arcadecandygames.exe

Arcade Candy

The application arcadecandygames.exe by Arcade Candy has been detected as adware by 22 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from d1.arcadecandy.com.
Publisher:
Arcade Candy  (signed and verified)

MD5:
a8dd29057998f66697a30d1c6013ae1c

SHA-1:
4fda8b2d7458a7f794b521214c273b0bba84834a

SHA-256:
ed95a22281ba6d937418a82ad42ece5c1dae75946cd869fae43b2c1e76b4062d

Scanner detections:
22 / 68

Status:
Adware

Analysis date:
4/25/2024 8:47:53 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.GameVance.BG
676

Agnitum Outpost
PUA.Gamevance
7.1.1

Avira AntiVirus
ADWARE/Adware.Gen7
3.6.1.96

avast!
Win32:Adware-gen [Adw]
150319-1

Bitdefender
Adware.GameVance.BG
1.0.20.445

Clam AntiVirus
Win.Adware.Gamevance-47049
0.98/21511

Dr.Web
Adware.GameVance.144, Adware.GameVance.140
9.0.1.05190

Emsisoft Anti-Malware
Adware.GameVance.BG
8.15.03.30.10

ESET NOD32
Win32/Adware.Gamevance.DD potentially unwanted application
9.7.0.302.0

F-Prot
W32/GameVance.X.gen
v6.4.6.5.141

F-Secure
Adware.GameVance.BG
11.2015-30-03_2

G Data
Adware.GameVance.BG
15.3.24

herdProtect (fuzzy)
2015.7.4.20

Malwarebytes
PUP.Optional.AracadeCandy.A
v2015.03.30.10

MicroWorld eScan
Adware.GameVance.BG
16.0.0.267

NANO AntiVirus
Riskware.Win32.Gamevance.ddtmsx
0.30.8.659

Norman
Adware.GameVance.BG
03.12.2014 13:20:04

nProtect
Adware.GameVance.BG
14.08.08.01

Reason Heuristics
PUP.EpicPlay
15.3.30.22

Rising Antivirus
PE:Adware.Gamevance!6.1E31
23.00.65.15328

VIPRE Antivirus
Threat.4139338
31208

Zillya! Antivirus
Adware.Gamevance.Win32.11533
2.0.0.2122

File size:
1.5 MB (1,572,296 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\arcadecandygames.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
3/22/2012 7:00:00 PM

Valid to:
3/23/2013 6:59:59 PM

Subject:
CN=Arcade Candy, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Arcade Candy, L=Irvine, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
43CB896C9AC049E1F87B8C09D8A61299

File PE Metadata
Compilation timestamp:
10/31/2012 3:39:35 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:02zsRzBPRXdyxQYrIDymaTZrIDR1gmILjhsJwMMwZ2TAbEr1ggIifNKNRf9wx:024RtlFDB1HIL14MuqiEWs1KNfo

Entry address:
0xF459

Entry point:
E8, 30, 37, 00, 00, E9, 79, FE, FF, FF, 6A, 0C, 68, B0, 40, 43, 00, E8, 3D, 13, 00, 00, 6A, 0E, E8, 3C, 08, 00, 00, 59, 83, 65, FC, 00, 8B, 75, 08, 8B, 4E, 04, 85, C9, 74, 2F, A1, 98, B3, 43, 00, BA, 94, B3, 43, 00, 89, 45, E4, 85, C0, 74, 11, 39, 08, 75, 2C, 8B, 48, 04, 89, 4A, 04, 50, E8, 76, EB, FF, FF, 59, FF, 76, 04, E8, 6D, EB, FF, FF, 59, 83, 66, 04, 00, C7, 45, FC, FE, FF, FF, FF, E8, 0A, 00, 00, 00, E8, 2C, 13, 00, 00, C3, 8B, D0, EB, C5, 6A, 0E, E8, 07, 07, 00, 00, 59, C3, CC, CC, CC, CC, CC, CC...
 
[+]

Entropy:
7.8290  (probably packed)

Code size:
161 KB (164,864 bytes)

The file arcadecandygames.exe has been seen being distributed by the following URL.

Remove arcadecandygames.exe - Powered by Reason Core Security