Home Possibly Unwanted Program PUP.Astromenda

PUP.Astromenda

Posted: July 29, 2014

Threat Metric

Ranking: 505
Threat Level: 1/10
Infected PCs: 354,224
First Seen: July 29, 2014
Last Seen: March 10, 2025
OS(es) Affected: Windows

Aliases

Generic36.AFHE [AVG]GrayWare[AdWare:not-a-virus]/Win32.Agent [Antiy-AVL]Troj/Agent-AJJO [Sophos]BehavesLike.Win32.Dropper.fh [McAfee-GW-Edition]ADW_STARTPAGE [TrendMicro]ApplicUnwnt [Comodo]not-a-virus:AdWare.Win32.Agent.gpgg [Kaspersky]Adware.DealPly [Symantec]Artemis!6C83D6FDCE5C [McAfee]AdWare.Agent.r6 (Not a Virus) [CAT-QuickHeal]Generic_s.DM [AVG]Adware.Downware.8492 [DrWeb]Win32:Dropper-gen [Drp] [Avast]Trojan Horse [Symantec]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Users\<username>\AppData\Local\Temp\Astroupdate.exe File name: Astroupdate.exe
Size: 478.2 KB (478208 bytes)
MD5: 08b32f1bd56854dcecdfbd7a5ac180a0
Detection count: 35,537
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\Astroupdate.exe
Group: Malware file
Last Updated: February 8, 2025
C:\Program Files\WSE_Astromenda\BRS\trz41FE.tmp File name: trz41FE.tmp
Size: 1.17 MB (1173504 bytes)
MD5: 6717478dcc4540f51fd8d760a7008e22
Detection count: 13,409
File type: Temporary File
Mime Type: unknown/tmp
Path: C:\Program Files\WSE_Astromenda\BRS\trz41FE.tmp
Group: Malware file
Last Updated: September 9, 2022
%LOCALAPPDATA%\AstromendaKMS\AstromendaKMS\1.3.11.0\AstromendaKMS.exe File name: AstromendaKMS.exe
Size: 470.24 KB (470240 bytes)
MD5: 932cadbd8717ad923c09d0664a8d715b
Detection count: 3,225
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\AstromendaKMS\AstromendaKMS\1.3.11.0
Group: Malware file
Last Updated: October 17, 2020
%APPDATA%\WSE_Astromenda\UpdateProc\bkup.dat File name: bkup.dat
Size: 16.9 KB (16901 bytes)
MD5: d99b3faa579c71391318c52462c3f21f
Detection count: 61
File type: Data file
Mime Type: unknown/dat
Path: %APPDATA%\WSE_Astromenda\UpdateProc
Group: Malware file
Last Updated: July 7, 2017

More files

Registry Modifications

The following newly produced Registry Values are:

File name without pathAstromenda.lnkRegexp file mask%LOCALAPPDATA%\Astromenda\Application\astromenda.exe%WinDir%\System32\Tasks\Astromenda%WINDIR%\System32\Tasks\WSE_Astromenda%windir%\Tasks\Astromenda.job%WINDIR%\Tasks\WSE_Astromenda.jobHKEY..\..\..\..{RegistryKeys}Software\astromendaSoftware\Astromenda BrowserSOFTWARE\Classes\AppID\{9CB2CD61-FFA0-406C-9D2D-8FDE6F4A4D8A}SOFTWARE\Classes\Wow6432Node\AppID\{9CB2CD61-FFA0-406C-9D2D-8FDE6F4A4D8A}Software\Microsoft\Internet Explorer\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\WSE_Astromenda.jobSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\WSE_Astromenda.job.fpSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AstromendaSOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\astromenda.exeSoftware\Microsoft\Windows\CurrentVersion\RunOnce\AstromendaSoftware\Microsoft\Windows\CurrentVersion\RunOnce\WSE_AstromendaSOFTWARE\Wow6432Node\Classes\AppID\{9CB2CD61-FFA0-406C-9D2D-8FDE6F4A4D8A}Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}SOFTWARE\Wow6432Node\Microsoft\MediaPlayer\ShimInclusionList\astromenda.exeSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\astromenda.exeSoftware\WSE_AstromendaHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}AstromendaWSE_Astromenda

Additional Information

The following directories were created:
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Astromenda%APPDATA%\WSE_Astromenda%AppData%\Astromenda%LOCALAPPDATA%\Astromenda%LOCALAPPDATA%\AstromendaKMS%PROGRAMFILES%\Astromenda%PROGRAMFILES%\WSE_ASTROMENDA%PROGRAMFILES(x86)%\Astromenda%PROGRAMFILES(x86)%\WSE_ASTROMENDA%UserProfile%\Local Settings\Application Data\Astromenda
The following URL's were detected:
Astromenda Search Addonastromenda.com
Loading...