My Eset Nod 32 found:
WIN32\Packed.Autoit.Gen
in C:\WINDOWS2\system32\csrsc.exe
Is it virus or not, can you please help?
Thanks in advance.
------------------------------------------------
DDS (Ver_09-05-14.01) - NTFSx86
Run by xxx at 9:10:05,93 on 04.06.2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional 5.1.2600.2.1250.385.1033.18.382.79 [GMT 2:00]
AV: ESET NOD32 Antivirus 3.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
============== Running Processes ===============
C:\WINDOWS2\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS2\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS2\system32\spoolsv.exe
C:\Program Files\Common Files\ActivCard\acautoreg.exe
C:\Program Files\Common Files\ActivCard\accoca.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS2\Explorer.exe
C:\WINDOWS2\system32\csrcs.exe
C:\WINDOWS2\system32\VTTimer.exe
C:\WINDOWS2\system32\S3trayp.exe
C:\Program Files\MSI\Live Update 3\LMonitor.exe
C:\WINDOWS2\RTHDCPL.EXE
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\ActivCard\ActivCard Gold\agquickp.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS2\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\MSI\PC Alert 4\PCAlert4.exe
C:\Program Files\MSI\SecureDoc\Logon.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS2\system32\svchost.exe -k imgsvc
C:\WINDOWS2\System32\svchost.exe -k HTTPFilter
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\xxx\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.hr/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
mWinlogon: Shell=Explorer.exe csrcs.exe
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
uRun: [CTFMON.EXE] c:\windows2\system32\ctfmon.exe
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
uRun: [BitTorrent] "c:\program files\bittorrent\bittorrent.exe" --force_start_minimized
mRun: [VTTimer] VTTimer.exe
mRun: [S3Trayp] S3trayp.exe
mRun: [NeroCheck] c:\windows2\system32\\NeroCheck.exe
mRun: [LiveMonitor] c:\program files\msi\live update 3\LMonitor.exe
mRun: [UpdateDriver] c:\program files\activcard\usb reader pcsc drivers\tools\update driver\updatedriver.exe -if:c:\program files\activcard\usb reader pcsc drivers\distribution\stcusb.inf -hd:usb\VID_0066&PID_1001 -bBothReader
mRun: [SkyTel] SkyTel.EXE
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop album starter edition\3.0\apps\apdproxy.exe"
mRun: [QuickPassword] c:\program files\activcard\activcard gold\agquickp.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [egui] "c:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice
dRun: [CTFMON.EXE] c:\windows2\system32\CTFMON.EXE
mExplorerRun: [csrcs] c:\windows2\system32\csrcs.exe
StartupFolder: c:\docume~1\xxx\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\pcaler~1.lnk - c:\program files\msi\pc alert 4\PCAlert4.exe
StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\secure~1.lnk - c:\program files\msi\securedoc\Logon.exe
StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\winzip~1.lnk - c:\program files\winzip\WZQKPICK.EXE
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: Microsoft XML Parser for Java - file://c:\windows2\java\classes\xmldso.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1189699918312
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1189701206718
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
============= SERVICES / DRIVERS ===============
R0 xfilt;VIA SATA IDE Hot-plug Driver;c:\windows2\system32\drivers\xfilt.sys [2007-7-3 11264]
R1 ATMhelpr;ATMhelpr;c:\windows2\system32\drivers\ATMHELPR.SYS [2007-12-6 4064]
R1 epfwtdir;epfwtdir;c:\windows2\system32\drivers\epfwtdir.sys [2008-7-1 34312]
R2 acautoreg;ActivCard Gold Autoregister;c:\program files\common files\activcard\acautoreg.exe [2005-12-13 53248]
R2 Accoca;ActivCard Gold service;c:\program files\common files\activcard\accoca.exe [2004-5-12 143360]
R2 ekrn;Eset Service;c:\program files\eset\eset nod32 antivirus\ekrn.exe [2008-7-1 468224]
R3 PCAlertDriver;PCAlertDriver;c:\program files\msi\pc alert 4\NTGLM7X.sys [2007-7-11 28160]
R3 S3GIGP;S3GIGP;c:\windows2\system32\drivers\S3gIGPm.sys [2007-7-3 659456]
S3 actccid;ActivCard USB Reader V2;c:\windows2\system32\drivers\actccid.sys [2002-8-2 47660]
S3 Actrpcsc;Actrpcsc;c:\windows2\system32\drivers\actrpcsc.sys --> c:\windows2\system32\drivers\actrpcsc.sys [?]
S3 akpcsc;ActivCard Virtual PC/SC Device Driver;c:\windows2\system32\drivers\akpcsc.sys --> c:\windows2\system32\drivers\akpcsc.sys [?]
S3 EZUSB;EZUSB PC/SC Smart Card Reader;c:\windows2\system32\drivers\ezusb.sys [2007-10-17 57356]
S3 SCMUSB;SCM Microsystems SCR301 USB Smart Card Reader;c:\windows2\system32\drivers\stcusb.sys [2007-10-17 17408]
S3 SE2Ebus;Sony Ericsson Device 046 Driver driver (WDM);c:\windows2\system32\drivers\SE2Ebus.sys [2006-5-1 61600]
S3 SE2Eobex;Sony Ericsson Device 046 USB WMC OBEX Interface;c:\windows2\system32\drivers\SE2Eobex.sys [2007-12-6 86560]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\e:\ntglm7x.sys --> e:\NTGLM7X.sys [?]
S3 USB_RNDIS_51;Broadcom USB Remote NDIS Device Driver;c:\windows2\system32\drivers\usb8023.sys [2004-8-4 12672]
=============== Created Last 30 ================
2009-06-03 13:46 0 a--shr-- C:\kht
2009-06-03 13:21 1,805 a--shr-- c:\windows2\system32\autorun.i
2009-06-03 13:21 1,057 a--shr-- c:\windows2\system32\autorun.in
2009-06-03 13:08 <DIR> --d----- c:\windows2\pss
2009-06-03 10:20 <DIR> --d----- c:\program files\ESET
2009-06-02 16:13 <DIR> --d----- c:\docume~1\alluse~1.win\applic~1\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-06-02 16:11 <DIR> --d----- c:\program files\Bonjour
2009-06-02 09:10 <DIR> --d----- c:\program files\trend micro
2009-05-26 17:18 90,112 a------- c:\windows2\system32\QuickTimeVR.qtx
2009-05-26 17:18 57,344 a------- c:\windows2\system32\QuickTime.qts
==================== Find3M ====================
2007-10-19 19:48 1,833,032 a------- c:\program files\InstallMusicnotes.exe
2007-05-14 20:44 128,624 a------- c:\program files\Download_dvdtomp3converter.exe
2007-05-08 21:58 11,552,256 a------- c:\program files\AudioConverter5-4.exe
2007-04-12 21:49 3,275,358 a------- c:\program files\Nero-6-Update[www.click-now.net].zip
2007-03-11 10:08 14,730,232 a------- c:\program files\DivXInstaller.exe
2007-03-01 20:25 5,186,048 a------- c:\program files\WindowsDefender.msi
2007-01-07 19:09 18,257,616 a------- c:\program files\avg75free_432a904.exe
2007-01-07 18:43 37,011,112 a------- c:\program files\avg75f_433a904.exe
2006-01-18 17:37 200 a------- c:\program files\Shortcut to CD Drive.lnk
2005-12-19 21:45 2,855,080 a------- c:\program files\aawsepersonal.exe
2004-08-04 13:43 429,202 a--shr-- c:\windows2\system32\csrcs.exe
============= FINISH: 9:10:38,62 ===============