Welcome to your place for tech questions! ( Log In or Join today ) Get answers from experts today. (it's 100% free) Virus removal forum

 
Closed TopicStart new topic
> Remove funmoods [Closed]
solo58
post Apr 23 2012, 06:37 PM
Post #1


Authentic Member
**

Group: Authentic Member
Posts: 198
Joined: 21-July 10
From: Norther Virginia
Member No.: 93,671
Operating System: xp sp3



One of the kids was playing Wizards 101, in trying to purchase an option, we inadvertently downloaded funmoods. A tool bar was set up on Chrome.
I ran malwarebytes and removed 55 objects...all funmoods related.
I restarted, removed the toolbar, reran MSE after updating.
How can I confirm that the malware has been removed completely?
Go to the top of the page
 
+Quote Post
mrp
post Apr 24 2012, 10:50 AM
Post #2


Advanced Member
Group Icon

Group: Malware Team
Posts: 992
Joined: 29-August 11
Member No.: 98,090
Operating System: Windows 7 Professional 64-bit, Windows XP Professional




Hello and welcome to What the Tech.

My name is Michael and I will be helping you with your computer problems.

Be aware that I am currently in training, which means that my replies must first be approved by one of my teachers. This may cause a slight delay in my responses, but keep in mind that this process is only to ensure you are receiving advice of the utmost accuracy.

Please keep the following points in mind:
  • Malware research is often a time consuming process and sometimes multiple tools/methods will have to be employed before an infection is completely dealt with. Please be patient during the process of removal.
  • Read my instructions carefully before carrying them out. Also, consider printing out any instructions in case you lose your Internet connection.
  • If you have any questions, please ask before carrying out a fix. Clearing up any confusion beforehand will save time in the long run. That said, I will try to post instructions as clearly and concisely as possible.
  • Please reply to this thread. Do not start a new topic, and do not request help on other forums during the course of the cleaning process.
  • If you do not reply after three (3) days, your thread will be closed.

IMPORTANT NOTE: Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

I will be back as soon as possible with a response.
Go to the top of the page
 
+Quote Post
mrp
post Apr 24 2012, 05:27 PM
Post #3


Advanced Member
Group Icon

Group: Malware Team
Posts: 992
Joined: 29-August 11
Member No.: 98,090
Operating System: Windows 7 Professional 64-bit, Windows XP Professional




  1. OTL

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Select All Users
    • Under the Custom Scan box paste this in
      netsvcs
      %SYSTEMDRIVE%\*.exe
      /md5start
      explorer.exe
      winlogon.exe
      Userinit.exe
      svchost.exe
      /md5stop
      %systemroot%\*. /rp /s
      DRIVES
      CREATERESTOREPOINT
    • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan won't take long.
      • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
      • Post both logs

  2. aswMBR

    Please download aswMBR and save it to your desktop.

    • Double click aswMBR.exe to start the tool.
    • When prompted to download virus definitions, please do so.
    • Click Scan. Note: Do NOT attempt any Fix yet.
    • When the scan completes, click Save log, save it to your desktop and post it in your next reply.
    • There should also be another file that is created on your desktop named MBR.dat. Please right-click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.
Go to the top of the page
 
+Quote Post
mrp
post Apr 27 2012, 11:16 AM
Post #4


Advanced Member
Group Icon

Group: Malware Team
Posts: 992
Joined: 29-August 11
Member No.: 98,090
Operating System: Windows 7 Professional 64-bit, Windows XP Professional




Hi solo58,

Do you still need help?
Go to the top of the page
 
+Quote Post
solo58
post Apr 27 2012, 01:10 PM
Post #5


Authentic Member
**

Group: Authentic Member
Posts: 198
Joined: 21-July 10
From: Norther Virginia
Member No.: 93,671
Operating System: xp sp3



sorry about that, have been out of town.
Go to the top of the page
 
+Quote Post
mrp
post Apr 30 2012, 10:44 AM
Post #6


Advanced Member
Group Icon

Group: Malware Team
Posts: 992
Joined: 29-August 11
Member No.: 98,090
Operating System: Windows 7 Professional 64-bit, Windows XP Professional




Hi solo58,

The instructions you need to carry out if you want my help are located in post #3 of this thread if you did not see them. smile.gif
Go to the top of the page
 
+Quote Post
CatByte
post May 10 2012, 06:43 PM
Post #7


Classroom Administrator
Group Icon

Group: Classroom Admin
Posts: 19,743
Joined: 18-November 04
From: Canada
Member No.: 18,614
Operating System: XP, Vista, Win7
MVP


Due to inactivity this topic will be closed.
If you need help please start a new thread.

New members follow the instructions here http://forums.whatthetech.com/you_Infected_t106388.html and start a new topic
Go to the top of the page
 
+Quote Post

Closed TopicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 


RSS Time is now: 21st May 2013 - 02:10 PM
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.
Member site: Alliance of Security Analysis Professionals | UNITE Against Malware
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy