Solved

How to remove WSE_Astromendav Malware?

Posted on 2014-10-30
3
523 Views
Last Modified: 2014-10-31
Hi,
I'm a local admin on Windows 7 PC.  I tried uninstalling in program and Feature but it said I have no access.  I followed this article, http://www.exterminate-it.com/malpedia/file/wse_astromenda#location, gain access to this folder, C:\Windows\System32\Tasks\WSE_Astromenda   (I see WSE_Astromenda file name there).
But still getting no access message when I tried to uninstall it.  
I have Sophos at work that Quarnteen the virus but I have not permission to take action.   The desktop support is coming this afternoon and maybe need to reimage my pc to remove the virus.  Is there a way to remove this without reimaging my PC?  Thank you.
0
Comment
Question by:lapucca
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 50

Accepted Solution

by:
jcimarron earned 500 total points
ID: 40414120
lapucca --
Try deleting in SafeMode.  Astromenda may be tied up with some other process in Normal Mode.

If no help take ownership and possession of the folder and file.
http://www.addictivetips.com/windows-tips/windows-7-access-denied-permission-ownership/

Try the procedure here
http://www.exterminate-it.com/malpedia/file/wse_astromenda
How to Remove WSE_Astromenda
I have never used software from this site, so cannot recommend you use it, but the procedure given may help.
0
 

Author Comment

by:lapucca
ID: 40414143
The problem is that I don't see the file name mentioned in this site, http://www.exterminate-it.com/malpedia/file/wse_astromenda , in the file folder or in the task manager to terminate or delete.  The only possible files found in the Tasks folders are
{7EC5DF29-7B59-4F7D-B6B6-065DACBFB051} and WSE_Astromenda.  However, I don't know what the first file is.

What about this Trojan Killer tool?  https://www.system-tips.net/tips-remove-astromenda-search-virus/
0
 
LVL 80

Expert Comment

by:David Johnson, CD, MVP
ID: 40415195
go into task scheduler and remove astromedia, task manager should be able to stop it now, now you can delete it.
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

There are many reasons malware will stay around and continue to grow as a business.  The biggest reason is the expanding customer base.  More than 40% of people who are infected with ransomware, pay the ransom.  That makes ransomware a multi-million…
If you are looking at this article, you have most likely been hit by some version of ransomware and are trying to find out if there is anything you can do, or what way you should react - READ ON!
This Micro Tutorial will go in depth within Systems and Security in Windows 7 and will go into detail regarding Action Center, Windows Firewall, System, etc. This will be demonstrated using Windows 7 operating system.
The Task Scheduler is a powerful tool that is built into Windows. It allows you to schedule tasks (actions) on a recurring basis, such as hourly, daily, weekly, monthly, at log on, at startup, on idle, etc. This video Micro Tutorial is a brief intro…

756 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question