How to Remove “rpcsandrasrv.exe”

What is rpcsandrasrv.exe?


rpcsandrasrv.exe is a legitimate process file popularly known as SiSoftware Sandra Agent Service. It belongs to SiSoftware Sandra, developed by SiSoftware. It is located in C:\Windows\System32 by default.

Malware programmers write virus files with malicious scripts and save them as rpcsandrasrv.exe with an intention to spread virus on the internet.

Affected Platforms: Windows OS
 

How to determine if your computer is infected with rpcsandrasrv.exe malware?


Look out for the these symptoms to check if your PC is infected with rpcsandrasrv.exe malware:
  • Unstable internet connection
  • rpcsandrasrv.exe occupies extra CPU space
  • PC processing speed slows down
  • Browser often redirects to irrelevant websites
  • Browser is bombarded with hordes of popup ads
  • Computer screen freezes repeatedly
Take the following steps to diagnose your PC for possible rpcsandrasrv.exe malware attack:

Step 1: Simultaneously press CTRL+ALT+DEL keys to open Task Manager.

Step 2: If you notice the file located outside C:\Windows\System32, perform an antivirus scan to get rid of the malware.

How to remove rpcsandrasrv.exe malware from system using Comodo Antivirus?

Step 1: Download our award-winning Free Antivirus

Step 2: Installation configuration frames will be displayed. Select the configuration you would like to apply.

Step 3: Select Customize Configuration option and arrange installers, configuration, and file location.

Step 4: Restart your PC after the installation gets over

Step 5: Wait for Comodo Internet Security to update the antivirus.

Step 6: Proceed with the quick scan that automatically begins after the update.

Step 7: If threats are found during the scanning, you will be notified through an alert screen.

Step 8: Comodo Antivirus will remove rpcsandrasrv.exe malware from your computer including all other malwares!
29

Malware Entries

First Seen: 30 March 2012 at 3:58 am
No. Company File Type SHA1 MD5 Malware
Name
Digitally
Signed
File
Version
Product
Version
Submitted
From
Malware Behavior
1 SiSoftware Executable c67dd4824d49eab2
a9deb912c8dba6fa
75b5258e
e6832ded381aab57
4d54dfa0caab43e4
Heur.Suspici
ous
Yes 18.52.2012
.6
18.52.2012
.6
Germany N/A
2 SiSoftware Executable 5deba191de510579
d36312a9ace9f1c1
43e4b4a2
2395d4e22797c6f3
bfa843bd6fb058bd
Heur.Suspici
ous
Yes 18.40.2012
.5
18.40.2012
.5
Czech Republic N/A
3 SiSoftware Executable c67dd4824d49eab2
a9deb912c8dba6fa
75b5258e
e6832ded381aab57
4d54dfa0caab43e4
Heur.Suspici
ous
Yes 18.52.2012
.6
18.52.2012
.6
Russian Federation N/A
4 SiSoftware Executable 5deba191de510579
d36312a9ace9f1c1
43e4b4a2
2395d4e22797c6f3
bfa843bd6fb058bd
Heur.Suspici
ous
Yes 18.40.2012
.5
18.40.2012
.5
Ukraine N/A
Display 4 items per page
  • 4 items per page
  • 8 items per page
  • 16 items per page
  • 32 items per page
37

Safe Entries

First Seen: 30 March 2012 at 8:23 am
No. Company File Type SHA1 MD5 Digitally
Signed
File
Version
Product
Version
Submitted
From
1 SiSoftware Executable a653074b5871bdd9
3f2996734f6ac996
5b567966
a6fc054d58e3263d
aaa45d16093b7bc3
Yes 18.47.2012
.6
18.47.2012
.6
United States
2 SiSoftware Executable aabcdaabddafacb5
78a2b785fadb76f2
a4fecea3
8b652c443da44871
013d9a0d75080cc0
Yes 18.40.2012
.5
18.40.2012
.5
France
3 SiSoftware Executable 9ea8bdcd8900cff6
3d085dd08b699359
4b1feeec
a2597fc6e6831726
60f9bf6f8f4941de
Yes 18.45.2012
.6
18.45.2012
.6
Netherlands
4 SiSoftware Executable a6efb45fb28a0dac
43118b6d7ed831e4
d05db343
ba4c8aa3b88932d5
444878e5e32c41a2
Yes 18.45.2012
.6
18.45.2012
.6
Germany
Display 4 items per page
  • 4 items per page
  • 8 items per page
  • 16 items per page
  • 32 items per page
 
Exclusive Offer
Get Free Endpoint Protection
Get Advanced
Endpoint
Protection

Award-Winning Security to Protect Your Clients from Cyber Attacks

Comodo Internet Security Pro

Antivirus Protection protection from hackers! Get the ultimate Antivirus solution to keep your PC clean and to remove viruses from a slow or infected PC. Improve the PC performance at home or use it on-the-go!

Get Comodo Internet Security Comodo Internet Security