Home Malware Programs Adware TheAnswerFinder

TheAnswerFinder

Posted: November 3, 2014

Threat Metric

Ranking: 16,470
Threat Level: 2/10
Infected PCs: 4,150
First Seen: November 3, 2014
Last Seen: December 9, 2024
OS(es) Affected: Windows

TheAnswerFinder is adware advertised as a 'free tool that allows you immediately to satisfy your curiosity about anything you are interested in!' Mime Ventures LLC publishes TheAnswerFinder, and it comes as a stand-alone installer via Amazon's CloudFront software distribution network. TheAnswerFinder is ad-supported browser extension and users of this app may see banners, pop-ups, pop-under and in-text link advertisement. TheAnswerFinder's creators do not take any responsibility for the nature of the websites you might be led to. TheAnswerFinder is an advertisement platform and by installing the app you give them the right to use your computer to mine Bitcoins. TheAnswerFinder may increase the loading time of your web browsers in order to facilitate its activity. TheAnswerFinder may lock your search settings and prevent you from changing them. Most users might not be comfortable with TheAnswerFinder's operation, and you might want to consider removal of TheAnswerFinder.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%WINDIR%\system32\config\systemprofile\AppData\Roaming\TheAnswerFinder\TheAnswerFinder.exe File name: TheAnswerFinder.exe
Size: 7.22 MB (7220168 bytes)
MD5: 2b08f07afda01b2c9ba8596c54a58be9
Detection count: 185
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32\config\systemprofile\AppData\Roaming\TheAnswerFinder
Group: Malware file
Last Updated: August 20, 2016

More files

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}SOFTWARE\Microsoft\Tracing\TheAnswerFinder_RASAPI32SOFTWARE\Microsoft\Tracing\TheAnswerFinder_RASMANCSSoftware\Microsoft\Windows\CurrentVersion\Run\TheAnswerFinderSoftware\TheAnswerFinderHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}TheAnswerFinder

Additional Information

The following directories were created:
%APPDATA%\TheAnswerFinder
Loading...