cityStatic
Seasoned Veteran
Well, sdra64.exe is the "trojan menace"
Here's how to remove it:
XP and Vista: Go to Start>Run. Type in regedit. Your Registry Editor should come up. Navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon. You should see "Userinit." It should only say "C:\Windows\System32\Userinit.exe," but it says, "C:\Windows\System32\Userinit.exe,C:\Windows\System32\sdra64.exe" instead. Right click on the name "Userinit" and click modify. Remove "C:\Windows\System32\stra64.exe", but DO NOT CLICK OK YET!!! The next part is very important. Go to Task Manager and click on the Processes tab. Start ending the svchost.exe processesses in the order of largest file size until you get an error message. It will start counting down from 60, which is a countdown to reboot. When the countdown reaches 1, click OK on the Registry Editor. Reboot your computer, and delete the file from the folder. If this did not work for you, try again, but click OK later.
If you don't feel like this, you can do it using this method.
Aliases:
alg.exe, racmond.dll, lxmjsa.dll, pwhpho.dll, rundll.dll, svchost.exe, Mal/Behav-010, arjrller.dll, 12345.dll, svp.dll, mh104.dll, services.exe, Mal/Zbot-I, spj.dll, jlgejgei32fg.dll, Trojan-Spy.Win32.Zbot.ouu, zbotkiller.exe, twext.exe, sp.dll, compbatc.dll, twex.exe, byshell32.dll, Trojan.Obfuscater.SDRA
Here's how to remove it:
XP and Vista: Go to Start>Run. Type in regedit. Your Registry Editor should come up. Navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon. You should see "Userinit." It should only say "C:\Windows\System32\Userinit.exe," but it says, "C:\Windows\System32\Userinit.exe,C:\Windows\System32\sdra64.exe" instead. Right click on the name "Userinit" and click modify. Remove "C:\Windows\System32\stra64.exe", but DO NOT CLICK OK YET!!! The next part is very important. Go to Task Manager and click on the Processes tab. Start ending the svchost.exe processesses in the order of largest file size until you get an error message. It will start counting down from 60, which is a countdown to reboot. When the countdown reaches 1, click OK on the Registry Editor. Reboot your computer, and delete the file from the folder. If this did not work for you, try again, but click OK later.
If you don't feel like this, you can do it using this method.
Aliases:
alg.exe, racmond.dll, lxmjsa.dll, pwhpho.dll, rundll.dll, svchost.exe, Mal/Behav-010, arjrller.dll, 12345.dll, svp.dll, mh104.dll, services.exe, Mal/Zbot-I, spj.dll, jlgejgei32fg.dll, Trojan-Spy.Win32.Zbot.ouu, zbotkiller.exe, twext.exe, sp.dll, compbatc.dll, twex.exe, byshell32.dll, Trojan.Obfuscater.SDRA







