Home Malware Programs Browser Hijackers Astromenda.com

Astromenda.com

Posted: July 30, 2014

Astromenda.com is a search engine and appears when a PC user installs the Astromenda add-on. Up to now China, Canada, Germany, Switzerland, USA and the UK are the countries that reported to have been infected. Andromeda Search is created by IronSource Ltd and is considered similar to other PUPs (Potentially Unwanted Programs) such as Mysearchdial, Groovorio, etc.

Astromenda is associated with browser hijackers that make changes on the targeted computer. This threat can infect only Windows systems and yet getting rid of it can be annoying for the user. This threat performs a reset to the parameters of your browsers, so your Internet Explorer, Mozilla Firefox and Google Chrome will have different homepages, still this is not all of it. Your homepages will be changed to mystart.vi-view.com and your default search engine will be now Astromenda.com. Although, Astromenda may seem like a dependable browser plug-in, do not be fooled and in case of infection it is advised to remove it as soon as possible. At first, you will simply notice the changes in your homepage and search engine. However, in a while, you will also notice that this threat is actually interfering with all of your browsing activities. So instead of helping users through their Web surfing, Astromenda may extract your browsing history, bookmarks and online habits in general. In case you have come to the decision that this threat is not worth the time to remove it, you will soon find out that this is not true. Since the Astromenda search engine is low grade one, sooner or later you will see that it may redirect you to harmful websites.

How Can I Get Infected with Astromenda Malware?

What happens is that you go to a popular freeware website and look for Adobe Flash Player, a PDF creator or a video converter, or maybe a Java update. In order to download that kind of free software freeware websites have developed special download managers. Here is the problem, this type of websites claim that they offer '100% legitimate and virus-free' content, but there's no assurance that you're not going to get bloatware. Usually, such a threat is bundled with the freeware that you downloaded, and in most cases, users are not aware where did it come from and thus consider Astromenda a virus. Technically, it is not a virus, and yet Astromenda shows a great deal of unfavorable qualities. For example, this threat is enabled to hook deeply into your computer's operating system, it can also make your browsing experience a nightmare since Astromenda supports banners and ad pop-ups too. In general, PC threat analysts consider Astromenda Search and add-on are linked to a browser hijacker. What is more important is the fact that Astromenda.com search engine is sponsored by third-parties, meaning that you will be seeing their advertisements.

I'm Infected, Now What?

In case you already got this threat into your system, specialists advise to quickly find a way to remove Astromenda. Unfortunately, this is not an easy task, since after you uninstall the add-on from your Windows system, you may need to reset the settings of your browsers, yes, to all of them. Have in mind that this reset is done differently for each browser, yet the way is basically the same. Last but not least, it is very important to understand that PC threats install in such a way that there is a hidden file that remains somewhere far from sight and what is worse that it usually remains hidden, so in case you have already removed Astromenda from the Control Panel, remember that this is not the only place there are components of Astromenda.

Use SpyHunter to Detect and Remove PC Threats

If you are concerned that malware or PC threats similar to Astromenda.com may have infected your computer, we recommend you start an in-depth system scan with SpyHunter. SpyHunter is an advanced malware protection and remediation application that offers subscribers a comprehensive method for protecting PCs from malware, in addition to providing one-on-one technical support service.

Download SpyHunter's Malware Scanner

Note: SpyHunter's free version is only for malware detection. If SpyHunter detects malware on your PC, you will need to purchase SpyHunter's malware tool to remove the malware threats. Learn more on SpyHunter. If you would like to uninstall SpyHunter for any reason, please follow these uninstall instructions. To learn more about our policies and practices, visit our EULA, Privacy Policy and Threat Assessment Criteria .

Why can't I open any program including SpyHunter? You may have a malware file running in memory that kills any programs that you try to launch on your PC. Tip: Download SpyHunter from a clean computer, copy it to a USB thumb drive, DVD or CD, then install it on the infected PC and run SpyHunter's malware scanner.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Program Files2\ASTROM~1\\uninstall.exe File name: C:\Program Files2\ASTROM~1\\uninstall.exe
File type: Executable File
Mime Type: unknown/exe
C:\Program Files\Astromenda File name: C:\Program Files\Astromenda
C:\Program Files\DIFX\277d1c50d2b49142\dpinst32.exe File name: C:\Program Files\DIFX\277d1c50d2b49142\dpinst32.exe
File type: Executable File
Mime Type: unknown/exe
C:\Program Files\WSE_Astromenda File name: C:\Program Files\WSE_Astromenda
C:\Users\[YOUR USERNAME]\AppData\Local\Astromenda\Application\astromenda.exe File name: C:\Users\[YOUR USERNAME]\AppData\Local\Astromenda\Application\astromenda.exe
File type: Executable File
Mime Type: unknown/exe
C:\Users\[YOUR USERNAME]\AppData\Local\Google\Chrome\UserData\Default\Extensions\pfkfdlcdbajamklbneflfbcmfgddmpae File name: C:\Users\[YOUR USERNAME]\AppData\Local\Google\Chrome\UserData\Default\Extensions\pfkfdlcdbajamklbneflfbcmfgddmpae
C:\Users\[YOUR USERNAME]\AppData\Roaming\Mozilla\Firefox\Profiles\XXXX.default\extensions\{ad7ce998-a77b-4062-9ffb-1d0b7cb23183} File name: C:\Users\[YOUR USERNAME]\AppData\Roaming\Mozilla\Firefox\Profiles\XXXX.default\extensions\{ad7ce998-a77b-4062-9ffb-1d0b7cb23183}
Mime Type: unknown/default\extensions\{ad7ce998-a77b-4062-9ffb-1d0b7cb23183}
C:\Users\[YOUR USERNAME]\AppData\Roaming\Mozilla\Firefox\Profiles\XXXX.default\searchplugins\Astromenda File name: C:\Users\[YOUR USERNAME]\AppData\Roaming\Mozilla\Firefox\Profiles\XXXX.default\searchplugins\Astromenda
Mime Type: unknown/default\searchplugins\Astromenda
C:\Users\[YOUR USERNAME]\AppData\Roaming\WSE_Astromenda File name: C:\Users\[YOUR USERNAME]\AppData\Roaming\WSE_Astromenda

One Comment