PUA

Should I remove “Funmoods Toolbar (PUA)”?

Malware Removal

The Funmoods Toolbar (PUA) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Funmoods Toolbar (PUA) virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Attempts to modify Internet Explorer’s start page
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Deletes executed files from disk

How to determine Funmoods Toolbar (PUA)?


File Info:

name: 0DCC7E8487273CC481F5.mlw
path: /opt/CAPEv2/storage/binaries/de68f392de1d8350be277d3965d2fc6ebe5d9323f3fd3e165bf2dc24dc77d80c
crc32: D3E2C94C
md5: 0dcc7e8487273cc481f52ca4d30dec1f
sha1: 452f7036cdae07d31653d56918e0beea33c41a97
sha256: de68f392de1d8350be277d3965d2fc6ebe5d9323f3fd3e165bf2dc24dc77d80c
sha512: 2431bd416479404e2a8c347822f47ba963dc0b13d0feca6d02f6653100ec6edf77b97df8c92393ca05bbb527bde40af58265a156c8cffc91b9518876e28b9ed5
ssdeep: 49152:CFQjdzmZI7sBubIqSmT/MLRpEPKPocxt1arufj5:CFQBSBubB90LRDocxWry
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13C8533A73397D7E3D2610772A53BD3027169CBCE10F85A6B4DE77A2A717C8064A23349
sha3_384: 917f11f87c948e954248709453f7379eed08d0a6cc280f20ee8707619dd7f19e01d7b864a143a5c58fe527bdcd682e6b
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:52

Version Info:

0: [No Data]

Funmoods Toolbar (PUA) also known as:

BkavW32.AIDetectMalware
LionicHacktool.NSIS.MyxaH.lwce
AVGWin32:PUP-gen [PUP]
SkyhighBehavesLike.Win32.PUP.tc
McAfeeArtemis!0DCC7E848727
Cylanceunsafe
SangforAdware.Win32.Uptodown.Vjmb
K7AntiVirusAdware ( 004ba3601 )
AlibabaAdWare:Win32/UpToDown.87e98cf3
K7GWAdware ( 004ba3601 )
VirITTrojan.Win32.Siggen6.BXQM
SymantecAdware.DealPly
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/UpToDown.B potentially unwanted
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Adware.UpToDown-1
Kasperskynot-a-virus:HEUR:AdWare.NSIS.DealPly.gen
NANO-AntivirusRiskware.Crx.Funmoods.dzvert
SUPERAntiSpywarePUP.BundleInstaller/Variant
AvastWin32:PUP-gen [PUP]
RisingMalware.InstallCore!8.12DCA (CLOUD)
SophosFunmoods Toolbar (PUA)
F-SecureProgram.APPL/UpToDown.Gen5
DrWebTool.InstallToolbar.21
ZillyaAdware.DealPly.Win32.192352
TrendMicroTROJ_GEN.R002C0OAU24
Trapminemalicious.moderate.ml.score
EmsisoftApplication.InstallCore (A)
IkarusPUA.DealPly
JiangminAdWare.FunMoods.q
VaristW32/Trojan.IXT.gen!Eldorado
AviraAPPL/UpToDown.Gen5
Antiy-AVLTrojan/Win32.TSGeneric
Kingsoftmalware.kb.a.988
MicrosoftPUADlManager:Win32/InstallCore
XcitiumSuspicious@#mfb051jdyozr
ZoneAlarmnot-a-virus:HEUR:AdWare.NSIS.DealPly.gen
GDataWin32.Application.UpToDown.C
GoogleDetected
VBA32Adware.DealPly
MalwarebytesPUP.Optional.BundleInstaller.DDS
TrendMicro-HouseCallTROJ_GEN.R002C0OAU24
YandexPUA.Toolbar.Escort!X9XYGJ1P5yo
SentinelOneStatic AI – Suspicious PE
ZonerPUA.Win32.52492
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_100% (W)
alibabacloudRansomware:Win/Agent.gen

How to remove Funmoods Toolbar (PUA)?

Funmoods Toolbar (PUA) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment