TechEnclave
New Tech Posts
New Market Posts
TechEnclave RuleBook



Reply
 
LinkBack (1) Thread Tools
  1 links from elsewhere to this Post. Click to view. #1 (permalink)  
Old 10 Jan 09, 02:33 PM
Bluffmaster's Avatar
Everybody Lies
 
Join Date: Jan 2006
Location: भारत
Posts: 2,379
Bluffmaster is just Great Bluffmaster is just Great Bluffmaster is just Great Bluffmaster is just Great Bluffmaster is just Great Bluffmaster is just Great Bluffmaster is just Great Bluffmaster is just Great Bluffmaster is just Great Bluffmaster is just Great Bluffmaster is just Great
Default regsvr.exe

I don't know what this is but its eating up 60% of my CPU resources. Can anybody shed some light on this?
Reply With Quote
  #2 (permalink)  
Old 10 Jan 09, 02:38 PM
6pack's Avatar
Anime Member
 
Join Date: Sep 2005
Location: forsaken land
Posts: 1,912
6pack is highly Famed 6pack is highly Famed 6pack is highly Famed 6pack is highly Famed 6pack is highly Famed 6pack is highly Famed 6pack is highly Famed 6pack is highly Famed 6pack is highly Famed
Default Re: regsvr.exe

regsvr.exe Windows process - What is it?
Reply With Quote
  #3 (permalink)  
Old 10 Jan 09, 02:45 PM
Bluffmaster's Avatar
Everybody Lies
 
Join Date: Jan 2006
Location: भारत
Posts: 2,379
Bluffmaster is just Great Bluffmaster is just Great Bluffmaster is just Great Bluffmaster is just Great Bluffmaster is just Great Bluffmaster is just Great Bluffmaster is just Great Bluffmaster is just Great Bluffmaster is just Great Bluffmaster is just Great Bluffmaster is just Great
Default Re: regsvr.exe

^Yes, I can google too. But most of the search results are sites which want you to download their software to remove this. I am looking for any safe freeware that can remove regsvr.exe from my computer permanently.
Reply With Quote
  #4 (permalink)  
Old 10 Jan 09, 03:10 PM
muzux2's Avatar
God TechiE™
 
Join Date: May 2008
Location: Srinagar
Posts: 1,307
muzux2 is highly Prominent muzux2 is highly Prominent muzux2 is highly Prominent muzux2 is highly Prominent muzux2 is highly Prominent
Default Re: regsvr.exe

Its a W32/Rbot Worm. It copies itself to a file named regsvr.exe in windws & creates several reg entries.. You can use 'Trojan Remover' or
' Regrun' tool to remove it. Though Trojan Remove isn't free, you can clean it with trail version..
Reply With Quote
  #5 (permalink)  
Old 10 Jan 09, 04:22 PM
Namic's Avatar
lolmachine
 
Join Date: May 2007
Posts: 415
Namic is somewhat of a mystery
Default Re: regsvr.exe

or better get the list of files this worm creates. Log on to linux and delete by urself coz some trail version softwares will not completely remove the trojans. It might have got into other partitions as well
Reply With Quote
  #7 (permalink)  
Old 10 Jan 09, 06:36 PM
Bluffmaster's Avatar
Everybody Lies
 
Join Date: Jan 2006
Location: भारत
Posts: 2,379
Bluffmaster is just Great Bluffmaster is just Great Bluffmaster is just Great Bluffmaster is just Great Bluffmaster is just Great Bluffmaster is just Great Bluffmaster is just Great Bluffmaster is just Great Bluffmaster is just Great Bluffmaster is just Great Bluffmaster is just Great
Default Re: regsvr.exe

Quote:
Originally Posted by Namic View Post
or better get the list of files this worm creates. Log on to linux and delete by urself coz some trail version softwares will not completely remove the trojans. It might have got into other partitions as well
Thats a neat suggestion. Now let me install another operating system and then I'll get rid of this worm ... finally


