google_chrome_21.0.1180.89.exe

Chip Downloader

Simply Tech Ltd

One Floor App (Simply Tech/Widdit) distributes and bundles potentially unwanted programs (PUPs) using its OneFloorApp install manager (SimplyInstaller). The application google_chrome_21.0.1180.89.exe, “Chip Downloader Setup ” by Simply Tech has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Widdit Setup installer. With this installer, users are expecting to download Google's Chrome web browser but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
Simply Tech Ltd  (signed and verified)

Product:
Chip Downloader

Description:
Chip Downloader Setup

Version:
6.4

MD5:
93f42b77c46f660fcc494f6a485317dd

SHA-1:
576351e9d5b518ce13ad8dff2f140a9da74966bc

SHA-256:
1a22064c5009d79705c52ef417c70431688b8e7750fdc31003953af67c1a3c55

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/25/2024 12:20:19 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Widdit.SimplyTe.Bundler (M)
16.7.1.15

File size:
853.7 KB (874,192 bytes)

Product version:
6.4

Copyright:
Copyright (c) 2012, www.simplytechltd.com

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Widdit Setup

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\google_chrome_21.0.1180.89.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
4/4/2012 2:00:00 AM

Valid to:
4/5/2014 1:59:59 AM

Subject:
CN=Simply Tech Ltd, O=Simply Tech Ltd, STREET=10 Zarhin street, L=Raanana, S=Raanana, PostalCode=43662, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
1FC78D842B3886BB8D32517578F7489C

File PE Metadata
Compilation timestamp:
7/9/2012 3:41:29 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:q3MjhnX888888888888W888888888887zKWY2fHMiLSH+BAFklHofzLwa9V7Uaor:UMjhR1u+BRHcLH4ZXVneOH

Entry address:
0x16478

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, B8, 52, 41, 00, E8, AC, 03, FF, FF, 33, C0, 55, 68, 45, 6B, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 01, 6B, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, AB, 41, 00, E8, 56, EC, FF, FF, E8, FD, E7, FF, FF, 8D, 55, EC, 33, C0, E8, 7F, 84, FF, FF, 8B, 55, EC, B8, E8, D6, 41, 00, E8, E2, E9, FE, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, E8, D6, 41, 00, B2, 01...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
84 KB (86,016 bytes)

The file google_chrome_21.0.1180.89.exe has been seen being distributed by the following URL.

Remove google_chrome_21.0.1180.89.exe - Powered by Reason Core Security