Astromenda and more?

I swear this thing downloaded during a version update of Spybot S&D or CCleaner, both of which came on my new computer and I thought were safe. I did make the mistake of deleting the astromenda program via the control panel, which may have made it harder to get rid of. As per instructions on the sticky in this section, I did run Malwarebytes, and it quarantined a lot, but not enough. I’m still getting ad pop ups in Chrome and some weather thing on my desktop. See all the attachments you guys requested.

Thanks so much. Practically new computer and I don’t remember clicking anything weird!

Oh, more attachments.

Spybot is obsolete … not very good with todays malware and not needed when you have malwarebytes
CCleaner only add a toolbar (can easily be uninstalled) and as one of few they have a toolbare free download
CCleaner slim https://www.piriform.com/ccleaner/builds

Removal team is notified, it may take some hours before they are online

Hello,

1. Open notepad and copy/paste the text present inside the code box below.
To do this highlight the contents of the box and right click on it. Paste this into the open notepad.
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to the operating system

Start HKU\S-1-5-21-4032765619-1182945057-2392746508-1000\...\Run: [Optimizer Pro] => C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe [146888 2014-08-21] (PC Utilities Software Limited) SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://astromenda.com/results.php?f=4&q={searchTerms}&a=ast_suma_14_36_ch&cd=2XzuyEtN2Y1L1QzuyCzztC0C0AtBtDtCzzyCzytDyEtA0ByDtN0D0Tzu0SzyyBzytN1L2XzutAtFtDtFtCyCtFyCtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StC0EtCyDzztD0CyEtG0A0D0EzztG0A0FzzyDtGyD0AyDtAtGyDyC0DtC0ByEtDzyzz0EzztA2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0B0B0AtD0EyByD0DtGyE0DyCtDtGyEtAtCzytG0BtCzyyCtGtC0ByD0EzyyD0F0DzytByCzz2Q&cr=1577362392&ir= SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://astromenda.com/results.php?f=4&q={searchTerms}&a=ast_suma_14_36_ch&cd=2XzuyEtN2Y1L1QzuyCzztC0C0AtBtDtCzzyCzytDyEtA0ByDtN0D0Tzu0SzyyBzytN1L2XzutAtFtDtFtCyCtFyCtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StC0EtCyDzztD0CyEtG0A0D0EzztG0A0FzzyDtGyD0AyDtAtGyDyC0DtC0ByEtDzyzz0EzztA2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0B0B0AtD0EyByD0DtGyE0DyCtDtGyEtAtCzytG0BtCzyyCtGtC0ByD0EzyyD0F0DzytByCzz2Q&cr=1577362392&ir= SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://astromenda.com/results.php?f=4&q={searchTerms}&a=ast_suma_14_36_ch&cd=2XzuyEtN2Y1L1QzuyCzztC0C0AtBtDtCzzyCzytDyEtA0ByDtN0D0Tzu0SzyyBzytN1L2XzutAtFtDtFtCyCtFyCtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StC0EtCyDzztD0CyEtG0A0D0EzztG0A0FzzyDtGyD0AyDtAtGyDyC0DtC0ByEtDzyzz0EzztA2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0B0B0AtD0EyByD0DtGyE0DyCtDtGyEtAtCzytG0BtCzyyCtGtC0ByD0EzyyD0F0DzytByCzz2Q&cr=1577362392&ir= SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://astromenda.com/results.php?f=4&q={searchTerms}&a=ast_suma_14_36_ch&cd=2XzuyEtN2Y1L1QzuyCzztC0C0AtBtDtCzzyCzytDyEtA0ByDtN0D0Tzu0SzyyBzytN1L2XzutAtFtDtFtCyCtFyCtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StC0EtCyDzztD0CyEtG0A0D0EzztG0A0FzzyDtGyD0AyDtAtGyDyC0DtC0ByEtDzyzz0EzztA2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0B0B0AtD0EyByD0DtGyE0DyCtDtGyEtAtCzytG0BtCzyyCtGtC0ByD0EzyyD0F0DzytByCzz2Q&cr=1577362392&ir= FF Homepage: hxxp://aa-comps.com/thank-you/ CHR HomePage: Default -> hxxp://www.drudgereport.com/ CHR StartupUrls: Default -> "hxxp://www.drudgereport.com/" R2 70e6ca8c; c:\Program Files (x86)\Optimizer Pro\OptProCrash.dll [3541448 2014-09-06] () C:\Program Files (x86)\Optimizer Pro C:\Users\User\AppData\Roaming\Optimizer Pro C:\Windows\System32\Tasks\Optimizer Pro Schedule C:\Users\User\Documents\Optimizer Pro C:\Users\User\Desktop\Backup CC Cleaner Registry C:\Users\User\AppData\Roaming\Optimizer Pro C:\Program Files (x86)\Optimizer Pro C:\Users\User\AppData\Local\Astromenda C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2 EmptyTemp: End

2. Save notepad as fixlist.txt to your Desktop.
NOTE: => It’s important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

3. Run FRST/FRST64 and press the Fix button just once and wait.
If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.

The tool will make a log on the Desktop (Fixlog.txt). Please attach it to your reply.
Note: If the tool warned you about the outdated version please download and run the updated version.

.

  1. Please download ComboFix by sUBs (
    http://www.mcshield.net/personal/magna86/Images/IconComboFix.png
    ) from here and save it to your Desktop.
    [i]If you are unsure how ComboFix works, read this guide.

  1. Temporarily disable your AntiVirus program, usually via a right click on the System Tray icon. They may interfere with Combofix.
    If you are unsure how to do this please read this or this Instruction.

