Home 






PCTech  >>  General  >>  Remove sdra64.exe virus and delete file



 Remove sdra64.exe virus and delete file
PCTech

Posted: 5/21/2009
12:13:29
PM
This sdra64.exe removal is a little harder to remove than your normal virus removal.  The file sdra64.exe is locked by the Winlogon process and therefore you are not able to delete it by using tools such as Hijackthis or Icesword. 
 
To remove this virus please download the following tool Process Explorer from Microsoft/Sysinternals. Process Explorer
 
Once you have downloaded the tool, open it.
 
1. Press CTRL+F on your keyboard to begin search.
2. Type sdra64.exe
3. Double click on the search results, it should be listed as winlogon and some additional details
4. On the toolbar select Handle then Close Handle
    Then you would be able to delete the file.  Follow the location listed in the registry. Typically it's going to be C:\windows\system32
5. Delete the sdra64.exe file or rename it.
6. While in the system32 folder delete the folder called lowsec which contains the spyware data. 
7. Restart your computer then open Regedit by going to Start --> Then Run and typing Regedit, then click ok.
8. The registry should look like this
 
 
9. Double click on the Userinit entry and then remove everything after the comma. 
10. Go to Edit then refresh your view to verify that the entry does not come back.
11. Turn off your system restore (under My Computer --> Then Properties) then you can turn it back on.
 
Your system should now be free from this sdra64.exe virus, we still recommend doing a full virus scan to remove any additional files the could potentially be remaining.
 
 Post Id: 39

 RE: Remove sdra64.exe virus and delete file
JoMarrable

Posted: 12/14/2009
3:44:18
PM
Hi, can anyone help me, I have Prevx on my laptop and when it scans it tells me I have this sdra64.exe but when I download the process tool and search for it it doesn't seem to be there?
 Post Id: 41

 RE: Remove sdra64.exe virus and delete file
Darque Dante

Posted: 12/31/2009
10:13:49
AM
What could be going on in your situation sir, is that you have the registry entry BUT NOT THE FILE, so the when you use your AV scanning software it scans through the registry sees the entry and throws out the flag to warn you of the infection, but not having the file actually present on your machine.
 Post Id: 42

 RE: Remove sdra64.exe virus and delete file
gibbsy999

Posted: 2/5/2010
9:15:03
PM
My account isn't an administators and every thread that I find tells you how to deal with this problem on an Admin account. The sdra64.exe file is located in C:\Documents and Settings\Dan\Application Data This file will not be deleted. I couldn't find it using regedit but did on the Process Explorer and it wouldn't let me close the handle saying 'The handle is invalid' I tried using a software calle Remove On Reboot but it remained. Please help.
 Post Id: 43




Home  |   Security  |   Networking  |   Web Design  |   Inventory Systems  |   Computer Repair  |   Computer Help  |   Consultations  |   Privacy Policy  |   Contact us