pup.funmoods removal

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by douglaswlee, Jul 3, 2012.

  1. douglaswlee

    douglaswlee Private E-2

    I have been having an issue with Malware-Bytes not being able to remove a file called pup.funmoods. At first I did not notice anything really being affected performance wise with my laptop. Only recently it seems a little sluggish, but I attribute it to adding more files to my hard drive. Anyway I have a little time on my hands and would like to maybe have this (or whatever else is the problem) taken care of. I have ran the "READ & RUN ME FIRST Malware Removal" procedure to the best of my ability and hope I can have some assistance with my problem. I am attaching what I believe is the files you are wanting. I have an ASUS laptop running Windows 7, not sure what other components you are needing to know. Anyway thanks in advance for your assistance.
     

    Attached Files:

  2. thisisu

    thisisu Malware Consultant

    Hello douglaswlee :)

    I am reviewing your logs now but noticed that you did not take any action with Malwarebytes.

    Code:
    Registry Keys Detected: 1
    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} (PUP.Funmoods) -> [B][COLOR="Red"]No action taken[/COLOR][/B].
    Make sure it is checked and then click Next after the scan has completed. It's definitely not a stubborn piece of malware so Malwarebytes should have no problem removing it.
     
  3. thisisu

    thisisu Malware Consultant

    [​IMG] From Programs and Features (via Control Panel), please uninstall the below:
    • Coupon Printer for Windows
    • Java(TM) 6 Update 31
    • Windows iLivid Toolbar

    [​IMG] Run C:\MGtools\analyse.exe by double-clicking it (Vista/7 right-click and select Run as Administrator)
    Shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts.
    Choose "Do a system scan only" and select the following lines but do not click fix until you exit all explorer windows and all browser sessions including the one you are reading in right now:

    1. R3 - URLSearchHook: (no name) - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - (no file)
    2. R3 - URLSearchHook: (no name) - {472734EA-242A-422b-ADF8-83D1E48CC825} - (no file)
    3. R3 - URLSearchHook: (no name) - {07364a98-eb02-4736-bc54-ebe437fccb87} - (no file)
    4. O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    5. O2 - BHO: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WI3C8A~1\Datamngr\ToolBar\searchqudtx.dll
    6. O3 - Toolbar: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WI3C8A~1\Datamngr\ToolBar\searchqudtx.dll

    After clicking Fix, exit out of Trend Micro HiJackThis - v2.0.4

    __

    Manually delete these:
    • C:\Users\Doug\Desktop\7zip_installer_1650.exe <-- File
    • C:\ProgramData\PC Optimizer Pro <-- Folder

    __

    [​IMG] Open Notepad and copy everything in the code box below into it.
    Code:
    REGEDIT4
    
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{A40B974C-389F-45B3-8DFE-26762F1CEE2E}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]
    
    • File -> Save As -> Save as type: "All Files" -> File Name: fixme.reg > Save.
    Now merge this into the registry by double-clicking it.
    Let me know if the merge was successful or not.

    __

    Now reboot your computer

    __

    [​IMG] Now run C:\MGtools\GetLogs.bat by right-mouse clicking it and then selecting Run as Administrator
    This updates all of the logs inside MGlogs.zip.
    When it is finished, attach C:\MGlogs.zip to your next message. (How to attach)

    __

    Let me know what problems remain after you have completed these steps.
     
  4. douglaswlee

    douglaswlee Private E-2

    Many thanks thisisu
    You see I have been running Malware Bytes and trying to remove this for over 1 month and each time after the corruption was deleted according to Malware Bytes I could run it again and get the same corrupted file showing up.

    The reason I did not take action last time I was under the false (I see now it is false after reading further) impression that the forum gurus wanted to see the diagnosis of the malware finding software programs. I gathered that from what was mentioned in this forum about Hitman Pro and something was said to the affect "if we see the need to have you to do what hitman pro says we can have you run it again" sorry rough paraphrase I think maybe you even may have said it. I now see that the story is different for Malware Bytes.

    I have attached a log below from Malware Bytes where after I ran the program I deleted affected file but ran the scan again after rebooting and it shows the same results. That is why I am trying to go this procedure. I see another post has some directions for me to follow. Thanks for your assistance.
     

    Attached Files:

  5. douglaswlee

    douglaswlee Private E-2

    I have attached the file as you requested. I do not know if there is any problems. I will run Malware Bytes & see if pup.funmoods shows up again.
     

    Attached Files:

    Last edited by a moderator: Jul 5, 2012
  6. thisisu

    thisisu Malware Consultant

    Ok, you can also do this. Recommended to run an additional MBAM scan after this has been completed:

    [​IMG] Run C:\MGtools\analyse.exe by double-clicking it (Vista/7 right-click and select Run as Administrator)
    Shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts.
    Choose "Do a system scan only" and select the following lines but do not click fix until you exit all explorer windows and all browser sessions including the one you are reading in right now:

    • O3 - Toolbar: (no name) - !{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} - (no file)

    After clicking Fix, exit out of Trend Micro HiJackThis - v2.0.4

    __

    Delete this folder if it still exists: c:\Program Files (x86)\Funmoods
     
  7. douglaswlee

    douglaswlee Private E-2

    Did all you requested and MBAM Scan came up clean. Many Many thanks for your help. Hope you have an awesome day!!!
     
    Last edited by a moderator: Jul 5, 2012
  8. thisisu

    thisisu Malware Consultant

    You're welcome. :)

    __

    If you are not having any other malware related problems, it is time to do our final steps:
    • Any programs we had you download and/or install can be removed at this time.
    • If we had you download and run ComboFix, here is how to uninstall it:
      • Press and hold the Windows key [​IMG] and then press the letter R on your keyboard.
      • This opens the Run dialog box.
      • Copy and paste the below text inside the text-field:
        • "%userprofile%\desktop\ComboFix" /uninstall
      • Now press ENTER
      • ComboFix will extract its files one last time and you should receive a notification that ComboFix has been uninstalled shortly after.
    • You can re-enable your Disk Emulation software at this time via DeFogger.
    • If we had you create or download a registry patch or "fix" script, these can be deleted at this time.
    • Go into the C:\MGtools folder and run the MGclean.bat file to remove additional traces of our tools.
    • Now we will toggle System Restore to remove any infected system restore points.
    • Lastly, here is a guide to protect you from future infections: How to Protect yourself from malware!
    • Be safe :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds