svchost and regserv

G

Guest

I am really hoping that there is a tech support rep online right now, because
I'm a bit freaked out. For the first time in 15 years of running computers I
have gotten my first virus and I have absolutely no clue what I am doing with
it. Let me post the log of what the virus scanner recorded:

Verizon Internet Security Suite Anti-Virus
Scanning Report (6/14/2006 8:18:35 PM)
Master Boot Records and Fixed Disk Boot Sectors
Scanned 1 Master Boot Record(s) for viruses.

Scanned 2 Boot Sector(s) for viruses.

Your Master Boot Record(s)/Boot Sector(s) are not infected.

Files
Drive C:\
C:\Documents and Settings\All Users\Application Data\Spybot - Search &
Destroy\Recovery\WildTangent.zip
Some files in this archive could not be scanned because they are password
protected. The real-time protection will automatically scan the files when
you extract them from the archive.
C:\WINDOWS\system\regserv.exe

File was infected with "W32/Shellbot.C" virus and was unable to be
disinfected. File was deleted instead.
C:\WINDOWS\system\svchost.exe

File was infected with "W32/Shellbot.C" virus and was unable to be
disinfected. File was deleted instead.
Files scanned: 103497
Infected files: 2
Disinfected files: 0
Deleted files: 2
Files unable to scan: 1
Report Summary
Files scanned: 103497
Total infected files: 2
Total disinfected files: 0
Total deleted files: 2
Total files unable to scan: 1
Anti-Virus engine status
Last update: 6/14/2006 7:55:25 PM
Virus definition file: avsdk-20061642.msp

As of right now, I am afraid to turn off my computer because I don't want to
lose the ability of turning it back on because something tells me that these
files might be important. Am I supposed to have these files on my computer
(Note: I did fine a svchost.exe file in the system32 folder, but no regserv
file resides anywhere on my computer), and if so, where do I get them to put
them back on my computer?

-David
 
L

Larry Gardner

The two files that were deleted ARE virus files.

The true location of svchost.exe is C:\Windows\System32.

And there is no regserv.exe in Windows XP.

Additonally, the locations these were found were in C:\Windows\System which
is present for support of legacy applications using non-XP processes.

More than likely, regserv.exe was downloaded to your system to register
something in the registry with leaving tracks.
You may want to search your registry for:

regserv, system\regserv, system\svchost.exe
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top