How to remove the ntsrv virus

Most antivirus programs identify ntsrv.exe as malware—for example TrendMicro identifies it as ADW_FANSLINKA, and F-Secure identifies it as Trojan.Generic.5134373.

The free file information forum can help you find out how to remove it. If you have additional information about this file, please leave a comment or a suggestion for other users.

Click to Run a Free Virus Scan for the ntsrv.exe malware

Ntsrv.exe file information

The process appears to belong to software NTLOAD by unknown.

Description: Ntsrv.exe is not essential for Windows and will often cause problems. The file ntsrv.exe is located in a subfolder of C:\Windows. The file size on Windows 10/8/7/XP is 16,896 bytes. 
There is no description of the program. The program is not visible. The file is an unknown file in the Windows folder. Ntsrv.exe is not a Windows core file. Therefore the technical security rating is 71% dangerous, however you should also read the user reviews.

Recommended: Identify ntsrv.exe related errors

External information from Paul Collins:

Important: You should check the ntsrv.exe process on your PC to see if it is a threat. We recommend Security Task Manager for verifying your computer's security. This was one of the Top Download Picks of The Washington Post and PC World.


User Comments

The same name of a system file, but in C:\WINDOWS\SYSTEM\DRIVER folder is suspicious. Cannot end it or remove it - ID as BDS/Iroffer.14b2 with Antivir
I found it at C:\WINDOWS\SYSTEM\DRIVER folder, it is run as a service. Maybe it's a FTP server program of a Trojen program. folder is hidden.
Yes it landed on my computer and I managed with BitDefender 9 to Quarantine it, and although I have not yet deleted it will use Knoppix to delete it from Quarantine.
(C:\Windows\System\driver, C:\Windows(WINNT)\system32\driver) TROJ_SERVU.Q {E21ACC41-BBFF-9D54-9535-D8D3A71E80E8} {F0EAF14D-488F-EF59-5214-968C1D261AD1} {1E570EE2-E21D-1C83-D447-B5C28B2C954D}
  ozzzz   (further information)
According to the link this is a bad file, a variant of Trojan!
  Aurora   (further information)
this is a dangerous backdoor trojan. i managed to delete it by doing this. First of all the reason you can't delete it is because it is already in use. get into your task manager (ctrl+alt+del) then click on ntsrv.exe and to disable it and then go to c:\windows\system\driver and delete it maually
Ftp server called Serv-U ! probably backdoors around too..
This is software that came with my UPS.
AVM Computersystems
  Ich natürlich  

Rating chart

Summary: Average user rating of ntsrv.exe: based on 11 votes with 9 user comments. 2 users think ntsrv.exe is essential for Windows or an installed application. 9 users think ntsrv.exe is dangerous and recommend removing it. One user is not sure about it.

Do you have additional information?
What do you know about ntsrv.exe:
How would you rate it:
Link for more info:
Your Name:

Best practices for resolving ntsrv issues

The following programs have also been shown useful for a deeper analysis: Security Task Manager examines the active ntsrv process on your computer and clearly tells you what it is doing. Malwarebytes' well-known anti-malware tool tells you if the ntsrv.exe on your computer displays annoying ads, slowing it down. This type of unwanted adware program is not considered by some antivirus software to be a virus and is therefore not marked for cleanup.

A clean and tidy computer is the key requirement for avoiding PC trouble. This means running a scan for malware, cleaning your hard drive using cleanmgr and sfc /scannow, uninstalling programs that you no longer need, checking for Autostart programs (using msconfig) and enabling Windows' Automatic Update. Always remember to perform periodic backups, or at least to set restore points.

Should you experience an actual problem, try to recall the last thing you did, or the last thing you installed before the problem appeared for the first time. Use the resmon command to identify the processes that are causing your problem. Even for serious problems, rather than reinstalling Windows, you are better off repairing of your installation or, for Windows 8 and later versions, executing the DISM.exe /Online /Cleanup-image /Restorehealth command. This allows you to repair the operating system without losing data.

Other processes

ntsrv.exe [all]