How to Remove “rpcsandrasrv.exe”

What is rpcsandrasrv.exe?


rpcsandrasrv.exe is a legitimate process file popularly known as SiSoftware Sandra Agent Service. It belongs to SiSoftware Sandra, developed by SiSoftware. It is located in C:\Windows\System32 by default.

Malware programmers write virus files with malicious scripts and save them as rpcsandrasrv.exe with an intention to spread virus on the internet.

Affected Platforms: Windows OS
 

How to determine if your computer is infected with rpcsandrasrv.exe malware?


Look out for the these symptoms to check if your PC is infected with rpcsandrasrv.exe malware:
  • Unstable internet connection
  • rpcsandrasrv.exe occupies extra CPU space
  • PC processing speed slows down
  • Browser often redirects to irrelevant websites
  • Browser is bombarded with hordes of popup ads
  • Computer screen freezes repeatedly
Take the following steps to diagnose your PC for possible rpcsandrasrv.exe malware attack:

Step 1: Simultaneously press CTRL+ALT+DEL keys to open Task Manager.

Step 2: If you notice the file located outside C:\Windows\System32, perform an antivirus scan to get rid of the malware.

How to remove rpcsandrasrv.exe malware from system using Comodo Antivirus?

Step 1: Download our award-winning Free Antivirus

Step 2: Installation configuration frames will be displayed. Select the configuration you would like to apply.

Step 3: Select Customize Configuration option and arrange installers, configuration, and file location.

Step 4: Restart your PC after the installation gets over

Step 5: Wait for Comodo Internet Security to update the antivirus.

Step 6: Proceed with the quick scan that automatically begins after the update.

Step 7: If threats are found during the scanning, you will be notified through an alert screen.

Step 8: Comodo Antivirus will remove rpcsandrasrv.exe malware from your computer including all other malwares!
29

Malware Entries

First Seen: 13 December 2011 at 5:25 pm
No. Company File Type SHA1 MD5 Malware
Name
Digitally
Signed
File
Version
Product
Version
Submitted
From
Malware Behavior
1 SiSoftware Executable e6b9f170dea2d281
3d77acce60c913a6
bb2a05c7
192c32b22ca3ec6c
5c29a3ee64215189
Heur.Suspici
ous
Yes 18.28.2012
.2
18.28.2012
.2
Iran, Islamic Republic of N/A
2 SiSoftware Executable 22df6aedf36ccd57
65ba9a430bf45a08
ba437d67
4a9ca3d154f60133
d8127565d9a94b52
Heur.Suspici
ous
Yes 18.30.2012
.2
18.30.2012
.2
Russian Federation N/A
3 SiSoftware Executable 9b32253943c79a11
4036ec5d5f27b414
8831494a
7b3fad3f226efe96
84cc8caa776e1bcb
Heur.Suspici
ous
Yes 18.30.2012
.2
18.30.2012
.2
Israel N/A
4 SiSoftware Executable 22df6aedf36ccd57
65ba9a430bf45a08
ba437d67
4a9ca3d154f60133
d8127565d9a94b52
Heur.Suspici
ous
Yes 18.30.2012
.2
18.30.2012
.2
Germany N/A
Display 4 items per page
  • 4 items per page
  • 8 items per page
  • 16 items per page
  • 32 items per page
31

Safe Entries

First Seen: 08 December 2011 at 7:38 am
No. Company File Type SHA1 MD5 Digitally
Signed
File
Version
Product
Version
Submitted
From
1 SiSoftware Executable 28b18ae4609e437a
f978b91ee0700197
de235d31
04e84c225a80b0e1
959f97e3b85653c0
Yes 18.20.2012
.1
18.20.2012
.1
France
2 SiSoftware Executable 537579750bdaa42e
f21d82a6a0cd2a53
a0ba5a42
a1a8713b9c2aaa1c
b2bcace8e0a41949
Yes 18.24.2012
.1
18.24.2012
.1
United Kingdom
3 SiSoftware Executable 537579750bdaa42e
f21d82a6a0cd2a53
a0ba5a42
a1a8713b9c2aaa1c
b2bcace8e0a41949
Yes 18.24.2012
.1
18.24.2012
.1
United States
4 SiSoftware Executable 537579750bdaa42e
f21d82a6a0cd2a53
a0ba5a42
a1a8713b9c2aaa1c
b2bcace8e0a41949
Yes 18.24.2012
.1
18.24.2012
.1
Switzerland
Display 4 items per page
  • 4 items per page
  • 8 items per page
  • 16 items per page
  • 32 items per page
 
Exclusive Offer
Get Free Endpoint Protection
Get Advanced
Endpoint
Protection

Award-Winning Security to Protect Your Clients from Cyber Attacks

Comodo Internet Security Pro

Free Antivirus protection from hackers! Get the ultimate Antivirus solution to keep your PC clean and to remove viruses from a slow or infected PC. Improve the PC performance at home or use it on-the-go!

Get Comodo Internet Security Comodo Internet Security