ComboFix 09-08-10.06 - Michael 08/14/2009 9:58.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.581 [GMT -4:00]
Running from: c:\documents and settings\Michael\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\Michael\LOCALS~1\Temp\521121kou.dll
c:\documents and settings\Michael\Local Settings\Temp\521121kou.dll
c:\windows\Installer\1184b65.msi
c:\windows\Installer\1184b6c.msi
c:\windows\Installer\1184b73.msi
c:\windows\Installer\1184b7a.msi
c:\windows\Installer\1184b7e.msi
c:\windows\Installer\28faf4c.msi
c:\windows\Installer\4660b12.msi
c:\windows\Installer\69500f3.msp
c:\windows\Installer\69500f4.msp
c:\windows\Installer\69500f5.msp
c:\windows\Installer\69500f6.msp
c:\windows\Installer\69500f7.msp
c:\windows\Installer\69500f8.msp
c:\windows\Installer\69500f9.msp
c:\windows\Installer\69500fa.msp
c:\windows\Installer\69500fb.msp
c:\windows\Installer\69768ef.msp
c:\windows\Installer\69768f0.msp
c:\windows\Installer\69768f1.msp
c:\windows\Installer\69768f2.msp
c:\windows\Installer\69768f3.msp
c:\windows\Installer\69768f4.msp
c:\windows\Installer\69768f5.msp
c:\windows\Installer\69768f6.msp
c:\windows\Installer\69768f7.msp
c:\windows\Installer\69768f8.msp
c:\windows\Installer\cd6af0.msi
c:\windows\system32\proquota.exe . . . is missing!!
.
((((((((((((((((((((((((( Files Created from 2009-07-14 to 2009-08-14 )))))))))))))))))))))))))))))))
.
2009-08-12 20:45 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2009-08-12 03:47 . 2009-08-12 03:47 -------- d-----w- c:\program files\PowerISO
2009-08-11 00:29 . 2009-08-11 00:29 -------- d-----w- c:\program files\Koei
2009-08-10 12:40 . 2009-08-10 12:40 -------- d-----w- c:\program files\Trend Micro
2009-08-08 13:19 . 2009-08-08 13:20 -------- d-----w- C:\dosgames
2009-08-08 13:18 . 2009-08-08 13:18 -------- d-----w- c:\documents and settings\Michael\Local Settings\Application Data\DOSBox
2009-08-08 13:18 . 2009-08-09 17:20 -------- d-----w- c:\program files\DOSBox-0.73
2009-08-05 09:01 . 2009-08-05 09:01 204800 -c----w- c:\windows\system32\dllcache\mswebdvd.dll
2009-08-01 06:24 . 2009-08-01 06:47 -------- d-----w- c:\program files\bfsyox
2009-07-29 13:44 . 2009-07-29 13:44 -------- d-----w- c:\program files\DAEMON Tools
2009-07-29 13:28 . 2009-07-29 18:43 -------- d-----w- c:\documents and settings\Michael\Local Settings\Application Data\Oblivion
2009-07-29 10:57 . 2009-07-29 14:21 -------- d-----w- c:\program files\Bethesda Softworks
2009-07-28 00:25 . 2009-07-28 00:25 -------- d-----w- c:\program files\LibUSB-Win32-0.1.10.1
2009-07-27 02:43 . 2009-07-27 02:43 58908 ----a-w- c:\windows\system32\drivers\scdemu.sys
2009-07-17 19:01 . 2009-07-17 19:01 58880 -c----w- c:\windows\system32\dllcache\atl.dll
2009-07-17 04:54 . 2009-07-17 04:55 -------- d-----r- c:\program files\Skype
2009-07-16 16:10 . 2009-07-16 16:10 -------- d-----w- C:\AeriaGames
2009-07-16 08:59 . 2009-08-03 17:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-16 08:59 . 2009-08-10 12:51 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-16 08:59 . 2009-08-03 17:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-16 01:40 . 2009-07-16 01:40 -------- d-----w- c:\program files\Creative Labs
2009-07-16 01:40 . 1999-07-06 18:13 40960 ----a-w- c:\windows\system32\eax.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-14 12:56 . 2009-06-10 21:33 -------- d-----w- c:\program files\DNA
2009-08-14 12:55 . 2009-07-13 02:27 -------- d-----w- c:\program files\Pando Networks
2009-08-14 04:08 . 2009-04-09 22:56 -------- d-----w- c:\docume~1\Michael\APPLIC~1\uTorrent
2009-08-14 00:16 . 2009-04-13 21:21 -------- d-----w- c:\program files\SpeedFan
2009-08-13 15:35 . 2009-06-25 01:25 -------- d-----w- c:\program files\Voyage Century Online
2009-08-10 12:17 . 2009-04-08 19:19 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-08-09 15:13 . 2009-06-20 15:36 -------- d-----w- c:\docume~1\Michael\APPLIC~1\Skype
2009-08-09 15:12 . 2009-06-20 15:37 -------- d-----w- c:\docume~1\Michael\APPLIC~1\skypePM
2009-08-05 09:01 . 2004-08-04 04:56 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-01 04:07 . 2009-06-06 01:24 -------- d-----w- c:\program files\Microsoft Silverlight
2009-07-29 14:47 . 2009-04-08 21:10 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-29 13:44 . 2009-07-14 01:17 -------- d-----w- c:\program files\DAEMON Tools Lite
2009-07-25 05:06 . 2009-07-14 01:10 -------- d-----w- c:\program files\zMUD
2009-07-17 19:01 . 2004-08-04 04:56 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-17 04:54 . 2009-06-20 15:36 -------- d-----w- c:\program files\Common Files\Skype
2009-07-17 04:54 . 2009-06-20 15:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-07-16 04:03 . 2009-06-18 07:59 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-07-14 05:57 . 2009-07-14 05:57 -------- d-----w- c:\docume~1\Michael\APPLIC~1\Xfire
2009-07-14 05:57 . 2009-07-14 05:57 -------- d-----w- c:\program files\Xfire
2009-07-14 03:43 . 2004-08-04 04:56 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-14 01:18 . 2009-07-11 22:28 -------- d-----w- c:\docume~1\Michael\APPLIC~1\DAEMON Tools Lite
2009-07-14 01:17 . 2009-07-14 01:17 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2009-07-14 01:17 . 2009-07-14 01:17 -------- d-----w- c:\program files\DAEMON Tools Toolbar
2009-07-14 01:14 . 2009-04-09 23:12 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-07-14 00:25 . 2009-06-10 19:19 -------- d-----w- c:\program files\DOOM Collector's Edition
2009-07-14 00:25 . 2009-07-14 00:25 -------- d-----w- c:\program files\Stardock
2009-07-14 00:24 . 2009-07-14 00:24 -------- d-----w- c:\program files\LucasArts
2009-07-14 00:23 . 2009-07-14 00:23 -------- d-----w- c:\program files\DAEMON Tools Pro
2009-07-13 23:22 . 2009-06-20 18:14 0 ----a-w- c:\windows\system32\drivers\lvuvc.hs
2009-07-13 23:22 . 2009-06-20 18:12 0 ----a-w- c:\windows\system32\drivers\logiflt.iad
2009-07-13 23:16 . 2009-06-20 18:14 -------- d-----w- c:\program files\Common Files\logishrd
2009-07-13 23:15 . 2009-07-13 23:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Logitech
2009-07-13 23:15 . 2009-07-13 23:15 -------- d-----w- c:\program files\Logitech
2009-07-13 23:10 . 2009-07-13 23:10 0 ----a-w- c:\documents and settings\LocalService\sluBC.tmp
2009-07-13 23:10 . 2009-07-13 23:10 0 ----a-w- c:\documents and settings\LocalService\sluBB.tmp
2009-07-13 23:10 . 2009-07-13 23:10 0 ----a-w- c:\documents and settings\LocalService\sluBA.tmp
2009-07-13 19:44 . 2009-07-13 19:44 -------- d-----w- c:\program files\MSBuild
2009-07-13 19:44 . 2009-07-13 19:44 -------- d-----w- c:\program files\Reference Assemblies
2009-07-11 23:39 . 2009-07-11 23:39 -------- d-----w- c:\program files\Eidos Interactive
2009-07-11 21:45 . 2009-06-09 00:29 -------- d-----w- c:\program files\Steam
2009-07-10 13:45 . 2009-04-08 19:39 335752 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-07-02 15:43 . 2009-04-08 19:39 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-07-02 15:43 . 2009-04-08 19:39 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-29 16:12 . 2004-08-04 04:56 827392 ----a-w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2004-08-04 04:56 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2004-08-04 04:56 17408 ----a-w- c:\windows\system32\corpol.dll
2009-06-24 19:51 . 2009-06-24 19:51 -------- d-----w- c:\program files\CCleaner
2009-06-24 18:50 . 2009-04-10 05:35 -------- d-----w- c:\program files\ATI Technologies
2009-06-24 18:30 . 2009-06-24 18:30 -------- d-----w- c:\program files\ATI
2009-06-22 20:54 . 2009-06-22 20:54 0 ----a-w- c:\windows\nsreg.dat
2009-06-22 10:42 . 2009-06-22 10:33 -------- d-----w- c:\docume~1\Michael\APPLIC~1\TeamViewer
2009-06-22 10:32 . 2009-06-22 10:32 -------- d-----w- c:\program files\TeamViewer
2009-06-20 15:37 . 2009-06-20 15:37 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-06-20 11:40 . 2009-06-20 11:40 -------- d-----w- c:\docume~1\Michael\APPLIC~1\Malwarebytes
2009-06-20 11:40 . 2009-06-20 11:40 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-19 00:05 . 2009-06-06 16:52 -------- d-----w- c:\program files\Electronic Arts
2009-06-18 23:56 . 2009-06-18 23:56 -------- d-----w- c:\program files\Microsoft WSE
2009-06-18 13:01 . 2009-06-18 13:01 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters
2009-06-18 08:00 . 2009-06-18 07:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-06-18 07:59 . 2009-06-18 07:58 -------- d-----w- c:\program files\Yahoo!
