Sophos

Sophos blogs

Fumn

Category
Type
What to do
  • If you've received an alert for a blocked PUA or adware and decide that the application is not suitable for your workplace, then follow the instructions for removing PUAs.

Summary

 
Protection available since 6 July 2009 10:07:30 (GMT)
Detected by Sophos Anti-Virus for Windows, version 7, and PureMessage for Microsoft Exchange.

More Information

Fumn is an hacktool application that works under ring0 for the Windows platform and allows to patches packed executables with exepackers.

When application loaded the FuckFmn.sys file is installed as "FuckFmn" system device.
Registry entries are created or modified under:

HKLM\SYSTEM\CurrentControlSet\Services\FuckFmn\

RSS|Atom
Get reports about the latest adware and potentially unwanted applications (PUAs) delivered to your computer