Home Malware Programs Adware Cyclon Gems

Cyclon Gems

Posted: May 6, 2014

Threat Metric

Ranking: 7,921
Threat Level: 2/10
Infected PCs: 175,917
First Seen: May 6, 2014
Last Seen: February 27, 2025
OS(es) Affected: Windows


The Cyclon Gems, also known as Context2Pro, is a potentially unwanted browser add-on that may claim to improve a computer user's Internet surfing activity by displaying discount coupon ads when visiting online shopping websites. The Cyclon Gems add-on is categorized as adware or a potentially unwanted program (PUP). The plug-in of Cyclon Gems may circulate and enter the Web browsers such as Internet Explorer, Google Chrome, and Mozilla Firefox as an optional program through bundled downloads of freeware. Cyclon Gems may reduce the Web browser's performance and show annoying ads. Cyclon Gems may spread using the DomaIQ free program download clients (fake downloads, such as Web browser updates, hacking applications, and other). After installation, Cyclon Gems may generate and display discount coupon ads and full screen pop-up ads. The plug-in of Cyclon Gems may track the PC user's Internet surfing routine by recording websites visited, search queries entered on search engines, IP addresses, clicks on social media web pages, operating systems, full URLs of web pages visited, and other information.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



H:\Windows.old\Users\<username>\AppData\Local\pgcchelper\pgcchelper.exe File name: pgcchelper.exe
Size: 465.92 KB (465920 bytes)
MD5: 7e396d4a774a1a4134ba6aba3b26cc6f
Detection count: 21,245
File type: Executable File
Mime Type: unknown/exe
Path: H:\Windows.old\Users\<username>\AppData\Local\pgcchelper\pgcchelper.exe
Group: Malware file
Last Updated: January 15, 2025
C:\Users\<username>\AppData\Local\ContextFree\framei.exe File name: framei.exe
Size: 567.8 KB (567808 bytes)
MD5: f0b1b497d073254cc6177532bd1a126e
Detection count: 12,617
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\ContextFree\framei.exe
Group: Malware file
Last Updated: December 6, 2022
C:\Users\<username>\AppData\Local\ContextFree\nvcmd.exe File name: nvcmd.exe
Size: 596.48 KB (596480 bytes)
MD5: 505e703afaf7f3dbdac879998cc8bc29
Detection count: 10,123
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\ContextFree\nvcmd.exe
Group: Malware file
Last Updated: July 25, 2023
C:\Users\<username>\AppData\Local\ContextFree\cntcmd.exe File name: cntcmd.exe
Size: 596.48 KB (596480 bytes)
MD5: 36e5b97f7a4afffcb6805ea12e9292d2
Detection count: 9,591
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\ContextFree\cntcmd.exe
Group: Malware file
Last Updated: July 25, 2023
%SYSTEMDRIVE%\Users\<username>\AppData\Local\Cyclon\Cyclon1050\frpdf.exe File name: frpdf.exe
Size: 507.9 KB (507904 bytes)
MD5: 9a3f2fb86372d80589c6d4a8b41100c8
Detection count: 2,492
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Local\Cyclon\Cyclon1050\frpdf.exe
Group: Malware file
Last Updated: November 18, 2022
%SYSTEMDRIVE%\INTENSO\ACER\Users\<username>\AppData\Local\Context2pro\Context2pro_Uninstaller.exe File name: Context2pro_Uninstaller.exe
Size: 33.24 KB (33244 bytes)
MD5: 8398dddd3aaef7874ba72284c2cfe41c
Detection count: 1,602
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\INTENSO\ACER\Users\<username>\AppData\Local\Context2pro\Context2pro_Uninstaller.exe
Group: Malware file
Last Updated: May 25, 2024
C:\Users\<username>\AppData\Local\Temp\clicon\clicon.exe File name: clicon.exe
Size: 446.96 KB (446960 bytes)
MD5: 7ff02f7a1843ae10b7db13cb0d1342ff
Detection count: 913
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\clicon\clicon.exe
Group: Malware file
Last Updated: January 21, 2024
%LOCALAPPDATA%\Context2pro\conadvanced.exe File name: conadvanced.exe
Size: 656.38 KB (656384 bytes)
MD5: e0fce5970fa5a1229a938a7e5e4d7033
Detection count: 204
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\Context2pro
Group: Malware file
Last Updated: December 18, 2019
%LOCALAPPDATA%\Context2pro\contextprod.exe File name: contextprod.exe
Size: 656.38 KB (656384 bytes)
MD5: e3cae39c5c0d1fae9e02775b0edf001a
Detection count: 201
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\Context2pro
Group: Malware file
Last Updated: December 18, 2019
%LOCALAPPDATA%\pgcchelper\pgcchelper_uninstaller.exe File name: pgcchelper_uninstaller.exe
Size: 210.9 KB (210902 bytes)
MD5: c041f31ff8effc8bce8cc6fb1338953d
Detection count: 44
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\pgcchelper
Group: Malware file
Last Updated: May 13, 2014

More files

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}Software\cliconSoftware\clicon\Agent\SystemInfoSoftware\clicupSoftware\clicup\Agent\SystemInfoSoftware\Context2proSoftware\ContextFreeSoftware\Microsoft\Windows\CurrentVersion\Run\clicon-AgentSoftware\Microsoft\Windows\CurrentVersion\Run\clicup-AgentSoftware\PgccAgentHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}cliconclicupContext2proContextFreepgcchelperwinengine

Additional Information

The following directories were created:
%LOCALAPPDATA%\Context2pro%LOCALAPPDATA%\ContextFree%LOCALAPPDATA%\clicup%LOCALAPPDATA%\pgcchelper%LOCALAPPDATA%\winengine%TEMP%\clicon%TEMP%\clicup%USERPROFILE%\Local Settings\Application Data\Context2pro
Loading...