Home Malware Programs Adware Cyclon Gems

Cyclon Gems

Posted: May 6, 2014

Threat Metric

Ranking: 5,203
Threat Level: 2/10
Infected PCs: 175,545
First Seen: May 6, 2014
Last Seen: October 15, 2023
OS(es) Affected: Windows


The Cyclon Gems, also known as Context2Pro, is a potentially unwanted browser add-on that may claim to improve a computer user's Internet surfing activity by displaying discount coupon ads when visiting online shopping websites. The Cyclon Gems add-on is categorized as adware or a potentially unwanted program (PUP). The plug-in of Cyclon Gems may circulate and enter the Web browsers such as Internet Explorer, Google Chrome, and Mozilla Firefox as an optional program through bundled downloads of freeware. Cyclon Gems may reduce the Web browser's performance and show annoying ads. Cyclon Gems may spread using the DomaIQ free program download clients (fake downloads, such as Web browser updates, hacking applications, and other). After installation, Cyclon Gems may generate and display discount coupon ads and full screen pop-up ads. The plug-in of Cyclon Gems may track the PC user's Internet surfing routine by recording websites visited, search queries entered on search engines, IP addresses, clicks on social media web pages, operating systems, full URLs of web pages visited, and other information.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



H:\Windows.old\Users\<username>\AppData\Local\pgcchelper\pgcchelper.exe File name: pgcchelper.exe
Size: 465.92 KB (465920 bytes)
MD5: 7e396d4a774a1a4134ba6aba3b26cc6f
Detection count: 21,224
File type: Executable File
Mime Type: unknown/exe
Path: H:\Windows.old\Users\<username>\AppData\Local\pgcchelper\pgcchelper.exe
Group: Malware file
Last Updated: October 7, 2023
C:\Users\<username>\AppData\Local\ContextFree\framei.exe File name: framei.exe
Size: 567.8 KB (567808 bytes)
MD5: f0b1b497d073254cc6177532bd1a126e
Detection count: 12,617
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\ContextFree\framei.exe
Group: Malware file
Last Updated: December 6, 2022
C:\DATA\DATA\NEO\AppData\Local\Context2pro\conadvanced.exe File name: conadvanced.exe
Size: 579.16 KB (579160 bytes)
MD5: 14064cd74d1ed190b9fa3297f451e075
Detection count: 11,373
File type: Executable File
Mime Type: unknown/exe
Path: C:\DATA\DATA\NEO\AppData\Local\Context2pro\conadvanced.exe
Group: Malware file
Last Updated: June 29, 2022
C:\Users\<username>\AppData\Local\ContextFree\nvcmd.exe File name: nvcmd.exe
Size: 596.48 KB (596480 bytes)
MD5: 505e703afaf7f3dbdac879998cc8bc29
Detection count: 10,123
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\ContextFree\nvcmd.exe
Group: Malware file
Last Updated: July 25, 2023
C:\Users\<username>\AppData\Local\ContextFree\cntcmd.exe File name: cntcmd.exe
Size: 596.48 KB (596480 bytes)
MD5: 36e5b97f7a4afffcb6805ea12e9292d2
Detection count: 9,591
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\ContextFree\cntcmd.exe
Group: Malware file
Last Updated: July 25, 2023
C:\DATA\DATA\NEO\AppData\Local\Context2pro\contextfr.exe File name: contextfr.exe
Size: 551 KB (551000 bytes)
MD5: 9db988516c3a6c86c6f27b99d44837ae
Detection count: 7,321
File type: Executable File
Mime Type: unknown/exe
Path: C:\DATA\DATA\NEO\AppData\Local\Context2pro\contextfr.exe
Group: Malware file
Last Updated: June 29, 2022
C:\Users\<username>\AppData\Local\Context2pro\contextfr.exe File name: contextfr.exe
Size: 557.65 KB (557656 bytes)
MD5: 0f4d90d0bb503c80165820dac4ad291e
Detection count: 4,045
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Context2pro\contextfr.exe
Group: Malware file
Last Updated: December 6, 2021
C:\Users\<username>\AppData\Local\Context2pro\conadvanced.exe File name: conadvanced.exe
Size: 586.84 KB (586840 bytes)
MD5: 7a3c058cb9844e78974b06c4b80ef50f
Detection count: 3,860
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Context2pro\conadvanced.exe
Group: Malware file
Last Updated: June 1, 2022
C:\Users\<username>\AppData\Local\Context2pro\contextprod.exe File name: contextprod.exe
Size: 586.84 KB (586840 bytes)
MD5: f0e863dc4a4c0fbd95a7b3edf546bc7d
Detection count: 2,942
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Context2pro\contextprod.exe
Group: Malware file
Last Updated: December 6, 2021
H:\Windows.old\Users\<username>\AppData\Local\pgcchelper\pgcchelper_uninstaller.exe File name: pgcchelper_uninstaller.exe
Size: 33.05 KB (33057 bytes)
MD5: 0013060feeadeeb7a63e27155f727830
Detection count: 1,611
File type: Executable File
Mime Type: unknown/exe
Path: H:\Windows.old\Users\<username>\AppData\Local\pgcchelper\pgcchelper_uninstaller.exe
Group: Malware file
Last Updated: March 20, 2023
%SYSTEMDRIVE%\INTENSO\ACER\Users\<username>\AppData\Local\Context2pro\Context2pro_Uninstaller.exe File name: Context2pro_Uninstaller.exe
Size: 33.24 KB (33244 bytes)
MD5: 8398dddd3aaef7874ba72284c2cfe41c
Detection count: 1,595
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\INTENSO\ACER\Users\<username>\AppData\Local\Context2pro\Context2pro_Uninstaller.exe
Group: Malware file
Last Updated: September 13, 2023
%TEMP%\clicon\clicon.exe File name: clicon.exe
Size: 450.03 KB (450032 bytes)
MD5: c96fd249523a1ada92e6552de4beb083
Detection count: 1,084
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\clicon
Group: Malware file
Last Updated: April 23, 2020
%TEMP%\clicon\clicon.exe File name: clicon.exe
Size: 446.96 KB (446960 bytes)
MD5: 7ff02f7a1843ae10b7db13cb0d1342ff
Detection count: 909
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\clicon
Group: Malware file
Last Updated: January 13, 2020
%LOCALAPPDATA%\Context2pro\contextprod.exe File name: contextprod.exe
Size: 573.95 KB (573952 bytes)
MD5: c114870eef4506c79078c4fd165fc1da
Detection count: 817
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\Context2pro
Group: Malware file
Last Updated: April 14, 2020
%LOCALAPPDATA%\Context2pro\conadvanced.exe File name: conadvanced.exe
Size: 577.12 KB (577128 bytes)
MD5: 1690a0d0dfcac5c0368f54a3cb2d7507
Detection count: 473
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\Context2pro
Group: Malware file
Last Updated: May 13, 2014
C:\Users\<username>\AppData\Local\Context2pro\contextfr.exe File name: contextfr.exe
Size: 549.48 KB (549480 bytes)
MD5: 3f5565f13142e74d396c8572970d7a40
Detection count: 354
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Context2pro\contextfr.exe
Group: Malware file
Last Updated: February 25, 2021
C:\Users\<username>\Documents\copia dades\Users\<username>\AppData\Local\pgcchelper\pgcchelper_uninstaller.exe File name: pgcchelper_uninstaller.exe
Size: 33.05 KB (33057 bytes)
MD5: 0c2e3cc577106fb3abfd84ce4ff0c842
Detection count: 220
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\Documents\copia dades\Users\<username>\AppData\Local\pgcchelper\pgcchelper_uninstaller.exe
Group: Malware file
Last Updated: March 2, 2023
%LOCALAPPDATA%\Context2pro\conadvanced.exe File name: conadvanced.exe
Size: 656.38 KB (656384 bytes)
MD5: e0fce5970fa5a1229a938a7e5e4d7033
Detection count: 204
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\Context2pro
Group: Malware file
Last Updated: December 18, 2019
%LOCALAPPDATA%\Context2pro\contextprod.exe File name: contextprod.exe
Size: 656.38 KB (656384 bytes)
MD5: e3cae39c5c0d1fae9e02775b0edf001a
Detection count: 201
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\Context2pro
Group: Malware file
Last Updated: December 18, 2019
%LOCALAPPDATA%\Context2pro\conadvanced.exe File name: conadvanced.exe
Size: 579.16 KB (579160 bytes)
MD5: 32e87f1e65145a1306aa9c9fc604fa27
Detection count: 101
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\Context2pro
Group: Malware file
Last Updated: May 13, 2014
%LOCALAPPDATA%\pgcchelper\pgcchelper_uninstaller.exe File name: pgcchelper_uninstaller.exe
Size: 210.9 KB (210902 bytes)
MD5: c041f31ff8effc8bce8cc6fb1338953d
Detection count: 44
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\pgcchelper
Group: Malware file
Last Updated: May 13, 2014

More files

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}Software\cliconSoftware\clicon\Agent\SystemInfoSoftware\clicupSoftware\clicup\Agent\SystemInfoSoftware\Context2proSoftware\ContextFreeSoftware\Microsoft\Windows\CurrentVersion\Run\clicon-AgentSoftware\Microsoft\Windows\CurrentVersion\Run\clicup-AgentSoftware\PgccAgentHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}cliconclicupContext2proContextFreepgcchelperwinengine

Additional Information

The following directories were created:
%LOCALAPPDATA%\Context2pro%LOCALAPPDATA%\ContextFree%LOCALAPPDATA%\clicup%LOCALAPPDATA%\pgcchelper%LOCALAPPDATA%\winengine%TEMP%\clicon%TEMP%\clicup%USERPROFILE%\Local Settings\Application Data\Context2pro
Loading...