Clicker.Cycler.grd Details

  • Category Clicker
  • Discovered 10/31/2018 10:54:44 PM
  • Modified 11/1/2018 4:25:46 PM
  • Threat Level Low
  • Category Description
    This family of Trojans redirects victim machines to specified websites or other Internet resources. Clickers either send the necessary commands to the browser or replace system files where standard Internet urls are stored. Clickers are used: 1. To raise the hit-count of a specific site for advertising purposes. 2. To organize a DoS attack on a specified server or site. 3. To lead the victim to an infected resource where the machine will be attacked by other malware (viruses or Trojans).

The following Files were created:
..\Download Data\Virussign\20120917\virussign.com_20120917_professional\exe32\virussign.com_d39afa141821f96aeded7a5b868636a2.exe 120320  d39afa141821f96aeded7a5b868636a2
..\Download Data\Virussign\Extracted Data\20121009\virussign.com_20121009_free\exe32\virussign.com_e2f9811d597e524383002472cf97ffbf.exe 81016  e2f9811d597e524383002472cf97ffbf
..\Download Data\Virussign\Extracted Data\20121010\virussign.com_20121010_professional\exe32\virussign.com_bb32b94af82bdfac628252311886e3a2.exe 84808  bb32b94af82bdfac628252311886e3a2
..\Download Data\Virussign\Extracted Data\20121008\virussign.com_20121008_standard\exe32\virussign.com_edf298ddc7a75c53856cbeadaf2e801b.exe 85788  edf298ddc7a75c53856cbeadaf2e801b
..\adobe\acrotray .exe 141268  982f7a30ae2b603f5e5cef90fd5e841f
..\Download Data\Virussign\Extracted Data\20121023\virussign.com_20121023_professional\exe32\virussign.com_e50757765a763684236ae80ae4be8a7d.exe 123720  e50757765a763684236ae80ae4be8a7d
..\Extracted data\21\samples\exe32\virussign.com_3b7f1d8153b28cdfd141365d550dff2f.vir.exe 94204  3b7f1d8153b28cdfd141365d550dff2f
..\d7e352de3fcd9394ae572009a47f4c27.exe 203164  d7e352de3fcd9394ae572009a47f4c27
..\e6bbe8c8e3b3db9e8c57701d8b7d7e71.exe 580428  e6bbe8c8e3b3db9e8c57701d8b7d7e71
..\e1b7064b68be109b6aa9bc49f1da8ba9.exe 603216  e1b7064b68be109b6aa9bc49f1da8ba9

The following Registry Entries were created:

