Home Possibly Unwanted Program PUP.EpicPlay

PUP.EpicPlay

Posted: December 22, 2014

Threat Metric

Ranking: 19,689
Threat Level: 1/10
Infected PCs: 43,198
First Seen: December 22, 2014
Last Seen: February 28, 2025
OS(es) Affected: Windows

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%SYSTEMDRIVE%\AdwCleaner\Quarantine\C\Users\<username>\AppData\Local\ArcadeGiant\cat\CatWSPrx.dll.vir File name: CatWSPrx.dll.vir
Size: 330.46 KB (330464 bytes)
MD5: a1e27f7b1556415737bf1449026433cc
Detection count: 1,998
Mime Type: unknown/vir
Path: %SYSTEMDRIVE%\AdwCleaner\Quarantine\C\Users\<username>\AppData\Local\ArcadeGiant\cat\CatWSPrx.dll.vir
Group: Malware file
Last Updated: April 23, 2024
%WINDIR%\System32\MRT\DD51B914-25C9-427C-BEC8-DA8BB2597585\FilesStash\5847BAD3-EE64-A5D9-08A8-C0E57BC9A7E4 File name: 5847BAD3-EE64-A5D9-08A8-C0E57BC9A7E4
Size: 42.6 KB (42600 bytes)
MD5: 27b6a8a62199af49287e9fcccbe0148e
Detection count: 1,944
Path: %WINDIR%\System32\MRT\DD51B914-25C9-427C-BEC8-DA8BB2597585\FilesStash\5847BAD3-EE64-A5D9-08A8-C0E57BC9A7E4
Group: Malware file
Last Updated: September 29, 2022
%SYSTEMDRIVE%\AdwCleaner\quarantine\files\zjqezvnshvsamzxfuvbykdrhioivmrey\CatWs\CatWSw864.sys File name: CatWSw864.sys
Size: 42.6 KB (42600 bytes)
MD5: 8cb1b67bcbca8bcb9914e535bd397469
Detection count: 569
File type: System file
Mime Type: unknown/sys
Path: %SYSTEMDRIVE%\AdwCleaner\quarantine\files\zjqezvnshvsamzxfuvbykdrhioivmrey\CatWs\CatWSw864.sys
Group: Malware file
Last Updated: August 8, 2021
%WINDIR%\System32\0fec54b10ce802a782c389d485480ad8\767b32169a9cb91d800204190ab142c7 File name: 767b32169a9cb91d800204190ab142c7
Size: 323.78 KB (323784 bytes)
MD5: f3585f5eb5f3a28bc5316449b61d8087
Detection count: 417
Path: %WINDIR%\System32\0fec54b10ce802a782c389d485480ad8\767b32169a9cb91d800204190ab142c7
Group: Malware file
Last Updated: February 27, 2021
%WINDIR%\system32\CatWSPrx.dll File name: CatWSPrx.dll
Size: 330.8 KB (330808 bytes)
MD5: 3e868bdbee8c31554fe5425c57661182
Detection count: 1
File type: Dynamic link library
Mime Type: unknown/dll
Path: %WINDIR%\system32
Group: Malware file
Last Updated: April 1, 2016

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{381F1945-55BB-4760-9050-726888B22C0F}{56E4076B-A42B-4745-BA35-34DA8AC4C2F2}{7D5716DC-76B4-4421-908C-12A6E587F1C3}{81699637-2BD9-4528-BD30-B066CB20E4A6}{B351B62C-A449-4E8B-9A81-9FEB79C24384}{BE1C29BB-72DB-4B0D-B922-609CF2A024B9}{BF188B93-ABA5-4F5B-8AE4-22D9B15ECF12}{C6E0D1F4-DFEB-49EA-BB26-4755A0023404}{E1897EF4-D58B-4871-8D38-65E04BC76E53}File name without pathb4.epicplay[1].xmlhttp_b4.epicplay.com_0.localstoragehttp_b4.epicplay.com_0.localstorage-journalHKEY..\..\..\..{RegistryKeys}Software\AppDataLow\ePlayConfSoftware\Microsoft\Internet Explorer\DOMStorage\b4.epicplay.comSoftware\Microsoft\Internet Explorer\DOMStorage\epicplay.comSOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{56E4076B-A42B-4745-BA35-34DA8AC4C2F2}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{18488039-9344-4dcf-A9B0-72AFA058EE44}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BF188B93-ABA5-4F5B-8AE4-22D9B15ECF12}SOFTWARE\MozillaPlugins\npEpicPlayDisplayHostSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{56E4076B-A42B-4745-BA35-34DA8AC4C2F2}SOFTWARE\Wow6432Node\MozillaPlugins\npEpicPlayDisplayHostHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}EpicPlay

Additional Information

The following directories were created:
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\plccnhhjonaiagjelpfkclblmlppjcik%PROGRAMFILES%\EpicPlay%PROGRAMFILES(X86)%\EpicPlay
Loading...