PUP.Astromenda

Threat Scorecard

Ranking: 607
Threat Level: 10 % (Normal)
Infected Computers: 149,349
First Seen: July 29, 2014
Last Seen: May 17, 2024
OS(es) Affected: Windows

Aliases

14 security vendors flagged this file as malicious.

Anti-Virus Software Detection
AVG Generic36.AFHE
Antiy-AVL GrayWare[AdWare:not-a-virus]/Win32.Agent
Sophos Troj/Agent-AJJO
McAfee-GW-Edition BehavesLike.Win32.Dropper.fh
TrendMicro ADW_STARTPAGE
Comodo ApplicUnwnt
Kaspersky not-a-virus:AdWare.Win32.Agent.gpgg
Symantec Adware.DealPly
McAfee Artemis!6C83D6FDCE5C
CAT-QuickHeal AdWare.Agent.r6 (Not a Virus)
AVG Generic_s.DM
DrWeb Adware.Downware.8492
Avast Win32:Dropper-gen [Drp]
Symantec Trojan Horse

SpyHunter Detects & Remove PUP.Astromenda

File System Details

PUP.Astromenda may create the following file(s):
# File Name MD5 Detections
1. UpdateTask.exe 1c03f480fbe4181a98346c9774dcb2f7 82
2. UpdateTask.exe 6e1f5d6ec652d993672aeda0ed35490c 55
3. UpdateTask.exe 1b96bd58fbaf9646448004effa61a25a 45
4. UpdateTask.exe 7872c835da46c29736d0e8b7d2f73ff5 30
5. UpdateTask.exe aad5fc7396c4117aa1bc1d2293af39a1 27
6. UpdateTask.exe 06ce970cd88d511d50fbe2c50eb671cb 26
7. bkup.dat d99b3faa579c71391318c52462c3f21f 26
8. UpdateTask.exe 228ef1c2d1c8d0f1b80da0ae9f9eb750 21
9. UpdateTask.exe 31536a79e297140ba591c6a634913d01 19
10. UpdateTask.exe 91af9bdce640e7e0eb08fab569fa4e1e 17
11. UpdateTask.exe 4a0a6d2cffa1bfcf80a805742e3cdc31 16
12. UpdateTask.exe 2af6fd501749d4abde7f1b8920cb3aba 14
13. UpdateTask.exe 756ee93646c9567480ac05a3261667b2 13
14. UpdateTask.exe 8807418aa5e4b7bac119017fa7bd8aaa 13
15. UpdateTask.exe 37e67a4947544814f6aa5accdd98ec4a 12
16. UpdateTask.exe 385928ae698e982e060955515576b6df 11
17. UpdateTask.exe 7f8e292ecece1f91690b5aee2391172b 11
18. UpdateTask.exe e90414b1b88e28ed45b69bfad696ef80 10
19. UpdateTask.exe 1ac29e2494eb03c60d9d9a5f0757d213 9
20. UpdateTask.exe 8a8fdc88d3b2644681b2ad1d886f4000 9
21. UpdateTask.exe 045dc81ccdc5da56a2c1f6986deffced 9
22. UpdateTask.exe 4f75285599ffe76130d96738a7fb85a4 9
23. UpdateTask.exe 7276dccac0f383fb945680da4d9eb2f0 9
24. UpdateTask.exe 7f6a78ea233028607d2dbd1aa4c74b66 8
25. UpdateTask.exe 9eca9703952e73cdd8c79d76e3dd485a 8
26. UpdateTask.exe 970cda0c11e2ca60a0827979a104125d 8
More files

Registry Details

PUP.Astromenda may create the following registry entry or registry entries:
File name without path
Astromenda.lnk
Regexp file mask
%LOCALAPPDATA%\Astromenda\Application\astromenda.exe
%WinDir%\System32\Tasks\Astromenda
%WINDIR%\System32\Tasks\WSE_Astromenda
%windir%\Tasks\Astromenda.job
%WINDIR%\Tasks\WSE_Astromenda.job
Software\astromenda
Software\Astromenda Browser
SOFTWARE\Classes\AppID\{9CB2CD61-FFA0-406C-9D2D-8FDE6F4A4D8A}
SOFTWARE\Classes\Wow6432Node\AppID\{9CB2CD61-FFA0-406C-9D2D-8FDE6F4A4D8A}
Software\Microsoft\Internet Explorer\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\WSE_Astromenda.job
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\WSE_Astromenda.job.fp
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Astromenda
SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\astromenda.exe
Software\Microsoft\Windows\CurrentVersion\RunOnce\Astromenda
Software\Microsoft\Windows\CurrentVersion\RunOnce\WSE_Astromenda
SOFTWARE\Wow6432Node\Classes\AppID\{9CB2CD61-FFA0-406C-9D2D-8FDE6F4A4D8A}
Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}
SOFTWARE\Wow6432Node\Microsoft\MediaPlayer\ShimInclusionList\astromenda.exe
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\astromenda.exe
Software\WSE_Astromenda

Directories

PUP.Astromenda may create the following directory or directories:

%APPDATA%\Microsoft\Windows\Start Menu\Programs\Astromenda
%APPDATA%\WSE_Astromenda
%AppData%\Astromenda
%LOCALAPPDATA%\Astromenda
%LOCALAPPDATA%\AstromendaKMS
%PROGRAMFILES%\Astromenda
%PROGRAMFILES%\WSE_ASTROMENDA
%PROGRAMFILES(x86)%\Astromenda
%PROGRAMFILES(x86)%\WSE_ASTROMENDA
%UserProfile%\Local Settings\Application Data\Astromenda

URLs

PUP.Astromenda may call the following URLs:

Astromenda Search Addon
astromenda.com
http://astromenda.com/?a=&q=

Trending

Most Viewed

Loading...