Already tried the Piyush labs solution but it doesn't work on Vista
Reply With Quote
  #8 (permalink)  
Old 10 Jan 09, 06:42 PM
6pack's Avatar
Anime Member
 
Join Date: Sep 2005
Location: forsaken land
Posts: 1,912
6pack is highly Famed 6pack is highly Famed 6pack is highly Famed 6pack is highly Famed 6pack is highly Famed 6pack is highly Famed 6pack is highly Famed 6pack is highly Famed 6pack is highly Famed
Default Re: regsvr.exe

oops.. sorry.
Reply With Quote
  #9 (permalink)  
Old 10 Jan 09, 07:06 PM
vishalk's Avatar
Steroids Member
 
Join Date: Mar 2005
Age: 34
Posts: 359
vishalk is very Respectable vishalk is very Respectable vishalk is very Respectable vishalk is very Respectable
Default Re: regsvr.exe

Download MULTI_AV.EXE from the URL --
http://www.ik-cs.com/programs/virtools/Multi_AV.exe


To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close


Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }


NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through your
FireWall to allow it to download the needed AV vendor related files.


C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal Mode.
This way all the components can be downloaded from each AV vendor's web site.
The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the PC.


You can choose to go to each menu item and just download the needed files or you can
download the files and perform a scan in Normal Mode. Once you have downloaded the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode [F8 key
during boot] and re-run the menu again and choose which scanner you want to run in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.


When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive PDF help
file. http://www.ik-cs.com/multi-av.htm

hope this helps u m8....if not well then i guess u should download spyware doctor and avira...maybe these 2 can help u...
Reply With Quote
  #10 (permalink)  
Old 10 Jan 09, 08:21 PM
techfreak's Avatar
Steroids Member
 
Join Date: Jun 2007
Location: Bangalore
Posts: 406
techfreak is very Notable techfreak is very Notable techfreak is very Notable
Default Re: regsvr.exe

Try malwarebytes anti malware ........free copy does the job
Reply With Quote
  #11 (permalink)  
Old 10 Jan 09, 08:56 PM
SoMxNemesis's Avatar
Fire at a Funeral!
 
Join Date: Oct 2007
Location: Bangalore
Age: 22
Posts: 1,103
SoMxNemesis is Notable
Default Re: regsvr.exe

Avast has a free trojan removal tool on their site.. try that.
Reply With Quote
  #12 (permalink)  
Old 10 Jan 09, 09:16 PM
Bluffmaster's Avatar
Everybody Lies
 
Join Date: Jan 2006
Location: भारत
Posts: 2,379
Bluffmaster is just Great Bluffmaster is just Great Bluffmaster is just Great Bluffmaster is just Great Bluffmaster is just Great Bluffmaster is just Great Bluffmaster is just Great Bluffmaster is just Great Bluffmaster is just Great Bluffmaster is just Great Bluffmaster is just Great
Default Re: regsvr.exe

Thanks for the response. I tried a few applications and it seems like, the issue has been solved. I cannot see regsvr.exe in the processes anymore. Thanks everyone for the help
Reply With Quote
  #13 (permalink)  
Old 18 Jan 09, 08:27 PM
happyandyk's Avatar
Newbie
 
Join Date: Jan 2009
Posts: 9
happyandyk is Mysterious
Default Re: regsvr.exe

Good to se your issue has been resolved.

Nevertheless, do a search for regsvr.exe . If it is situated in C:\Windows\System32, its the legit MS file used to register or unregister dll's.

If not it is malware. In future to delete such nasty undeletable files, you can always use 'delete doctor' freeware utility.
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


LinkBacks (?)
LinkBack to this Thread: http://www.techenclave.com/applications/regsvr-exe-126021.html
Posted By For Type Date
regsvr.exe / rundll.exe / ‘Microsoft CorpAration’ virus details & heal uploaded : : : Piyush Labs : : : This thread Refback 2 May 09 05:21 PM

Search TechEnclave
Register on TechEnclave to Remove the ads and the sidebar
Have some Fun!


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.3.2