Astromenda sucks, attached are logs from FRST, Malwarebytes, and aswmbr. Please help me get rid of this shitty virus.
Hi Wyatt2,<$1alt=“” title=“” onresizestart=“return false;” id=“smiley__$2” style=“padding: 0 3px 0 3px;” />
Greetings!
My name is Valinorum and I will be the acolyte today. Before we proceed, please, acknowledge yourself the following(s):
- Please do not create any new threads on this while we are working on your system as it wastes another volunteer’s time. If you are being helped/have solved the issue/no longer wish to continue, notify me in your reply and I will quickly close this thread. Failing to comply will result in denial of future assistance.
- Please do not install any new software while we are working on this system as it may hinder our process.
- Malware removal is a complicated process so don’t stop following the steps even if the symptoms are not found. Keep up with me until I declare you clean.
- Please do not try to fix anything without being ask.
- Please do not attach your logs or put them inside code/quote tags. Do a Copy/Paste of the entire contents of the log file and submit it inside your post unless directed otherwise.
- Please print or save the instructions I give you for quick reference. We may be using Safe mode which will cut you off from internet and you will not always be able to access this thread.
- Back up your data. I will not knowingly suggest your any course that might damage your system but sometimes Malware infections are so severe that only option we have is to re-format and re-install the operating system.
- If you are confused about any instruction stop and ask. Do not keep on going.
- Do not repeat the steps if you face any problems.
- I am not an omniscient. There are things even I cannot foresee. But what I know took years to learn and perfect the skill. This site is run by volunteers who help people in need in their own free time. I would ask you to respect their time and be patient as sometimes real life demands our time and replies to you can be delayed.
- Private Message(PM) if and only if I have not responded to your thread within three days or your query is offtopic and personal. Do not PM me under any other circumstances. Your thread is the only medium of communication.
- The fixes are for your system only. Please refrain from using these fixes on other system as it may do serious damage.
-
Step #1 P2P Warning
**IMPORTANT I notice there are signs of one or more P2P (Person to Person) File Sharing Programs on your computer.[li]µTorrent
I shall provide you with a few reference links, please read them up to know the risks of having a P2P program.
- [url=http://www.ftc.gov/bcp/edu/pubs/consumer/alerts/alt128.shtm][b]P2P File-Sharing: Evaluate the Risks[/b][/url] - [url=http://www.cuhk.edu.hk/itsc/about/p2p-risk.html][b]ITSC: Risks in Peer-to-peer File Sharing[/b][/url]
Note: Even if you are using a “safe” P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P file-sharing as a major conduit to spread their wares.
My recommendation is that you uninstall the programs listed above. If you choose not to remove them, please do not use them until this computer is clean.[/li]
- Step #2 Fix with FRST
Make sure that you still have FRST.exe on your Desktop. If you do not have it, download the suitable version from here to your Desktop.
