Home Malware Programs Adware Findizer Ads

Findizer Ads

Posted: July 20, 2016

Threat Metric

Ranking: 5,598
Threat Level: 2/10
Infected PCs: 53,402
First Seen: July 19, 2016
Last Seen: October 15, 2023
OS(es) Affected: Windows

Findizer is an online shopping assistant that is supposed to provide users with special offers, deals and coupon codes that can help save money. Judging by Findizer's official website, this browser extension is meant to be used by French-speaking computer users, but because of Findizer's distribution methods, this software also may be installed on the computers of people who don't know a single word in French silently. This may lead to annoying issues due to Findizer's tendency to inject advertisements in the user's browser, as well as to display special offers written in French. Seeing French ads and offers in your Web browser isn't something most users would expect, and it goes without saying that the program responsible for this weird behavior should not be trusted.

Anti-malware software identifies Findizer as adware, and any potent cyber security product should be able to fully remove Findizer's components from your computer. If you don't take the necessary action to remove Findizer from your machine, you may be exposed to 'Findizer ads' whenever you launch your Web browser. These advertisements may include product offers, discounts, and coupon codes, but they may link to dubious websites, as well as to irrelevant or fraudulent content sometimes. Apart from displaying marketing content, the Findizer extension also may collect information regarding the Web browser's usage, IP address, geographical location, search queries, and other data that may be used to improve the quality of 'Findizer ads'. Findizer's background operations may raise severe privacy concerns and are another excellent reason to remove Findizer from your computer as soon as possible.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES%\IMCCalcularInstaller\BHO.dll File name: BHO.dll
Size: 525.31 KB (525312 bytes)
MD5: 3e6d3a716585802cbfe048ce4c653526
Detection count: 11,486
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\IMCCalcularInstaller\BHO.dll
Group: Malware file
Last Updated: September 9, 2023
%PROGRAMFILES%\ItinéraireInfoInstaller\BHO.dll File name: BHO.dll
Size: 525.31 KB (525312 bytes)
MD5: 1d6fa2b9d5fb3c8d09a73b240494c93a
Detection count: 11,453
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\ItinéraireInfoInstaller\BHO.dll
Group: Malware file
Last Updated: October 15, 2023
C:\Program Files (x86)\RecettesInstaller\BHO.dll File name: BHO.dll
Size: 464.89 KB (464896 bytes)
MD5: dace9aea408085eced89ae5e8c523ed2
Detection count: 3,314
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\Program Files (x86)\RecettesInstaller\BHO.dll
Group: Malware file
Last Updated: July 26, 2023
%PROGRAMFILES%\YummmiesInstaller\BHO.dll File name: BHO.dll
Size: 525.31 KB (525312 bytes)
MD5: ef6790e68ec0a7675d2a8af404de8884
Detection count: 1,625
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\YummmiesInstaller
Group: Malware file
Last Updated: July 19, 2016
%PROGRAMFILES%\YummmiesInstaller\BHO.dll File name: BHO.dll
Size: 464.89 KB (464896 bytes)
MD5: 052dfad1a4e845647daf4d620a918847
Detection count: 75
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\YummmiesInstaller
Group: Malware file
Last Updated: June 24, 2018

Registry Modifications

The following newly produced Registry Values are:

CLSID{73F255E2-F188-4AA5-BE95-17B0C974EE7C}{D8680EDF-94BB-4335-AA3B-9426F4A672EA}{F4A9D6FE-8C16-4D72-B845-7AE0FFAB2DAB}File name without pathapi.findizer[1].xmlhttp_www.wikimot.fr_0.localstoragehttp_www.wikimot.fr_0.localstorage-journalHKEY..\..\..\..{RegistryKeys}SOFTWARE\AppDataLow\FindizerSOFTWARE\Microsoft\Internet Explorer\Approved Extensions\{F4A9D6FE-8C16-4D72-B845-7AE0FFAB2DAB}Software\Microsoft\Internet Explorer\DOMStorage\api.findizer.frSoftware\Microsoft\Internet Explorer\DOMStorage\findizer.frSOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4A9D6FE-8C16-4D72-B845-7AE0FFAB2DAB}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{F4A9D6FE-8C16-4D72-B845-7AE0FFAB2DAB}SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4A9D6FE-8C16-4D72-B845-7AE0FFAB2DAB}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{B55B479C-5CA9-41BD-9611-24BD3F9C39EA}_is1

Additional Information

The following directories were created:
%PROGRAMFILES%\Application Findizer%PROGRAMFILES%\ItiMapsInstaller%PROGRAMFILES%\LettresInstaller%PROGRAMFILES%\RecettesInstaller%PROGRAMFILES%\WikiMotInstaller%PROGRAMFILES%\allopagesinstaller%PROGRAMFILES%\yummmiesinstaller%PROGRAMFILES(x86)%\Application Findizer%PROGRAMFILES(x86)%\ItiMapsInstaller%PROGRAMFILES(x86)%\LettresInstaller%PROGRAMFILES(x86)%\RecettesInstaller%PROGRAMFILES(x86)%\WikiMotInstaller%PROGRAMFILES(x86)%\allopagesinstaller%PROGRAMFILES(x86)%\yummmiesinstaller
Loading...