Home Malware Programs Adware Arcade Candy

Arcade Candy

Posted: June 22, 2015

Threat Metric

Ranking: 3,117
Threat Level: 2/10
Infected PCs: 43,950
First Seen: April 23, 2013
Last Seen: October 16, 2023
OS(es) Affected: Windows

Arcade Candy is a Potentially Unwanted Program that may modify your browser automatically. Although Arcade Candy may be associated with browser hijackings, Arcade Candy also may show some of the symptoms of adware, such as loading pop-ups or other advertisements. Unless you have pressing reasons for doing otherwise, most PC users should consider deleting Arcade Candy with specialized PC security tools for guaranteeing both the safety and optimal performance of their Web browsers.

The Candy Leaving an Aftertaste of Advertisements

Arcade Candy is a browser add-on promoted by arcadecandy.com as a utility for playing its library of games. However, malware experts have seen websites using marketing and downloading models that aren't necessarily up front about Arcade Candy's installation and ensuing modification of the PC's Web browser. Despite the popularity of Chrome with recent adware products, only Internet Explorer, along with Firefox, have been confirmed as being compatible targets of the Arcade Candy installations.

Arcade Candy, once installed, may monitor your browsing activity, such as which search terms you use. Besides taking up your PC's resources to record your general online behavior, Arcade Candy also may inject pop-ups and other advertisements into the content of each Web page your browser loads. Besides pop-up windows, Arcade Candy's advertisement formats may include hyperlink-based keywords, full-page transitional advertisements and banners.

Arcade Candy has been in circulation for years, much like the campaign behind its website gaming company. Although Arcade Candy isn't classifiable as threatening software, malware analysts do occasionally see Arcade Candy promoting threatening advertisement content. The last known case of such attacks involved Arcade Candy advertisements promoting Ilitili.com, a phishing website using outdated Yahoo notifications. The domain, which may use misleading methods to collect information from any Web traffic, still is operational at the time of this article's authorship.

Keeping Arcade Candy from Leaving Your Browser Broke

Arcade Candy may be a long-running adware program associated with some theoretically benign gaming services, but Arcade Candy also is a confirmed source of potential attacks against your PC. Apart from that potentially significant security issue, malware analysts also tend to find correlations between adware like Arcade Candy and general browser problems. The most common of these problems may include unusually high loading times, hijacked search results or problems accessing various Web pages. Nonetheless, most anti-adware programs should be able to detect and remove Arcade Candy when you grant them the opportunity.

