How to remove the regsrv virus

Most antivirus programs identify regsrv.exe as malware—for example Symantec identifies it as W32.Mubla, and TrendMicro identifies it as BKDR_IRCBOT.CU.

The free file information forum can help you find out how to remove it. If you have additional information about this file, please leave a comment or a suggestion for other users.

Click to Run a Free Virus Scan for the regsrv.exe malware

Regsrv.exe file information

The process known as maLnJ or UToo belongs to software UToo or IlBToHBrQg by uctg or UToo.

Description: Regsrv.exe is not essential for Windows and will often cause problems. The regsrv.exe file is located in the "C:\Program Files\Common Files" folder. The file size on Windows 10/8/7/XP is 643,072 bytes. 
The program has a visible window. The process starts upon Windows startup (see Registry key: MACHINE\RunServices, MACHINE\Run). The file is not a Windows system file. regsrv.exe appears to be a compressed file. Therefore the technical security rating is 28% dangerous.

Recommended: Identify regsrv.exe related errors

If regsrv.exe is located in the C:\Windows\System32\drivers folder, the security rating is 62% dangerous. The file size is 148,480 bytes. It is a file with no information about its developer. It is located in the Windows folder, but it is not a Windows core file. The program has no visible window. It is not a Windows core file. Regsrv.exe is able to hide itself and monitor applications.

If regsrv.exe is located in the C:\Windows\System32 folder, the security rating is 96% dangerous. The file size is 72,704 bytes. There is no information about the author of the file. It is located in the Windows folder, but it is not a Windows core file. The program has no visible window. The application starts when Windows starts (see Registry key: MACHINE\RunServices, MACHINE\Run). The application listens for or sends data on open ports to a LAN or the Internet. The file is not a Windows core file.

External information from Paul Collins:
There are different files with the same name:

Important: You should check the regsrv.exe process on your PC to see if it is a threat. We recommend Security Task Manager for verifying your computer's security. This was one of the Top Download Picks of The Washington Post and PC World.


User Comments

One user thinks it's probably harmless. One user thinks regsrv.exe is dangerous and recommends removing it.

Do you have additional information? Help other users!
What do you know about regsrv.exe:
How would you rate it:
Link for more info:
Your Name:

Best practices for resolving regsrv issues

The following programs have also been shown useful for a deeper analysis: Security Task Manager examines the active regsrv process on your computer and clearly tells you what it is doing. Malwarebytes' well-known anti-malware tool tells you if the regsrv.exe on your computer displays annoying ads, slowing it down. This type of unwanted adware program is not considered by some antivirus software to be a virus and is therefore not marked for cleanup.

A clean and tidy computer is the key requirement for avoiding PC trouble. This means running a scan for malware, cleaning your hard drive using cleanmgr and sfc /scannow, uninstalling programs that you no longer need, checking for Autostart programs (using msconfig) and enabling Windows' Automatic Update. Always remember to perform periodic backups, or at least to set restore points.

Should you experience an actual problem, try to recall the last thing you did, or the last thing you installed before the problem appeared for the first time. Use the resmon command to identify the processes that are causing your problem. Even for serious problems, rather than reinstalling Windows, you are better off repairing of your installation or, for Windows 8 and later versions, executing the DISM.exe /Online /Cleanup-image /Restorehealth command. This allows you to repair the operating system without losing data.

Other processes

regsrv.exe [all]