theanswerfinderuninstall.exe

Installer

Mime Ventures LLC

This is the Softpulse installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application theanswerfinderuninstall.exe by Mime Ventures has been detected as adware by 17 anti-malware scanners. The program is a setup application that uses the Softpulse SoftwareBundler installer. While running, it connects to the Internet address www.ibbalance.com on port 443.
Publisher:
Mime Ventures LLC  (signed and verified)

Product:
Installer

Version:
1.0.0.0

MD5:
e583f76ac5f51b082e7dd3f31703e6b6

SHA-1:
f96a1c3abebc6aca21a4139ce0ad3aa5ab467c50

SHA-256:
9e7ee98b8c9a7bdf6583db1fd4c60381f21612f2d004f48e44cf421558b2ec69

Scanner detections:
17 / 68

Status:
Adware

Explanation:
The software cotains keystroke monitoring/logging capablities which may or may not be installed without the user's knowledge.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/24/2024 11:04:51 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Avira AntiVirus
Adware/iBryte.plsaza
7.11.205.246

AVG
Generic
2016.0.3183

Baidu Antivirus
Adware.Win32.iBryte
4.0.3.1532

Comodo Security
Application.MSIL.iBryte.JA
20898

ESET NOD32
MSIL/Adware.iBryte.R application
7.0.302.0

Fortinet FortiGate
Adware/IBryte
3/2/2015

F-Secure
Gen:Variant.Adware.Mplug.23
11.2015-02-03_2

IKARUS anti.virus
Trojan-Spy.MSIL.Keylogger
t3scan.1.8.6.0

Malwarebytes
PUP.Optional.TheAnswerFinder.A
v2015.03.02.12

McAfee
Artemis!3F20828BC733
5600.6839

Norman
IBryte.AJQ
11.20150302

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1015

Reason Heuristics
PUP.Installer.Softpulse
15.3.2.0

Sophos
Generic PUA CA
4.98

Trend Micro House Call
TROJ_GEN.R02SC0OAP15
7.2.61

Trend Micro
TROJ_GEN.R02SC0OAP15
10.465.02

VIPRE Antivirus
iBryte
36982

File size:
367.9 KB (376,776 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2014

Original file name:
TheAnswerFinderInstall.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Softpulse SoftwareBundler

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\roaming\theanswerfinder\theanswerfinderuninstall.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
10/17/2014 1:39:32 PM

Valid to:
10/18/2015 1:39:32 PM

Subject:
E=admin@theanswerfinder.com, CN=Mime Ventures LLC, OU=TheAnswerFinder.com, O=Mime Ventures LLC, L=Los Angeles, S=California, C=US

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121EDDEAF81A380FF278B94B619A213DEEE

File PE Metadata
Compilation timestamp:
2/24/2015 4:16:30 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:XaAIXMb5hJsLfmGTo5bcQAN5+CTjmoBqZASs/nWkBUzGf2:/HJGhs4Q0pvl8Xi2

Entry address:
0x59526

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.8255

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
349.5 KB (357,888 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.softologic.com  (174.37.181.31:80)

TCP (HTTP SSL):
Connects to www.ibbalance.com  (173.192.190.227:443)

TCP (HTTP):

Remove theanswerfinderuninstall.exe - Powered by Reason Core Security