PUA

PUAAdvertising:Win32/ArcadeCandy malicious file

Malware Removal

The PUAAdvertising:Win32/ArcadeCandy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUAAdvertising:Win32/ArcadeCandy virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine PUAAdvertising:Win32/ArcadeCandy?


File Info:

name: 8A62F08B30E0A2F82E7E.mlw
path: /opt/CAPEv2/storage/binaries/6e22e94b41932de3d0caa7c5edbfb6b511b2d9c646a3f7d0ea123e06f3d3d7d3
crc32: 0EC9F7E1
md5: 8a62f08b30e0a2f82e7eb3cfbf26364f
sha1: 895a6ec9e8f3f2b5259af301b06e892f2e13c6da
sha256: 6e22e94b41932de3d0caa7c5edbfb6b511b2d9c646a3f7d0ea123e06f3d3d7d3
sha512: 0795e81d2d7ae84cec85a60799b2c11ae7ae33e07154c739f1d8ca9e19d304261da17db5310c7474ad6c544735d77c7d069a96d7deaf2496c6bbab756d38d007
ssdeep: 24576:h4PjhpBPRXdyxQYrIDymaTZrIDR1gmILjhsJwMMwZ2AKljID:h47h/lFDB1HIL14MuPKFi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FC45026771C08277C6A302305AE9F992B23AF83855E5544736D4E37C4BB3EA5CB3522B
sha3_384: f276205c3f57e489a5cea9be9b73eddf8b8a7a8845f42fa1b82104e0d02cb16ea2aa911c2a2233e16a6723906b7ac55c
ep_bytes: e830370000e979feffff6a0c68a0dc42
timestamp: 2012-06-20 12:42:33

Version Info:

0: [No Data]

PUAAdvertising:Win32/ArcadeCandy also known as:

BkavW32.AIDetectMalware
LionicAdware.Win32.Gamevance.lzzb
Elasticmalicious (high confidence)
MicroWorld-eScanAdware.GameVance.BG
ALYacAdware.GameVance.BG
MalwarebytesGeneric.Adware.Agent.DDS
SangforPUA.Win32.Sign.a
K7AntiVirusAdware ( 004c36a81 )
Cybereasonmalicious.b30e0a
VirITAdware.Win32.GameVance.144, is
SymantecSMG.Heur!gen
tehtrisGeneric.Malware
APEXMalicious
ClamAVWin.Adware.609820-1
ViRobotAdware.Gamevance.1272776.DNF
ZillyaAdware.GamevanceCRTD.Win32.7220
Trapminemalicious.high.ml.score
SophosGeneric ML PUA (PUA)
IkarusAdWare.GameVance
AviraADWARE/Adware.Gen7
Antiy-AVLGrayWare[AdWare]/Win32.Gamevance
KingsoftWin32.Troj.Undef.a
MicrosoftPUAAdvertising:Win32/ArcadeCandy
SUPERAntiSpywareAdware.GameVance
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.AdLoad.R222747
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002C0OBN24
TencentMalware.Win32.Gencirc.10b65d26
SentinelOneStatic AI – Malicious PE
FortinetAdware/Gamevance
CrowdStrikewin/grayware_confidence_100% (W)
alibabacloudAdware:Win/ArcadeCandy.A

How to remove PUAAdvertising:Win32/ArcadeCandy?

PUAAdvertising:Win32/ArcadeCandy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment