Home Possibly Unwanted Program Funshion

Funshion

Posted: September 18, 2014

Threat Metric

Ranking: 2,157
Threat Level: 1/10
Infected PCs: 170,025
First Seen: September 18, 2014
Last Seen: October 17, 2023
OS(es) Affected: Windows


Funshion is a Chinese peer-to-peer video streaming application that may be associated with some suspicious marketing practices and tricks. Many anti-virus product vendors identify Funshion as a Potentially Unwanted Programs, and their anti-virus software can be used to identify and remove all of Funshion's files and components. The Funshion application may sometimes be installed with the help of software bundles that utilize misleading instructions and marketing tricks to convince users to install Funshion. The Funshion application is popular in China and other Asian countries because it allows users to find and watch video content that is popular in China and nearby countries quickly. However, non-Chinese speaking users who find Funshion on their computers may be confused, because the application doesn't feature an English interface. Its installation may occur without the user's knowledge, so many people may end up mistaking Funshion for a threatening and intrusive application. If you see Funshion on your computer, you should remember that this application doesn't put your files and online safety in danger. It is harmless, but having it on your computer may cause some problems, especially if you are not planning to fully utilize the features it provides. The Funshion software may display advertisements and pop-ups in the application as well as in the user's Web browser, so don't hesitate to remove the software if its marketing content is bothering you.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Windows\System32\Funshion.scr File name: Funshion.scr
Size: 343.55 KB (343552 bytes)
MD5: 03b881a55e1400de892d59e664f06620
Detection count: 8,172
Mime Type: unknown/scr
Path: C:\Windows\System32\Funshion.scr
Group: Malware file
Last Updated: September 6, 2022
%APPDATA%\FunPierides_c7137_s.exe File name: FunPierides_c7137_s.exe
Size: 10.56 MB (10566648 bytes)
MD5: bfaccfabb42ba9bb0d100ede917cd250
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: June 16, 2016

Registry Modifications

The following newly produced Registry Values are:

CLSID{162CC9EB-F1CE-4CED-84CE-F80AA5DD8130}{18689D3E-CF06-482F-AEB1-0880F859F0AA}{1CF25200-FD42-45F6-ABBD-6C0C9C89B77A}{332C1DFF-B83D-40E3-968F-F85E20BF0CFB}{43BE7926-9B51-46FD-98DD-8DCCFB231113}{456A8A65-6E0E-464B-80C6-A16E6528FADF}{4ADBABBD-E1CA-4F11-BD01-73B0B6E4B5BA}{4E3E2094-8FF4-457E-ACB5-29DABF6E1A27}{5165BFF4-4E35-446F-B00E-EA4185B64F76}{8D0F6366-8F2E-4F7F-872E-5AB98554D78C}{961ABF2E-D191-4542-90DC-C3406555FC62}{97DDF214-9B68-4CAF-8F6F-4B4112912349}{A5662DF9-0C2E-4A56-9FE1-BACFF6966D88}{CC88AD54-054C-4B38-9AB3-D932E4039187}{CE55D900-9EE4-4666-A1A1-1F6D59E32277}File name without pathFunshion HD Media.lnkfunshion.iniFunshion.lnkvas.funshion[1].xmlHKEY..\..\..\..{RegistryKeys}SOFTWARE\Classes\Fun.OnlineInstallCtrlSOFTWARE\Classes\Fun.OnlineInstallCtrl.1SOFTWARE\Classes\FunshionSOFTWARE\Classes\Funshion TaskSOFTWARE\Classes\FunshionFsvSOFTWARE\Classes\FunshionMP4SOFTWARE\Classes\FunshionRMVBSoftware\Microsoft\Internet Explorer\Approved Extensions\{4ADBABBD-E1CA-4F11-BD01-73B0B6E4B5BA}Software\Microsoft\Internet Explorer\DOMStorage\fun.tvSoftware\Microsoft\Internet Explorer\DOMStorage\funshion.comSoftware\Microsoft\Internet Explorer\DOMStorage\vas.funshion.comSoftware\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{435ABB6D-825E-464D-9431-E0421B09300C}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59561D56-F79A-4A4B-B7B6-48CB08CCF495}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5AF9AF91-F941-45E2-BA44-004A79709C18}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{80A7D4B9-D2B8-48DE-B835-0407CEBEDEC0}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FE38678E-8518-481C-B318-D654C1620DC5}SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\FunshionSOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{4ADBABBD-E1CA-4f11-BD01-73B0B6E4B5BA}SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\FunOverlaySoftware\Microsoft\Windows\CurrentVersion\Run\FunshionSOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{A5662DF9-0C2E-4A56-9FE1-BACFF6966D88}SOFTWARE\SystemSresSOFTWARE\Wow6432Node\FunshionSOFTWARE\Wow6432Node\Funshion_CopySOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{4ADBABBD-E1CA-4f11-BD01-73B0B6E4B5BA}SOFTWARE\Wow6432Node\MozillaPlugins\@funshion.com/npFunshionSYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\{27432F77-A1B8-484D-8CCF-75B211B82E42}SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\{AD2ECDE3-5B1F-49B2-BD7D-56AB3BC3D3FF}SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\{27432F77-A1B8-484D-8CCF-75B211B82E42}SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\{AD2ECDE3-5B1F-49B2-BD7D-56AB3BC3D3FF}SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\{27432F77-A1B8-484D-8CCF-75B211B82E42}SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\{AD2ECDE3-5B1F-49B2-BD7D-56AB3BC3D3FF}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}FunAcceleratorFunshion

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Application Data\Funshion%ALLUSERSPROFILE%\Funshion%ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\Funshion%APPDATA%\Avatder%APPDATA%\FunTemp%APPDATA%\Funshion%APPDATA%\FunshionV%HOMEDRIVE%\AptData%HOMEDRIVE%\FunshionMedia%PROGRAMFILES%\Funshion Online%PROGRAMFILES%\FunshionV%PROGRAMFILES(x86)%\Funshion Online%PROGRAMFILES(x86)%\FunshionV%PUBLIC%\FunAcce%PUBLIC%\Fundata%USERPROFILE%\Documents\Funshion HD Media%USERPROFILE%\Funshion%WINDIR%\System32\Tasks\Funshion%WINDIR%\Tasks\Funshion%appdata%\Acceclient%appdata%\Arefresh%appdata%\FunUninst%appdata%\funspeed%temp%\funshiontmp
Loading...