Home Malware Programs Browser Hijackers Astromenda.com

Astromenda.com

Posted: July 30, 2014

Astromenda.com is a search engine and appears when a PC user installs the Astromenda add-on. Up to now China, Canada, Germany, Switzerland, USA and the UK are the countries that reported to have been infected. Andromeda Search is created by IronSource Ltd and is considered similar to other PUPs (Potentially Unwanted Programs) such as Mysearchdial, Groovorio, etc.

Astromenda is associated with browser hijackers that make changes on the targeted computer. This threat can infect only Windows systems and yet getting rid of it can be annoying for the user. This threat performs a reset to the parameters of your browsers, so your Internet Explorer, Mozilla Firefox and Google Chrome will have different homepages, still this is not all of it. Your homepages will be changed to mystart.vi-view.com and your default search engine will be now Astromenda.com. Although, Astromenda may seem like a dependable browser plug-in, do not be fooled and in case of infection it is advised to remove it as soon as possible. At first, you will simply notice the changes in your homepage and search engine. However, in a while, you will also notice that this threat is actually interfering with all of your browsing activities. So instead of helping users through their Web surfing, Astromenda may extract your browsing history, bookmarks and online habits in general. In case you have come to the decision that this threat is not worth the time to remove it, you will soon find out that this is not true. Since the Astromenda search engine is low grade one, sooner or later you will see that it may redirect you to harmful websites.

How Can I Get Infected with Astromenda Malware?

What happens is that you go to a popular freeware website and look for Adobe Flash Player, a PDF creator or a video converter, or maybe a Java update. In order to download that kind of free software freeware websites have developed special download managers. Here is the problem, this type of websites claim that they offer '100% legitimate and virus-free' content, but there's no assurance that you're not going to get bloatware. Usually, such a threat is bundled with the freeware that you downloaded, and in most cases, users are not aware where did it come from and thus consider Astromenda a virus. Technically, it is not a virus, and yet Astromenda shows a great deal of unfavorable qualities. For example, this threat is enabled to hook deeply into your computer's operating system, it can also make your browsing experience a nightmare since Astromenda supports banners and ad pop-ups too. In general, PC threat analysts consider Astromenda Search and add-on are linked to a browser hijacker. What is more important is the fact that Astromenda.com search engine is sponsored by third-parties, meaning that you will be seeing their advertisements.

I'm Infected, Now What?

In case you already got this threat into your system, specialists advise to quickly find a way to remove Astromenda. Unfortunately, this is not an easy task, since after you uninstall the add-on from your Windows system, you may need to reset the settings of your browsers, yes, to all of them. Have in mind that this reset is done differently for each browser, yet the way is basically the same. Last but not least, it is very important to understand that PC threats install in such a way that there is a hidden file that remains somewhere far from sight and what is worse that it usually remains hidden, so in case you have already removed Astromenda from the Control Panel, remember that this is not the only place there are components of Astromenda.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Program Files2\ASTROM~1\\uninstall.exe File name: C:\Program Files2\ASTROM~1\\uninstall.exe
File type: Executable File
Mime Type: unknown/exe
C:\Program Files\Astromenda File name: C:\Program Files\Astromenda
C:\Program Files\DIFX\277d1c50d2b49142\dpinst32.exe File name: C:\Program Files\DIFX\277d1c50d2b49142\dpinst32.exe
File type: Executable File
Mime Type: unknown/exe
C:\Program Files\WSE_Astromenda File name: C:\Program Files\WSE_Astromenda
C:\Users\<username>\AppData\Local\Astromenda\Application\astromenda.exe File name: C:\Users\<username>\AppData\Local\Astromenda\Application\astromenda.exe
File type: Executable File
Mime Type: unknown/exe
C:\Users\<username>\AppData\Local\Google\Chrome\UserData\Default\Extensions\pfkfdlcdbajamklbneflfbcmfgddmpae File name: C:\Users\<username>\AppData\Local\Google\Chrome\UserData\Default\Extensions\pfkfdlcdbajamklbneflfbcmfgddmpae
C:\Users\<username>\AppData\Roaming\Mozilla\Firefox\Profiles\XXXX.default\extensions\{ad7ce998-a77b-4062-9ffb-1d0b7cb23183} File name: C:\Users\<username>\AppData\Roaming\Mozilla\Firefox\Profiles\XXXX.default\extensions\{ad7ce998-a77b-4062-9ffb-1d0b7cb23183}
Mime Type: unknown/default\extensions\{ad7ce998-a77b-4062-9ffb-1d0b7cb23183}
C:\Users\<username>\AppData\Roaming\Mozilla\Firefox\Profiles\XXXX.default\searchplugins\Astromenda File name: C:\Users\<username>\AppData\Roaming\Mozilla\Firefox\Profiles\XXXX.default\searchplugins\Astromenda
Mime Type: unknown/default\searchplugins\Astromenda
C:\Users\<username>\AppData\Roaming\WSE_Astromenda File name: C:\Users\<username>\AppData\Roaming\WSE_Astromenda

One Comment

Loading...