toparcadehitsuninstaller.exe

EpicPlay, LLC

The application toparcadehitsuninstaller.exe by EpicPlay has been detected as adware by 3 anti-malware scanners. The file has been seen being downloaded from toparcadehits.com.
Publisher:
EpicPlay, LLC  (signed and verified)

MD5:
5c1a6b89478d093ca0b998f0c28b8609

SHA-1:
3417bffc60e7be388119129b9304b04b99f20098

SHA-256:
dc50f1a949f9b409e170a75dd0b706052c28cadd43760f0a6aaf19b883737182

Scanner detections:
3 / 68

Status:
Adware

Analysis date:
5/8/2024 3:59:32 AM UTC  (today)

Scan engine
Detection
Engine version

Malwarebytes
Adware.GameVance
v2014.07.19.07

Reason Heuristics
PUP.EpicPlay.Y
14.7.19.19

VIPRE Antivirus
GameVance
22104

File size:
134.3 KB (137,560 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\toparcadehitsuninstaller.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
10/3/2012 7:01:13 AM

Valid to:
10/2/2013 7:37:01 PM

Subject:
CN="EpicPlay, LLC", O="EpicPlay, LLC", L=Irvine, S=CA, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
078B090DE98B9D

File PE Metadata
Compilation timestamp:
3/25/2013 8:42:55 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:xd3onbN2gWswdpw8v+DGGdjaY4+nL8wTGQzy8Z:oNSi9DG1Y4RA4k

Entry address:
0x5357

Entry point:
E8, 4C, 4F, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, 7D, 08, 00, 74, 2D, FF, 75, 08, 6A, 00, FF, 35, D8, BF, 41, 00, FF, 15, 94, 50, 41, 00, 85, C0, 75, 18, 56, E8, 49, EE, FF, FF, 8B, F0, FF, 15, 38, 50, 41, 00, 50, E8, F9, ED, FF, FF, 59, 89, 06, 5E, 5D, C3, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 08, B6, 41, 00, 89, 0D, 04, B6, 41, 00, 89, 15, 00, B6, 41, 00, 89, 1D, FC, B5, 41, 00, 89, 35, F8, B5, 41, 00, 89, 3D, F4, B5, 41, 00, 66, 8C, 15, 20, B6, 41, 00, 66, 8C, 0D, 14, B6, 41, 00...
 
[+]

Entropy:
6.2949

Code size:
80 KB (81,920 bytes)

The file toparcadehitsuninstaller.exe has been seen being distributed by the following URL.

Remove toparcadehitsuninstaller.exe - Powered by Reason Core Security