uasputnik.com: a Windows ClickFix malware site serving .msi installers, and what to do if you ran one

uasputnik.com is a website that URLhaus lists for three Windows installer (.msi) malware downloads, two of them tagged ClickFix and one tagged Loader, and it refused our test connection. If you pasted a command from it or ran one of its .msi files, treat the PC as compromised: change your passwords from another device, then scan it offline.

Facts checked October 10, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation.

Automatic

Get a free scan and check if your PC is infected.

Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.

An automatic scan checks installed programs, startup items and browser extensions for anything that came with an .msi installer from uasputnik.com, or a command pasted from its page.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.

Do it yourself · free Remove uasputnik.com (ClickFix, neon.msi, astra.msi, relax.msi) yourself 5 steps, about 15 minutes, no software needed.

Start the steps
Table of three URLhaus entries for uasputnik.com: neon.msi and astra.msi tagged ClickFix, astra.msi also tagged Loader, and relax.msi, all offline, added on 17 and 29 September 2026
The three URLhaus entries for uasputnik.com that we read on 10 October 2026, with the addresses defanged. Our own browser test of the site was refused, so this table of reports, not a screenshot of the site, is the main evidence.

Uasputnik.com (ClickFix, neon.msi, astra.msi, relax.msi): summary

TypeA malware download address for Windows: URLhaus lists three .msi installers, two tagged ClickFix and one also tagged Loader
RiskHigh if you pasted its command or ran its files: passwords, sessions, crypto and PC control may have been taken
SymptomsOften none. A strange line in the Run history, an unknown program in Installed apps or a window that flashed and closed are the signs
How to get rid of itDisconnect, change passwords from another device, move crypto, run a Microsoft Defender Offline scan, then back up documents and reinstall Windows if in doubt
Our check (9 October 2026)One visit: connection refused, no page. A quiet or broken site clears nothing; the danger rating comes from URLhaus
Running since / first seenDomain registered 9 September 2026; first malware URLs reported 17 September 2026
Removal

Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.
Show 9 more facts
PlatformWindows, by the msi tag; no source says other systems are affected
Detection namesNo detection name is known for the files on this server, because we did not open them. For the ClickFix technique in general Microsoft Defender Antivirus uses Behavior:Win32/ClickFix, Behavior:Win32/SuspClickFix, Trojan:Win32/ClickFix, Trojan:Script/ClickFix, Behavior:Win32/RegRunMRU and Trojan:HTML/FakeCaptcha (Microsoft Security Blog); none was checked against these files
NameUasputnik.com
Domain registered9 September 2026
Evidence3 write-ups by security sites; details still limited
First seen17 September 2026
DistributionTypically fake installers, cracked programs, e-mail attachments, fake "verify you are human" pages and ads for popular apps
DamageInstalls other malware, often several programs at once
Facts checked10 October 2026

Facts checked on 10 October 2026 against our copy of the URLhaus data for uasputnik.com, RDAP, one browser visit of our own on 9 October, Microsoft's Security Blog and Microsoft Learn (the offline scan page was read on 9 October). We did not download the files and we infected no PC; the removal steps follow Microsoft's pages and were not tried on a live infection.

What uasputnik.com is, and what we know about it

uasputnik.com is a web address, not a program on your PC. It is a domain that the abuse.ch project URLhaus lists as a place where malware was served: three Windows installer files, two with the tag ClickFix. No public write-up of this one domain exists that we could find, so this page rests on what URLhaus shows, what we saw ourselves and what Microsoft has published about the trick.

  1. 1

    What URLhaus lists

    Three file addresses on uasputnik.com, all in the top folder of the site and all ending in .msi: neon.msi, astra.msi and relax.msi. On 17 September 2026 an anonymous reporter added neon.msi with the tags ClickFix and msi, and a minute later the reporter alister1448 added astra.msi with the tags ClickFix, Loader and msi. On 29 September 2026 abuse.ch itself added relax.msi with the tag msi. All three have the threat type malware_download and were offline when we read them.

  2. 2

    What the tags mean

    msi is the ending of a Windows Installer package, the kind of file that installs a program. ClickFix is a trick in which a fake verification or fix page makes you copy a command and run it yourself. Loader is the reporter's word for a program whose job is to download or start something else. They are the reporters' labels, not our findings.

  3. 3

    What we could not confirm

    We did not download any of the files and we never saw the page that tells visitors what to paste. So we do not know the lure, what the installers contain, which malware family they bring or whether the three belong to one chain. Our site test was refused, so we cannot see the site as a visitor would.

  4. 4

    What this means for you

    If you only saw the name in a log, a link or a warning, you are not infected by that alone. The risk is for people who pasted a command from the site into the Run box or PowerShell, or who opened an .msi file from it.

Kind of threat
A malware download address; three Windows installer (.msi) files, two tagged ClickFix, one also tagged Loader
Delivery trick
ClickFix: a fake page asks you to copy a command and paste it into Run, Terminal or PowerShell
Domain registered
9 September 2026, expires 9 September 2027, registrar Gransy, s.r.o. (RDAP, read 9 October 2026)
URLhaus entries
3 file addresses, added 17 and 29 September 2026; all offline when we read them
Platform
Windows, by the msi tag. No source says which other systems are hit

What uasputnik.com (ClickFix, neon.msi, astra.msi, relax.msi) does on an infected PC

What we checked on 9 October 2026, and what we could not

We opened https://uasputnik.com/ once, from Lithuania, in an automated Chromium browser set to English. The connection was refused and no page loaded. That tells you nothing good about the site, and it clears nothing.

Our site test, 9 October 2026

  • The site did not answerOur browser reported ERR_CONNECTION_REFUSED for the main address. A refused connection means nothing was listening for us on the secure web port.
  • Why that is not a clean resultA refusal can mean the operators took the server down, that it blocks our kind of visitor or our country, or that it was only used to hand out files. We cannot tell which from one visit. Sites that hand out malware often show different things by country, device or visit.
  • Notification request, pop-ups, redirects, ad networksNone seen. There was nothing to see: no page loaded on this one visit.
  • URLhaus listingThree malware addresses on this domain, added on 17 and 29 September 2026. All three were offline when we read the database.
  • Downloads and the page itselfWe did not download the files and we did not reach any page that shows a command. We cannot tell you what the installers do.

Dangerous: treat it as a malware site The site test was one visit that ended in a refused connection, so it proves nothing either way. The danger rating comes from the three URLhaus reports, not from our visit. Do not open files from this address, and do not run anything it gives you.

What happened to uasputnik.com, from registration to our test

The history is short: the domain is a month old and its first report came eight days after registration. The dates come from RDAP and from the URLhaus database.

  1. 9 September 2026

    The domain is registered

    RDAP shows uasputnik.com registered on 9 September 2026 through the registrar Gransy, s.r.o., valid until 9 September 2027. We found nothing that shows a real organisation behind the name.

  2. 17 September 2026

    Two ClickFix installers are reported

    At 05:44 UTC an anonymous reporter adds neon.msi with the tags ClickFix and msi. At 05:45 UTC the reporter alister1448 adds astra.msi with the tags ClickFix, Loader and msi. This is the first time URLhaus sees the host.

    Table of the three URLhaus entries for uasputnik.com with dates, status and tags
    The three URLhaus entries for uasputnik.com as we read them on 10 October 2026. Addresses are defanged.
  3. 29 September 2026

    A third installer is added

    At 08:18 UTC abuse.ch adds relax.msi with the tag msi only. It is the same kind of file in the same folder, twelve days after the first two, so the site was still in use then.

  4. 9 October 2026

    Our test is refused

    Our browser visit to https://uasputnik.com/ ends in ERR_CONNECTION_REFUSED. We do not know what a visitor who arrives from the lure page would see.

We could not read the URLhaus pages themselves, because they ask for a browser check. The entries above come from the same data in our own database, which holds the URLhaus feed.

How the ClickFix trick works on Windows, and where an .msi fits

ClickFix does not use a security hole. It makes you do the infecting yourself, so the warnings of your browser and your antivirus often never get a say. We did not see uasputnik.com's page; this is how Microsoft describes the trick.

Four steps of a ClickFix attack ending in an msi installer: a fake check page, a hidden copy to the clipboard, pasting into the Run box, and the Windows Installer starting a package
How ClickFix works on Windows, following Microsoft's description, and where an .msi file could come in. The last step is our reading for this site, not something we saw.
  1. 1

    You land on a page with a check

    Microsoft says the lure is often a fake CAPTCHA, human verification or error page, sometimes made to look like Cloudflare Turnstile or Google reCAPTCHA. It reaches you through phishing email, malicious ads or compromised sites.

  2. 2

    The page copies a command for you

    A button puts a command on your clipboard through the browser, without showing it. The page then tells you to paste it into the Run dialog, Windows Terminal or PowerShell.

  3. 3

    You open Run and paste

    The steps ask you to press the Windows key + R, press Ctrl + V and press Enter. Microsoft says the Run dialog is favoured because many users do not know what it is for.

  4. 4

    The command fetches the real malware

    Microsoft says these commands usually call PowerShell, mshta, rundll32, wscript, curl or wget. Microsoft's own page does not describe an .msi route. Windows can install a package from a command with msiexec /i, and /qn or /quiet hides every window, according to Microsoft's msiexec page. We do not know that this is what the three files are for.

  5. 5

    Nothing seems to happen

    A window that flashes and closes, or a CAPTCHA that never finishes, is the whole experience for many victims. Microsoft says the final payloads are often loaded into memory through built-in tools such as powershell.exe, msbuild.exe and regasm.exe.

Because a person starts the command, many automated defences treat it as normal. This is why the Run box history matters later: Windows records what was typed there, but only when the command worked.

The three files: what each name suggests, and what we do not know

File names are weak evidence. We list what URLhaus says about each and mark which statements are only a reading.

Source: the URLhaus database, read 10 October 2026. The third column is our interpretation of the names, not a finding.
File on uasputnik.comWhat URLhaus saysWhat it may be (our reading)
/neon.msiOffline, tags ClickFix and msi, added 17 September 2026 by an anonymous reporterA Windows installer started by a command the visitor pasted. Its contents are not confirmed
/astra.msiOffline, tags ClickFix, Loader and msi, added 17 September 2026 by alister1448The reporter calls it a loader, meaning a program that brings in something else. That is the reporter's label, not our check
/relax.msiOffline, tag msi, added 29 September 2026 by abuse.chThe same kind of file twelve days later, with no ClickFix tag. Whether it belongs to the same chain is not confirmed

Three short names, all in the top folder, tell us only that the files were put there to be fetched by address. We fetched none of them, so we give no malware family name.

What uasputnik.com (ClickFix, neon.msi, astra.msi, relax.msi) can steal or download

What a ClickFix payload on Windows can take

We do not know what uasputnik.com's installers contain. Microsoft names the payloads it has seen at the end of ClickFix chains, and the list below is those, not a claim about this site.

Malware named in Microsoft's ClickFix report

  • Lumma Stealer
  • Lampion
  • Xworm
  • AsyncRAT
  • NetSupport
  • SectopRAT
  • ScreenConnect
  • Latrodectus
  • MintsLoader
  • DarkGate
  • modified r77

Microsoft groups these into infostealers (Lumma, Lampion), remote access tools (Xworm, AsyncRAT, NetSupport, SectopRAT, ScreenConnect), loaders (Latrodectus, MintsLoader, DarkGate) and one rootkit, a modified r77. The loader group matters most for this site, because astra.msi carries the Loader tag: a loader's first file is not the last.

What this can cost you

Reading the site name or seeing a warning costs nothing. The risks below apply to a PC where a pasted command was run, or an .msi file from the site was installed.

  • High

    Your accounts used by someone else

    If the files hold a stealer, the saved logins and cookies in your browser are the prize. With a cookie, a thief can sit in your mailbox without knowing your password.

  • High

    Money in a crypto wallet

    Wallet data is a common target and a transfer cannot be called back. If a wallet lived on this PC, treat it as emptied until proven otherwise.

  • High

    A stranger at your keyboard

    A remote tool shows your screen to another person and lets them install more. The network cable is the first thing to pull.

  • Medium

    A program that stays installed

    An .msi writes itself into the list of installed apps and can leave services or tasks behind. Until they are found, the PC keeps running them.

  • Medium

    Your employer's data

    A work laptop carries tokens for company systems. Report it to your IT team the same day so they can cut those accounts.

  • Low

    No harm from reading the name

    Seeing the address in a log, an alert or a blocked link does nothing to your PC.

What you may notice, and what you may not

Most victims notice nothing. The signs below follow from how ClickFix chains and Windows installers work; the first two are the best evidence you have.

Sources: Microsoft Security Blog on ClickFix and Microsoft Learn on msiexec, read 10 October 2026.
SignWhat it means
A strange line in the Run box historyWindows keeps what was typed into Run. A long line with powershell, msiexec, a web address, hidden or -enc is the command that was pasted
A program in Installed apps you did not installA Windows Installer package registers itself there. Look for names and dates around the time you pasted the command
A window that flashed and closed after you pressed EnterA command that downloads and runs something, then exits
A scheduled task you did not makeMicrosoft lists Suspicious Scheduled Task Process Launched among its ClickFix alerts
Sign-ins or password resets you did not startA sign that a login or a session was taken. This is our reading, not a quote
Nothing at allStealers are built to finish in minutes and stay quiet

How to check the PC for uasputnik.com (ClickFix, neon.msi, astra.msi, relax.msi)

How people end up on a page like this

We do not know how visitors reach uasputnik.com, and no source says. The routes below are the ones Microsoft names for ClickFix in general.

  1. 1

    A phishing email with a link or attachment

    Microsoft names HTML attachments and links to ClickFix landing pages. The email says a document or delivery needs a check, and the page opens a fake verification.

  2. 2

    A malicious ad

    Microsoft describes fake Play pages on free movie streaming sites, and a fake government site reached through an ad redirect.

  3. 3

    A hacked website

    A normal site that was broken into shows the fake check on top of its own page. Microsoft says some such sites were probably hacked through WordPress weaknesses.

  4. 4

    A fake fix for a Windows or browser problem

    Pages that claim a browser or Windows needs repair, or that a document cannot be shown until you fix it, end in the same paste step.

Check your Windows PC before you delete anything

Start with the question that matters: did you paste a command from a website into Run, Windows Terminal or PowerShell, or run an .msi file from uasputnik.com? If yes, follow the plan on this page, because a clean-looking check does not clear a PC. If you are not sure, do these checks first. None of them deletes anything.

While you check, stop using the PC for banking, email, work or crypto, and disconnect it from Wi-Fi and the network cable if you can.

Five steps after running an installer from a ClickFix site: disconnect the PC, change passwords from another device, check installed apps and Task Scheduler, run an offline scan, then back up and reinstall Windows
The order of actions after running a file from the site: accounts first, from another device; the PC last.
  1. 1

    Look in Installed apps

    Open Settings > Apps > Installed apps on Windows 11, or Settings > Apps > Apps & features on Windows 10. Sort by install date and look for a program you did not choose that appeared when you pasted the command. Write down its name and publisher. Do not uninstall it yet.

  2. 2

    Find the line you pasted

    Run regedit, then browse to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU. Every value there is something typed into Run. Photograph any line with uasputnik.com, powershell or msiexec in it, and leave it in place.

  3. 3

    Open Task Scheduler

    Search for Task Scheduler in the Start menu, open the Task Scheduler Library and read any task with a random name or a recent date. Write the name down; deleting comes later.

  4. 4

    Read the Windows Security history

    Windows Security > Virus & threat protection > Protection history lists what Defender caught and when. Windows 10 reaches the same page through Settings > Update & Security > Windows Security. Look for dates near your paste.

  5. 5

    Do not read too much into a quiet result

    Deleting the RunMRU line hides the evidence and does not remove malware. Memory-only payloads leave nothing in these places, so a quiet check only lowers the doubt.

How to remove uasputnik.com (ClickFix, neon.msi, astra.msi, relax.msi)

How to remove uasputnik.com

A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.

  1. Step 1: Delete scheduled tasks that bring it back

    Open Task Scheduler from the Start menu and click Task Scheduler Library. Select each task you do not recognise and read the Actions tab:

    • a task that starts a file in %AppData% or %Temp%
    • runs powershell with a long encoded line
    • opens a web address belongs to uasputnik.com or a similar program

    Right-click such a task and choose Delete, and check the subfolders too. Leave tasks from Microsoft, your PC's maker and programs you use. Task Scheduler is the same in Windows 11 and Windows 10.

    Task Scheduler Library with a task selected and its Actions tab showing the program it starts
    Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  2. Step 2: Remove it from startup

    Whatever uasputnik.com installed usually starts with Windows. Open Task Manager with Ctrl + Shift + Esc, go to Startup apps in Windows 11 or the Startup tab in Windows 10, and disable what you do not know, starting with entries that have an empty Publisher column.

    Open file location on the right-click menu shows the file, which helps you decide and tells you what to delete later. Disabling is safe: if something you need stops working, switch it back on.

    Full procedure with screenshots: Stop apps from opening at startup On uGetFix

  3. Step 3: Delete the folders left behind

    What the uninstaller leaves behind is usually in the user folders. Open File Explorer, switch on View > Show > Hidden items (in Windows 10 View > Hidden items), and go through %LocalAppData%, %AppData%, %ProgramData% and the two Program Files folders.

    Sort by Date modified and delete folders that appeared together with the problem and belong to no program you use. Folders with random names that hold .exe, .dll, .js or .ps1 files are the strongest sign.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  4. Step 4: Scan the PC, then run the offline scan

    Open Windows Security > Virus & threat protection > Scan options, run a Full scan and remove everything it finds. Then select Microsoft Defender Antivirus (offline scan) and click Scan now: the PC restarts and scans before Windows loads, which finds files that hide while Windows runs.

    Save your work first, because the offline scan takes about 15 minutes. Both scans are built into Windows 11 and Windows 10, and a second scanner from another vendor is a useful extra opinion.

    Windows Security Scan options with Microsoft Defender Antivirus offline scan selected
    Windows 11: Windows Security > Virus & threat protection > Scan options.

    Full procedure with screenshots: Run a Microsoft Defender Offline scan

  5. Step 5: Change passwords from another device and sign out other sessions

    Assume that the passwords saved in this PC's browsers, and the accounts that were open in them, are known to the attacker. From a phone or a clean computer, change the e-mail password first, then banking, shopping, social and gaming accounts.

    Use each service's option to sign out of all other sessions, because stolen cookies keep a session open even after a password change. Turn on two-step verification on each account. Wait with the infected Windows 11 or Windows 10 PC until the scans are clean.

    Full procedure with screenshots: Turn on two-step verification / secure a hacked account

Scan from outside Windows: Microsoft Defender Offline

Most scans run inside the Windows that may be infected. This one starts first and looks at the system from outside, which is why Microsoft recommends it for stubborn malware.

Source: Microsoft Learn, Microsoft Defender Offline scan in Windows, read 9 October 2026.
QuestionAnswer from Microsoft Learn
How long does it take?About 15 minutes. The PC restarts, scans and starts Windows again
What does it need?An administrator account, Windows Recovery Environment turned on and Microsoft Defender Antivirus as the main antivirus
How do you check the recovery environment?In an administrator Command Prompt run reagentc /info. If it says Disabled, run reagentc /enable
What if BitLocker is on?Suspend it for the system drive first, or the PC may ask for the recovery key at restart
Where is it?Windows Security > Virus & threat protection > Scan options > Microsoft Defender Offline scan > Scan now
Where is the result?Protection history, on the same Virus & threat protection page
Where does it not work?On ARM versions of Windows. It runs on x64 Windows 10 and 11 only

A clean result is not a clearance. If a pasted command ran, or an installer from this site finished, plan to copy your documents out and reinstall Windows.

Uninstalling a program that came from the .msi

Only do this after the offline scan, and only if you know which entry it is. Removing a program does not remove what it already started.

  1. 1

    Use Installed apps

    In Settings > Apps > Installed apps, select the three dots next to the entry and choose Uninstall. On Windows 10 use Apps & features and select Uninstall. Windows Installer packages remove themselves this way, as Microsoft's msiexec page describes with its /x option for uninstalling a package.

  2. 2

    Then check what is left

    Look again at Task Scheduler and at shell:startup (Windows key + R) for files you did not make. Run the offline scan once more.

  3. 3

    Do not trust the uninstall alone

    If the package was a loader, it may already have fetched other programs that have no entry in the list. This is why we end the plan with a reinstall.

If you use a Mac, an iPhone or an Android phone

The msi tag points at Windows. We found nothing that says the three files run on anything else.

Your deviceWhat we knowWhat to do
MacAn .msi is a Windows format and does not install on macOS. Microsoft notes a Mac version of ClickFix exists, but we do not know what this page shows a MacNothing from these three files. If you pasted into Terminal, that is a different case, so use a Mac guide and not these Windows steps
iPhone or iPadThere is no Run box or Terminal in which to pasteNothing to remove. Change any password you typed
AndroidNo source mentions itNothing to remove for these files. Change any password you typed

After removal: passwords, accounts and prevention

After a clean PC: protect what was taken

Cleaning the PC does not take back what it already sent. Treat every login that touched it as known to someone else, and work through the list below on a different device.

What was on the PCWhat to do, in this order
Email accountChange its password first, because resets for your other accounts go there. Then use the sign out of all sessions option
Bank and card sitesChange the password, check recent activity and call the bank if anything looks wrong. Ask for a new card if you saved the number in the browser
Crypto wallet or exchangeMake a new wallet with a new recovery phrase on a clean device and move the funds. Do this before anything slower
Work accounts, VPN, cloud keysTell IT. Revoke tokens, SSH keys and API keys that were stored on the PC
Microsoft accountChange the password at account.microsoft.com and review the devices signed in to it
All accounts that offer itSwitch on an authenticator app or a security key for sign-in
  1. 1

    Reset the PC

    Copy only documents and photos to an external drive, never programs. Then go to Settings > System > Recovery on Windows 11, or Settings > Update & Security > Recovery on Windows 10, and reset the PC with the option to remove everything.

  2. 2

    Keep watching for a while

    For some weeks look at your bank, email and crypto for activity you did not start.

Keep a Windows PC out of this kind of trap

The rule that would have stopped this site is one line: a website never needs you to paste something into Run or PowerShell.

Do

  • Close any tab that tells you to press Windows key + R, then Ctrl + V, then Enter.
  • Install software only from the maker's own site or the Microsoft Store.
  • On a company PC, ask IT to remove the Run command by Group Policy. Microsoft names the setting under User Configuration, Administrative Templates, Start Menu and Taskbar.
  • Let Windows Update and your browser update themselves, and keep Windows Security on.
  • Keep one backup of documents on a drive that stays unplugged.

Don't

  • Do not paste anything to prove you are human, to fix a browser or to read a document.
  • Do not run an .msi file that a web page hands you after a check or an error message.
  • Do not follow a fix that means typing a line into a box.
  • Do not take a quiet scan as proof that you are safe.

Questions about uasputnik.com (ClickFix, neon.msi, astra.msi, relax.msi)

What is uasputnik.com?

It is a website that URLhaus lists for handing out malware, not a program on your computer. Three Windows installer files on it, neon.msi, astra.msi and relax.msi, were added on 17 and 29 September 2026, two of them tagged ClickFix. The domain was registered on 9 September 2026, so it is only weeks old.

On 9 October 2026 our test visit was refused, so we cannot say what the site shows today. If you only saw the name in a warning or a log, you are not infected by that. If you ran a command or a file from it, use the cleaning steps on this page.

Is uasputnik.com a virus?

A website is not a virus, but this one is listed as a source of malware. URLhaus gives all three of its file addresses the threat type malware_download. Two are tagged ClickFix, a trick that makes you start the infection yourself, and one of those is also tagged Loader.

We did not download the files, so we cannot name the malware or say exactly what it does. Treat the domain as dangerous, do not open it, and do not run anything it offers. Reading about it on this page cannot infect you.

What is ClickFix?

ClickFix is a con that gets you to run the attack on your own PC. A web page, usually posing as a CAPTCHA or an error, quietly copies a command and then walks you through pasting it into Run, Terminal or PowerShell. No software flaw is used, so many protections stay silent.

Microsoft says it spreads by phishing mail, ads and hacked sites. The malware at the end can be a stealer or a remote access tool. No genuine site needs you to paste a command, so closing the tab is the right reply.

I ran a file or command from uasputnik.com. What do I do now?

Disconnect the PC from the network first, by turning off Wi-Fi and unplugging the cable. Then, from another device, change your email, bank and work passwords, sign out of accounts everywhere and move any crypto to a new wallet.

After that run a Microsoft Defender Offline scan on the PC. If the command ran or the installer finished, the safest end is to back up documents and reinstall Windows, because a remote access tool may leave little trace. Tell your IT team if it is a work PC.

What if I only visited the site and pasted nothing?

Then you are very likely fine. The trick needs you to run something, and a page view alone does not do that. Close the tab and keep away from the address.

As a cheap precaution, run a quick scan in Windows Security. There is one catch: the page may have put hidden text on your clipboard, so before you paste anywhere, copy a plain word to replace it. If you did download a file and opened it, read the plan on this page instead.

How can I see what I pasted into Run?

Windows keeps a list of the lines typed into the Run box. Open Registry Editor and go to HKEY_CURRENT_USER, Software, Microsoft, Windows, CurrentVersion, Explorer, RunMRU. Each value is one line.

Microsoft says entries appear there only when the command ran successfully. A long line that contains powershell, msiexec, a web address, hidden or bypass is the sort of command used in ClickFix.

Read it without running it. Clearing it removes the evidence, not the malware, so scan the PC first and keep a note of what you found.

Will a scan with Windows Security remove it?

It may find part of it, and you should run it, but we cannot promise it finds everything. We never opened the installers, so we do not know what they hold or whether a memory-only stage followed them.

For the best chance use the offline scan, which Windows runs before it starts. If a remote tool was active, a clean reinstall is the only step that settles it. We have not tested any removal tool against these files, and we do not claim one removes them.

Which malware do neon.msi, astra.msi and relax.msi install?

We do not know. We did not download the files, and URLhaus shows no malware family name for them. The tags are ClickFix, msi and, on astra.msi, Loader.

Microsoft lists the final payloads seen in ClickFix chains, among them Lumma Stealer, AsyncRAT, Xworm, NetSupport and loaders such as Latrodectus and DarkGate, but that is a list for the trick in general, not a result for this site.

If you need a name, a malware analyst with the file could give one. Until then, plan as if a stealer and a remote access tool are both possible.

Why did our test of uasputnik.com show no page?

Our browser got ERR_CONNECTION_REFUSED when it opened the secure address of the domain on 9 October 2026. That means nothing answered us on that port. URLhaus showed all three files offline when we read it, so the server may have been taken down.

The operators may also block visitors from some countries or tools, or may use the domain only to hand out files. One failed visit proves nothing, and a site that shows nothing is not cleared.

Will Fortect remove uasputnik.com?

Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.

For uasputnik.com, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.

Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.

Sources

More removal guides

Remove stanarcservice.com: a Windows ClickFix malware site (s.ps1) and what to do if you pasted its command

stanarcservice.com is a website that URLhaus lists for malware downloads, one of them a PowerShell script (s.ps1) tagged ClickFix, and it refused our test connection. If you pasted a command from it into the Windows...TRHigh riskUgnius Kiguolis ·

Remove reinigung-kosanke.de: a hacked WordPress site that served Formbook PowerShell scripts, and what to do

reinigung-kosanke.de is a German cleaning business website that URLhaus lists for four PowerShell (.ps1) malware downloads tagged Formbook, and it answered our test with a 503 error. If you ran a script from it,...TRHigh riskUgnius Kiguolis ·

Remove evacompltd.site: a Windows VIP Keylogger malware site (script files and PowerShell) and what to do if one ran

evacompltd.site is a website that URLhaus lists for malware downloads: The site no longer answers when we look it up. If you opened a script file that came from it on Windows, treat the PC as compromised: change your...TRHigh riskUgnius Kiguolis ·

Remove johnsonsvalves.cam: a Windows XWorm malware site that hides code in a PNG, and what to do if a script from it ran

johnsonsvalves.cam is a website that URLhaus lists for malware downloads: The site no longer answers when we look it up. If you ran a script or a pasted command from it on Windows, treat the PC as compromised: change...TRHigh riskUgnius Kiguolis ·

Questions and experiences: uasputnik.com (ClickFix, neon.msi, astra.msi, relax.msi)

Still seeing it, or found something we did not cover? Ask here: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

5,444 members already hereReading, writing, commenting and voting. 0 verified · 169 joined this year