~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.0 (11.12.2015)
Operating System: Windows 7 Professional x64
Ran by V (Administrator) on Thu 11/19/2015 at 15:47:48.07
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
File System: 1
Successfully deleted: C:\Users\V\AppData\Roaming\Mozilla\Firefox\Profiles\kkfusthh.default\user.js (File)
Registry: 2
Successfully deleted: HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827} (Registry Key)
Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827} (Registry Key)
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Thu 11/19/2015 at 16:05:51.82
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Malwarebytes Anti-Malware
www.malwarebytes.orgScan Date: 11/10/2015
Scan Time: 2:31 PM
Logfile: Malwarebytes log.txt
Administrator: Yes
Version: 2.2.0.1024
Malware Database: v2015.11.10.07
Rootkit Database: v2015.11.04.02
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: V
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 337025
Time Elapsed: 20 min, 41 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 4
PUP.Optional.InstallCore, HKLM\SOFTWARE\WOW6432NODE\InstallCore, Quarantined, [035c205c0e7dc07661025620ec174cb4],
PUP.Optional.Astromenda, HKU\S-1-5-21-639823073-3137791329-2892488224-1001\SOFTWARE\astromenda, Quarantined, [16498bf19dee9f97058b29320cf7936d],
PUP.Optional.InstallCore, HKU\S-1-5-21-639823073-3137791329-2892488224-1001\SOFTWARE\InstallCore, Quarantined, [3d222e4e96f57db9d78b690d50b332ce],
PUP.Optional.Astromenda, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Astromenda, Quarantined, [98c7b8c4e0ab78be29005ef16c963ac6],
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 2
PUP.Optional.Astromenda, C:\Program Files (x86)\Astromenda, Quarantined, [98c7b8c4e0ab78be29005ef16c963ac6],
PUP.Optional.Astromenda, C:\Program Files (x86)\Astromenda\bh, Quarantined, [98c7b8c4e0ab78be29005ef16c963ac6],
Files: 5
PUP.Optional.Astromenda, C:\Users\V\AppData\Roaming\Mozilla\Firefox\Profiles\kkfusthh.default\searchplugins\Astromenda.xml, Quarantined, [bba44f2db9d2c6703477f899ff03b14f],
PUP.Optional.Astromenda, C:\Program Files (x86)\Astromenda\FavIcon.ico, Quarantined, [98c7b8c4e0ab78be29005ef16c963ac6],
PUP.Optional.Astromenda, C:\Program Files (x86)\Astromenda\Sqlite3.dll, Quarantined, [98c7b8c4e0ab78be29005ef16c963ac6],
PUP.Optional.Astromenda, C:\Program Files (x86)\Astromenda\uninst.dat, Quarantined, [98c7b8c4e0ab78be29005ef16c963ac6],
PUP.Optional.Astromenda, C:\Program Files (x86)\Astromenda\uninstall.exe, Quarantined, [98c7b8c4e0ab78be29005ef16c963ac6],
Physical Sectors: 0
(No malicious items detected)
(end)
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
# AdwCleaner v5.021 - Logfile created 19/11/2015 at 15:41:59
# Updated 14/11/2015 by Xplode
# Database : 2015-11-19.3 [Server]
# Operating system : Windows 7 Professional Service Pack 1 (x64)
# Username : V - V-HP
# Running from : C:\Users\V\Downloads\adwcleaner_5.021.exe
# Option : Scan
# Support :
http://toolslib.net/forum***** [ Services ] *****
***** [ Folders ] *****
***** [ Files ] *****
File Found : C:\Users\V\AppData\Roaming\Mozilla\Firefox\Profiles\kkfusthh.default\user.js
***** [ DLL ] *****
***** [ Shortcuts ] *****
***** [ Scheduled tasks ] *****
***** [ Registry ] *****
Key Found : HKLM\SOFTWARE\Classes\AppID\{9CB2CD61-FFA0-406C-9D2D-8FDE6F4A4D8A}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}
***** [ Web browsers ] *****
[C:\Users\V\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : aol.com
[C:\Users\V\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : ask.com
[C:\Users\V\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : Astromenda.com
########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [1279 bytes] ##########