Home Malware Programs Potentially Unwanted Programs (PUPs) PUP.FourFinders

PUP.FourFinders

Posted: March 18, 2014

Threat Metric

Threat Level: 2/10
Infected PCs: 173
First Seen: March 18, 2014
Last Seen: March 30, 2023
OS(es) Affected: Windows


PUP.FourFinders is a potentially unwanted program/adware that may attack Internet Explorer, Mozilla Firefox or Google Chrome and other well-known Web browsers. PUP.FourFinders may show disturbing pop-up advertisements while the Web browser is operating. The main purpose of PUP.FourFinders may be to market a variety of suspicious websites that might have been made for commercial intentions that is to market numerous services and deals which, in truth, are intrusive and may interfere with the PC user's online activity. PUP.FourFinders may unwillingly divert the computer user to questionable websites if he clicks on the pop-up advertisements shown by PUP.FourFinders. PUP.FourFinders may also replace the default start page and search engine or a new tab page with a tricky website. PUP.FourFinders may reduce the PC's performance. PUP.FourFinders may trace the computer user's surfing routine and record his surfing history which may then be transferred and used for the aim of showing targeted advertisements and messages.

Aliases

Artemis!6927AE733288 [McAfee]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%TEMP%\fourfinders_di.exe File name: fourfinders_di.exe
Size: 233.09 KB (233096 bytes)
MD5: 6927ae733288b4a806191da4a2058ba0
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: August 17, 2022

Registry Modifications

The following newly produced Registry Values are:

CLSID{c5d16229-03ba-453f-949b-cd0dd970fb0e}HKEY..\..\..\..{RegistryKeys}SOFTWARE\Wow6432Node\Microsoft\Tracing\FourFinders_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\FourFinders_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\updateFourFinders_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\updateFourFinders_RASMANCSSYSTEM\ControlSet001\services\eventlog\Application\Update Four FindersSYSTEM\ControlSet002\services\eventlog\Application\Update Four FindersSYSTEM\CurrentControlSet\services\eventlog\Application\Update Four Finders

Additional Information

The following directories were created:
%PROGRAMFILES%\Four Finders%PROGRAMFILES%\FourFinders%PROGRAMFILES(x86)%\Four Finders%PROGRAMFILES(x86)%\FourFinders
Loading...