Online gaming sites also may promote their products on advertising networks not directly related to the company in question. Before you install a game from a banner or other, potentially risky download source, you may want to read the terms of service. In some cases, you may notice being asked to install products like Arcade Candy along with the game of your choice.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%SYSTEMDRIVE%\Users\<username>\AppData\Local\ArcadeCandy\candyUpdater.exe File name: candyUpdater.exe
Size: 77.99 KB (77992 bytes)
MD5: e22a1a74e015d10c95820800c5379767
Detection count: 7,071
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Local\ArcadeCandy\candyUpdater.exe
Group: Malware file
Last Updated: October 11, 2022
%SYSTEMDRIVE%\Old BUs\C Drive\AppData\Local\ArcadeCandy\candyEX.dll File name: candyEX.dll
Size: 131.24 KB (131240 bytes)
MD5: 37534d800b4f74a5cea4a68e9ff2e791
Detection count: 2,504
File type: Dynamic link library
Mime Type: unknown/dll
Path: %SYSTEMDRIVE%\Old BUs\C Drive\AppData\Local\ArcadeCandy\candyEX.dll
Group: Malware file
Last Updated: October 11, 2022
%SYSTEMDRIVE%\Users\<username>\AppData\Local\ArcadeCandy\candyEXPE.dll File name: candyEXPE.dll
Size: 124.07 KB (124072 bytes)
MD5: eeb02e2c137325eda05df55c1d2c58a5
Detection count: 848
File type: Dynamic link library
Mime Type: unknown/dll
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Local\ArcadeCandy\candyEXPE.dll
Group: Malware file
Last Updated: October 11, 2022
C:\Users\<username>\AppData\Local\ArcadeCandy\candyUpdater.exe File name: candyUpdater.exe
Size: 77.99 KB (77992 bytes)
MD5: bb7a5de770e197c59996790e98edfb4d
Detection count: 820
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\ArcadeCandy\candyUpdater.exe
Group: Malware file
Last Updated: November 2, 2022
%LOCALAPPDATA%\ArcadeCandy\candyUpdater.exe File name: candyUpdater.exe
Size: 85.16 KB (85160 bytes)
MD5: 864ac8b2ff02daeeeed79089a96ac0c0
Detection count: 239
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\ArcadeCandy
Group: Malware file
Last Updated: June 1, 2020
%SYSTEMDRIVE%\Users\<username>\AppData\Local\ArcadeCandy\candyRemove.exe File name: candyRemove.exe
Size: 155.3 KB (155304 bytes)
MD5: 36903d6f393b2033c7ee5b0f08a3b5f1
Detection count: 138
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Local\ArcadeCandy\candyRemove.exe
Group: Malware file
Last Updated: October 11, 2022
%SYSTEMDRIVE%\Users\<username>\AppData\Local\ArcadeCandy\ACGames.exe File name: ACGames.exe
Size: 408.23 KB (408232 bytes)
MD5: d8148a740c5b6d25d5641ab2f5c95377
Detection count: 122
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Local\ArcadeCandy\ACGames.exe
Group: Malware file
Last Updated: October 11, 2022
%LOCALAPPDATA%\ArcadeCandy\games@acandy.com\components\compare.js.tmp File name: compare.js.tmp
Size: 3.9 KB (3900 bytes)
MD5: 35035e69cfa57f77bf2266f39847b9e8
Detection count: 108
File type: Temporary File
Mime Type: unknown/tmp
Path: %LOCALAPPDATA%\ArcadeCandy\games@acandy.com\components
Group: Malware file
Last Updated: November 2, 2022
%SYSTEMDRIVE%\Old BUs\C Drive\AppData\Local\ArcadeCandy\candyRemove.exe File name: candyRemove.exe
Size: 153.76 KB (153768 bytes)
MD5: a8ba082976b6ba69857c6187b5fbc241
Detection count: 84
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Old BUs\C Drive\AppData\Local\ArcadeCandy\candyRemove.exe
Group: Malware file
Last Updated: March 12, 2022
%SystemDrive%\Users\<username>\AppData\Local\Adobe\ArcadeCandy\ojpligdk.dll File name: ojpligdk.dll
Size: 1.86 MB (1861632 bytes)
MD5: fcfe475fea9d86ed637a04899f36988a
Detection count: 82
File type: Dynamic link library
Mime Type: unknown/dll
Path: %SystemDrive%\Users\<username>\AppData\Local\Adobe\ArcadeCandy
Group: Malware file
Last Updated: July 1, 2014
%LOCALAPPDATA%\ArcadeCandy\ACGames.exe File name: ACGames.exe
Size: 408.23 KB (408232 bytes)
MD5: 71026bf43e03c3efed0cf2e3754780e3
Detection count: 73
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\ArcadeCandy
Group: Malware file
Last Updated: April 30, 2020
%SYSTEMDRIVE%\Users\<username>\AppData\Local\ArcadeCandy\games@acandy.com\components\candyx.dll File name: candyx.dll
Size: 90.79 KB (90792 bytes)
MD5: 6219de58d4cda30411ded725acaa1c4d
Detection count: 44
File type: Dynamic link library
Mime Type: unknown/dll
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Local\ArcadeCandy\games@acandy.com\components\candyx.dll
Group: Malware file
Last Updated: November 2, 2022
%LOCALAPPDATA%\ArcadeCandy\Apps\mnubog.dll File name: mnubog.dll
Size: 566.78 KB (566784 bytes)
MD5: 1b69d7ce975d05fd37b6bc9cb787b422
Detection count: 40
File type: Dynamic link library
Mime Type: unknown/dll
Path: %LOCALAPPDATA%\ArcadeCandy\Apps
Group: Malware file
Last Updated: July 1, 2014
%LOCALAPPDATA%\ArcadeCandy\candyUpdater.exe File name: candyUpdater.exe
Size: 263.13 KB (263132 bytes)
MD5: 3c775d1d85f17c4a0420b620d604fe26
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\ArcadeCandy
Group: Malware file
Last Updated: July 1, 2014
%LOCALAPPDATA%\ArcadeCandy\LogMeIn Rescue Applet\olflbjogjp.dll File name: olflbjogjp.dll
Size: 1.86 MB (1867264 bytes)
MD5: 7be8ca2d764f40643af952466fa6f121
Detection count: 6
File type: Dynamic link library
Mime Type: unknown/dll
Path: %LOCALAPPDATA%\ArcadeCandy\LogMeIn Rescue Applet
Group: Malware file
Last Updated: July 1, 2014
%LOCALAPPDATA%\ArcadeCandy\candyUpdater.exe File name: candyUpdater.exe
Size: 263.12 KB (263126 bytes)
MD5: 7f109dc0f007e110415cc7a40f8c90e2
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\ArcadeCandy
Group: Malware file
Last Updated: July 1, 2014
%LOCALAPPDATA%\ArcadeCandy\APN\bxutn.dll File name: bxutn.dll
Size: 319.48 KB (319488 bytes)
MD5: 48af3d1e570ed0c984160895117c4610
Detection count: 5
File type: Dynamic link library
Mime Type: unknown/dll
Path: %LOCALAPPDATA%\ArcadeCandy\APN
Group: Malware file
Last Updated: July 1, 2014
%LOCALAPPDATA%\ArcadeCandy\ACGames.exe File name: ACGames.exe
Size: 408.23 KB (408232 bytes)
MD5: 49752f49e3626c33ad5e9f4f82ff8289
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\ArcadeCandy
Group: Malware file
Last Updated: July 1, 2014
%LOCALAPPDATA%\ArcadeCandy\Logishrd\nkem.dll File name: nkem.dll
Size: 1.83 MB (1836032 bytes)
MD5: 321e87677229a375808cfa821b98c0cb
Detection count: 0
File type: Dynamic link library
Mime Type: unknown/dll
Path: %LOCALAPPDATA%\ArcadeCandy\Logishrd
Group: Malware file
Last Updated: July 1, 2014

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{70B84CD6-1E9F-4D51-A166-F39934D52FD8}File name without pathb4.arcadecandy[1].xmlHKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\DOMStorage\arcadecandy.comSoftware\Microsoft\Internet Explorer\DOMStorage\b4.arcadecandy.comSOFTWARE\Mozilla\Firefox\EXTENSIONS\games@arcadecandy.comSOFTWARE\Wow6432Node\Mozilla\Firefox\EXTENSIONS\games@arcadecandy.comHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}ArcadeCandy Games

Additional Information

The following directories were created:
%PROGRAMFILES%\ACGames%PROGRAMFILES(x86)%\ACGames
Loading...