Home Malware Programs Potentially Unwanted Programs (PUPs) Arcade Twist Ads

Arcade Twist Ads

Posted: March 20, 2015

Threat Metric

Ranking: 17,149
Threat Level: 1/10
Infected PCs: 2,942
First Seen: March 20, 2015
Last Seen: September 23, 2023
OS(es) Affected: Windows

Arcade Twist Ads Screenshot 1Arcade Twist is classified a Potentially Unwanted Program (PUP) with adware capabilities that may be found bundled with other free applications. Arcade Twist is a product created and developed by ArcadeYum LLC that is also the creator of Arcade Giant. At first glance, Arcade Twist claims to provide users with access to thousands of flash games. At their official website on arcadetwist.com, users may find different categories of games according to preferences. The presence of Arcade Twist program on your PC may cause your browser to display unwanted commercial advertisements while web browsing. Typically, apps like Arcade Twist collect information about your browsing habits in order to generate more appealing ads.

Arcade Twist Ads Screenshot 2Arcade Twist Ads Screenshot 2

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Users\<username>\AppData\Local\OutstandHoriz8\VOTPrx.dll File name: VOTPrx.dll
Size: 293.45 KB (293456 bytes)
MD5: c859b6b1099a6246872f593dc83356fe
Detection count: 244
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\Users\<username>\AppData\Local\OutstandHoriz8\VOTPrx.dll
Group: Malware file
Last Updated: April 13, 2022
C:\WINDOWS\System32\drivers\VOTw864.sys File name: VOTw864.sys
Size: 44.13 KB (44136 bytes)
MD5: 6c50bd013dd96c9bdb5f3f68d641e12f
Detection count: 218
File type: System file
Mime Type: unknown/sys
Path: C:\WINDOWS\System32\drivers\VOTw864.sys
Group: Malware file
Last Updated: April 2, 2022
C:\Users\<username>\AppData\Local\OutstandHoriz8\VOTw8.sys File name: VOTw8.sys
Size: 36.96 KB (36968 bytes)
MD5: f8b151d5dd844b06ceb3ee1290607237
Detection count: 66
File type: System file
Mime Type: unknown/sys
Path: C:\Users\<username>\AppData\Local\OutstandHoriz8\VOTw8.sys
Group: Malware file
Last Updated: March 14, 2022

Registry Modifications

The following newly produced Registry Values are:

CLSID{007F707C-3F7A-4FBF-9BB1-4C9404211A9C}{0394AE51-F76F-4FBF-848D-CF9407CE868F}{058281DD-014E-4E81-A5D3-9E14A1EBC8B7}{09CBD86E-22AC-4BFF-A97C-85744B2819AB}{1AB1CA27-FA6E-434B-8433-612346BBDD3B}{34A729EE-F357-4A94-9243-D33E50A504A7}{420A2140-FB38-4984-B681-2A0217483077}{46A200C2-2B44-4C47-8EA9-5DB33859BC7C}{47F18772-002C-4A49-AA12-EE88297CCDD0}{542B7A6A-C8B6-4372-8829-FD8E35FA4CB8}{55AB8477-ED99-431F-ABB3-22022902A934}{5C567C55-75EF-4000-B36F-FF562D4204C1}{78AC0B67-463E-4702-A7B1-CFB4C33B3D56}{79701C41-C345-47EC-B57C-02C39A698A0D}{86937CB9-BDDC-482F-A3B3-E05E3DFDFF08}{95980124-E89B-48C2-BA92-DF835F62ABFB}{AA33003C-AB62-428E-B24E-59933BE52393}{AE479D24-AF59-4DEB-9D8B-D1E7DFA2C6A6}{BED722AF-1533-4596-964F-B5E1F8A6456E}{D22566FE-4D97-4D5D-968B-0E79353F22E4}{E94546E8-E2A0-48FE-BC53-568F314EAA7A}{F0C53D54-F8AF-4156-8D66-420036A79A28}Regexp file mask%WINDIR%\System32\Tasks\ArcadeTwist Support%WINDIR%\System32\Tasks\ArcadeTwist Updater%WINDIR%\System32\VOTPrx64.dll%WINDIR%\System32\VOTPrxOff.ini%WINDIR%\SysWOW64\VOTPrx.dll%WINDIR%\SysWOW64\VOTPrxOff.ini%WINDIR%\Tasks\ArcadeTwist Support.job%WINDIR%\Tasks\ArcadeTwist Updater.job%WINDIR%\Temp\VOTPrx.log%WINDIR%\Temp\VOTPrxr.logHKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\QljeSpRnUuIQtnUREZFjFpyfrBfdkXJCsTOGhTaeSOFTWARE\Classes\AppID\VOTPrx.EXESOFTWARE\Classes\AppID\{0B7CB21B-2D13-4315-9E35-69742BF77530}SOFTWARE\Classes\VOTPrxLib.DataContainerSOFTWARE\Classes\VOTPrxLib.DataContainer.1SOFTWARE\Classes\VOTPrxLib.DataControllerSOFTWARE\Classes\VOTPrxLib.DataController.1SOFTWARE\Classes\VOTPrxLib.DataTableSOFTWARE\Classes\VOTPrxLib.DataTable.1SOFTWARE\Classes\VOTPrxLib.DataTableFieldsSOFTWARE\Classes\VOTPrxLib.DataTableFields.1SOFTWARE\Classes\VOTPrxLib.DataTableHolderSOFTWARE\Classes\VOTPrxLib.DataTableHolder.1SOFTWARE\Classes\VOTPrxLib.LSPLogicSOFTWARE\Classes\VOTPrxLib.LSPLogic.1SOFTWARE\Classes\VOTPrxLib.ReadOnlyManagerSOFTWARE\Classes\VOTPrxLib.ReadOnlyManager.1SOFTWARE\Classes\VOTPrxLib.WFPControllerSOFTWARE\Classes\VOTPrxLib.WFPController.1SOFTWARE\Classes\Wow6432Node\AppID\VOTPrx.EXESOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\ArcadeTwist Support.jobSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\ArcadeTwist Support.job.fpSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\ArcadeTwist Updater.jobSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\ArcadeTwist Updater.job.fpSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ArcadeTwist SupportSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ArcadeTwist UpdaterSoftware\Mozilla\Firefox\Extensions\{81a9e7a1-5cda-462d-bd06-d4450c6d9077}SOFTWARE\Wow6432Node\Classes\AppID\{0B7CB21B-2D13-4315-9E35-69742BF77530}SOFTWARE\Wow6432Node\VOTPrxSYSTEM\ControlSet001\Control\SafeBoot\Network\VOTPrxSYSTEM\ControlSet001\Control\SafeBoot\Network\VOTw8SYSTEM\ControlSet001\services\VOTPrxSYSTEM\ControlSet001\Services\VOTw8SYSTEM\ControlSet002\Control\SafeBoot\Network\VOTPrxSYSTEM\ControlSet002\services\VOTPrxSYSTEM\CurrentControlSet\Control\SafeBoot\Network\VOTw8SYSTEM\CurrentControlSet\services\VOTPrxSYSTEM\CurrentControlSet\Services\VOTw8HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{2E73670A-F0AF-4A88-8BDF-ED0710B305B2}

Additional Information

The following directories were created:
%LOCALAPPDATA%\ArcadeTwist%PROGRAMFILES%\ArcadeTwist%WINDIR%\SysWOW64\config\systemprofile\AppData\Local\VOTPrx%WINDIR%\system32\config\systemprofile\AppData\Local\VOTPrx
The following URL's were detected:
arcadetwist.com
Loading...