Virus Alert – SVCHST.EXE
A file called svchst.exe installs with the RBot.ED worm. This worm spreads across network shares. You'll find it in your Windows\System or System32 folder. You may see it described as "WinAmpAgent". In reality, it is not related to Winamp. This file runs as a service and can allow a remote user to access your PC using an IRC chat channel.
We'd recommend removing this file using WinPatrol. First, go to you Active Tasks folder and kill the file there. Next, go to your Startup Programs and remove the file there. If you're running WinPatrol 8.x or later, we'd recommend right clicking the file then selecting "Delete file on reboot". Then reboot your system. We'd also recommend a full system scan with an up to date antivirus program. Please do not remove a file called "svchost.exe" as this is a Microsoft file that Windows needs to run properly.
More background info on this virus can be found at http://www.sophos.com/virusinfo/analyses/w32rboted.html.
Virus
Remove