uninstall.exe

QUICKREF

This is part of the InfoAtoms browser extension which will display variopus forms of advertising in the web browser by injecting new ads such as banner, text-links and search results. The application uninstall.exe by QUICKREF has been detected as adware by 15 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This is the uninstaller utility registered in the Windows Control Panel for the program Quick Ref 1.10.0.12 by Quick Ref.
Publisher:
Quick Ref  (signed by QUICKREF)

Product:
Quick Ref

Description:
Quick Ref Setup

Version:
1.10.0.12

MD5:
b3c87acb2956e53add49c047b33530bf

SHA-1:
608751386ff5cd8058b78b0aed78756bfb812b63

SHA-256:
13658880d010659d7290b02a7e87728ec83735645537d0d247f370036075cc6e

Scanner detections:
15 / 68

Status:
Adware

Analysis date:
1/12/2025 5:36:11 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Vitruvian.J
676

AhnLab V3 Security
PUP/Win32.Vitruvian
2015.03.31

AVG
Generic
2016.0.3154

Baidu Antivirus
Adware.Win32.Vitruvian
4.0.3.15331

Bitdefender
Adware.Vitruvian.J
1.0.20.450

Bkav FE
W32.HfsAdware
1.3.0.6379

Dr.Web
Adware.Plugin.274
9.0.1.090

Emsisoft Anti-Malware
Adware.Vitruvian
8.15.03.31.05

F-Secure
Adware.Vitruvian.J
11.2015-31-03_3

G Data
Adware.Vitruvian
15.3.25

Kaspersky
not-a-virus:AdWare.Win32.Vitruvian
14.0.0.2264

Malwarebytes
PUP.Optional.QuickRef.A
v2015.03.31.05

MicroWorld eScan
Adware.Vitruvian.J
16.0.0.270

nProtect
Adware.Vitruvian.J
15.03.30.01

Reason Heuristics
PUP.Installer.InfoAtoms
15.3.31.5

File size:
308.9 KB (316,296 bytes)

Product version:
1.10.0.12

Copyright:
(c) 2014 Quick Ref

Original file name:
quickref-setup.exe

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\Program Files\quickref_1.10.0.12\uninstall.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
9/5/2014 6:50:56 AM

Valid to:
9/5/2016 6:50:56 AM

Subject:
E=Support@quickrefapp.com, CN=QUICKREF, O=QUICKREF, L=Dover, S=DE, C=US

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11219B2E795F5F7739842A0C0B7E7F9F1A08

File PE Metadata
Compilation timestamp:
12/6/2009 11:52:06 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:KS6WkGQXR9ts8U0yr1owWBOMvMSEMF7hR:KbRwtuwWUmnp

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 6F, 44, 00, E8, 09, 2C, 00, 00, A3, A4, 6E, 44, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, 9C, 42, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 2E, 44, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, F0, 46, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Entropy:
6.8561

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

Program Uninstaller
Program name:
Quick Ref 1.10.0.12

Display publisher:
Quick Ref

Display version:
1.10.0.12

Uninstall string:
C:\Program Files\QuickRef_1.10.0.12\Uninstall.exe


Remove uninstall.exe - Powered by Reason Core Security