Home / Spyware Encyclopedia / Clicker.Arus << Back

Recommendation to Automatically remove Clicker.Arus


Our products can remove Clicker.Arus and thousands of other Virus and Spyware automatically and instantly.

Clicker.Arus Details


  • Category Clicker
  • Discovered 7/26/2012 2:44:13 PM
  • Modified 7/24/2023 3:09:49 PM
  • Threat Level High
  • Category Description
    This family of Trojans redirects victim machines to specified websites or other Internet resources. Clickers either send the necessary commands to the browser or replace system files where standard Internet urls are stored. Clickers are used: 1. To raise the hit-count of a specific site for advertising purposes. 2. To organize a DoS attack on a specified server or site. 3. To lead the victim to an infected resource where the machine will be attacked by other malware (viruses or Trojans).

The following Files were created:
VALUEFILESIZECOMPANYNAMEVERSIONSIGNATUREDate
svcpool.dll 109568  b1d65cbacaf2570eb709a62fbb2484a6 
XGBPlugin.dll 128512  347ce90a0001e3651c105d0995d7805b 
svcpool.dll 13824  154652960528964a144599ce6827c726 
TROJAN-SPY.WIN32.BANKER.AWX.EXE 239616  06ba038c07e22e335e291b2f7ed6a81c 
PerfStringV4.1.dll 43    
ie_32.exe 148852  50b8879ef0482d62dbc4e9344fbee38f 
ccd695ebd302f71926504b8d17be0dac.exe 151627  ccd695ebd302f71926504b8d17be0dac 
ad3fb4dbb35eef4c9099b8c7f525c2a7.vir.exe 395124  ad3fb4dbb35eef4c9099b8c7f525c2a7 
ie_32.exe 148852  50b8879ef0482d62dbc4e9344fbee38f13/07/2023
virusshare_715ff5ec9378bafe37c020805e5be55a.exe 363083  715ff5ec9378bafe37c020805e5be55a23/07/2023

The following Registry Entries were created:
..\Software\Microsoft\Windows\CurrentVersion\Run\\"IEXPLORER"\"%DAS.AU.LS%\Temp\iexplorer.exe"
..\Software\Microsoft\Windows\CurrentVersion\Run\\"Apoint System"\"%DAS.AU.LS%\Temp\trojan-spy.win32.banker.awx.exe"
..\Software\Microsoft\Windows\CurrentVersion\Run\\"services"\"%DAS.AU.LS%\Temp\trojan-spy.win32.banker.bar.exe"
..\Software\Microsoft\Windows\CurrentVersion\Run\\"TROJAN-SPY.WIN32.BANKER.AXK"\"%DAS.AU.LS%\Temp\TROJAN-SPY.WIN32.BANKER.AXK.EXE"
..\Software\Microsoft\Windows\CurrentVersion\Run\\"System Update"\"%DAS.AU.LS%\Temp\trojan-spy.win32.banker.bab.exe"
..\Software\COWMON System Shared\(Default)
..\System\CurrentControlSet\Services\svchost\(Default)

Notice
Please note that the following information is not controlled or endorsed by Max Secure Software. They are captured automatically by tools in our malware Research Lab as a result of executing Spyware Files or browsing Internet in virtual environment. Please contact us if you find any information inappropriate for removal. All the work contained in this report is copyrighted and should not be copied without permission from Max Secure Antivirus. We do not recommend browsing or removing these entries on your own manually. We do not take any warranty against the use or result of the use of this information.

Home / Malware Encyclopedia << Back

Max Total Security can detect & quarantine this Malware