PCTech Home 

Want More Tips, Sign Up Today!


Follow us on Facebook

PCTech  >>  General  >>  Remove sdra64.exe virus and delete file

 Remove sdra64.exe virus and delete file

Posted: 5/21/2009
This sdra64.exe removal is a little harder to remove than your normal virus removal.  The file sdra64.exe is locked by the Winlogon process and therefore you are not able to delete it by using tools such as Hijackthis or Icesword. 
To remove this virus please download the following tool Process Explorer from Microsoft/Sysinternals. Process Explorer
Once you have downloaded the tool, open it.
1. Press CTRL+F on your keyboard to begin search.
2. Type sdra64.exe
3. Double click on the search results, it should be listed as winlogon and some additional details
4. On the toolbar select Handle then Close Handle
    Then you would be able to delete the file.  Follow the location listed in the registry. Typically it's going to be C:\windows\system32
5. Delete the sdra64.exe file or rename it.
6. While in the system32 folder delete the folder called lowsec which contains the spyware data. 
7. Restart your computer then open Regedit by going to Start --> Then Run and typing Regedit, then click ok.
8. The registry should look like this
9. Double click on the Userinit entry and then remove everything after the comma. 
10. Go to Edit then refresh your view to verify that the entry does not come back.
11. Turn off your system restore (under My Computer --> Then Properties) then you can turn it back on.
Your system should now be free from this sdra64.exe virus, we still recommend doing a full virus scan to remove any additional files the could potentially be remaining.
 Post Id: 39

 RE: Remove sdra64.exe virus and delete file

Posted: 3/1/2010
If I understand you correctly, your account is not an administator account? In an virus removal situation you will want to login as the administrator to remove it. Try running through these instructions as the administrator on this computer and let me know your results.
 Post Id: 44

 RE: Remove sdra64.exe virus and delete file

Posted: 5/7/2010
i was reading this forum while i was running antivir - the process explorer was open at the same time - i saw sda64.exe and the lowsec folder (hidden) - but the handle disappeared and the files were locked still. i tried opening regedit anyway and change the Userinit entry rebooted and now the sda64.exe and lowsec folder are gone. but i can not change the Userinit entry ... what do you think has happened?
 Post Id: 48

 RE: Remove sdra64.exe virus and delete file

Posted: 5/7/2010
i booted in safemode and followed the procedure my machine is clean now. thanks!
 Post Id: 49

 RE: Remove sdra64.exe virus and delete file

Posted: 6/4/2010
NeoRetro10K can you explain at what step in the process you are having the problem?  The more details the better so we can help troubleshoot.  It's possible you may have other rootkits or viruses making the process a little more complicated than normal.

 Post Id: 55

You're welcome to reprint or republish these articles on your website and in your e-newsletter free of charge, provided that you don't change the article in any way and you include the byline (including a link to our website)
In doing so you agree to indeminfy PCTech and its directors, officers, employees, and agents from and against all losses, claims, damages, and liabilities that arise out of their use.

Article provided by PCTech Computer Repair Topics

Home  |   Business Computer Repair  |   Security  |   Networking  |   Web Design  |   Computer Repair  |   Computer Help  |   Consultations  |   Privacy Policy  |   Contact us