Threat Database Bad Toolbars FunMoods Toolbar

FunMoods Toolbar

By CagedTech in Bad Toolbars

Threat Scorecard

Ranking: 1,630
Threat Level: 50 % (Medium)
Infected Computers: 145,182
First Seen: January 18, 2012
Last Seen: March 12, 2024
OS(es) Affected: Windows

File System Details

FunMoods Toolbar may create the following file(s):
# File Name MD5 Detections
1. UpdateTask.exe 09bae50e8b3eb8eadcd0e3408d2ba0d2 705
2. UpdateTask.exe 9a680b2ca832439aaf55e6c1eae1aaeb 73
3. UpdateTask.exe 5f3c086fdf17cc6b9cc058337eb31949 45
4. UpdateTask.exe d266ab0db340aab1b8e790bebf7d65bd 39
5. UpdateTask.exe e6e2cef6dded1a9ad8906c0c60e1a2cd 30
6. UpdateTask.exe 6246030af2f2283d92c7a22bcfaf4711 14
7. UpdateTask.exe b7621f5f0412a701fa9abad2dd4cc60d 13
8. UpdateTask.exe 45a6f5d2427cce5ac1a6b6f1f87364cb 11
9. UpdateTask.exe d0a5716a7b85798fea424eb5037e6b98 10
10. UpdateTask.exe da7295e339729a9451df57e47a56e456 8
11. UpdateTask.exe c774b95382d644b533dea073879c65df 8
12. UpdateTask.exe e02b5775e10188505232649c584a7dcc 8
13. UpdateTask.exe b5c3eac6e63f690575ca087f986c6b2b 7
14. UpdateTask.exe 41f951fbdcf8467e92befb5b27d7927c 7
15. UpdateTask.exe 0e259e4b82811137a1e88cdfd349f412 7
16. UpdateTask.exe 327942a224fcd0595fa15a7c9529c861 6
17. UpdateTask.exe b124e575b45e65e6432a3396c1a00dec 6
18. UpdateTask.exe c54ebf16f46eed72929aeaf0b8ae5b9e 6
19. UpdateTask.exe 4ad2dfde280461e96baf4c9a166e33c6 5
20. UpdateTask.exe 15e77ce205bfb1d221824b8933b8be0d 5
21. UpdateTask.exe e5b884ddfde6b470aed85d03d8f49aeb 5
22. UpdateTask.exe 320a054e3918170ee2d0e1fcabbd10ec 5
23. UpdateTask.exe acec1cf15bca1e8591fa136dd590a3c0 4
24. UpdateTask.exe accf1b719e95f2b16d279812c4d93641 4
25. UpdateTask.exe bb441069afb00d03eb10cf862380a4a5 4
26. UpdateTask.exe 8ab33ae5cb61282008eafed2be66a698 4
27. UpdateTask.exe d021a4ee6267369c27af944d844153e2 4
28. UpdateTask.exe e5f3af873b125fc190e774ff5e357740 4
29. UpdateTask.exe 79d8f7d4d111bb9daa30d8b263f5ca78 3
30. UpdateTask.exe a4b25fb924704a2b682d1fffb926859d 3
More files

Registry Details

FunMoods Toolbar may create the following registry entry or registry entries:
CLSID
{1D085C0A-E4F4-4F66-BDBF-4BE51015BFC3}
{75A4D144-506D-4BE5-81DB-EC7DA1E7F840}
{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7}
{960DF771-CFCB-4E53-A5B5-6EF2BBE6E706}
{965B9DBE-B104-44AC-950A-8A5F97AFF439}
{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3}
{A9DB719C-7156-415E-B49D-BAD039DE4F13}
{EA28B360-05E0-4F93-8150-02891F1D8D3C}
{F03FD9D0-4F2B-497C-8A71-DD41D70B07D9}
File name without path
funmoods-speeddial.crx
Regexp file mask
%LOCALAPPDATA%\funmoods-speeddial_sf.crx
%LOCALAPPDATA%\funmoods.crx
%LOCALAPPDATA%\funmoods.exe
%USERPROFILE%\Local Settings\Application Data\funmoods-speeddial_sf.crx
%USERPROFILE%\Local Settings\Application Data\funmoods.crx
SOFTWARE\Classes\AppID\escort.DLL
SOFTWARE\Classes\AppID\escortApp.DLL
SOFTWARE\Classes\AppID\escortEng.DLL
SOFTWARE\Classes\AppID\escorTlbr.DLL
SOFTWARE\Classes\AppID\esrv.EXE
SOFTWARE\Classes\escort.escortIEPane
SOFTWARE\Classes\escort.escortIEPane.1
SOFTWARE\Classes\esrv.funmoodsESrvc
SOFTWARE\Classes\esrv.funmoodsESrvc.1
SOFTWARE\Classes\funmoods.dskBnd
SOFTWARE\Classes\funmoods.dskBnd.1
SOFTWARE\Classes\funmoods.funmoodsHlpr
SOFTWARE\Classes\funmoods.funmoodsHlpr.1
SOFTWARE\Classes\funmoodsApp.appCore
SOFTWARE\Classes\funmoodsApp.appCore.1
SOFTWARE\Classes\Wow6432Node\AppID\escort.DLL
SOFTWARE\Classes\Wow6432Node\AppID\escortApp.DLL
SOFTWARE\Classes\Wow6432Node\AppID\escortEng.DLL
SOFTWARE\Classes\Wow6432Node\AppID\escorTlbr.DLL
SOFTWARE\Classes\Wow6432Node\AppID\esrv.EXE
Software\funmoods
Software\funmoodsToolbar
Software\Microsoft\Internet Explorer\DOMStorage\searchfunmoods.com
Software\Microsoft\Internet Explorer\SearchScopes\{B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B}
SOFTWARE\Microsoft\Internet Explorer\Toolbar\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3}
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Funmoods
Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7}
SOFTWARE\Wow6432Node\Classes\AppID\escort.DLL
SOFTWARE\Wow6432Node\Classes\AppID\escortEng.DLL
SOFTWARE\Wow6432Node\Classes\AppID\esrv.EXE
SOFTWARE\Wow6432Node\Funmoods
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C87FC351-A80D-43E9-9A86-CF1E29DC443A}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3}
SOFTWARE\Wow6432Node\Microsoft\Tracing\FunmoodsSetup_RASAPI32
SOFTWARE\Wow6432Node\Microsoft\Tracing\FunmoodsSetup_RASMANCS
SOFTWARE\Wow6432Node\Microsoft\Tracing\FUNMOO~1_RASAPI32
SOFTWARE\Wow6432Node\Microsoft\Tracing\FUNMOO~1_RASMANCS
Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7}

Directories

FunMoods Toolbar may create the following directory or directories:

%APPDATA%\Funmoods
%PROGRAMFILES%\Funmoods
%PROGRAMFILES(x86)%\Funmoods
%USERPROFILE%\AppData\LocalLow\Funmoods

URLs

FunMoods Toolbar may call the following URLs:

http://searchfunmoods.com/results.php?q

Related Posts

Trending

Most Viewed

Loading...