Trojan

Should I remove “Trojan-Clicker.Win32.Cycler.pef”?

Malware Removal

The Trojan-Clicker.Win32.Cycler.pef is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Clicker.Win32.Cycler.pef virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Scheduled file move on reboot detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Behavior consistent with a dropper attempting to download the next stage.
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • CAPE detected the mimikatz malware family
  • Creates a copy of itself
  • The sample wrote data to the system hosts file.
  • Modifies Image File Execution Options, indicative of process injection or persistence
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan-Clicker.Win32.Cycler.pef?


File Info:

name: BD3517EB1F7AC39C1630.mlw
path: /opt/CAPEv2/storage/binaries/879659f11f1fb7f8f5e435adb39ec1dd6de00eecba540b9022c00b32804ab155
crc32: E2F08E7D
md5: bd3517eb1f7ac39c1630ccdf0572379b
sha1: 0a3a16483decfe72ababd45cc7fecb3212038720
sha256: 879659f11f1fb7f8f5e435adb39ec1dd6de00eecba540b9022c00b32804ab155
sha512: 1ccd6ab35e897675de3479a6925c8f0c1b8c29c2c9820d0a2cd44d955c80cea45c0155364e903310aabbabc746fcf61b915fa7084a6424dbe11e98a312924c7c
ssdeep: 98304:TRoeO6XTBJYazImknGzZr+HIPFtmOZ9G17xwFB5URUSKnaSOdroSCa:NoeO6XTYxmknGzwHIPHd9swFBubKT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18EC6E031564360E2C0C241F0C276DEFF38F775BD45D8794A778A66A39E68280B5AD32B
sha3_384: 9bdd360898113893ff04740b7c4b396ff448e1486184d5e596b44cefc60b4cf8fd6773550b093cadeda3907531bff600
ep_bytes: 558bec6aff68a06f460068e4ec440064
timestamp: 2019-10-03 13:36:42

Version Info:

0: [No Data]

Trojan-Clicker.Win32.Cycler.pef also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Cycler.8!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.54407
CAT-QuickHealTrojanpws.Qqpass.16554
McAfeeGenericRXAA-AA!BD3517EB1F7A
MalwarebytesTrojan.MalPack
ZillyaTrojan.Mimikatz.Win32.599
SangforTrojan.Win32.Save.a
K7AntiVirusAdware ( 005070c51 )
AlibabaTrojanClicker:Win32/Cycler.8099c0b3
K7GWAdware ( 005070c51 )
CrowdStrikewin/malicious_confidence_90% (W)
CyrenW32/BlackMoon.J.gen!Eldorado
ESET-NOD32a variant of Win32/Packed.BlackMoon.A potentially unwanted
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
ClamAVWin.Trojan.BlackMoon-7136668-0
KasperskyHEUR:Trojan-Clicker.Win32.Cycler.pef
BitDefenderGen:Variant.Barys.54407
NANO-AntivirusTrojan.Win32.Cycler.hcewxi
TencentMalware.Win32.Gencirc.10b86d41
Ad-AwareGen:Variant.Barys.54407
F-SecureHeuristic.HEUR/AGEN.1105983
DrWebTrojan.Hosts.46779
McAfee-GW-EditionBehavesLike.Win32.Generic.wm
FireEyeGeneric.mg.bd3517eb1f7ac39c
EmsisoftGen:Variant.Barys.54407 (B)
GDataWin32.Trojan.Agent.WP
JiangminTrojanClicker.Cycler.bvj
AviraHEUR/AGEN.1105983
Antiy-AVLTrojan/Generic.ASCommon.F9
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Barys.DD487
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Backdoor.R284823
Acronissuspicious
VBA32BScope.Trojan.Miancha
ALYacGen:Variant.Barys.54407
MAXmalware (ai score=86)
CylanceUnsafe
RisingDownloader.Agent!1.B837 (CLASSIC)
YandexTrojan.GenAsa!A5ls4aMnsZQ
SentinelOneStatic AI – Malicious PE
eGambithacktool.mimikatz
FortinetW32/CoinMiner.ESFJ!tr
BitDefenderThetaGen:NN.ZexaF.34084.@pZ@a0DbsOo
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.b1f7ac
Paloaltogeneric.ml
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan-Clicker.Win32.Cycler.pef?

Trojan-Clicker.Win32.Cycler.pef removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment