arcadewebsetup.exe

The application arcadewebsetup.exe has been detected as a potentially unwanted program by 29 anti-malware scanners. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from d1.arcadeweb.com.
MD5:
d25f309e3c37efeac888413223f19934

SHA-1:
d27b2864ecb57ce1a139fddeda74132f4dfca31c

SHA-256:
12366bd1733c0f81c2b3c8f37b591990f4e47cb38ed61cc24b4dec384b731381

Scanner detections:
29 / 68

Status:
Potentially unwanted

Analysis date:
12/28/2024 5:10:52 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Gamevance.10
5694270

Agnitum Outpost
Adware.ArcadeWeb
7.1.1

AhnLab V3 Security
Adware/Win32.Gamevance
2015.11.29

Avira AntiVirus
ADWARE/ArcadeWeb.cm
8.3.2.4

Arcabit
Trojan.Adware.Gamevance.10
1.0.0.624

avast!
Win32:Gamevance-DC [PUP]
151004-0

AVG
Adware Generic5.BVP
2015.0.4460

Bitdefender
Gen:Variant.Adware.Gamevance.10
1.0.20.1665

Bkav FE
HW32.Packed
1.3.0.7383

Clam AntiVirus
Adware.GameVance-389
0.98/21110

Comodo Security
ApplicUnwnt.Win32.AdWare.GameVance.BUB
23677

Dr.Web
Trojan.Click2.48303
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Adware.Gamevance.10
10.0.0.5366

ESET NOD32
Win32/Adware.Gamevance.CF potentially unwanted application
7.0.302.0

F-Prot
W32/GameVance.S.gen
4.6.5.141

F-Secure
Gen:Variant.Adware.Gamevance
11.2015-29-11_1

G Data
Gen:Variant.Adware.Gamevance.10
15.11.25

IKARUS anti.virus
not-a-virus:AdWare.Win32.ArcadeWeb
t3scan.1.9.5.0

K7 AntiVirus
Adware
13.212.17998

Kaspersky
not-a-virus:AdWare.Win32.ArcadeWeb
15.0.0.543

MicroWorld eScan
Gen:Variant.Adware.Gamevance.10
16.0.0.999

NANO AntiVirus
Riskware.Win32.ArcadeWeb.cuclfj
0.30.26.4751

Norman
Gen:Variant.Adware.Gamevance.10
28.10.2015 12:55:53

nProtect
Trojan-Clicker/W32.Agent.1041408
15.11.27.01

Qihoo 360 Security
QVM10.1.Malware.Gen
1.0.0.1077

Trend Micro House Call
HV_GAMEVANCE_BL2104AE.TOMC
7.2.333

Vba32 AntiVirus
AdWare.ArcadeWeb
3.12.26.4

VIPRE Antivirus
Threat.4139338
45468

Zillya! Antivirus
Adware.ArcadeWeb.Win32.50
2.0.0.2536

File size:
1017 KB (1,041,408 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\arcadewebsetup.exe

File PE Metadata
Compilation timestamp:
4/12/2012 11:09:08 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:rA8fAW5Loye8PZWTruaw94sm3nO9XXxy7OWgTDp5aOsfIhrGay:rl2ye8PZWTKb9PbkKWY5sg

Entry address:
0x25C83

Entry point:
E8, FB, 68, 00, 00, E9, 78, FE, FF, FF, 6A, 0C, 68, 30, 38, 44, 00, E8, 43, E6, FF, FF, 6A, 0E, E8, 7E, 2E, 00, 00, 59, 83, 65, FC, 00, 8B, 75, 08, 8B, 4E, 04, 85, C9, 74, 2F, A1, E8, 87, 4F, 00, BA, E4, 87, 4F, 00, 89, 45, E4, 85, C0, 74, 11, 39, 08, 75, 2C, 8B, 48, 04, 89, 4A, 04, 50, E8, 99, E3, FF, FF, 59, FF, 76, 04, E8, 90, E3, FF, FF, 59, 83, 66, 04, 00, C7, 45, FC, FE, FF, FF, FF, E8, 0A, 00, 00, 00, E8, 32, E6, FF, FF, C3, 8B, D0, EB, C5, 6A, 0E, E8, 49, 2D, 00, 00, 59, C3, 55, 8B, EC, 83, EC, 04...
 
[+]

Entropy:
7.7647  (probably packed)

Code size:
205 KB (209,920 bytes)

The file arcadewebsetup.exe has been seen being distributed by the following URL.

Remove arcadewebsetup.exe - Powered by Reason Core Security