Malware

Clicker.4 removal

Malware Removal

The Clicker.4 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Clicker.4 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Japanese
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Deletes its original binary from disk
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
researchers01.sve-ce-da-nas-pojebe.com
researchers02.sve-ce-da-nas-pojebe.net
researchers03.sve-ce-da-nas-pojebe.biz
researchers04.sve-ce-da-nas-pojebe.info
researchers05.pusikuracbre.me
researchers06.mrdd8937453454352.in
a.tomx.xyz

How to determine Clicker.4?


File Info:

crc32: C2D95DF6
md5: 82e9a647cb1cfa7c3aa1cd2c83d48447
name: 82E9A647CB1CFA7C3AA1CD2C83D48447.mlw
sha1: 4777cd33396cc05d8fbafaa69e77d20f27856b62
sha256: d1349f8e9682bdeb02399a81810b73243b425a382fe66c9ca1ef00d4f411a6db
sha512: de98f45376ca944dcfaa503c8e08badff97aeaabdaa0e9442a91045fffab106100d36bf345241bbb1a0c7c901c05827334b3dae971471c8b098435116781264c
ssdeep: 1536:FIuC7/F0RZkQLe/LnmNWtKWlraIHfI9btmOc:C5F0RZkydUK6rtHA9btk
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

Translation: 0x0409 0x04b0
InternalName: UxY756XEnyQyYI1g
FileVersion: 8.16.0016
CompanyName: IIj8WjdJM F4OiZXY CNxgHct3
Comments: OaDTQkF HoQCdo XlHPSz
ProductName: OaDTQkF HoQCdo XlHPSz
ProductVersion: 8.16.0016
FileDescription: OaDTQkF HoQCdo XlHPSz
OriginalFilename: UxY756XEnyQyYI1g.exe

Clicker.4 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusNetWorm ( 700000151 )
LionicTrojan.Win32.VB.b!c
DrWebBackDoor.Andromeda.22
CynetMalicious (score: 100)
ALYacGen:Variant.Clicker.4
CylanceUnsafe
ZillyaDropper.VB.Win32.52640
K7GWNetWorm ( 700000151 )
Cybereasonmalicious.7cb1cf
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.URA
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.kocu
BitDefenderGen:Variant.Clicker.4
NANO-AntivirusTrojan.Win32.VB2.vpszs
MicroWorld-eScanGen:Variant.Clicker.4
TencentWin32.Trojan-dropper.Vb.Ebqv
Ad-AwareGen:Variant.Clicker.4
SophosMal/Generic-S
ComodoSuspicious@#3sl0j41h036yq
BitDefenderThetaGen:NN.ZevbaF.34142.dmKfayWkCQeO
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Trojan.qc
FireEyeGen:Variant.Clicker.4
EmsisoftGen:Variant.Clicker.4 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Malware.Gen
AviraTR/Dropper.VB.Gen
Antiy-AVLTrojan/Generic.ASMalwS.626E03
KingsoftWin32.Troj.VB.(kcloud)
MicrosoftWorm:Win32/Gamarue.I
ZoneAlarmTrojan-Ransom.Win32.Blocker.kocu
GDataGen:Variant.Clicker.4
AhnLab-V3Dropper/Win32.VB.C2321842
McAfeeArtemis!82E9A647CB1C
MAXmalware (ai score=87)
VBA32BScope.Worm.WBNA
PandaGeneric Malware
YandexTrojan.DR.VB!nVKwMRQ1omU
IkarusTrojan-Dropper.Win32.VB
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AP.1A5CF3!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Clicker.4?

Clicker.4 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment