Recently, I tried to install FileZilla, a ftp program which I had downloaded from SourceForge.net.
Unfortunately, downloading from SourceForge requires that you use their downloader, even if you pick the direct download option.
After I had installed Filezilla after dealing with the installation adware, I had noticed that it had installed a strange program onto my computer called Astromenda.
This program injects your computer and web browsers with malicious code and cause everything to behave strangely.
From what I have read, I'm not the only person that has experienced this incident.
Unfortunately, I couldn't uninstall Astromenda correctly because it kept telling me that one of my browsers were in use, even though they were all closed, so because of that, I decided that I would do the removal myself by deleting the program from the Program Files directory, resetting each one of my web browsers and removing every mention of the term "Astromenda" from my files and registry.
For the most part, I think that may have pretty much gotten rid of it.
There is only one problem though.
I can't seem to delete these two Astromenda keys from the registry.
Every time that I try to delete them, I get an error saying "unable to delete all specified values"
In the registry, the keys are located in Computer\HKEY_LOCAL_MACHINE_SOFTWARE\Microsoft\Windows NT\ Schedule\CompatabilityAdapter\Signatures
Here is a screenshot of the keys in the Registry Editor:
![]()
Here is a screenshot of the error in the Registry Editor:
![]()
-
-
Boot into safe mode and try to remove them there?
-
You don't need to use the downloader. Just click "show additional download options" from the download site and you can download the file directly.
That's kind of crappy because SourceForge is usually pretty safe and reliable. I would report it to SourceForge because I know they don't condone such things. The downloader does say that there are offers in it that you will have to carefully read and deselect/select proper options (I hate that) to say no in different ways. But to put an annoying addition like that is just pathetic. Hope it works out for you! -
@RCB
Booting into safe mode to delete the keys didn't work, it still came up with the same error.
@HTWingNut
I am not sure if they've changed their download links but back when I had tried to download FileZilla, every option took me to the SourceForge downloader, I had to download the application from cNET to get a direct download.
Any other ideas? -
You may need to take ownership of the keys and change permissions to allow you to delete them. Right click on the key(s) in question, and click on Permissions.
RCB likes this. -
what virus scanner are you using and have you also tried malwarebytes.
i will post some links up when i get home to see if they help but in the mean time try some of these found on google https://www.google.co.uk/search?hl=....0...1ac..34.heirloom-hp..0.1.109.XVq26FDSa84 -
i used these for a rootkit but they work on other trojan viruses. try trend micro anti threat toolkit and Avast aswMBR Win32:Evo-gen [Susp] - Virus Removal Guide
-
one more option is esets online scanner and remover
Free Virus Scan | Online Virus Scanner from ESET -
When I try to apply these settings, it says "Permission Denied"
I haven't tried Malware Bytes yet, I might have to try it out later
-
I'd try malwarebytes they have a program for lots of issues-Here we go.
https://www.malwarebytes.org/downloads/
Malwarebytes Anti-Malware Free -Anti malware
Malwarebytes Anti-root kit program-Beta-Version:1.08.2
Malwarebytes FileASSASSIN -removes locked files-Version: 1.06
Malwarebytes RegASSASSIN -removes malware registry keys-Version: 1.03
Malwarebytes Chameleon- installs Malwarebytes Anti-Malware on an infected computer
Lots more
One or more of those will clean up the virus. Enjoy
Cheers
3FeesLast edited: Dec 16, 2014 -
I've posted this a few other times, but I've had pretty good luck with these programs:
Rkill
ADWcleaner
Combofix
Malwarebytes
start with Rkill, it temporarily terminates unknown running processes that windows doesn't need, then without rebooting, run the other programs.
you can download them safely for free here:
http://www.bleepingcomputer.com/download/windows/
Astromenda Virus
Discussion in 'Windows OS and Software' started by Ultra_Gizmo_64, Oct 27, 2014.