Trojan

TrojanClicker:Win32/BuddyLinks.A removal

Malware Removal

The TrojanClicker:Win32/BuddyLinks.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanClicker:Win32/BuddyLinks.A virus can do?

  • Attempts to connect to a dead IP:Port (4 unique times)
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • A process attempted to delay the analysis task by a long amount of time.
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Creates a copy of itself
  • Collects information to fingerprint the system

Related domains:

www.clickspring.net
clickspring.net
fonts.googleapis.com
fonts.gstatic.com

How to determine TrojanClicker:Win32/BuddyLinks.A?


File Info:

crc32: 3156B868
md5: ef2d0bc5a132140c02a4e3000debf9c6
name: EF2D0BC5A132140C02A4E3000DEBF9C6.mlw
sha1: 0b17dd4099607b9391403e4e3500bde5cdc447a5
sha256: 8ae6363a0bf2d31b4965f76620d48831d8b9a89197b2a9f9ad0d20eef9740b99
sha512: 422c3dba3d635129f71aeef3d7bb65e644b6ba458bf42abd4cc0b245f2457f589af7c0b9f2962acbb6a0c006b8d9235f95a3626717d94d9922045e5635194601
ssdeep: 1536:3gX73CYOT9X5ZQeudTQMumxd7BzrB92n95nx7hogbEPXFw9puvz13DZaL:P9QeudTPt9B9Qx7euEPCSvzDaL
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 2002
InternalName: sear1
FileVersion: 1, 0, 0, 1
CompanyName:
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: sear1 Application
SpecialBuild:
ProductVersion: 1, 0, 0, 1
FileDescription: sear1 MFC Application
OriginalFilename: sear1.EXE
Translation: 0x0409 0x04b0

TrojanClicker:Win32/BuddyLinks.A also known as:

BkavW32.AIDetect.malware2
K7AntiVirusAdware ( 004ee78f1 )
Elasticmalicious (high confidence)
DrWebTrojan.PurityAd
CynetMalicious (score: 100)
CAT-QuickHealRansom.Locky.A6
ALYacGen:Trojan.Heur.PT.gmKfby4P@5ki
CylanceUnsafe
ZillyaAdware.PurityScan.Win32.397
SangforTrojan.Win32.Save.a
AlibabaTrojanClicker:Win32/BuddyLinks.be4f9c83
K7GWAdware ( 004ee78f1 )
Cybereasonmalicious.5a1321
CyrenW32/PurityScan.D.gen!Eldorado
SymantecAdware.Purityscan
ESET-NOD32a variant of Win32/Adware.PurityScan.AA
APEXMalicious
AvastFileRepMalware
ClamAVWin.Trojan.Scapur-11
Kasperskynot-a-virus:AdWare.Win32.PurityScan.bl
BitDefenderGen:Trojan.Heur.PT.gmKfby4P@5ki
NANO-AntivirusRiskware.Win32.PurityScan.bnrew
MicroWorld-eScanGen:Trojan.Heur.PT.gmKfby4P@5ki
Ad-AwareGen:Trojan.Heur.PT.gmKfby4P@5ki
SophosMal/DownLdr-O
ComodoMalware@#oasapqds5rky
VIPREClickSpring.PuritySCAN (fs)
TrendMicroADW_PURITYSCA.AG
McAfee-GW-EditionAdware-PurityScan.c
FireEyeGeneric.mg.ef2d0bc5a132140c
EmsisoftGen:Trojan.Heur.PT.gmKfby4P@5ki (B)
SentinelOneStatic AI – Suspicious PE
JiangminAdware.PurityScan.i
WebrootAdware:Win32/Clickspring.C
AviraHEUR/AGEN.1117944
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.60577
MicrosoftTrojanClicker:Win32/BuddyLinks.A
SUPERAntiSpywareAdware.ClickSpring/PuritySCAN
GDataGen:Trojan.Heur.PT.gmKfby4P@5ki
AhnLab-V3Trojan/Win32.Xema.C139945
McAfeeAdware-PurityScan.c
MAXmalware (ai score=100)
VBA32Malware-Cryptor.SB.gen
PandaAdware/PurityScan
TrendMicro-HouseCallADW_PURITYSCA.AG
YandexTrojan.GenAsa!/eHGU77vYVk
Ikarusnot-a-virus:AdWare.Win32.PurityScan.j
MaxSecureTrojan.Malware.300983.susgen
FortinetAdware/Purityscan
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360Win32/Adware.PurityScan.HgIASQoA

How to remove TrojanClicker:Win32/BuddyLinks.A?

TrojanClicker:Win32/BuddyLinks.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment