Hi,
Hmmm, well, something changed
When I run hijackthis to make a log file, it says it can not open the script file c:\windows\rogerca.vbs… So I can not present you with a log for this.
Here is the combofix log however…
ComboFix 08-04-26.5 - Rogerca 2008-04-28 20:12:06.9 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.311 [GMT 2:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\rogerca\Desktop\cfscript.txt
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\00008NL.D
C:\administrator.vbs
C:\Documents and Settings\administrator.LNK
C:\rogerca.vbs
C:\sqmdata02.sqm
C:\sqmdata03.sqm
C:\sqmdata04.sqm
C:\sqmdata05.sqm
C:\sqmnoopt02.sqm
C:\sqmnoopt03.sqm
C:\sqmnoopt04.sqm
C:\sqmnoopt05.sqm
C:\Temp\ar6341
C:\Temp\Repl_explorer
C:\Temp\snagit.exe
C:\Temp\Update Helpfile.sql
C:\Temp\Windows-KB890830-V1.39.exe
C:\Temp\xp_emergencyutil.exe
C:\Temp\xp_emergencyutil.zip
C:\WINDOWS\administrator.vbs
C:\WINDOWS\rogerca.vbs
C:\WINDOWS\system32\administrator.ini
C:\WINDOWS\system32\administrator.vbs
C:\WINDOWS\system32\DELS3ci.dll
C:\WINDOWS\system32\DELS3ci.exe
C:\WINDOWS\system32\DELS3L3.DLL
C:\WINDOWS\system32\DELS3L3.SMT
C:\WINDOWS\system32\rogerca.vbs
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\00008NL.D
C:\administrator.vbs
C:\Autorun.inf
C:\Documents and Settings\administrator.LNK
C:\rogerca.vbs
C:\sqmdata02.sqm
C:\sqmdata03.sqm
C:\sqmdata04.sqm
C:\sqmdata05.sqm
C:\sqmnoopt02.sqm
C:\sqmnoopt03.sqm
C:\sqmnoopt04.sqm
C:\sqmnoopt05.sqm
C:\Temp\cbm
C:\Temp\cbm\Counter.dat
C:\Temp\cbm\CU-0313-B SW Rev History for RhComm.exe.doc
C:\Temp\cbm\RhComm.exe
C:\Temp\snagit.exe
C:\Temp\TORHAFNIA_DELIVERY
C:\Temp\TORHAFNIA_DELIVERY\Acceptance_Test_ HW_403.doc
C:\Temp\TORHAFNIA_DELIVERY\Jinling Acceptance Test AMOS MP_403.doc
C:\Temp\Update Helpfile.sql
C:\Temp\Windows-KB890830-V1.39.exe
C:\Temp\xp_emergencyutil.exe
C:\Temp\xp_emergencyutil.zip
C:\WINDOWS\administrator.vbs
C:\WINDOWS\rogerca.vbs
C:\WINDOWS\system32\administrator.ini
C:\WINDOWS\system32\administrator.vbs
C:\WINDOWS\system32\DELS3ci.dll
C:\WINDOWS\system32\DELS3ci.exe
C:\WINDOWS\system32\DELS3L3.DLL
C:\WINDOWS\system32\DELS3L3.SMT
C:\WINDOWS\system32\rogerca.vbs
.
—- Previous Run ——-
.
C:\Autorun.inf
C:\Temp\ABS8515.zip
C:\Temp\Amos Replication Export Files Explorer.zip
C:\Temp\avg75free_519a1276.exe
C:\Temp\HJTInstall.exe
C:\Temp\Norman_Malware_Cleaner.exe
C:\Temp\putty.zip
C:\Temp\spybotsd152.exe
C:\Temp\TS-fix.bat
C:\Temp\uploaded-8407_update helpfile.zip
C:\Temp\vnc-4_1_2-x86_win32.exe
C:\WINDOWS\MS_Ext1.DLL
C:\WINDOWS\MS_VXD_Ext.DLL
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_FAD
——-\Legacy_IPRIP
——-\Service_Iprip
((((((((((((((((((((((((( Files Created from 2008-03-28 to 2008-04-28 )))))))))))))))))))))))))))))))
.
2008-04-28 18:40 . 2008-04-28 18:40 d——– C:\Documents and Settings\All Users\Application Data\InstallShield
2008-04-28 18:37 . 2008-04-28 18:37 d——– C:\Program Files\SpecTec
2008-04-28 18:34 . 2008-04-28 18:34 d——– C:\Program Files\Amos Pocket Server installation
2008-04-28 18:26 . 2008-04-28 19:18 d——– C:\Temp\200803 AMOS Pockewt
2008-04-21 08:43 . 2001-03-18 20:52 766 ——— C:\WINDOWS\Uninstall.ico
2008-04-15 15:32 . 2006-10-11 14:26 546,560 -ra—— C:\WINDOWS\system32\drivers\mos24ser.sys
2008-04-15 15:32 . 2006-10-11 14:36 299,008 -ra—— C:\WINDOWS\system32\Mos24Serial.EXE
2008-04-15 15:32 . 2006-10-11 14:35 258,048 -ra—— C:\WINDOWS\system32\MSUninst.exe
2008-04-15 15:32 . 2006-10-11 14:36 61,440 -ra—— C:\WINDOWS\system32\Mos24SerPropPage.dll
2008-04-15 15:28 . 2007-03-31 13:43 253,952 –a—— C:\WINDOWS\system32\MultiMP.exe
2008-04-15 15:28 . 2006-11-06 07:58 159 –a—— C:\WINDOWS\system32\MSConfig.ini
2008-04-15 15:27 . 2008-04-15 15:27 d——– C:\Mos24Ser
2008-04-15 14:17 . 2003-12-12 09:12 18,240 –a—— C:\WINDOWS\system32\drivers\DbgMsg.sys
2008-04-15 13:54 . 2008-04-15 13:54 d——– C:\Documents and Settings\administrator.SPECTECAB\WINDOWS
2008-04-15 13:54 . 2004-04-01 12:24 1,369,264 –a—— C:\WINDOWS\system32\FPSPR70.OCX
2008-04-15 13:54 . 1997-08-11 11:43 817,152 –a—— C:\WINDOWS\system32\VCF132.OCX
2008-04-15 13:54 . 1997-01-18 11:40 299,520 –a—— C:\WINDOWS\uninst.exe
2008-04-15 10:04 . 2008-04-15 10:04 d——– C:\ampo
2008-04-15 10:01 . 2008-04-15 10:01 d——– C:\Program Files\Xantic
2008-04-15 10:01 . 2003-01-17 22:13 688,128 ——— C:\WINDOWS\system32\PolarSpellChecker.dll
2008-04-15 10:01 . 2006-05-11 17:33 266,240 –a—— C:\WINDOWS\system32\mapitif.dll
2008-04-15 10:01 . 2006-05-11 17:41 81,920 –a—— C:\WINDOWS\system32\mssshl32.dll
2008-04-15 10:01 . 2005-04-06 14:56 22,016 –a—— C:\WINDOWS\system32\mssmonnt.dll
2008-04-15 08:43 . 2008-04-15 08:43 1,075,712 –a—— C:\Temp\AMOS Mail Vrs[1]. 5.1.xx Installation Guide.exe
2008-04-13 23:15 . 2008-04-13 23:15 d——– C:\fsaua.data
2008-04-13 22:54 . 2008-04-13 22:54 d——– C:\EmergencyUtils
2008-04-13 16:36 . 2008-04-13 16:36 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-04-13 16:36 . 2008-04-13 16:36 d——– C:\Documents and Settings\rogerca\Application Data\Malwarebytes
2008-04-13 16:36 . 2008-04-13 16:36 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-13 16:33 . 2008-04-13 16:33 50,688 –a—— C:\Temp\ATF-Cleaner.exe
2008-04-13 16:22 . 2008-04-13 16:22 d——– C:\Documents and Settings\All Users\Application Data\Avg7
2008-04-13 13:08 . 2008-04-13 13:01 10,360,321 –a—— C:\Enterprise_LEV_080413.zip
2008-04-11 11:25 . 2004-05-05 18:40 414,720 -ra—— C:\WINDOWS\system32\ftcunin.exe
2008-04-11 11:25 . 2004-03-16 12:03 69,632 -ra—— C:\WINDOWS\system32\ftd2xx.dll
2008-04-11 11:25 . 2004-03-23 18:36 56,031 -ra—— C:\WINDOWS\system32\drivers\ftcser2k.sys
2008-04-11 11:25 . 2003-06-11 13:48 48,625 -ra—— C:\WINDOWS\system32\ftcsui2.dll
2008-04-11 11:25 . 2004-05-05 12:10 43,235 -ra—— C:\WINDOWS\system32\drivers\ftcusb.sys
2008-04-11 11:25 . 2004-05-06 13:47 20,198 -ra—— C:\WINDOWS\system32\ftcserco.dll
2008-04-11 11:25 . 2004-03-11 13:27 92 -ra—— C:\WINDOWS\system32\ftcun2k.ini
2008-04-11 11:14 . 2008-04-15 13:54 d——– C:\Program Files\Kockum Sonics
2008-04-11 11:14 . 2004-10-07 20:03 74,240 –a—— C:\Norcontrol_sim.exe
2008-04-10 16:10 . 2008-04-25 01:33 d——– C:\Program Files\Spybot - Search & Destroy
2008-04-10 16:10 . 2008-04-11 11:11 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-07 11:28 . 2008-04-07 11:28 d——– C:\Temp\ar6341
2008-04-07 08:17 . 2008-04-07 08:17 d——– C:\Program Files\Trend Micro
2008-04-04 14:01 . 2008-04-07 07:54 d——– C:\cbm
2008-04-04 09:15 . 2008-04-04 09:12 102,664 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2008-04-04 09:12 . 2008-04-04 12:41 d——– C:\Documents and Settings\rogerca\.housecall6.6
2008-04-01 12:03 . 2008-04-02 08:58 d——– C:\Temp\Repl_explorer
2008-04-01 08:30 . 2008-04-01 08:30 d——– C:\Program Files\RealVNC
2008-03-28 15:48 . 2008-03-28 15:57 d——– C:\Program Files\putty
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-28 18:22 ——— d—–w C:\Documents and Settings\rogerca\Application Data\Skype
2008-04-28 18:21 ——— d—–w C:\Program Files\Plaxo
2008-04-28 16:40 ——— d—–w C:\Program Files\Common Files\InstallShield
2008-04-28 16:37 ——— d—–w C:\Program Files\AMOS Mobile
2008-04-28 14:02 ——— d—–w C:\Documents and Settings\rogerca\Application Data\skypePM
2008-04-21 06:43 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-04-21 06:41 ——— d—–w C:\Program Files\Dell
2008-04-10 12:05 ——— d—–w C:\Program Files\LOGIHOLD
2008-04-07 07:39 ——— d—–w C:\Program Files\DB Commander 2000 PRO
2008-04-04 14:54 ——— d—–w C:\Program Files\AMOS
2008-04-04 12:54 ——— d—–w C:\Program Files\Hourcnt
2008-03-28 14:03 ——— d—–w C:\Program Files\Wfwin
2008-03-19 09:47 1,845,248 —-a-w C:\WINDOWS\system32\win32k.sys
2008-03-18 07:00 ——— d—–w C:\Program Files\Java
2008-03-13 07:00 ——— d—–w C:\Documents and Settings\All Users\Application Data\X-Setup Pro
2008-03-10 07:14 32 —-a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2008-03-10 07:13 ——— d—–w C:\Program Files\Skype
2008-03-10 07:13 ——— d—–w C:\Program Files\Common Files\Skype
2008-03-07 13:04 ——— d—–w C:\Program Files\Oracle
2008-03-06 09:54 ——— d—–w C:\Program Files\TechSmith
2008-03-06 09:54 ——— d—–w C:\Documents and Settings\All Users\Application Data\TechSmith
2008-03-06 09:53 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-03-01 13:06 826,368 —-a-w C:\WINDOWS\system32\wininet.dll
2008-02-28 07:27 ——— d—–w C:\Program Files\Seiko Instruments USA Inc
2008-02-20 06:51 282,624 —-a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 —-a-w C:\WINDOWS\system32\dnsrslvr.dll
2007-11-09 15:10 30,288 —-a-w C:\Program Files\mozilla firefox\plugins\cgpcfg.dll
2007-11-09 15:10 79,440 —-a-w C:\Program Files\mozilla firefox\plugins\CgpCore.dll
2007-11-09 15:10 75,344 —-a-w C:\Program Files\mozilla firefox\plugins\confmgr.dll
2007-11-09 15:10 140,880 —-a-w C:\Program Files\mozilla firefox\plugins\ctxmui.dll
2007-11-09 15:10 42,576 —-a-w C:\Program Files\mozilla firefox\plugins\icafile.dll
2007-11-09 15:10 50,768 —-a-w C:\Program Files\mozilla firefox\plugins\icalogon.dll
2007-11-09 15:10 34,384 —-a-w C:\Program Files\mozilla firefox\plugins\logging.dll
2007-06-21 17:39 685,640 —-a-w C:\Program Files\mozilla firefox\plugins\sslsdk_b.dll
2007-11-09 15:11 30,288 —-a-w C:\Program Files\mozilla firefox\plugins\TcpPServ.dll
.
((((((((((((((((((((((((((((( snapshot_2008-04-28_ 8.10.10.00 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-24 23:31:18 2,048 –s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-28 18:17:32 2,048 –s-a-w C:\WINDOWS\bootstat.dat
+ 2002-07-25 16:13:18 24,576 —-a-w C:\WINDOWS\Downloaded Program Files\dwusplay.dll
+ 2002-07-25 16:13:12 196,608 —-a-w C:\WINDOWS\Downloaded Program Files\dwusplay.exe
+ 2004-04-13 04:04:24 307,200 —-a-w C:\WINDOWS\Downloaded Program Files\isusweb.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 09:56 15360]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54 5674352]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-02-01 18:22 21898024]
"DBISQL9"="C:\Program Files\Sybase\SQL Anywhere 9\win32\dbisqlg.exe" [2008-01-17 21:38 144688]
"PlaxoUpdate"="C:\Program Files\Plaxo\2.13.1.3\PlaxoHelper.exe" [2007-12-11 18:21 227914]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2007-04-04 00:29 165784]
"GoToMeeting"="C:\Program Files\Citrix\GoToMeeting\198\g2mstart.exe" [2007-12-19 11:15 31816]
"H/PC Connection Agent"="C:\PROGRA~1\MI3AA1~1\wcescomm.exe" [2006-06-26 17:13 1207080]
"SybaseCentral43"="C:\Program Files\Sybase\Shared\Sybase Central 4.3\win32\scjview.exe" [2008-01-17 21:38 136496]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Norman ZANDA"="C:\program filesNorman\Npm\bin\ZLH.exe" [2007-08-09 14:40 183352]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 09:56 110592 C:\WINDOWS\system32\bthprops.cpl]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-22 15:09 63712]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 14:59 385024]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"Creative WebCam Tray"="C:\Program Files\Creative\Shared Files\CAMTRAY.EXE" [2003-10-13 03:04 184320]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-10-14 14:49 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-10-14 14:46 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-10-14 14:50 114688]
"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 17:37 2178832]
"LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 17:33 563984]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-04-17 12:41 196608]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-04-13 06:07 69632]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 09:56 15360]
C:\Documents and Settings\rogerca\Start Menu\Programs\Startup\
SmartCapture.lnk - C:\WINDOWS\Seiko\slpcap.exe [2006-07-12 03:29:00 123917]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2005-11-18 18:46:00 1724416]
SnagIt 8.lnk - C:\Program Files\TechSmith\SnagIt 8\SnagIt32.exe [2007-05-01 12:11:48 6395464]
StartKSA.lnk - C:\Program Files\Kockum Sonics\KSL450\Archive\080415-135649\StartKSA.cmd [2005-03-03 16:12:42 14]
