The Notebook Review forums were hosted by TechTarget, who shut down them down on January 31, 2022. This static read-only archive was pulled by NBR forum users between January 20 and January 31, 2022, in an effort to make sure that the valuable technical information that had been posted on the forums is preserved. For current discussions, many NBR forum users moved over to NotebookTalk.net after the shutdown.
Problems? See this thread at archive.org.

    Astromenda Virus

    Discussion in 'Windows OS and Software' started by Ultra_Gizmo_64, Oct 27, 2014.

  1. Ultra_Gizmo_64

    Ultra_Gizmo_64 Notebook Enthusiast

    Reputations:
    0
    Messages:
    36
    Likes Received:
    3
    Trophy Points:
    16
    Recently, I tried to install FileZilla, a ftp program which I had downloaded from SourceForge.net.

    Unfortunately, downloading from SourceForge requires that you use their downloader, even if you pick the direct download option.

    After I had installed Filezilla after dealing with the installation adware, I had noticed that it had installed a strange program onto my computer called Astromenda.

    This program injects your computer and web browsers with malicious code and cause everything to behave strangely.

    From what I have read, I'm not the only person that has experienced this incident.
    Unfortunately, I couldn't uninstall Astromenda correctly because it kept telling me that one of my browsers were in use, even though they were all closed, so because of that, I decided that I would do the removal myself by deleting the program from the Program Files directory, resetting each one of my web browsers and removing every mention of the term "Astromenda" from my files and registry.

    For the most part, I think that may have pretty much gotten rid of it.
    There is only one problem though.
    I can't seem to delete these two Astromenda keys from the registry.
    Every time that I try to delete them, I get an error saying "unable to delete all specified values"

    In the registry, the keys are located in Computer\HKEY_LOCAL_MACHINE_SOFTWARE\Microsoft\Windows NT\ Schedule\CompatabilityAdapter\Signatures

    Here is a screenshot of the keys in the Registry Editor:
    [​IMG]


    Here is a screenshot of the error in the Registry Editor:
    [​IMG]
     
  2. RCB

    RCB Notebook Deity

    Reputations:
    644
    Messages:
    1,065
    Likes Received:
    103
    Trophy Points:
    81
    Boot into safe mode and try to remove them there?
     
  3. HTWingNut

    HTWingNut Potato

    Reputations:
    21,580
    Messages:
    35,370
    Likes Received:
    9,877
    Trophy Points:
    931
    You don't need to use the downloader. Just click "show additional download options" from the download site and you can download the file directly.

    [​IMG]

    That's kind of crappy because SourceForge is usually pretty safe and reliable. I would report it to SourceForge because I know they don't condone such things. The downloader does say that there are offers in it that you will have to carefully read and deselect/select proper options (I hate that) to say no in different ways. But to put an annoying addition like that is just pathetic. Hope it works out for you!
     
  4. Ultra_Gizmo_64

    Ultra_Gizmo_64 Notebook Enthusiast

    Reputations:
    0
    Messages:
    36
    Likes Received:
    3
    Trophy Points:
    16
    @RCB
    Booting into safe mode to delete the keys didn't work, it still came up with the same error.

    @HTWingNut
    I am not sure if they've changed their download links but back when I had tried to download FileZilla, every option took me to the SourceForge downloader, I had to download the application from cNET to get a direct download.

    Any other ideas?
     
  5. Pirx

    Pirx Notebook Virtuoso

    Reputations:
    3,001
    Messages:
    3,005
    Likes Received:
    416
    Trophy Points:
    151
    You may need to take ownership of the keys and change permissions to allow you to delete them. Right click on the key(s) in question, and click on Permissions.
     
    RCB likes this.
  6. MrDJ

    MrDJ Notebook Nobel Laureate

    Reputations:
    2,594
    Messages:
    10,832
    Likes Received:
    363
    Trophy Points:
    501
  7. MrDJ

    MrDJ Notebook Nobel Laureate

    Reputations:
    2,594
    Messages:
    10,832
    Likes Received:
    363
    Trophy Points:
    501
  8. KCETech1

    KCETech1 Notebook Prophet

    Reputations:
    2,527
    Messages:
    4,112
    Likes Received:
    449
    Trophy Points:
    151
  9. Ultra_Gizmo_64

    Ultra_Gizmo_64 Notebook Enthusiast

    Reputations:
    0
    Messages:
    36
    Likes Received:
    3
    Trophy Points:
    16
    I have tried to take permission of the keys by adding my user name and by ticking allow for Full Control and Read.
    When I try to apply these settings, it says "Permission Denied"
    [​IMG]

    The virus scanner that I am using is Norton Internet Security 2014.
    I haven't tried Malware Bytes yet, I might have to try it out later

    I might have to check out those other ones too.

    I might look into that one too.
     
  10. 3Fees

    3Fees Notebook Deity

    Reputations:
    541
    Messages:
    970
    Likes Received:
    136
    Trophy Points:
    56
    I'd try malwarebytes they have a program for lots of issues-Here we go.

    https://www.malwarebytes.org/downloads/

    Malwarebytes Anti-Malware Free -Anti malware
    Malwarebytes Anti-root kit program-Beta-Version:1.08.2
    Malwarebytes FileASSASSIN -removes locked files-Version: 1.06
    Malwarebytes RegASSASSIN -removes malware registry keys-Version: 1.03
    Malwarebytes Chameleon- installs Malwarebytes Anti-Malware on an infected computer
    Lots more

    One or more of those will clean up the virus. Enjoy

    Cheers
    3Fees :)
     
    Last edited: Dec 16, 2014
  11. Primes

    Primes Notebook Deity

    Reputations:
    919
    Messages:
    1,736
    Likes Received:
    718
    Trophy Points:
    131
    I've posted this a few other times, but I've had pretty good luck with these programs:

    Rkill
    ADWcleaner
    Combofix
    Malwarebytes

    start with Rkill, it temporarily terminates unknown running processes that windows doesn't need, then without rebooting, run the other programs.

    you can download them safely for free here:

    http://www.bleepingcomputer.com/download/windows/