Funmoods

Publisher Information

Funmoods is a software publisher located in Tel Aviv, Israel*. The company is a primary distributor of potentially unwanted software.
Remove Funmoods Malware - Powered by Reason Core Security
Authority:
COMODO CA Limited

Valid from:
2/18/2013 12:00:00 AM

Valid to:
2/18/2014 11:59:59 PM

Subject:
CN=Funmoods, O=Funmoods, STREET=63 Rothschild Blvd., L=Tel Aviv, S=NA, PostalCode=65785, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00f7100ae286d6d9ae97789c22f156c88f

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.Funmoods.I, PUP.Installer.Funmoods.F, PUP.Installer.Funmoods.N, PUP.Installer.Funmoods.J, PUP.Installer.Funmoods.K, PUP.installCore.Installer (M)
100.00%

ESET NOD32
Win32/Toolbar.Funmoods, Win32/Toolbar.Funmoods (variant), Win32/InstallCore, Win32/InstallCore.CH (variant)
45.83%

VIPRE Antivirus
Trojan.Win32.Generic, InstallCore, Threat.4786018
45.83%

Dr.Web
Adware.Funmoods.5, Adware.InstallCore.97, Adware.InstallCore.133, Adware.InstallCore.122
41.67%

avast!
Win32:FunMood-A [PUP], Win32:Malware-gen
33.33%

ESET NOD32
Win32/Kryptik.BWJC trojan, Win32/InstallCore.BL potentially unwanted application
33.33%

Trend Micro House Call
TROJ_GEN.R0CBH07JN13, TROJ_GEN.F47V1114, TROJ_GEN.F47V1017, TROJ_GEN.R0CBOH0AQ14, TROJ_GEN.R0CCC0RHU13, TROJ_GEN.F47V0109, ADW_FUNMOODS.A
29.17%

F-Prot
W32/InstallCore.G4.gen, W32/InstallCore.R3.gen, W32/InstallCore.R.gen
29.17%

Sophos
Funmoods Toolbar, Mal/Generic-S, PUA 'Funmoods Toolbar' (of type Adware)
29.17%

Bkav FE
W32.Clodb88.Trojan, W32.Clod15a.Trojan, W32.Clod70d.Trojan, W32.Clod2a0.Trojan, W32.Clod09e.Trojan
25.00%

6 / 68      (PUP)
fmappsetup.exe  (5d96a9c66ce38ce3cd694778abb31ddc)

1 / 68      (PUP)
fmappsetup.exe  (58074beb549e803f027a7b2c7047e053)

1 / 68      (PUP)
fmappsetup.exe  (5c053ea89c1af65b1353956b84835dbc)

1 / 68      (PUP)
icreinstall_fmappsetup.exe  (0bf34b4ef99bd2c2b24a6e775d4c0edc)

5 / 68      (PUP)
fmappsetup.exe  (4b17b084ae1d901ff60a3a7df2998b95)

4 / 68      (PUP)
fmappsetup.exe  (cdb0e7c3d67a9f946598e7ee73a8f8a1)

6 / 68      (PUP)
fmappsetup.exe  (2ca97b7839ddddf4a3ca4df8358816a5)

6 / 68      (PUP)
fmappsetup.exe  (928c387e8f53890792b0384f9cfbad3e)

3 / 68      (PUP)
fmappsetup.exe  (c4e01da3df46400cd40230ded64474cc)

3 / 68      (PUP)
fmappsetup.exe  (d9a0f713b6654292de55a12ebcb43f5f)

4 / 68      (PUP)
fmappsetup.exe  (39f031fa95b07e156292e77950f65f0b)

1 / 68      (PUP)
funmoodssetup.exe (Setup© by Setup ©)  (80d89f4e61b94c17dd3b30125fc7b4bb)

10 / 68    (PUP)
fmappsetup.exe  (f103cb0b8d9d097c8284a4fa52cbc637)

5 / 68      (PUP)
100413_f.exe (Setup© by Setup ©)  (d1b50d411a72cfbbf9bae6970e8c9884)

5 / 68      (PUP)
funmoodssetup.exe (Setup© by Setup ©)  (ad4a3b30898a81c710dcaaf14261753b)

1 / 68      (PUP)
311213_f2.exe (Setup© by Setup ©)  (b6697ec64041fde053575eef65f3258d)

8 / 68      (PUP)
130113_f.exe (Setup© by Setup ©)  (f7c09c3cb8c2cf29826704b84cfe4846)

28 / 68    (PUP)
funmoodssetup.exe (Setup© by Setup ©)  (0118396440bdff42d187ecc1a5b26e12)

15 / 68    (PUP)
setup.exe  (6c8a63f61ed9b081522e4fa9e222d482)

13 / 68    (PUP)
setup.exe  (592f35f9954a7ec4c0b4985857f81ad8)

6 / 68      (PUP)
180713_f.exe (Setup© by Setup ©)  (976cdb0499d4443fbc4f84e69a121f03)

5 / 68      (PUP)
291113_f.exe (Setup© by Setup ©)  (46396fce6091f9f03e16bb2199dff4cf)

8 / 68      (PUP)
231013_f.exe (Setup© by Setup ©)  (9ae24ebc591d476606a90d5aec69419b)

7 / 68      (PUP)
180713_f.exe (Setup© by Setup ©)  (442153a4ee9af27d17353294e4046bd9)

Downloads URLs for files signed by Funmoods.

3 / 68      (PUP)
https://funmoods.com/.../wbst  (fmappsetup.exe)

3 / 68      (PUP)
https://funmoods.com/.../wbst  (fmappsetup.exe)

4 / 68      (PUP)
https://funmoods.com/.../wbst  (fmappsetup.exe)

10 / 68    (PUP)
http://funmoods.com/.../wbst  (fmappsetup.exe)

15 / 68    (PUP)
http://i.funmoods.com/fm/snd/.../Setup.exe  (6c8a63f61ed9b081522e4fa9e222d482)

The following websites host and distribute files published by Funmoods.

The following publishers (by Authenticode signature organization name) are related.

Remove Funmoods Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to Funmoods by COMODO CA Limited on February 18, 2013 with the serial number '00f7100ae286d6d9ae97789c22f156c88f'.