PUP.Astromenda

Threat Scorecard

Ranking: 642
Threat Level: 10 % (Normal)
Infected Computers: 151,007
First Seen: July 29, 2014
Last Seen: February 9, 2025
OS(es) Affected: Windows

Aliases

14 security vendors flagged this file as malicious.

Anti-Virus Software Detection
AVG Generic36.AFHE
Antiy-AVL GrayWare[AdWare:not-a-virus]/Win32.Agent
Sophos Troj/Agent-AJJO
McAfee-GW-Edition BehavesLike.Win32.Dropper.fh
TrendMicro ADW_STARTPAGE
Comodo ApplicUnwnt
Kaspersky not-a-virus:AdWare.Win32.Agent.gpgg
Symantec Adware.DealPly
McAfee Artemis!6C83D6FDCE5C
CAT-QuickHeal AdWare.Agent.r6 (Not a Virus)
AVG Generic_s.DM
DrWeb Adware.Downware.8492
Avast Win32:Dropper-gen [Drp]
Symantec Trojan Horse

SpyHunter Detects & Remove PUP.Astromenda

File System Details

PUP.Astromenda may create the following file(s):
# File Name MD5 Detections
1. brs.exe 6c83d6fdce5ca49634988b96f788feec 18,295
2. Astroupdate.exe 08b32f1bd56854dcecdfbd7a5ac180a0 15,173
3. trz41FE.tmp 6717478dcc4540f51fd8d760a7008e22 5,725
4. astromendaGames.exe b16a123f0e6b3f0916830d7cbe51d553 2,921
5. astromenda (2).exe 66f739f9a09f49164e1b99023884298a 1,640
6. AstromendaKMS.exe 932cadbd8717ad923c09d0664a8d715b 1,377
7. trz6BEC.tmp 4427c4a01474d6b0e3b21091cde22eaa 1,177
8. uninstall.exe 440985006caecff06871e278a2f03bfe 53
9. bkup.dat d99b3faa579c71391318c52462c3f21f 26
10. astromenda.exe fc9848343f72d1c75af6e601e3d35986 13
More files

Registry Details

PUP.Astromenda may create the following registry entry or registry entries:
File name without path
Astromenda.lnk
Regexp file mask
%LOCALAPPDATA%\Astromenda\Application\astromenda.exe
%WinDir%\System32\Tasks\Astromenda
%WINDIR%\System32\Tasks\WSE_Astromenda
%windir%\Tasks\Astromenda.job
%WINDIR%\Tasks\WSE_Astromenda.job
Software\astromenda
Software\Astromenda Browser
SOFTWARE\Classes\AppID\{9CB2CD61-FFA0-406C-9D2D-8FDE6F4A4D8A}
SOFTWARE\Classes\Wow6432Node\AppID\{9CB2CD61-FFA0-406C-9D2D-8FDE6F4A4D8A}
Software\Microsoft\Internet Explorer\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\WSE_Astromenda.job
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\WSE_Astromenda.job.fp
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Astromenda
SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\astromenda.exe
Software\Microsoft\Windows\CurrentVersion\RunOnce\Astromenda
Software\Microsoft\Windows\CurrentVersion\RunOnce\WSE_Astromenda
SOFTWARE\Wow6432Node\Classes\AppID\{9CB2CD61-FFA0-406C-9D2D-8FDE6F4A4D8A}
Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}
SOFTWARE\Wow6432Node\Microsoft\MediaPlayer\ShimInclusionList\astromenda.exe
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\astromenda.exe
Software\WSE_Astromenda

Directories

PUP.Astromenda may create the following directory or directories:

%APPDATA%\Microsoft\Windows\Start Menu\Programs\Astromenda
%APPDATA%\WSE_Astromenda
%AppData%\Astromenda
%LOCALAPPDATA%\Astromenda
%LOCALAPPDATA%\AstromendaKMS
%PROGRAMFILES%\Astromenda
%PROGRAMFILES%\WSE_ASTROMENDA
%PROGRAMFILES(x86)%\Astromenda
%PROGRAMFILES(x86)%\WSE_ASTROMENDA
%UserProfile%\Local Settings\Application Data\Astromenda

URLs

PUP.Astromenda may call the following URLs:

Astromenda Search Addon
astromenda.com

Trending

Most Viewed

Loading...