[li]Open Notepad.exe. Do not use any other text editor software;
- Copy and Paste the contents inside the code-box to your Notepad –
[/li]
Start
Task: {99D6963E-A7D6-496B-BC41-3380330FF69D} - \ASP No Task File <==== ATTENTION
HKU\S-1-5-21-2764993964-2745009671-1230133713-1001\...\Run: [Pokki] => C:\windows\system32\rundll32.exe "%LOCALAPPDATA%\Pokki\Engine\Launcher.dll",RunLaunchPlatform
%LOCALAPPDATA%\Pokki\
SearchScopes: HKLM - DefaultScope {E17F1F0D-EA2E-43BA-ABEB-331E43B7AE7C} URL = http://astromenda.com/results.php?f=4&q={searchTerms}&a=ast_dnldstr_14_40_ch&cd=2XzuyEtN2Y1L1QzuzztDzzyC0FtB0D0F0BtD0DyB0B0FyCzztN0D0Tzu0StCtDtDtAtN1L2XzutAtFtBtFtCtFyDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StC0Azy0F0B0DyC0AtGyE0CyEtAtG0DyE0D0AtGtDyE0EzztGtByBtA0Dzz0EzzzzyB0B0FyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyDtC0ByCtA0A0A0EtGyBzz0F0BtGyEtCtCyDtG0ByBtDyCtGzyzzyB0EyBtCzy0EtB0C0Fzz2Q&cr=1946544700&ir=
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {E17F1F0D-EA2E-43BA-ABEB-331E43B7AE7C} URL = http://astromenda.com/results.php?f=4&q={searchTerms}&a=ast_dnldstr_14_40_ch&cd=2XzuyEtN2Y1L1QzuzztDzzyC0FtB0D0F0BtD0DyB0B0FyCzztN0D0Tzu0StCtDtDtAtN1L2XzutAtFtBtFtCtFyDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StC0Azy0F0B0DyC0AtGyE0CyEtAtG0DyE0D0AtGtDyE0EzztGtByBtA0Dzz0EzzzzyB0B0FyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyDtC0ByCtA0A0A0EtGyBzz0F0BtGyEtCtCyDtG0ByBtDyCtGzyzzyB0EyBtCzy0EtB0C0Fzz2Q&cr=1946544700&ir=
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {E17F1F0D-EA2E-43BA-ABEB-331E43B7AE7C} URL = http://astromenda.com/results.php?f=4&q={searchTerms}&a=ast_dnldstr_14_40_ch&cd=2XzuyEtN2Y1L1QzuzztDzzyC0FtB0D0F0BtD0DyB0B0FyCzztN0D0Tzu0StCtDtDtAtN1L2XzutAtFtBtFtCtFyDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StC0Azy0F0B0DyC0AtGyE0CyEtAtG0DyE0D0AtGtDyE0EzztGtByBtA0Dzz0EzzzzyB0B0FyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyDtC0ByCtA0A0A0EtGyBzz0F0BtGyEtCtCyDtG0ByBtDyCtGzyzzyB0EyBtCzy0EtB0C0Fzz2Q&cr=1946544700&ir=
S2 Update Framed Display; "C:\Program Files (x86)\Framed Display\updateFramedDisplay.exe" [X]
S2 Util Framed Display; "C:\Program Files (x86)\Framed Display\bin\utilFramedDisplay.exe" [X]
C:\Program Files (x86)\Framed Display\
C:\Users\Goon\AppData\Local\Temp\Ableton Swapper.exe
C:\Users\Goon\AppData\Local\Temp\LenovoExperienceImprovement.exe
C:\Users\Goon\AppData\Local\Temp\octF805.tmp.exe
Emptytemp:
End
-
[li]Click on [b]File[/b] > [b]Save as...[/b]
[list]
[li]Inside the File Name box type fixlist.txt
- From the Save as type drop down list, choose All Files
[/li]
- Save the file to your Desktop;
- Re-run FRST.exe and click Fix;
[li][b]Note[/b]: If FRST advises there is a new updated version to be downloaded, do so/allow this.
[/li]
- After the completion, a log will be produced;
- Attach the log in your next reply.
[/list][/li]
-
Required Log(s):
[li]FRST Fix Log
[/li]
Regards,
Valinorum
Alright, here’s the fixlog. Currently it appears that when I start up Chrome I am no longer redirected to MSN or to Astromenda’s site but even so I still am not so confident it’s entirely gone. I also removed uTorrent just in case. Thanks for the help Valinorum, it means a lot.
Hi,
-
Step #3 Fix with AdwCleaner
[li]Download [b]AdwCleaner[/b] by [i][b]Xplode[/b][/i] to your [i]Desktop[/i] from the following link.
[list]
[li]Download Link #1
- Download Link #2
[/li]
- Right-click on AdwCleaner.exe and choose Run as administrator;
- Click on Scan and let the program run unhindered;
- When done, click on Clean and allow the system to reboot after it is done;
- A log will be opened automatically after the restart;
- Attach the log in your reply.
[/list][/li]
-
Step #4 Fix with Junkware Removal Tool
Download Junkware Removal Tool by thisisu to your Desktop from the link below.
