Home Malware Programs Adware FindoPolis

FindoPolis

Posted: February 3, 2014

Threat Metric

Ranking: 19,538
Threat Level: 2/10
Infected PCs: 4,347
First Seen: February 3, 2014
Last Seen: December 30, 2024
OS(es) Affected: Windows


FindoPolis is adware that may display a variety of pop-up random advertisements, banners and messages while computer users are browsing the Web. FindoPolis may affect Internet Explorer, Mozilla Firefox and Google Chrome Web browsers. FindoPolis may alter the default browser settings and interrupt into every Internet session of the computer user. FindoPolis may lead to continuous browser diversions to suspicious websites that may be commercial in an effort to boost website traffic, market a variety of products and services and benefit from clicks on advertisements. FindoPolis may also gather and record information about the computer user's browsing activities. FindoPolis may circulate and penetrate into the computer system through bundled free software that computer users can download from unreliable download websites on the Internet. FindoPolis may also attempt to trick PC user into thinking it is a genuine and helpful tool that the computer user may need to carry out certain online activities, for example, when shopping online.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

CLSID{426F0A1E-6828-4F97-AD4F-5BBBAA2A85AA}{4911C564-1CDE-44CC-92ED-6DA256C696DC}{A807F3B8-4DB5-473D-A4D5-6F0853F6CAA7}{ccfd8427-0c44-4b91-abbb-d6aa65f7d2a1}HKEY..\..\..\..{RegistryKeys}Software\findopolisSoftware\Microsoft\Internet Explorer\Approved Extensions\{56E6EC26-4FAB-42B5-91FA-2E72CE608727}SOFTWARE\Microsoft\Tracing\findopolis_RASAPI32SOFTWARE\Microsoft\Tracing\findopolis_RASMANCSSOFTWARE\Microsoft\Tracing\updatefindopolis_RASAPI32SOFTWARE\Microsoft\Tracing\updatefindopolis_RASMANCSSOFTWARE\Microsoft\Tracing\utilfindopolis_RASAPI32SOFTWARE\Microsoft\Tracing\utilfindopolis_RASMANCSSOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{ccfd8427-0c44-4b91-abbb-d6aa65f7d2a1}SOFTWARE\Wow6432Node\findopolisSOFTWARE\Wow6432Node\Microsoft\Tracing\findopolis_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\findopolis_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\updatefindopolis_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\updatefindopolis_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\utilfindopolis_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\utilfindopolis_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{ccfd8427-0c44-4b91-abbb-d6aa65f7d2a1}SYSTEM\ControlSet001\services\eventlog\Application\Update findopolisSYSTEM\ControlSet001\services\eventlog\Application\Util findopolisSYSTEM\ControlSet001\services\Update findopolisSYSTEM\ControlSet001\services\Util findopolisSYSTEM\ControlSet002\services\eventlog\Application\Update findopolisSYSTEM\ControlSet002\services\eventlog\Application\Util findopolisSYSTEM\ControlSet002\services\Update findopolisSYSTEM\ControlSet002\services\Util findopolisSYSTEM\CurrentControlSet\services\eventlog\Application\Update findopolisSYSTEM\CurrentControlSet\services\eventlog\Application\Util findopolisSYSTEM\CurrentControlSet\services\Update findopolisSYSTEM\CurrentControlSet\services\Util findopolisHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}findopolis

Additional Information

The following directories were created:
%PROGRAMFILES%\findopolis%PROGRAMFILES(x86)%\findopolis%temp%\findopolis
The following URL's were detected:
findopolis
Loading...