Trojan

Trojan-Clicker.Win32.Cycler (file analysis)

Malware Removal

The Trojan-Clicker.Win32.Cycler is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Clicker.Win32.Cycler virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan-Clicker.Win32.Cycler?


File Info:

name: 65E4CAC710FF31F6DEC4.mlw
path: /opt/CAPEv2/storage/binaries/946ce18eec855409be8eac93810855953e9d9deeab6bb74f4bd93120f31965f8
crc32: 1325244B
md5: 65e4cac710ff31f6dec49e8186cf1292
sha1: 52cd02b9c683263458e2ac8dfe6cf6234ee3aa00
sha256: 946ce18eec855409be8eac93810855953e9d9deeab6bb74f4bd93120f31965f8
sha512: e32d9d398c187cad2f5e51bd3ae0a2b3c7a526cb98af1bbaa168d8baa642ba87e1270ebe5852695358e6e5d0a6fa3ef134f26bc1e1dccec8275b32fe85dce338
ssdeep: 12288:Pj4slRXL/kjYRYIHws+NDBR7I/tULBRg1AAMni:PjtXLH4JEGLBRkp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C1C4B16095655B3AF37BDB7B88BA7D3DC71523B3BBC3B18B443865911522281AF4230E
sha3_384: d9de8c14f36539c1180601c8ba30378b466167de17b1b928a925a6f79243d8e5a4b2e5d8e5d9cb6a4b4ee25655cae9a4
ep_bytes: 558bec6aff68c880400068ac58400064
timestamp: 2009-12-11 21:31:37

Version Info:

0: [No Data]

Trojan-Clicker.Win32.Cycler also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Cycler.tqY4
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Jaik.50182
FireEyeGeneric.mg.65e4cac710ff31f6
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Generic.ht
McAfeeGenericRXMN-SQ!65E4CAC710FF
Cylanceunsafe
VIPREGen:Variant.Jaik.50182
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 004bcce41 )
BitDefenderGen:Variant.Jaik.50182
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.710ff3
BitDefenderThetaGen:NN.ZexaF.36802.HmZ@aCKciAi
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Unruy.AY
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Downloader.Unruy-6988793-0
KasperskyHEUR:Trojan-Clicker.Win32.Cycler.gen
NANO-AntivirusTrojan.Win32.Unruy.ibnpwx
RisingDownloader.Unruy!1.AE5E (CLASSIC)
EmsisoftGen:Variant.Jaik.50182 (B)
BaiduWin32.Trojan-Clicker.Cycler.a
F-SecureTrojan.TR/Dropper.Gen
DrWebWin32.HLLC.Asdas.22
ZillyaDownloader.Unruy.Win32.7751
TrendMicroTROJ_UNRUY.SMT
Trapminemalicious.high.ml.score
SophosTroj/Cycler-C
IkarusTrojan-Downloader.Win32.Unruy
JiangminTrojan.Generic.glpgv
VaristW32/Unruy.N.gen!Eldorado
AviraTR/Dropper.Gen
Antiy-AVLTrojan[Downloader]/Win32.Unruy
MicrosoftTrojanDownloader:Win32/Unruy!pz
XcitiumTrojWare.Win32.TrojanSpy.BZub.~IP@f810f
ArcabitTrojan.Jaik.DC406
ZoneAlarmHEUR:Trojan-Clicker.Win32.Cycler.gen
GDataWin32.Trojan.PSE.RE8W1H
GoogleDetected
AhnLab-V3Trojan/Win.Unruy.C5602215
Acronissuspicious
ALYacGen:Variant.Jaik.50182
MAXmalware (ai score=84)
DeepInstinctMALICIOUS
VBA32BScope.TrojanDownloader.Unruy
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UNRUY.SMT
TencentTrojan.Win32.Unruy.wa
YandexTrojan.GenAsa!S4Mv8DNs2+w
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Cycler.TL!tr
AVGWin32:Unruy-AA [Trj]
AvastWin32:Unruy-AA [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudTrojan[downloader]:Win/Unruy

How to remove Trojan-Clicker.Win32.Cycler?

Trojan-Clicker.Win32.Cycler removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment