Hello
i have a keyboard virus that changes the keys here is an exempe:
ei hv3ei k3eiuyvbotrd veitr6uys 4trh4tr chng3eis 4trh3ei k3eiuys
this message was written with keyboard on scrreen, i researched but it and scannedwith hijackthis here s the log, please help.
sry if iwritten something wrong its hard to write.
Logfile of HijackThis v1.99.1
Scan saved at 3:16:06, on 20-09-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Programas\TGTSoft\StyleXP\StyleXPService.exe
D:\Programas\DigitalPersona\Bin\DPWinLct.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Programas\AntiVir PersonalEdition Classic\sched.exe
D:\Programas\AntiVir PersonalEdition Classic\avguard.exe
D:\WINDOWS\ATKKBService.exe
D:\WINDOWS\system32\CTsvcCDA.EXE
D:\Programas\DigitalPersona\Bin\DpHost.exe
D:\Programas\Ficheiros comuns\Microsoft Shared\VS7DEBUG\MDM.EXE
D:\Programas\Eset\nod32krn.exe
D:\WINDOWS\system32\nvsvc32.exe
D:\WINDOWS\system32\svchost.exe
D:\Programas\DigitalPersona\Bin\DPFUSMgr.exe
D:\WINDOWS\Explorer.EXE
D:\Programas\Creative\Shared Files\Module Loader\DLLML.exe
D:\Programas\AntiVir PersonalEdition Classic\avgnt.exe
D:\WINDOWS\system32\LVCOMSX.EXE
D:\Programas\Logitech\Video\LogiTray.exe
D:\Programas\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE
D:\Programas\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe
D:\WINDOWS\CTHELPER.EXE
D:\WINDOWS\system32\CTXFIHLP.EXE
D:\WINDOWS\SYSTEM32\CTXFISPI.EXE
D:\Programas\MessengerPlus! 3\MsgPlus.exe
D:\Programas\Java\jre1.5.0_06\bin\jusched.exe
D:\Programas\DAEMON Tools\daemon.exe
D:\Programas\QuickTime\qttask.exe
D:\WINDOWS\system32\RUNDLL32.EXE
D:\Programas\DigitalPersona\Bin\DPAgnt.exe
D:\Programas\Ficheiros comuns\Real\Update_OB\realsched.exe
D:\Programas\AGEIA Technologies\TrayIcon.exe
D:\Programas\Eset\nod32kui.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Programas\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
D:\Programas\Logitech\Video\FxSvr2.exe
D:\Programas\Creative\MediaSource\Detector\CTDetect.exe
D:\programas\steam\steam.exe
D:\Programas\Messenger\msmsgs.exe
D:\Programas\Microsoft ActiveSync\wcescomm.exe
D:\Programas\Sprite Software\Sprite Backup\SpriteService.exe
D:\Programas\MSN Messenger\msnmsgr.exe
D:\PROGRA~1\MI3AA1~1\rapimgr.exe
D:\Programas\Logitech\SetPoint\KEM.exe
D:\Programas\Creative\ShareDLL\CADI\NotiMan.exe
D:\Programas\Logitech\SetPoint\KHALMNPR.EXE
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\wscntfy.exe
D:\Programas\Mozilla Firefox\firefox.exe
D:\WINDOWS\system32\osk.exe
D:\WINDOWS\system32\MSSWCHX.EXE
D:\Programas\WinRAR\WinRAR.exe
D:\DOCUME~1\ADMINI~1\DEFINI~1\Temp\Rar$EX10.203\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pt
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pt
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Programas\Adobe\Acrobat
7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: ChangerBHO Class - {0D4C7057-EAD2-44C6-AD18-9092905F28F1} - D:\WINDOWS\system32\Audiodevs.dll (file missing)
O2 - BHO: ShprRprts - {2A8A997F-BB9F-48F6-AA2B-2762D50F9289} - D:\Programas\ShopperReports\Bin\2.0.0\ShprRprt.dll
O2 - BHO: IeCatch5 Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - D:\PROGRA~1\FlashGet\jccatch.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Programas\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Programas\Ficheiros comuns\Microsoft
Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Great Offers Displayer - {CE05B815-6F98-4ADD-AEB7-60BB2D4264F1} - c:\windows\bh.dll (file missing)
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - D:\PROGRA~1\FlashGet\fgiebar.dll
O4 - HKLM\..\Run: [AudioDrvEmulator] "D:\Programas\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator
"D:\Programas\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [NeroFilterCheck] D:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [avgnt] "D:\Programas\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [LVCOMSX] D:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] D:\Programas\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] D:\Programas\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [CTDVDDET] "D:\Programas\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [RCSystem] "D:\Programas\Creative\Shared Files\Module Loader\DLLML.exe" RCSystem * -Startup
O4 - HKLM\..\Run: [VolPanel] "D:\Programas\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" /r
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [UpdReg] D:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [LogonStudio] "D:\Programas\WinCustomize\LogonStudio\logonstudio.exe" /RANDOM
O4 - HKLM\..\Run: [GhostSurfDelSatellite] "D:\Programas\GhostSurf 2005\DeleteSatellite.exe"
O4 - HKLM\..\Run: [SeePassword] D:\Programas\SeePassword\SeePassword.exe
O4 - HKLM\..\Run: [MessengerPlus3] "D:\Programas\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] D:\Programas\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [DAEMON Tools] "D:\Programas\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [QuickTime Task] "D:\Programas\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [DPAgnt] D:\Programas\DigitalPersona\Bin\DPAgnt.exe
O4 - HKLM\..\Run: [4028202b.exe] D:\WINDOWS\system32\4028202b.exe
O4 - HKLM\..\Run: [TkBellExe] "D:\Programas\Ficheiros comuns\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AGEIA PhysX SysTray] D:\Programas\AGEIA Technologies\TrayIcon.exe
O4 - HKLM\..\Run: [nod32kui] "D:\Programas\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LDM] D:\Programas\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [Creative Detector] "D:\Programas\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [Steam] "d:\programas\steam\steam.exe" -silent
O4 - HKCU\..\Run: [STYLEXP] D:\Programas\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [MessengerPlus3] "D:\Programas\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [MSMSGS] "D:\Programas\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIP] D:\WINDOWS\aip.exe
O4 - HKCU\..\Run: [HOTASMode] "D:\Programas\HOTAS\HOTASConfig.exe" /MODE /FOXY /AU /DM /BW
O4 - HKCU\..\Run: [H/PC Connection Agent] "D:\Programas\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [Hide IP Platinum] D:\Programas\Hide IP Platinum\hideippla.exe
O4 - HKCU\..\Run: [SpriteService] "D:\Programas\Sprite Software\Sprite Backup\SpriteService.exe"
O4 - HKCU\..\Run: [ASUS SmartDoctor] D:\Programas\ASUS\SmartDoctor\SmartDoctor.exe /start
O4 - HKCU\..\Run: [Trust Cleaner] "D:\Programas\Trust Cleaner\Trust Cleaner.exe"
O4 - HKCU\..\Run: [4028202b.exe] D:\Documents and Settings\Administrador\Definições locais\Application Data\4028202b.exe
O4 - HKCU\..\Run: [SSS2006] "D:\Programas\Steganos Security Suite 2006\SSS2006.exe" -boot
O4 - HKCU\..\Run: [msnmsgr] "D:\Programas\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [AdobeUpdater] D:\Programas\Ficheiros comuns\Adobe\Updater\AdobeUpdater.exe
O4 - Startup: Adobe Gamma.lnk = D:\Programas\Ficheiros comuns\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = D:\Programas\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Logitech SetPoint.lnk = D:\Programas\Logitech\SetPoint\KEM.exe
O8 - Extra context menu item: &NeoTrace It! - D:\PROGRA~1\NEOTRA~1\NTXcontext.htm
O8 - Extra context menu item: Download All by FlashGet - D:\Programas\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - D:\Programas\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Programas\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
D:\Programas\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Criar Favorito Móvel... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} -
D:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ShopperReports - Compare product prices - {946B3E9E-E21A-49c8-9F63-900533FAFE14} -
D:\Programas\ShopperReports\Bin\2.0.0\ShprRprt.dll
O9 - Extra button: ShopperReports - Compare travel rates - {946B3E9E-E21A-49c8-9F63-900533FAFE15} -
D:\Programas\ShopperReports\Bin\2.0.0\ShprRprt.dll
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Programas\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Programas\Messenger\msmsgs.exe
O9 - Extra button: NeoTrace It! - {9885224C-1217-4c5f-83C2-00002E6CEF2B} - D:\PROGRA~1\NEOTRA~1\NTXtoolbar.htm (HKCU)
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) -
https://signup.msn.com/pages/MsnInstC.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) -
http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) -
http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{667316D1-7FF9-4FF6-BC93-FA09D876066D}: NameServer = 194.65.100.117,194.65.5.2
O18 - Protocol: bw+0 - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: offline-8876480 - {8EADD250-C2D9-40D6-8A74-05C962231FCF} - D:\Programas\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O20 - Winlogon Notify: DPWLN - D:\WINDOWS\system32\DPWLEvHd.dll
O23 - Service: Adobe LM Service - Adobe Systems - D:\Programas\Ficheiros comuns\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - D:\Programas\AntiVir
PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - D:\Programas\AntiVir PersonalEdition
Classic\avguard.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - D:\WINDOWS\ATKKBService.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - D:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Windows XP FUS Manager (DPFUSMgr) - DigitalPersona, Inc. - D:\Programas\DigitalPersona\Bin\DPFUSMgr.exe
O23 - Service: Biometric Authentication Service (DpHost) - DigitalPersona, Inc. - D:\Programas\DigitalPersona\Bin\DpHost.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Programas\Ficheiros
comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - D:\Programas\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc32.exe
O23 - Service: rpcapd - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file
missing)
O23 - Service: StyleXPService - Unknown owner - D:\Programas\TGTSoft\StyleXP\StyleXPService.exe