RegToolExport_Logo

Funmoods is a software usually installed without your knowledge with the download of freeware. In fact some sites use the method of repackaging. This is an operation that is to redo the module software installation by adding download options. These options allow to add other software as for example toolbars browser, or potentially unwanted software. The addition of these new programs can decrease the performance of the system but also slow or redirect internet surfing. As a general rule, should focus on the author’s official site to download your software.
Identified : 10/03/2012.

0_Features

– It belongs to a family of PUP (Potentially Unwanted Program).
– A polluteware is a software that pollutes storage and/or the Base of registers.
– Vendor : PUP.Optional

 

0_Main_Actions

– It installs a plugin of the browser Google Chrome (G2),
– It installs a program of extension for browser Mozilla Firefox (M2),
– It installs a plugin of the browser Mozilla Firefox (P2),
– It changes the start page of the browser Mozilla Firefox (M0),
– It changes the start page of the browser Internet Explorer (R0),
– It changes the browser Internet Explorer search page (R1),
– It is installed as a BHO (Browser Helper Object) of internet browser (O2),
– It installs as a toolbar internet browser (O3),
– It installs as a process launched at startup of the system (RP),
– It starts a task planned in automatic (O39),
– It installs as a program (O42),
– It creates to many registry keys ‘Software’,
– It creates additional folders (O43),
– It moved to the Windows prefetcher folder (O45),
– It creates multiple files users (O61),
– It changes the Internet research provider (O69),

0_Zhpdiag

[MD5.7D795EAE3016A8FE380E9E8CC1FDC160] – (…) — C:\Program Files\DLLEscort\DLLTool.exe[MD5.8803469DB08FF031832CB781D7F49584] – (…) — C:\Program Files\DLLEscort\DLLEscort.exe
G2 – GCE: Preference [User Data\Default] [bbjciahceamgodcoidkjpchnokgfpphh] Funmoods v.2.1.3 (Désactivé )
P2 – MFPP: Plugins – [VERO] — C:\Documents and Settings\Coolman\Application Data\Mozilla\Firefox\Profiles\kmzgulko.default\searchplugins\Funmoods.xml
R0 – HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com
R1 – HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs = http://start.funmoods.com
O2 – BHO: Funmoods Helper Object [64Bits] – {75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} . (.Funmoods BHO – Pas de description.) — C:\Program Files (x86)\Funmoods\1.5.23.22\bh\escort.dll
O3 – Toolbar: Funmoods Toolbar – {A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} – C:\Program Files\Funmoods\funmoods\1.5.11.16\funmoodsTlbr.dll[MD5.00000000000000000000000000000000] [APT] [Funmoods] (…) — C:\Users\MARY\AppData\Roaming\Funmoods\UPDATE~1\UPDATE~1.exe
O42 – Logiciel: Funmoods – (…) [HKLM] — funmoods
O42 – Logiciel: DLLEscort version 2014 – (…) [HKLM] — {2F13CA65-0FFB-4760-824B-D459836AACFE}_is1[HKLM\Software\Funmoods] [HKCU\Software\Funmoods] O43 – CFD: 11/10/2012 – 17:52:07 – [2,726] —-D C:\Program Files\Funmoods
O43 – CFD: 4/04/2013 – 20:05:22 – [0,000] —-D C:\Users\Coolman\AppData\Roaming\Funmoods
O43 – CFD: 02/07/2015 – 10:53:50 – [] —-D C:\Program Files\DLLEscort
O43 – CFD: 02/07/2015 – 10:52:15 – [] —-D C:\ProgramData\dllescort
O43 – CFD: 02/07/2015 – 10:50:36 – [] —-D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DLL Escort 2014
O61 – LFC: 02/07/2015 – 10:56:38 —A- . (…) — C:\Users\MY – PC\Desktop\DLLEscort_Setup.exe[MD5.B2570122DFDB008D650166C7CF01E7C1] [SPRF][02/07/2015] (.Pas de propriétaire – DLL Escort Setup.) — C:\Users\MY – PC\Desktop\DLLEscort_Setup.exe
O69 – SBI: SearchScopes [HKCU] {5C2C9C72-FE1F-44D7-A1ED-1D9A87FDAD8C} [DefaultScope] – (Search) – http://start.funmoods.com
O69 – SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} – (Funmoods) – http://searchfunmoods.com
O69 – SBI: SearchScopes [HKCU] {B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B} – (Funmoods) – http://searchfunmoods.com[HKLM\Software\Microsoft\Internet Explorer\Toolbar]:{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3}[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7}] [HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Funmoods Web Search] [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\funmoods] [HKLM\Software\Classes\AppID\esrv.EXE] [HKLM\Software\Classes\escort.escortIEPane] [HKLM\Software\Classes\escort.escortIEPane.1] [HKLM\Software\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}] [HKLM\Software\Wow6432Node\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}] [HKLM\Software\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}] [HKLM\Software\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}] [HKLM\Software\Wow6432Node\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}] [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C87FC351-A80D-43E9-9A86-CF1E29DC443A}] [HKLM\SOFTWARE\Classes\esrv.funmoodsESrvc.1] [HKLM\SOFTWARE\Classes\esrv.funmoodsESrvc] [HKLM\Software\Classes\funmoods.dskBnd.1] [HKLM\Software\Classes\funmoods.dskBnd] [HKLM\SOFTWARE\Classes\funmoods.funmoodsHlpr.1] [HKLM\SOFTWARE\Classes\funmoods.funmoodsHlpr] [HKLM\SOFTWARE\Classes\funmoodsApp.appCore.1] [HKLM\SOFTWARE\Classes\funmoodsApp.appCore] [HKCR\CLSID\{75A4D144-506D-4BE5-81DB-EC7DA1E7F840}] [HKCR\TypeLib\{960DF771-CFCB-4E53-A5B5-6EF2BBE6E706}] [HKCR\CLSID\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7}] [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7}] [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7}] [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7}] [HKCR\CLSID\{965B9DBE-B104-44AC-950A-8A5F97AFF439}] [HKCR\CLSID\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3}] [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3}] [HKCR\CLSID\{A9DB719C-7156-415E-B49D-BAD039DE4F13}] [HKCR\CLSID\{F03FD9D0-4F2B-497C-8A71-DD41D70B07D9}] [HKLM\SOFTWARE\Classes\f] [HKCU\Software\Funmoods] [HKCR\Typelib\{1D085C0A-E4F4-4F66-BDBF-4BE51015BFC3}] [HKCR\Interface\{0D80F1C5-D17B-4177-AC68-955F3EF9F191}] [HKLM\SOFTWARE\Google\chrome\Extensions\fdloijijlkoblmigdofommgnheckmaki] [HKCU\Software\Google\Chrome\Extensions\bbjciahceamgodcoidkjpchnokgfpphh] [HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3}] C:\Program Files\Funmoods
C:\Users\Coolman\AppData\LocalLow\Funmoods
C:\Users\Coolman\AppData\Roaming\Funmoods

0_Alias

PUP.Optional.Funmoods.A [ Malwarebytes Antimalware ] PUP.Funmoods
Hijacker.Funmoods
Adware.Funmoods

Remove_Software

– Remove software in Windows Configuration Panel,
0_ZHPcleaner
Remove with ZHPcleaner
ZHPCleaner_EN2
0_Zhpdiag
Diagnose with ZHPDiag
ZHPDiag_2-300x220

2016-12-30T07:34:16+00:00 Categories: Polluteware, PUP, Toolbar|Tags: , , |Comments Off on PUP.Optional.Funmoods