uasputnik.com: a Windows ClickFix malware site serving .msi installers, and what to do if you ran one
uasputnik.com is a website that URLhaus lists for three Windows installer (.msi) malware downloads, two of them tagged ClickFix and one tagged Loader, and it refused our test connection. If you pasted a command from it or ran one of its .msi files, treat the PC as compromised: change your passwords from another device, then scan it offline.
Facts checked October 10, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
An automatic scan checks installed programs, startup items and browser extensions for anything that came with an .msi installer from uasputnik.com, or a command pasted from its page.
Do it yourself · free Remove uasputnik.com (ClickFix, neon.msi, astra.msi, relax.msi) yourself 5 steps, about 15 minutes, no software needed.
Start the steps
Uasputnik.com (ClickFix, neon.msi, astra.msi, relax.msi): summary
| Type | A malware download address for Windows: URLhaus lists three .msi installers, two tagged ClickFix and one also tagged Loader |
|---|---|
| Risk | High if you pasted its command or ran its files: passwords, sessions, crypto and PC control may have been taken |
| Symptoms | Often none. A strange line in the Run history, an unknown program in Installed apps or a window that flashed and closed are the signs |
| How to get rid of it | Disconnect, change passwords from another device, move crypto, run a Microsoft Defender Offline scan, then back up documents and reinstall Windows if in doubt |
| Our check (9 October 2026) | One visit: connection refused, no page. A quiet or broken site clears nothing; the danger rating comes from URLhaus |
| Running since / first seen | Domain registered 9 September 2026; first malware URLs reported 17 September 2026 |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 9 more facts
| Platform | Windows, by the msi tag; no source says other systems are affected |
|---|---|
| Detection names | No detection name is known for the files on this server, because we did not open them. For the ClickFix technique in general Microsoft Defender Antivirus uses Behavior:Win32/ClickFix, Behavior:Win32/SuspClickFix, Trojan:Win32/ClickFix, Trojan:Script/ClickFix, Behavior:Win32/RegRunMRU and Trojan:HTML/FakeCaptcha (Microsoft Security Blog); none was checked against these files |
| Name | Uasputnik.com |
| Domain registered | 9 September 2026 |
| Evidence | 3 write-ups by security sites; details still limited |
| First seen | 17 September 2026 |
| Distribution | Typically fake installers, cracked programs, e-mail attachments, fake "verify you are human" pages and ads for popular apps |
| Damage | Installs other malware, often several programs at once |
| Facts checked | 10 October 2026 |
Facts checked on 10 October 2026 against our copy of the URLhaus data for uasputnik.com, RDAP, one browser visit of our own on 9 October, Microsoft's Security Blog and Microsoft Learn (the offline scan page was read on 9 October). We did not download the files and we infected no PC; the removal steps follow Microsoft's pages and were not tried on a live infection.
What uasputnik.com is, and what we know about it
uasputnik.com is a web address, not a program on your PC. It is a domain that the abuse.ch project URLhaus lists as a place where malware was served: three Windows installer files, two with the tag ClickFix. No public write-up of this one domain exists that we could find, so this page rests on what URLhaus shows, what we saw ourselves and what Microsoft has published about the trick.
- 1
What URLhaus lists
Three file addresses on uasputnik.com, all in the top folder of the site and all ending in .msi: neon.msi, astra.msi and relax.msi. On 17 September 2026 an anonymous reporter added neon.msi with the tags ClickFix and msi, and a minute later the reporter alister1448 added astra.msi with the tags ClickFix, Loader and msi. On 29 September 2026 abuse.ch itself added relax.msi with the tag msi. All three have the threat type malware_download and were offline when we read them.
- 2
What the tags mean
msi is the ending of a Windows Installer package, the kind of file that installs a program. ClickFix is a trick in which a fake verification or fix page makes you copy a command and run it yourself. Loader is the reporter's word for a program whose job is to download or start something else. They are the reporters' labels, not our findings.
- 3
What we could not confirm
We did not download any of the files and we never saw the page that tells visitors what to paste. So we do not know the lure, what the installers contain, which malware family they bring or whether the three belong to one chain. Our site test was refused, so we cannot see the site as a visitor would.
- 4
What this means for you
If you only saw the name in a log, a link or a warning, you are not infected by that alone. The risk is for people who pasted a command from the site into the Run box or PowerShell, or who opened an .msi file from it.
- Kind of threat
- A malware download address; three Windows installer (.msi) files, two tagged ClickFix, one also tagged Loader
- Delivery trick
- ClickFix: a fake page asks you to copy a command and paste it into Run, Terminal or PowerShell
- Domain registered
- 9 September 2026, expires 9 September 2027, registrar Gransy, s.r.o. (RDAP, read 9 October 2026)
- URLhaus entries
- 3 file addresses, added 17 and 29 September 2026; all offline when we read them
- Platform
- Windows, by the msi tag. No source says which other systems are hit
What uasputnik.com (ClickFix, neon.msi, astra.msi, relax.msi) does on an infected PC
What we checked on 9 October 2026, and what we could not
We opened https://uasputnik.com/ once, from Lithuania, in an automated Chromium browser set to English. The connection was refused and no page loaded. That tells you nothing good about the site, and it clears nothing.
Our site test, 9 October 2026
- The site did not answerOur browser reported ERR_CONNECTION_REFUSED for the main address. A refused connection means nothing was listening for us on the secure web port.
- Why that is not a clean resultA refusal can mean the operators took the server down, that it blocks our kind of visitor or our country, or that it was only used to hand out files. We cannot tell which from one visit. Sites that hand out malware often show different things by country, device or visit.
- Notification request, pop-ups, redirects, ad networksNone seen. There was nothing to see: no page loaded on this one visit.
- URLhaus listingThree malware addresses on this domain, added on 17 and 29 September 2026. All three were offline when we read the database.
- Downloads and the page itselfWe did not download the files and we did not reach any page that shows a command. We cannot tell you what the installers do.
Dangerous: treat it as a malware site The site test was one visit that ended in a refused connection, so it proves nothing either way. The danger rating comes from the three URLhaus reports, not from our visit. Do not open files from this address, and do not run anything it gives you.
What happened to uasputnik.com, from registration to our test
The history is short: the domain is a month old and its first report came eight days after registration. The dates come from RDAP and from the URLhaus database.
9 September 2026
The domain is registered
RDAP shows uasputnik.com registered on 9 September 2026 through the registrar Gransy, s.r.o., valid until 9 September 2027. We found nothing that shows a real organisation behind the name.
17 September 2026
Two ClickFix installers are reported
At 05:44 UTC an anonymous reporter adds neon.msi with the tags ClickFix and msi. At 05:45 UTC the reporter alister1448 adds astra.msi with the tags ClickFix, Loader and msi. This is the first time URLhaus sees the host.

The three URLhaus entries for uasputnik.com as we read them on 10 October 2026. Addresses are defanged. 29 September 2026
A third installer is added
At 08:18 UTC abuse.ch adds relax.msi with the tag msi only. It is the same kind of file in the same folder, twelve days after the first two, so the site was still in use then.
9 October 2026
Our test is refused
Our browser visit to https://uasputnik.com/ ends in ERR_CONNECTION_REFUSED. We do not know what a visitor who arrives from the lure page would see.
We could not read the URLhaus pages themselves, because they ask for a browser check. The entries above come from the same data in our own database, which holds the URLhaus feed.
How the ClickFix trick works on Windows, and where an .msi fits
ClickFix does not use a security hole. It makes you do the infecting yourself, so the warnings of your browser and your antivirus often never get a say. We did not see uasputnik.com's page; this is how Microsoft describes the trick.

- 1
You land on a page with a check
Microsoft says the lure is often a fake CAPTCHA, human verification or error page, sometimes made to look like Cloudflare Turnstile or Google reCAPTCHA. It reaches you through phishing email, malicious ads or compromised sites.
- 2
The page copies a command for you
A button puts a command on your clipboard through the browser, without showing it. The page then tells you to paste it into the Run dialog, Windows Terminal or PowerShell.
- 3
You open Run and paste
The steps ask you to press the Windows key + R, press Ctrl + V and press Enter. Microsoft says the Run dialog is favoured because many users do not know what it is for.
- 4
The command fetches the real malware
Microsoft says these commands usually call PowerShell, mshta, rundll32, wscript, curl or wget. Microsoft's own page does not describe an .msi route. Windows can install a package from a command with msiexec /i, and /qn or /quiet hides every window, according to Microsoft's msiexec page. We do not know that this is what the three files are for.
- 5
Nothing seems to happen
A window that flashes and closes, or a CAPTCHA that never finishes, is the whole experience for many victims. Microsoft says the final payloads are often loaded into memory through built-in tools such as powershell.exe, msbuild.exe and regasm.exe.
Because a person starts the command, many automated defences treat it as normal. This is why the Run box history matters later: Windows records what was typed there, but only when the command worked.
The three files: what each name suggests, and what we do not know
File names are weak evidence. We list what URLhaus says about each and mark which statements are only a reading.
| File on uasputnik.com | What URLhaus says | What it may be (our reading) |
|---|---|---|
| /neon.msi | Offline, tags ClickFix and msi, added 17 September 2026 by an anonymous reporter | A Windows installer started by a command the visitor pasted. Its contents are not confirmed |
| /astra.msi | Offline, tags ClickFix, Loader and msi, added 17 September 2026 by alister1448 | The reporter calls it a loader, meaning a program that brings in something else. That is the reporter's label, not our check |
| /relax.msi | Offline, tag msi, added 29 September 2026 by abuse.ch | The same kind of file twelve days later, with no ClickFix tag. Whether it belongs to the same chain is not confirmed |
Three short names, all in the top folder, tell us only that the files were put there to be fetched by address. We fetched none of them, so we give no malware family name.
What uasputnik.com (ClickFix, neon.msi, astra.msi, relax.msi) can steal or download
What a ClickFix payload on Windows can take
We do not know what uasputnik.com's installers contain. Microsoft names the payloads it has seen at the end of ClickFix chains, and the list below is those, not a claim about this site.
Malware named in Microsoft's ClickFix report
- Lumma Stealer
- Lampion
- Xworm
- AsyncRAT
- NetSupport
- SectopRAT
- ScreenConnect
- Latrodectus
- MintsLoader
- DarkGate
- modified r77
Microsoft groups these into infostealers (Lumma, Lampion), remote access tools (Xworm, AsyncRAT, NetSupport, SectopRAT, ScreenConnect), loaders (Latrodectus, MintsLoader, DarkGate) and one rootkit, a modified r77. The loader group matters most for this site, because astra.msi carries the Loader tag: a loader's first file is not the last.
What this can cost you
Reading the site name or seeing a warning costs nothing. The risks below apply to a PC where a pasted command was run, or an .msi file from the site was installed.
- High
Your accounts used by someone else
If the files hold a stealer, the saved logins and cookies in your browser are the prize. With a cookie, a thief can sit in your mailbox without knowing your password.
- High
Money in a crypto wallet
Wallet data is a common target and a transfer cannot be called back. If a wallet lived on this PC, treat it as emptied until proven otherwise.
- High
A stranger at your keyboard
A remote tool shows your screen to another person and lets them install more. The network cable is the first thing to pull.
- Medium
A program that stays installed
An .msi writes itself into the list of installed apps and can leave services or tasks behind. Until they are found, the PC keeps running them.
- Medium
Your employer's data
A work laptop carries tokens for company systems. Report it to your IT team the same day so they can cut those accounts.
- Low
No harm from reading the name
Seeing the address in a log, an alert or a blocked link does nothing to your PC.
What you may notice, and what you may not
Most victims notice nothing. The signs below follow from how ClickFix chains and Windows installers work; the first two are the best evidence you have.
| Sign | What it means |
|---|---|
| A strange line in the Run box history | Windows keeps what was typed into Run. A long line with powershell, msiexec, a web address, hidden or -enc is the command that was pasted |
| A program in Installed apps you did not install | A Windows Installer package registers itself there. Look for names and dates around the time you pasted the command |
| A window that flashed and closed after you pressed Enter | A command that downloads and runs something, then exits |
| A scheduled task you did not make | Microsoft lists Suspicious Scheduled Task Process Launched among its ClickFix alerts |
| Sign-ins or password resets you did not start | A sign that a login or a session was taken. This is our reading, not a quote |
| Nothing at all | Stealers are built to finish in minutes and stay quiet |
How to check the PC for uasputnik.com (ClickFix, neon.msi, astra.msi, relax.msi)
How people end up on a page like this
We do not know how visitors reach uasputnik.com, and no source says. The routes below are the ones Microsoft names for ClickFix in general.
- 1
A phishing email with a link or attachment
Microsoft names HTML attachments and links to ClickFix landing pages. The email says a document or delivery needs a check, and the page opens a fake verification.
- 2
A malicious ad
Microsoft describes fake Play pages on free movie streaming sites, and a fake government site reached through an ad redirect.
- 3
A hacked website
A normal site that was broken into shows the fake check on top of its own page. Microsoft says some such sites were probably hacked through WordPress weaknesses.
