Bundler/Installer:
AirInstaller Download Manager

Common path:
C:\users\{user}\downloads\chrome_update.exe

File PE Metadata
Compilation timestamp:
10/22/2013 2:50:37 PM

OS version:
5.1

OS bitness:
Win16

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:UqhgoLN73ax6Rwok/id4EaIx9epDViQMwY:UqtGXpid64cpH8

Entry address:
0x25D120

Entry point:
60, BE, 00, B0, 59, 00, 8D, BE, 00, 60, E6, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89...
 
[+]

Entropy:
7.8801

Packer / compiler:
UPX 2.90LZMA

Code size:
780 KB (798,720 bytes)

The file chrome_update.exe has been seen being distributed by the following URL.

Remove chrome_update.exe - Powered by Reason Core Security