quickmacro6.exe

The application quickmacro6.exe has been detected as a potentially unwanted program by 12 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from www.qmacro.com.
MD5:
75baeac27edb446cd940e106e6449737

SHA-1:
0e9118a29aebb280f772cfeca2c2a6a635531797

SHA-256:
5e3b1053f5d8f6dc4a9e40ba3f45102a908da6ef8f9cf8c7735c92c5a3c17969

Scanner detections:
12 / 68

Status:
Potentially unwanted

Analysis date:
8/16/2025 1:16:06 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Malware-gen
2014.9-151109

AVG
Generic5
2016.0.2930

Comodo Security
UnclassifiedMalware
23553

Dr.Web
Win32.HLLW.Autoruner2.19999
9.0.1.0313

ESET NOD32
Win32/Adware.VrBrothers.AA potentially unwanted
9.12533

IKARUS anti.virus
Win32.Malware
t3scan.1.9.5.0

K7 AntiVirus
Adware
13.212.17783

NANO AntiVirus
Riskware.Win32.Autoruner2.dtlnff
0.30.26.4437

Rising Antivirus
PE:Trojan.Win32.Generic.135F1748!324998984 [F]
23.00.65.151107

Sophos
Generic PUA AO (PUA)
4.98

VIPRE Antivirus
Trojan.Win32.Generic
45086

ViRobot
Trojan.Win32.S.Agent.2264064.A[h]
2014.3.20.0

File size:
2.1 MB (2,184,780 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\downloads\quickmacro6.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
49152:IK1SXOfCvgt0RL4MqT22+2NxzIPUicTwRWxMVCltKd:kOkgiLr2+2NBI/MwawCw

Entry point:
50, 4B, 03, 04, 14, 00, 00, 00, 08, 00, 45, 53, A8, 3C, 7E, 6D, 13, 9A, A8, 55, 21, 00, 00, 8C, 22, 00, 0F, 00, 00, 00, 71, 75, 69, 63, 6B, 6D, 61, 63, 72, 6F, 36, 2E, 65, 78, 65, EC, FD, 0B, 7C, 54, D5, D5, 00, 8E, 9E, C9, 4C, 92, 01, 06, 66, 80, 01, 06, 89, 12, 65, 54, 34, A8, D1, 01, 4D, 1C, D0, 04, 32, 21, 28, 81, 49, 42, 66, 88, 90, 44, 2B, A6, E9, D4, 56, 0A, 73, 00, 2B, 81, C4, 93, D1, 1C, 36, A7, D2, 56, 5A, DB, 6A, 2B, 45, 5B, FA, F8, 5A, DA, 0A, C6, FA, 4A, 08, 66, C2, 43, E4, A5, A2, 50, 8D, 9A...
 
[+]

The file quickmacro6.exe has been seen being distributed by the following URL.

Remove quickmacro6.exe - Powered by Reason Core Security