- 4
A fake fix for a Windows or browser problem
Pages that claim a browser or Windows needs repair, or that a document cannot be shown until you fix it, end in the same paste step.
Check your Windows PC before you delete anything
Start with the question that matters: did you paste a command from a website into Run, Windows Terminal or PowerShell, or run an .msi file from uasputnik.com? If yes, follow the plan on this page, because a clean-looking check does not clear a PC. If you are not sure, do these checks first. None of them deletes anything.
While you check, stop using the PC for banking, email, work or crypto, and disconnect it from Wi-Fi and the network cable if you can.

- 1
Look in Installed apps
Open Settings > Apps > Installed apps on Windows 11, or Settings > Apps > Apps & features on Windows 10. Sort by install date and look for a program you did not choose that appeared when you pasted the command. Write down its name and publisher. Do not uninstall it yet.
- 2
Find the line you pasted
Run
regedit, then browse toHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU. Every value there is something typed into Run. Photograph any line with uasputnik.com, powershell or msiexec in it, and leave it in place. - 3
Open Task Scheduler
Search for Task Scheduler in the Start menu, open the Task Scheduler Library and read any task with a random name or a recent date. Write the name down; deleting comes later.
- 4
Read the Windows Security history
Windows Security > Virus & threat protection > Protection history lists what Defender caught and when. Windows 10 reaches the same page through Settings > Update & Security > Windows Security. Look for dates near your paste.
- 5
Do not read too much into a quiet result
Deleting the RunMRU line hides the evidence and does not remove malware. Memory-only payloads leave nothing in these places, so a quiet check only lowers the doubt.
How to remove uasputnik.com (ClickFix, neon.msi, astra.msi, relax.msi)
How to remove uasputnik.com
A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.
Step 1: Delete scheduled tasks that bring it back
Open Task Scheduler from the Start menu and click Task Scheduler Library. Select each task you do not recognise and read the Actions tab:
- a task that starts a file in
%AppData%or%Temp% - runs
powershellwith a long encoded line - opens a web address belongs to uasputnik.com or a similar program
Right-click such a task and choose Delete, and check the subfolders too. Leave tasks from Microsoft, your PC's maker and programs you use. Task Scheduler is the same in Windows 11 and Windows 10.

Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs. Full procedure with screenshots: Remove what malware leaves behind in Windows
- a task that starts a file in
Step 2: Remove it from startup
Whatever uasputnik.com installed usually starts with Windows. Open Task Manager with Ctrl + Shift + Esc, go to Startup apps in Windows 11 or the Startup tab in Windows 10, and disable what you do not know, starting with entries that have an empty Publisher column.
Open file location on the right-click menu shows the file, which helps you decide and tells you what to delete later. Disabling is safe: if something you need stops working, switch it back on.
Full procedure with screenshots: Stop apps from opening at startup On uGetFix
Step 3: Delete the folders left behind
What the uninstaller leaves behind is usually in the user folders. Open File Explorer, switch on View > Show > Hidden items (in Windows 10 View > Hidden items), and go through
%LocalAppData%,%AppData%, %ProgramData% and the two Program Files folders.Sort by Date modified and delete folders that appeared together with the problem and belong to no program you use. Folders with random names that hold
.exe,.dll, .js or .ps1 files are the strongest sign.Full procedure with screenshots: Remove what malware leaves behind in Windows
Step 4: Scan the PC, then run the offline scan
Open Windows Security > Virus & threat protection > Scan options, run a Full scan and remove everything it finds. Then select Microsoft Defender Antivirus (offline scan) and click Scan now: the PC restarts and scans before Windows loads, which finds files that hide while Windows runs.
Save your work first, because the offline scan takes about 15 minutes. Both scans are built into Windows 11 and Windows 10, and a second scanner from another vendor is a useful extra opinion.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Step 5: Change passwords from another device and sign out other sessions
Assume that the passwords saved in this PC's browsers, and the accounts that were open in them, are known to the attacker. From a phone or a clean computer, change the e-mail password first, then banking, shopping, social and gaming accounts.
Use each service's option to sign out of all other sessions, because stolen cookies keep a session open even after a password change. Turn on two-step verification on each account. Wait with the infected Windows 11 or Windows 10 PC until the scans are clean.
Full procedure with screenshots: Turn on two-step verification / secure a hacked account
Scan from outside Windows: Microsoft Defender Offline
Most scans run inside the Windows that may be infected. This one starts first and looks at the system from outside, which is why Microsoft recommends it for stubborn malware.
| Question | Answer from Microsoft Learn |
|---|---|
| How long does it take? | About 15 minutes. The PC restarts, scans and starts Windows again |
| What does it need? | An administrator account, Windows Recovery Environment turned on and Microsoft Defender Antivirus as the main antivirus |
| How do you check the recovery environment? | In an administrator Command Prompt run reagentc /info. If it says Disabled, run reagentc /enable |
| What if BitLocker is on? | Suspend it for the system drive first, or the PC may ask for the recovery key at restart |
| Where is it? | Windows Security > Virus & threat protection > Scan options > Microsoft Defender Offline scan > Scan now |
| Where is the result? | Protection history, on the same Virus & threat protection page |
| Where does it not work? | On ARM versions of Windows. It runs on x64 Windows 10 and 11 only |
A clean result is not a clearance. If a pasted command ran, or an installer from this site finished, plan to copy your documents out and reinstall Windows.
Uninstalling a program that came from the .msi
Only do this after the offline scan, and only if you know which entry it is. Removing a program does not remove what it already started.
- 1
Use Installed apps
In Settings > Apps > Installed apps, select the three dots next to the entry and choose Uninstall. On Windows 10 use Apps & features and select Uninstall. Windows Installer packages remove themselves this way, as Microsoft's msiexec page describes with its /x option for uninstalling a package.
- 2
Then check what is left
Look again at Task Scheduler and at
shell:startup(Windows key + R) for files you did not make. Run the offline scan once more. - 3
Do not trust the uninstall alone
If the package was a loader, it may already have fetched other programs that have no entry in the list. This is why we end the plan with a reinstall.
If you use a Mac, an iPhone or an Android phone
The msi tag points at Windows. We found nothing that says the three files run on anything else.
| Your device | What we know | What to do |
|---|---|---|
| Mac | An .msi is a Windows format and does not install on macOS. Microsoft notes a Mac version of ClickFix exists, but we do not know what this page shows a Mac | Nothing from these three files. If you pasted into Terminal, that is a different case, so use a Mac guide and not these Windows steps |
| iPhone or iPad | There is no Run box or Terminal in which to paste | Nothing to remove. Change any password you typed |
| Android | No source mentions it | Nothing to remove for these files. Change any password you typed |
After removal: passwords, accounts and prevention
After a clean PC: protect what was taken
Cleaning the PC does not take back what it already sent. Treat every login that touched it as known to someone else, and work through the list below on a different device.
| What was on the PC | What to do, in this order |
|---|---|
| Email account | Change its password first, because resets for your other accounts go there. Then use the sign out of all sessions option |
| Bank and card sites | Change the password, check recent activity and call the bank if anything looks wrong. Ask for a new card if you saved the number in the browser |
| Crypto wallet or exchange | Make a new wallet with a new recovery phrase on a clean device and move the funds. Do this before anything slower |
| Work accounts, VPN, cloud keys | Tell IT. Revoke tokens, SSH keys and API keys that were stored on the PC |
| Microsoft account | Change the password at account.microsoft.com and review the devices signed in to it |
| All accounts that offer it | Switch on an authenticator app or a security key for sign-in |
- 1
Reset the PC
Copy only documents and photos to an external drive, never programs. Then go to Settings > System > Recovery on Windows 11, or Settings > Update & Security > Recovery on Windows 10, and reset the PC with the option to remove everything.
- 2
Keep watching for a while
For some weeks look at your bank, email and crypto for activity you did not start.
Keep a Windows PC out of this kind of trap
The rule that would have stopped this site is one line: a website never needs you to paste something into Run or PowerShell.
Do
- Close any tab that tells you to press Windows key + R, then Ctrl + V, then Enter.
- Install software only from the maker's own site or the Microsoft Store.
- On a company PC, ask IT to remove the Run command by Group Policy. Microsoft names the setting under User Configuration, Administrative Templates, Start Menu and Taskbar.
- Let Windows Update and your browser update themselves, and keep Windows Security on.
- Keep one backup of documents on a drive that stays unplugged.
Don't
- Do not paste anything to prove you are human, to fix a browser or to read a document.
- Do not run an .msi file that a web page hands you after a check or an error message.
- Do not follow a fix that means typing a line into a box.
- Do not take a quiet scan as proof that you are safe.
Questions about uasputnik.com (ClickFix, neon.msi, astra.msi, relax.msi)
What is uasputnik.com?
It is a website that URLhaus lists for handing out malware, not a program on your computer. Three Windows installer files on it, neon.msi, astra.msi and relax.msi, were added on 17 and 29 September 2026, two of them tagged ClickFix. The domain was registered on 9 September 2026, so it is only weeks old.
On 9 October 2026 our test visit was refused, so we cannot say what the site shows today. If you only saw the name in a warning or a log, you are not infected by that. If you ran a command or a file from it, use the cleaning steps on this page.
Is uasputnik.com a virus?
A website is not a virus, but this one is listed as a source of malware. URLhaus gives all three of its file addresses the threat type malware_download. Two are tagged ClickFix, a trick that makes you start the infection yourself, and one of those is also tagged Loader.
We did not download the files, so we cannot name the malware or say exactly what it does. Treat the domain as dangerous, do not open it, and do not run anything it offers. Reading about it on this page cannot infect you.
What is ClickFix?
ClickFix is a con that gets you to run the attack on your own PC. A web page, usually posing as a CAPTCHA or an error, quietly copies a command and then walks you through pasting it into Run, Terminal or PowerShell. No software flaw is used, so many protections stay silent.
Microsoft says it spreads by phishing mail, ads and hacked sites. The malware at the end can be a stealer or a remote access tool. No genuine site needs you to paste a command, so closing the tab is the right reply.
I ran a file or command from uasputnik.com. What do I do now?
Disconnect the PC from the network first, by turning off Wi-Fi and unplugging the cable. Then, from another device, change your email, bank and work passwords, sign out of accounts everywhere and move any crypto to a new wallet.
After that run a Microsoft Defender Offline scan on the PC. If the command ran or the installer finished, the safest end is to back up documents and reinstall Windows, because a remote access tool may leave little trace. Tell your IT team if it is a work PC.
What if I only visited the site and pasted nothing?
Then you are very likely fine. The trick needs you to run something, and a page view alone does not do that. Close the tab and keep away from the address.
As a cheap precaution, run a quick scan in Windows Security. There is one catch: the page may have put hidden text on your clipboard, so before you paste anywhere, copy a plain word to replace it. If you did download a file and opened it, read the plan on this page instead.
How can I see what I pasted into Run?
Windows keeps a list of the lines typed into the Run box. Open Registry Editor and go to HKEY_CURRENT_USER, Software, Microsoft, Windows, CurrentVersion, Explorer, RunMRU. Each value is one line.
Microsoft says entries appear there only when the command ran successfully. A long line that contains powershell, msiexec, a web address, hidden or bypass is the sort of command used in ClickFix.
Read it without running it. Clearing it removes the evidence, not the malware, so scan the PC first and keep a note of what you found.
Will a scan with Windows Security remove it?
It may find part of it, and you should run it, but we cannot promise it finds everything. We never opened the installers, so we do not know what they hold or whether a memory-only stage followed them.
For the best chance use the offline scan, which Windows runs before it starts. If a remote tool was active, a clean reinstall is the only step that settles it. We have not tested any removal tool against these files, and we do not claim one removes them.
Which malware do neon.msi, astra.msi and relax.msi install?
We do not know. We did not download the files, and URLhaus shows no malware family name for them. The tags are ClickFix, msi and, on astra.msi, Loader.
Microsoft lists the final payloads seen in ClickFix chains, among them Lumma Stealer, AsyncRAT, Xworm, NetSupport and loaders such as Latrodectus and DarkGate, but that is a list for the trick in general, not a result for this site.
If you need a name, a malware analyst with the file could give one. Until then, plan as if a stealer and a remote access tool are both possible.
Why did our test of uasputnik.com show no page?
Our browser got ERR_CONNECTION_REFUSED when it opened the secure address of the domain on 9 October 2026. That means nothing answered us on that port. URLhaus showed all three files offline when we read it, so the server may have been taken down.
The operators may also block visitors from some countries or tools, or may use the domain only to hand out files. One failed visit proves nothing, and a site that shows nothing is not cleared.
Will Fortect remove uasputnik.com?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For uasputnik.com, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- URLhaus (abuse.ch): host page for uasputnik.com (entries read from our copy of the feed) (read October 10, 2026)
- RDAP registration record for uasputnik.com (read October 9, 2026)
- Microsoft Security Blog: Think before you ClickFix, analyzing the ClickFix social engineering technique (read October 10, 2026)
- Microsoft Learn: msiexec command reference (read October 10, 2026)
- Microsoft Learn: Microsoft Defender Offline scan in Windows (read October 9, 2026)