Uninstall.exe

qksee

Jinnan Wu

The application Uninstall.exe by Jinnan Wu has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. This is the uninstaller utility registered in the Windows Control Panel for the program qksee by Taiwan Shui Mu Chih Ching Technology Limited.
Publisher:
Qksee Pvt Ltd.  (signed by Jinnan Wu)

Product:
qksee

Version:
3.1.0.0

MD5:
0f0ded4188bdda8bfc25f609374a0ea4

SHA-1:
6378c778d8a57815a27c6e639069c8060c1b7c30

SHA-256:
7422f487f9b424181a0c324a6511b805d6ea64a19ea98def2689963258b41222

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/26/2024 12:49:48 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Elex.Qksee (M)
16.7.30.18

File size:
1.4 MB (1,433,240 bytes)

Product version:
3.1.0.0

Copyright:
Copyright (c) 2015 Qksee Pvt Ltd. All Rights Reserved.

Original file name:
Uninstall.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\qksee\uninstall.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
1/18/2016 2:00:00 AM

Valid to:
1/18/2017 1:59:59 AM

Subject:
CN=Jinnan Wu, OU=Individual Developer, O=No Organization Affiliation, L=Beijing, S=Beijing, C=CN

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
18229C0F3250464B242D5DD76615C1EC

File PE Metadata
Compilation timestamp:
4/8/2016 6:17:27 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:H4QE9OJkbPb7WK6sHzplJLV44bTN9TojYQ6q6YCZA3sAOj1AOKngrYDjY56ptCbL:T+447O8p1c7kr0KJt

Entry address:
0xB6BC2

Code size:
906.5 KB (928,256 bytes)

Program Uninstaller
Program name:
qksee

Display publisher:
Taiwan Shui Mu Chih Ching Technology Limited

Uninstall string:
C:\Program Files (x86)\qksee\uninstall.exe


Remove Uninstall.exe - Powered by Reason Core Security