quickshare.exe

Linkury

This is part of the Linkury monetization software, a web browser toolbar used to 'hijack' a user's search in order to collect revenues. The application quickshare.exe by Linkury has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Browser Infrastructure Helper’. This file is typically installed with the program QuickShare by Linkury Inc. which is a potentially unwanted software program.
Publisher:
Smartbar  (signed by Linkury)

Product:
Smartbar

Version:
1.6.1.905

MD5:
2c3239b5355babf5e575ddc1b3f573f7

SHA-1:
b935c71132b8d077a249f39a96c6b7d82f51952e

SHA-256:
7edd296ee58f2599454970c6ec4097faa6987d9f5b851b9b4cb118b50f7d1e6a

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/23/2024 4:34:50 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Linkury (M)
17.2.28.7

File size:
19.8 KB (20,248 bytes)

Product version:
1.6.1.905

Original file name:
Smartbar.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\smartbar\application\quickshare.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
4/12/2012 9:00:00 AM

Valid to:
5/12/2015 8:59:59 AM

Subject:
CN=Linkury, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Linkury, L=Ramat Gan, S=Israel, C=IL

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
77A9B89A06B99100955A838E8BB46FF8

File PE Metadata
Compilation timestamp:
4/2/2013 9:15:18 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

Entry address:
0x4DAE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 01, 00, 10, 00, 00, 00, 18, 00, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 01, 00, 01, 00, 00, 00, 30, 00...
 
[+]

Entropy:
6.2776

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
11.5 KB (11,776 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Browser Infrastructure Helper

Command:
C:\users\{user}\appdata\local\smartbar\application\quickshare.exe startup


The file quickshare.exe has been discovered within the following program.

QuickShare  by Linkury Inc.
QuickShare, also know as Smartbar, is an auto-starting program that is typically bundled with various shareware software. It displays advertising and is designed to run when Windows boots up.
www.linkury.com/faq/NS/faq.aspx?c=QuickShare
79% remove it
 
Powered by Should I Remove It?

Remove quickshare.exe - Powered by Reason Core Security