amdquickstream.exe

AMD Quick Stream

APPEX NETWORKS CORPORATION

The executable amdquickstream.exe has been detected as malware by 12 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘AppEx Accelerator UI’.
Publisher:
APPEX NETWORKS CORPORATION  (signed and verified)

Product:
AMD Quick Stream

Version:
3.7.16.0

MD5:
c758515d41bafdc28ade8d7ec1263f16

SHA-1:
be8e694e50eb6d7b90aa7830b076529c0ad02588

SHA-256:
0cb4660501791c2324d11c8e1d2a33a182123c468056c25d653beb7584c8c2bf

Scanner detections:
12 / 68

Status:
Malware

Analysis date:
4/4/2025 7:08:08 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Patched-JI
160503-1

AVG
Win32/Slugin.A
2015.0.4604

Dr.Web
Win32.Wplugin.2
9.0.1.05190

Emsisoft Anti-Malware
Win32.SlugIn
11.5.0.6191

ESET NOD32
Win32/Slugin.A virus
8.0.319.0

F-Prot
W32/Slugin.B
4.6.5.141

F-Secure
Win32.SlugIn.A
5.15.96

Kaspersky
Virus.Win32.Slugin
15.0.0.562

Microsoft Security Essentials
Threat.Undefined
1.225.2018.0

File size:
405.2 KB (414,915 bytes)

Product version:
2.0.16.0

Copyright:
© AppEx Networks Corporation. All rights reserved.

Original file name:
AMDQuickStream.exe.mui

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\amd quick stream\amdquickstream.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
10/9/2012 7:00:00 AM

Valid to:
11/9/2013 6:59:59 AM

Subject:
CN=APPEX NETWORKS CORPORATION, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=APPEX NETWORKS CORPORATION, L=MOUNTAIN VIEW, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
329B1B3311AF8EC6925748C282C215BB

File PE Metadata
Compilation timestamp:
4/11/2013 5:40:02 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:/HL9QQuP/0O+RQrQNczDzFJWfqXshOL1Ltz+k5PY8qMyZ4zytbLn:vL5ub+0FJJchOBF+k5PC4zkD

Entry address:
0x2E22C

Entry point:
60, E8, 00, 00, 00, 00, 5B, 81, EB, D0, 48, D9, 01, 83, EC, 74, 8B, EC, 8B, 83, AB, 4B, D9, 01, 89, 45, 00, 8B, 83, B3, 4B, D9, 01, 03, 45, 00, 89, 45, 2C, 8B, 83, B7, 4B, D9, 01, 03, 45, 00, 89, 45, 30, C7, 45, 14, 00, 00, 00, 00, C7, 45, 18, 00, 00, 00, 00, C7, 45, 1C, 00, 00, 00, 00, 8B, 45, 14, FF, 45, 14, 66, 33, C9, 8A, 8C, 03, FF, 4B, D9, 01, 84, C9, 74, 7A, 8B, 45, 1C, 66, 01, 4D, 1C, 03, C3, 05, 13, 4C, D9, 01, 50, 8B, 45, 2C, FF, 10, 85, C0, 0F, 84, 5E, 02, 00, 00, 89, 45, 10, 8B, 45, 1C, 03, C3...
 
[+]

Packer / compiler:
ASPack v1.08.04

Code size:
284 KB (290,816 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
AppEx Accelerator UI

Command:
C:\Program Files\amd quick stream\amdquickstream.exe -h


Remove amdquickstream.exe - Powered by Reason Core Security