VPN Client.lnk - C:\WINDOWS\Installer\{D25122BC-A60E-4663-B602-B01718F12044}\Icon3E5562ED7.ico [2008-02-18 09:49:44 6144]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2004-09-07 16:08 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Sybase\\SQL Anywhere 9\\win32\\dbisqlg.exe"=
"C:\\Program Files\\Sybase\\Shared\\Sybase Central 4.3\\win32\\scjview.exe"=
"C:\\Program Files\\Sybase\\ASA 8.0\\win32\\dbeng8.exe"=
"C:\\Program Files\\Sybase\\SQL Anywhere 9\\win32\\dbeng9.exe"=
"C:\\Program Files\\totalcmd\\TOTALCMD.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Nortel Networks\\Extranet.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\Program Files\\Star IPS\\Star.exe"=
"C:\\Program Files\\Xantic\\AMOS Mail\\winmss32.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1207:UDP"= 1207:UDP:Windows Media Format SDK (firefox.exe)
"1206:UDP"= 1206:UDP:Windows Media Format SDK (firefox.exe)
"1183:UDP"= 1183:UDP:Windows Media Format SDK (firefox.exe)
"1182:UDP"= 1182:UDP:Windows Media Format SDK (firefox.exe)
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R2 DbsRpcService;AMOS Mail Database;C:\Program Files\Xantic\AMOS Mail\dbssvc.exe [2006-05-11 17:31]
R2 Ndiskio;Ndiskio;C:\program filesNorman\Nse\bin\NDISKIO.SYS [2007-01-02 10:55]
R2 SQLWriter;SQL Server VSS Writer;"c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [2007-02-10 05:29]
R3 Eacfilt;Eacfilt Miniport;C:\WINDOWS\system32\DRIVERS\eacfilt.sys [2006-05-09 18:47]
R3 IPSECSHM;Nortel IPSECSHM Adapter;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys [2006-05-09 18:46]
R3 NvcMFlt;NvcMFlt;C:\WINDOWS\system32\DRIVERS\nvcw32mf.sys [2008-02-11 15:56]
R3 nvcoas;Norman Virus Control on-access component;C:\program filesNorman\Nvc\bin\nvcoas.exe [2007-12-12 12:45]
R3 NVCScheduler;Norman Virus Control Scheduler;C:\program filesNorman\Nvc\BIN\NVCSCHED.EXE [2007-05-23 13:23]
S3 ASANYm_mobil;MobiLink Synchronization - mobil;C:\Program Files\Sybase\SQL Anywhere 9\win32\dbmlsrv9.exe [2008-01-17 21:38]
S3 D100IB;D100IB;C:\WINDOWS\system32\DRIVERS\D100IB5.SYS [2001-08-17 12:12]
S3 Dell1110_FUService;Dell 1110 Status Monitor Service;"C:\Program Files\DELL\Dell Laser Printer 1110\LocalSM\ssmsrvc /Service []
S3 FTCSER2K;FTDI USB Dual Serial Port Driver;C:\WINDOWS\system32\drivers\ftcser2k.sys [2004-03-23 18:36]
S3 FTCUSB;FTCUSB.SYS FT2232C IO test driver;C:\WINDOWS\system32\drivers\ftcusb.sys [2004-05-05 12:10]
S3 IPSECEXT;Nortel Extranet Access Protocol;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys [2006-05-09 18:46]
S3 mos24ser;MosChip High-Speed USB MultiSerial Device Service;C:\WINDOWS\system32\DRIVERS\mos24ser.sys [2006-10-11 14:26]
S3 NetWlan5;Symbol Based 802.11b Wireless LAN Card Driver;C:\WINDOWS\system32\DRIVERS\NetWlan5.sys [2004-08-04 07:31]
S3 OracleOraHome92ClientCache;OracleOraHome92ClientCache;C:\oracle\ora92\BIN\ONRSD.EXE [2002-04-26 20:34]
.
Contents of the 'Scheduled Tasks' folder
"2008-04-03 12:33:08 C:\WINDOWS\Tasks\CKUtil.job"
Best Regards
/Triton