Download Link 1
Download Link 2[li]Disable your anti-virus to avoid potential conflicts. For more information please acknowledge yourself [url=http://www.bleepingcomputer.com/forums/t/114351/how-to-temporarily-disable-your-anti-virus-firewall-and-anti-malware-programs/]this[/url] article; - Run the program either by double-clicking(Windows XP) or Right-clicking and choosing [i]Run as administrator[/i](Windows Vista and above); - Please be patient as the tool cleans your system; - After completion of the process a log named [b]JRT.txt[/b] will automatically open and is save to your Desktop; - Attach the log in your next reply.
[/li]
-
Step #5 Scan with Malwarebytes’ Anti-Malware
[li]Download [b]Malwarebytes' Anti-Malware[/b] from the suitable link below --
[list]
[li]Download Link #1
- Download Link #2
- Download Link #3
[/li]
- Double-click mbam-setup.exe to install the application.
- Before clicking Finish perform the following actions –
[li][b]Un-check[/b] the box beside [i]Enable free trial of Malwarebytes Anti-Malware Premium[/i].
- [b]Check[/b] the box beside [i]Launch Malwarebytes Anti-Malware[/i]
[/li]
- Once the program has loaded, The MBAM dashboard will appear with an alert to update - click the green button [b]Update Now[/b];
- Click on [b]Setting[/b]--
[li]Navigate to the tab [b]Detection and Protection[/b] and check [i]all[/i] the boxes under [b]Detection Options[/b]
[/li]
- From the [b]Dashboard[/b] click on [b]Scan Now[/b];
- If threats are detected click on [b]Apply actions[/b]. If the program asks to reboot your PC, let it do so;
- On completion of the scan click on [b]View Detailed Log[/b] after that click on [b]Export Button[/b], select [b]Text File[/b] and save the log to your [i]Desktop[/i];
- Attach the log in your next reply.
[/list][/li]
-
Step #6 ESET Online Scanner
Disable your security programs which includes but not limited to anti-virus, anti-malware, anti-spyware et cetera. Peruse this for additional information.[li]Download [b]esetsmartinstaller_enu.exe[/b] by clicking [url=http://download.eset.com/special/eos/esetsmartinstaller_enu.exe][b]here[/b][/url]. - Right-click on the program and choose [i]Run as administrator[/i]. - Accept their terms and condition and proceed. - Install [b]Add-On/Active X[/b] if prompted. - From the [b]Computer Scan Setting[/b] --
[list]
[li]Uncheck the box beside Remove Found Threats;
- Check the box beside Scan archives
[/li]
- Click on Advanced Setting and check the following boxes–
[li][b]Scan for potentially unwanted applications[/b]
- [b]Scan for potentially unsafe applications[/b]
- [b]Enable Anti-Stealth Technology[/b]
[/li]
- Click on [b]Start[/b] and wait for the [b]virus signature database[/b] to update.
- The online scan will begin [i]automatically[/i] and can take several hours.
[li][b]Note:[/b] Do not touch either the Mouse or keyboard during the scan. Otherwise it may stall.
[/li]
- After the Scan finishes --
-
[li][b]If no threats were found:[/b]
[list]
[li]Put a checkmark in Uninstall application on close.
- Close the program and report that nothing was found
[/li]
- If threats were found:
[li]Open the file located in [b]C:\Program Files\ESET\ESET Online Scanner\log.txt[/b] (32-bit) or [b]C:\Program Files (x86)\ESET\ESET Online Scanner\log.txt[/b] (64-bit).
- Attach the log file in your next reply.
[/li]
[/list][/li]
[/list][b]Note:[/b] Enable your security programs afterwards.[/li]
-
Required Log(s):
[li]AdwCleaner Log - Junkware Removal Tool Log - Malwarebytes' Anti-Malware Log - ESET Scan Log
[/li]
Regards,
Valinorum
Thank you for the above solution. It helped me clean up couple of malwares, along with Framed Display advert!
Do include these updates in avast as well please, so that we need not go through so many tools to clean up.