Is this a virus?

skinlab

Gawd
Joined
Dec 13, 2002
Messages
965
Hiya,

I'm using AVG free as my current virus scanner and i seem to have run into a problem here

using WinXP Pro, so the installation directory is C:\Windows

however, i have a folder called Winnt with the following subfolders

C:\Winnt\System32\Drivers\Etc\

there's a file called svchost1.exe and has the Serv-U logo (an FTP client which i DONT have installed)

there's also a secure.bat file which AVG detects as a virus but cant clean

a ServUStartUpLog.txt file shows the following

Wed 20Jul05 23:58:30 - Serv-U FTP Server v4.0 (4.1.0.0) - Copyright (c) 1995-2002 Cat Soft, All Rights Reserved - by Rob Beckers
Wed 20Jul05 23:58:30 - Cat Soft is an affiliate of Rhino Software, Inc.
Wed 20Jul05 23:58:31 - Using WinSock 2.0 - max. 32767 sockets
Wed 20Jul05 23:58:32 - PROBLEM: Unable to load the SSL/TLS libraries (SSLEAY32.DLL and LIBEAY32.DLL) - No SSL support
Wed 20Jul05 23:58:32 - FTP Server listening on port number 526, IP 192.168.1.100, 127.0.0.1
Wed 20Jul05 23:58:32 - FTP Server listening on port number 43958, IP 127.0.0.1
Wed 20Jul05 23:58:32 - Valid registration key found

i say again, ServU isnt even installed, hasnt been downloaded on my system either prior

Windows Task Manager shows 4 instances of svchost.exe and ONE instance of svchost1.exe

so, long story short. is there a virus around these parts? since AVG isnt doing the cleaning, what else should i use?

and lastly, the most important questions: can i delete the folder C:\Winnt ???

thanks
 
yup, first goto safemode, and delete that folder...
secondly..its the ftp server part, not client. so someone has installed a ftp server on your b0x.

meh im pressed for time here now, but goto trendmicro.com and do their housecall scan.
 
^^^In addition to Trend Micro's, also run the free online scanner from BitDefender.....
 
well i just ended the instance running and then deleted the folder, that went fine

scanned the pc for viruses and nothing came up (using AVG)

shut down and just booted up again now, seems to be working fine

thx fellas
 
Back
Top