Wilders Security Forums  

Go Back   Wilders Security Forums > Software, Hardware and General Services > sandboxing & virtualization
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old August 8th, 2012, 04:31 PM
WilliamP WilliamP is offline
Very Frequent Poster
 
Join Date: Jun 2003
Location: Fayetteville, Ga
Posts: 2,125
Question Pup Funmoods

I have the latest Sandboxie and Avira. This morning I was some where on the web where I shouldn't have been. I have SB set to empty the sandbox when I close the browser. When I closed FF I noticed that my taskbar icon for Avira had moved. So I ran Superantispyware and it found Pup Funmoods toolbar. Then I ran Malwarebytes and it found a whole bunch of trash. I have run several scans and I believe I have cleaned it all out. It has really caused me to question the effectivity of SB. How was this stuff able to get to my system
  #2  
Old August 8th, 2012, 06:32 PM
bo elam bo elam is offline
Very Frequent Poster
 
Join Date: Jun 2010
Posts: 1,043
Default Re: Pup Funmoods

Quote:
Originally Posted by WilliamP
How was this stuff able to get to my system
After searching Google for a little while, I found that people get Funmood either bundled with other software that gets installed in the computer or someone gets an installer and installs it. I am no expert on any of this but I don't think you get Funmood browsing. According to what I read is an addon for social networks like Facebook.

Good luck

Bo
  #3  
Old August 8th, 2012, 06:39 PM
WilliamP WilliamP is offline
Very Frequent Poster
 
Join Date: Jun 2003
Location: Fayetteville, Ga
Posts: 2,125
Default Re: Pup Funmoods

I didn't download anything that I know of.
  #4  
Old August 8th, 2012, 07:23 PM
Montmorency's Avatar
Montmorency Montmorency is offline
Regular Poster
 
Join Date: Oct 2011
Posts: 184
Default Re: Pup Funmoods

I can assure you something like this would never come out of Sandboxie.
You made some mistake.
  #5  
Old August 8th, 2012, 08:27 PM
WilliamP WilliamP is offline
Very Frequent Poster
 
Join Date: Jun 2003
Location: Fayetteville, Ga
Posts: 2,125
Default Re: Pup Funmoods

I know that you are correct but I don't how. I never came out of FF ,so I never left the sandbox. And I didn't download anything.
  #6  
Old August 8th, 2012, 10:42 PM
bo elam bo elam is offline
Very Frequent Poster
 
Join Date: Jun 2010
Posts: 1,043
Default Re: Pup Funmoods

Quote:
Originally Posted by WilliamP
I didn't download anything that I know of.
Look around your system, you ll find folders or files in Program files, AppData, Document and settings, related to Funmoods. Theres got to be some, somewhere. When you locate it, look at the date and you ll see that Funmoods was installed before the browsing session that you think is when you got the PUP.

Bo
  #7  
Old August 9th, 2012, 08:32 AM
WilliamP WilliamP is offline
Very Frequent Poster
 
Join Date: Jun 2003
Location: Fayetteville, Ga
Posts: 2,125
Default Re: Pup Funmoods

I have done several searches and there is nothing left. And there was nothing there before. Some how it got out of SB ,shut down Avira, got on the system then re-started Avira. I know it is hard to understand. But that is how I noticed that the Avira icon in the task bar had moved. It had been re-started.
  #8  
Old August 9th, 2012, 08:40 AM
Montmorency's Avatar
Montmorency Montmorency is offline
Regular Poster
 
Join Date: Oct 2011
Posts: 184
Default Re: Pup Funmoods

Do you have FF to force run in Sandboxie (paid version).
If not, are you absolutely sure FF was sandboxed? When you noticed Avira icon moving did you see the red X in Sandboxie's icon?
  #9  
Old August 9th, 2012, 10:14 AM
WilliamP WilliamP is offline
Very Frequent Poster
 
Join Date: Jun 2003
Location: Fayetteville, Ga
Posts: 2,125
Default Re: Pup Funmoods

I have the paid version of SB and I always watch for the little red X on the SB icon when I close FF. It did that time. So I know it was sandboxed. I always open FF sandboxed.
  #10  
Old August 10th, 2012, 12:05 PM
Doodler Doodler is offline
Frequent Poster
 
Join Date: Dec 2007
Posts: 204
Default Re: Pup Funmoods

Doubtful that we'll ever know what really happened. Malware experts like Buster (who frequents the Sandboxie forum and this one) test thousands and thousands of malware on an ongoing basis using Sandboxie. Not to discount your sincerity, but it seems to me if something was able to escape your sandbox, he'd be aware of it.
  #11  
Old August 10th, 2012, 02:09 PM
WilliamP WilliamP is offline
Very Frequent Poster
 
Join Date: Jun 2003
Location: Fayetteville, Ga
Posts: 2,125
Default Re: Pup Funmoods

Well Doodler,I have always had faith in SB. I have no idea how it happened. All I know is that it had to have gotten around it some how.
  #12  
Old August 10th, 2012, 02:31 PM
Montmorency's Avatar
Montmorency Montmorency is offline
Regular Poster
 
Join Date: Oct 2011
Posts: 184
Default Re: Pup Funmoods

Quote:
Originally Posted by WilliamP
All I know is that it had to have gotten around it some how.
That's exactly what I find to be strange.
If we were talking about something sophisticated... but even the most perfected malware can't break out of SBIE (up to now)... let alone this simple stuf.
  #13  
Old August 10th, 2012, 02:54 PM
WilliamP WilliamP is offline
Very Frequent Poster
 
