Solved

How to remove WSE_Astromendav Malware?

Posted on 2014-10-30
3
526 Views
Last Modified: 2014-10-31
Hi,
I'm a local admin on Windows 7 PC.  I tried uninstalling in program and Feature but it said I have no access.  I followed this article, http://www.exterminate-it.com/malpedia/file/wse_astromenda#location, gain access to this folder, C:\Windows\System32\Tasks\WSE_Astromenda   (I see WSE_Astromenda file name there).
But still getting no access message when I tried to uninstall it.  
I have Sophos at work that Quarnteen the virus but I have not permission to take action.   The desktop support is coming this afternoon and maybe need to reimage my pc to remove the virus.  Is there a way to remove this without reimaging my PC?  Thank you.
0
Comment
Question by:lapucca
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 50

Accepted Solution

by:
jcimarron earned 500 total points
ID: 40414120
lapucca --
Try deleting in SafeMode.  Astromenda may be tied up with some other process in Normal Mode.

If no help take ownership and possession of the folder and file.
http://www.addictivetips.com/windows-tips/windows-7-access-denied-permission-ownership/

Try the procedure here
http://www.exterminate-it.com/malpedia/file/wse_astromenda
How to Remove WSE_Astromenda
I have never used software from this site, so cannot recommend you use it, but the procedure given may help.
0
 

Author Comment

by:lapucca
ID: 40414143
The problem is that I don't see the file name mentioned in this site, http://www.exterminate-it.com/malpedia/file/wse_astromenda , in the file folder or in the task manager to terminate or delete.  The only possible files found in the Tasks folders are
{7EC5DF29-7B59-4F7D-B6B6-065DACBFB051} and WSE_Astromenda.  However, I don't know what the first file is.

What about this Trojan Killer tool?  https://www.system-tips.net/tips-remove-astromenda-search-virus/
0
 
LVL 81

Expert Comment

by:David Johnson, CD, MVP
ID: 40415195
go into task scheduler and remove astromedia, task manager should be able to stop it now, now you can delete it.
0

Featured Post

Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you thought ransomware was bad, think again! Doxware has the potential to be even more damaging.
By default the complete memory dump option is disabled in windows . If we want to enable the complete memory dump for a diagnostic purpose, we have a solution for it. here we are using the registry method to enable this.
This Micro Tutorial will give you basic overview of the control panel section on Windows 7. It will depth in Network and Internet, Hardware and Sound, etc. This will be demonstrated using Windows 7 operating system.
The viewer will learn how to successfully download and install the SARDU utility on Windows 7, without downloading adware.

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question