Instructions how to disable avast:
• Right click on the avast! system tray icon (
http://www.mcshield.net/pg/images/avast5.png
) in the lower right corner of the screen and scroll up to avast! shield controls;
• In the menu that appears, choose Disable Permanently. When you are prompted to turn off security, click Yes.

Note: Do not forget to turn back on this option after the cleaning by choosing avast! shield controls > Enable all shield options.


  1. Run ComboFix. Then, on disclaimer window, click I Agree! button.

[i][size=7pt]- ComboFix will check if there is a newer version of ComboFix available.
Click Yes if prompted to download.
-If Recovery Console is not installed, ComboFix will offer download & installation.
Click Yes to allow ComboFix to install Recovery Console.

  • ComboFix will scan your computer in stages, total of 50 stages.
    Do not mouse-click around while ComboFix is running.
  • If malware is detected, ComboFix will begin with its removal, and may need to restart Windows.
    Note:If you see a message like “Illegal operation attempted on a registry key that has been marked for deletion” just restart your computer.
    [/i]

  1. When the tool is finished, it will produce a log report for you. (typical location: C:\ComboFix.txt)
    => Attach log report (ComboFix.txt) back to topic.

ComboFix shall also create addition log (typical location: C:\Qoobox\ComboFix-quarantined-files.txt)
=> Please attach that report (ComboFix-quarantined-files.txt) as well.

Thanks so much for your help. See attached files.

FYI. Astromenda just tried to install a new tab in Chrome, so it’s still around. I just said no and so far no pop-up ads. Also weatherbug is still installed. That installed at the same time astromenda did.

Turet

Hi, WeatherBug is legit app and I shall not target that. You should be able to uninstall that app from Control Panel.

Please download Zoek tool by Smeenk (
http://www.mcshield.net/personal/magna86/Images/Zoek_icon.png
) from here and save it to your Desktop.
Unpack the archive…

[*]Close any open browsers and temporarily disable your AntiVirus program. (if it is necessary)
If you are unsure how to do this please read this or this Instruction.

[*]Double click on zoek.exe to run the tool. Please wait while the tool does not start…
[*]Copy the text present inside the code box below and paste it into the large window in the zoek tool:

EmptyFoldersCheck;Delete
c:\programdata\{E0A9340B-C01B-42C1-9910-C307D7BE4756};vs
c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69;vs
c:\windows\Downloaded Installations;vs
c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll;i
c:\program files (x86)\Optimizer Pro;fs
EmptyCLSID;
FFDefaults;
CHRDefaults;
AutoClean;

[*] Click on
http://www.mcshield.net/personal/magna86/Images/Run%20Script%20by%20zoek.png
button.
Please wait until a logreport will open (this can be after reboot)

[*]Save notepad to your Desktop and attach here zoek-results.log
Note: It will also create a log in the C:\ directory named “zoek-results.log

.

Then reset browser settings back on defaults.

Firefox::
https://support.mozilla.org/en-US/kb/reset-firefox-easily-fix-most-problems

Chrome::
https://support.google.com/chrome/answer/3296214?hl=en

.

Then tell me how is the computer running now? Re-run FRST tool, press the Scan button and post me the fresh created FRST.txt logfile.

Done. Here are two more files. Thanks again. Computer seems normal to me now.

1. Open notepad and copy/paste the text present inside the code box below.
To do this highlight the contents of the box and right click on it. Paste this into the open notepad.
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to the operating system

CloseProcesses:
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
EmptyTemp:
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Preferences

2. Save notepad as fixlist.txt to your Desktop.
NOTE: => It’s important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

3. Run FRST/FRST64 and press the Fix button just once and wait.

Note: The tool shall warned you about the outdated version, fresh version shall be download!

If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.

The tool will make a log on the Desktop (Fixlog.txt). Please attach it to your reply.

It didn’t ask for an updated version, just ran and rebooted. Here’s the file. Thanks again.

All is good now? No more alearts?

It seems fine. Do you think this is all good now? Thanks so much for your help. You have saved me!

Yes, all traces has been removed. You are clean now.

The following will implement some post-cleanup procedures:

It is necessary to uninstall ComboFix :

[*] Click Start (or
http://amf.mycity.rs/pg/images/VistaStartButton.png
) then Run.

On Windows7 or Vista you may use Start Search field if Run is not available.

[*] In the line of text type in (Copy) the following:

ComboFix /Uninstall

Note that there is a space between " ComboFix " and " /Uninstall " .

[*] then click OK (or press Enter ).

Wait for the uninstall process is complete.

.

=> Please download DelFix by Xplode to your Desktop.

Run the tool and check the following boxes below;
[i]
http://www.mcshield.net/personal/magna86/Images/checkmark.png
Remove disinfection tools

http://www.mcshield.net/personal/magna86/Images/checkmark.png
Create registry backup

http://www.mcshield.net/personal/magna86/Images/checkmark.png
Purge System Restore [/i]
Click Run button and wait a few seconds for the programme completes his work.
At this point all the tools we used here should be gone. Tool will create an report for you (C:[b]DelFix.txt[/b])

The tool will also record healthy state of registry and make a backup using ERUNT program in %windir%\ERUNT\DelFix
Tool deletes old system restore points and create a fresh system restore point after cleaning.

Looks good except I had put the zoek tool in a separate file folder and I don’t think it got deleted. Can I just delete that, or should I run DelFix again? Sorry…

Yes, feel free to manualy remove all leftovers.