Join Date: Jun 2003
Location: Fayetteville, Ga
Posts: 2,125
Default Re: Pup Funmoods

I don't know if this means anything but Superantspyware found the toolbar and Malwarebytes found 33 other things that I know were not there before.
  #14  
Old August 10th, 2012, 05:24 PM
Montmorency's Avatar
Montmorency Montmorency is offline
Regular Poster
 
Join Date: Oct 2011
Posts: 184
Default Re: Pup Funmoods

I tried to install Funmoods inside Sandboxie
Attached Images
     
  #15  
Old August 10th, 2012, 05:26 PM
Montmorency's Avatar
Montmorency Montmorency is offline
Regular Poster
 
Join Date: Oct 2011
Posts: 184
Default Re: Pup Funmoods

Afterwards I scanned the machine with MBAM and HitmanPro and it came out clean.
  #16  
Old August 10th, 2012, 05:27 PM
Gullible Jones
 
Posts: n/a
Default Re: Pup Funmoods

Think "alternative vectors." Is it possible for instance that you plugged in an infected USB stick at some point?
  #17  
Old August 10th, 2012, 05:29 PM
AlexC's Avatar
AlexC AlexC is offline
Very Frequent Poster
 
Join Date: Apr 2009
Posts: 1,111
Default Re: Pup Funmoods

Quote:
Originally Posted by WilliamP
I don't know if this means anything but Superantspyware found the toolbar and Malwarebytes found 33 other things that I know were not there before.

Its easy to test if funmoods can get out the sandbox or not... but i really don´t think that it can.

edit: Montmorency already did it

Maybe you have recovered the file to the real location or you have your download location with direct access?
__________________
Linux Mint 13 MATE x64
  #18  
Old August 10th, 2012, 05:35 PM
crofttk's Avatar
crofttk crofttk is offline
Very Frequent Poster
 
Join Date: May 2004
Location: Eastern PA, USA
Posts: 1,952
Default Re: Pup Funmoods

Quote:
Originally Posted by Gullible Jones
Think "alternative vectors." Is it possible for instance that you plugged in an infected USB stick at some point?
Another for instance, I don't believe it's been established that the OP is the only user or person having access to the machine in question. I would hope OP, however, would have pointed out that possibility.
__________________
"Ignorance more frequently begets confidence than does knowledge..." - Charles Darwin -
  #19  
Old August 10th, 2012, 05:55 PM
WilliamP WilliamP is offline
Very Frequent Poster
 
Join Date: Jun 2003
Location: Fayetteville, Ga
Posts: 2,125
Default Re: Pup Funmoods

I am willing to just let it go as something unexplainable. I am an old retired fart that has a computer and my wife has her computer. No one uses this computer but me. I can guarantee you that nothing came up on my display showing anything like what was shown in Montmorency's post.
  #20  
Old August 10th, 2012, 05:57 PM
DBone's Avatar
DBone DBone is online now
Frequent Poster
 
Join Date: Nov 2010
Location: SoCal USA
Posts: 803
Default Re: Pup Funmoods

The OP made a mistake somewhere, somehow. That PUP did not bypass Sandboxie.
__________________
~ Windows 7 Home Premium x64 ~ Clean Install ~ Router NAT Firewall ~ Windows 7 Firewall ~ EXE Radar Pro ~ MBAM ~ Chrome ~ Ghostery ~ Windows 7 System Image ~ DBone's Common Sense ~ Lady Luck ~
  #21  
Old August 10th, 2012, 07:00 PM
cheater87's Avatar
cheater87 cheater87 is offline
Massive Poster
 
Join Date: Apr 2005
Location: West Chester Pennsylvania.
Posts: 3,003
Default Re: Pup Funmoods

CAV detected the exe. Will test with Avast soon to see what it detects in it.
__________________
I have Windows 7 64 bit Comodo Firewall 6 set to block, Avast Free Edition, K9 Web Protection set to block malicious and phishing sites only, Zemana Free Anti Keylogger, Comodo DNS, Firefox with Noscript, Adblock Plus, WOT set to block, Secunia PSI, and common sense. ^_^
  #22  
Old August 10th, 2012, 07:36 PM
crofttk's Avatar
crofttk crofttk is offline
Very Frequent Poster
 
Join Date: May 2004
Location: Eastern PA, USA
Posts: 1,952
Default Re: Pup Funmoods

Quote:
Originally Posted by WilliamP
I am willing to just let it go as something unexplainable. I am an old retired fart that has a computer and my wife has her computer. No one uses this computer but me. I can guarantee you that nothing came up on my display showing anything like what was shown in Montmorency's post.
Nothing at all wrong with that and an admirable place to be as far as I'm concerned. I was just trying to help rule out some possibilities.
__________________
"Ignorance more frequently begets confidence than does knowledge..." - Charles Darwin -
  #23  
Old August 10th, 2012, 09:00 PM
Osaban's Avatar
Osaban Osaban is offline
Massive Poster
 
Join Date: Apr 2005
Posts: 3,093
Default Re: Pup Funmoods

Quote:
Originally Posted by WilliamP
I have the latest Sandboxie and Avira. This morning I was some where on the web where I shouldn't have been.
If you remember where you shouldn't have been, maybe you can try to create the same situation and see if that happens again.
__________________
Samsung Series 7 Chronos & Windows 8 (64bit)
“We are the cosmos made conscious and life is the means by which the universe understands itself.” Brian Cox
 

Wilders Security Forums > Software, Hardware and General Services > sandboxing & virtualization « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 01:35 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums