Cyclon Gems
Posted: May 6, 2014
Threat Metric
The following fields listed on the Threat Meter containing a specific value, are explained in detail below:
Threat Level: The threat level scale goes from 1 to 10 where 10 is the highest level of severity and 1 is the lowest level of severity. Each specific level is relative to the threat's consistent assessed behaviors collected from SpyHunter's risk assessment model.
Detection Count: The collective number of confirmed and suspected cases of a particular malware threat. The detection count is calculated from infected PCs retrieved from diagnostic and scan log reports generated by SpyHunter.
Volume Count: Similar to the detection count, the Volume Count is specifically based on the number of confirmed and suspected threats infecting systems on a daily basis. High volume counts usually represent a popular threat but may or may not have infected a large number of systems. High detection count threats could lay dormant and have a low volume count. Criteria for Volume Count is relative to a daily detection count.
Trend Path: The Trend Path, utilizing an up arrow, down arrow or equal symbol, represents the level of recent movement of a particular threat. Up arrows represent an increase, down arrows represent a decline and the equal symbol represent no change to a threat's recent movement.
% Impact (Last 7 Days): This demonstrates a 7-day period change in the frequency of a malware threat infecting PCs. The percentage impact correlates directly to the current Trend Path to determine a rise or decline in the percentage.
| Ranking: | 7,921 |
|---|---|
| Threat Level: | 2/10 |
| Infected PCs: | 175,917 |
| First Seen: | May 6, 2014 |
|---|---|
| Last Seen: | February 27, 2025 |
| OS(es) Affected: | Windows |
The Cyclon Gems, also known as Context2Pro, is a potentially unwanted browser add-on that may claim to improve a computer user's Internet surfing activity by displaying discount coupon ads when visiting online shopping websites. The Cyclon Gems add-on is categorized as adware or a potentially unwanted program (PUP). The plug-in of Cyclon Gems may circulate and enter the Web browsers such as Internet Explorer, Google Chrome, and Mozilla Firefox as an optional program through bundled downloads of freeware. Cyclon Gems may reduce the Web browser's performance and show annoying ads. Cyclon Gems may spread using the DomaIQ free program download clients (fake downloads, such as Web browser updates, hacking applications, and other). After installation, Cyclon Gems may generate and display discount coupon ads and full screen pop-up ads. The plug-in of Cyclon Gems may track the PC user's Internet surfing routine by recording websites visited, search queries entered on search engines, IP addresses, clicks on social media web pages, operating systems, full URLs of web pages visited, and other information.
Technical Details
File System Modifications
Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.
The following files were created in the system:H:\Windows.old\Users\<username>\AppData\Local\pgcchelper\pgcchelper.exe
File name: pgcchelper.exeSize: 465.92 KB (465920 bytes)
MD5: 7e396d4a774a1a4134ba6aba3b26cc6f
Detection count: 21,245
File type: Executable File
Mime Type: unknown/exe
Path: H:\Windows.old\Users\<username>\AppData\Local\pgcchelper\pgcchelper.exe
Group: Malware file
Last Updated: January 15, 2025
C:\Users\<username>\AppData\Local\ContextFree\framei.exe
File name: framei.exeSize: 567.8 KB (567808 bytes)
MD5: f0b1b497d073254cc6177532bd1a126e
Detection count: 12,617
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\ContextFree\framei.exe
Group: Malware file
Last Updated: December 6, 2022
C:\Users\<username>\AppData\Local\ContextFree\nvcmd.exe
File name: nvcmd.exeSize: 596.48 KB (596480 bytes)
MD5: 505e703afaf7f3dbdac879998cc8bc29
Detection count: 10,123
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\ContextFree\nvcmd.exe
Group: Malware file
Last Updated: July 25, 2023
C:\Users\<username>\AppData\Local\ContextFree\cntcmd.exe
File name: cntcmd.exeSize: 596.48 KB (596480 bytes)
MD5: 36e5b97f7a4afffcb6805ea12e9292d2
Detection count: 9,591
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\ContextFree\cntcmd.exe
Group: Malware file
Last Updated: July 25, 2023
%SYSTEMDRIVE%\Users\<username>\AppData\Local\Cyclon\Cyclon1050\frpdf.exe
File name: frpdf.exeSize: 507.9 KB (507904 bytes)
MD5: 9a3f2fb86372d80589c6d4a8b41100c8
Detection count: 2,492
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Local\Cyclon\Cyclon1050\frpdf.exe
Group: Malware file
Last Updated: November 18, 2022
%SYSTEMDRIVE%\INTENSO\ACER\Users\<username>\AppData\Local\Context2pro\Context2pro_Uninstaller.exe
File name: Context2pro_Uninstaller.exeSize: 33.24 KB (33244 bytes)
MD5: 8398dddd3aaef7874ba72284c2cfe41c
Detection count: 1,602
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\INTENSO\ACER\Users\<username>\AppData\Local\Context2pro\Context2pro_Uninstaller.exe
Group: Malware file
Last Updated: May 25, 2024
C:\Users\<username>\AppData\Local\Temp\clicon\clicon.exe
File name: clicon.exeSize: 446.96 KB (446960 bytes)
MD5: 7ff02f7a1843ae10b7db13cb0d1342ff
Detection count: 913
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\clicon\clicon.exe
Group: Malware file
Last Updated: January 21, 2024
%LOCALAPPDATA%\Context2pro\conadvanced.exe
File name: conadvanced.exeSize: 656.38 KB (656384 bytes)
MD5: e0fce5970fa5a1229a938a7e5e4d7033
Detection count: 204
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\Context2pro
Group: Malware file
Last Updated: December 18, 2019
%LOCALAPPDATA%\Context2pro\contextprod.exe
File name: contextprod.exeSize: 656.38 KB (656384 bytes)
MD5: e3cae39c5c0d1fae9e02775b0edf001a
Detection count: 201
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\Context2pro
Group: Malware file
Last Updated: December 18, 2019
%LOCALAPPDATA%\pgcchelper\pgcchelper_uninstaller.exe
File name: pgcchelper_uninstaller.exeSize: 210.9 KB (210902 bytes)
MD5: c041f31ff8effc8bce8cc6fb1338953d
Detection count: 44
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\pgcchelper
Group: Malware file
Last Updated: May 13, 2014
More files
Registry Modifications
HKEY..\..\..\..{RegistryKeys}Software\cliconSoftware\clicon\Agent\SystemInfoSoftware\clicupSoftware\clicup\Agent\SystemInfoSoftware\Context2proSoftware\ContextFreeSoftware\Microsoft\Windows\CurrentVersion\Run\clicon-AgentSoftware\Microsoft\Windows\CurrentVersion\Run\clicup-AgentSoftware\PgccAgentHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}cliconclicupContext2proContextFreepgcchelperwinengine
Leave a Reply
Please note that we are not able to assist with billing and support issues regarding SpyHunter or other products. If you're having issues with SpyHunter, please get in touch with SpyHunter customer support through your SpyHunter . If you have SpyHunter billing questions, we recommend you check the Billing FAQ. For general suggestions or feedback, contact us.