2009-06-18 07:59 . 2009-06-18 07:59 -------- d-----w- c:\docume~1\Michael\APPLIC~1\Yahoo!
2009-06-17 20:57 . 2009-06-17 20:57 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Pro
2009-06-17 20:57 . 2009-06-17 20:56 -------- d-----w- c:\docume~1\Michael\APPLIC~1\DAEMON Tools Pro
2009-06-17 20:38 . 2009-06-17 20:38 -------- d-----w- c:\program files\EA GAMES
2009-06-17 20:35 . 2009-06-17 20:35 -------- d-----w- c:\program files\MagicDisc
2009-06-17 20:31 . 2009-06-17 20:31 -------- d-----w- c:\program files\MagicISO
2009-06-16 14:36 . 2004-08-04 04:56 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2002-08-29 12:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-12 12:31 . 2004-08-04 04:56 76288 ----a-w- c:\windows\system32\telnet.exe
2009-06-11 22:28 . 2009-06-11 22:28 41808 ----a-w- c:\windows\system32\xfcodec.dll
2009-06-10 14:13 . 2004-08-04 04:56 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 13:19 . 2009-04-07 13:03 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-06-10 06:14 . 2004-08-04 04:56 132096 ----a-w- c:\windows\system32\wkssvc.dll
2009-06-09 11:18 . 2009-06-09 11:18 616448 --sha-w- c:\documents and settings\LocalService\jk5i7wqy.TMP
2009-06-06 17:06 . 2009-06-06 17:06 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-06-06 17:05 . 2009-06-06 17:05 1216 ----a-w- c:\windows\system32\ealregsnapshot1.reg
2009-06-06 01:24 . 2009-04-10 05:51 14160 ----a-w- c:\documents and settings\Michael\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-06 00:21 . 2009-04-08 19:39 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-06-03 19:09 . 2004-08-04 04:56 1291264 ----a-w- c:\windows\system32\quartz.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-08 39408]
"EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2009-04-29 3338240]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2007-08-16 167368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-07-02 1948440]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2005-04-15 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-07-02 15:43 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\LucasArts\\Star Wars Galactic Battlegrounds Saga\\Game\\battlegrounds_x1.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\left 4 dead\\left4dead.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Voyage Century Online\\voyagecentury.exe"=
"c:\\nDoors\\Atlantica\\AtlanticaRun.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 nvcchflt;NVIDIA Disk Cache Filter Driver;c:\windows\system32\drivers\nvcchflt.sys [2/11/2005 6:11 PM 16640]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [4/8/2009 3:39 PM 335752]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [4/8/2009 3:39 PM 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [4/8/2009 3:39 PM 907032]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [4/8/2009 3:39 PM 298776]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [6/5/2009 9:23 PM 55152]
R2 libusbd;LibUsb-Win32 - Daemon, Version 0.1.10.1;system32\libusbd-nt.exe --> system32\libusbd-nt.exe [?]
R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);c:\windows\system32\drivers\A3AB.sys [5/24/2007 6:15 PM 547744]
R3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\system32\drivers\AtiHdmi.sys [7/20/2007 6:40 PM 84992]
R3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;c:\windows\system32\drivers\libusb0.sys [6/18/2009 9:07 AM 33792]
S3 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [2/6/2009 6:08 PM 533360]
.
Contents of the 'Scheduled Tasks' folder
2009-08-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
.
.
------- Supplementary Scan -------
.
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-08-14 10:09
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1202660629-776561741-682003330-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-1202660629-776561741-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\Koei\ NW×_1*1*]
"Order"=hex:08,00,00,00,02,00,00,00,0c,03,00,00,01,00,00,00,06,00,00,00,82,00,
00,00,00,00,00,00,74,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,62,00,32,\
[HKEY_USERS\S-1-5-21-1202660629-776561741-682003330-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:04,d3,2c,ff,14,fe,5f,0e,6f,d0,06,89,32,ea,ac,06,13,cb,59,0a,7a,bb,2a,
74,9d,e8,64,12,e9,a4,8c,f7,c2,64,93,63,20,69,24,4f,4a,a7,55,e3,af,a2,56,1d,\
"??"=hex:69,6f,5c,46,6a,89,f9,ee,2d,48,e0,10,87,42,1e,12
[HKEY_USERS\S-1-5-21-1202660629-776561741-682003330-1004\Software\SecuROM\License information*]
"datasecu"=hex:3d,21,df,16,33,e4,74,6a,e2,ad,35,67,19,63,00,d3,31,8d,3e,94,96,
3f,df,0d,48,ee,66,03,3e,36,92,f4,87,a2,e1,a5,d5,de,64,9b,fe,16,b8,19,fa,78,\
"rkeysecu"=hex:3e,80,9e,c4,40,b4,90,83,87,8e,33,49,64,ac,f8,d9
[HKEY_LOCAL_MACHINE\software\Classes\L*i*n*k*S*a*n*1*1*R*e*s*.*’A*’v*’`’P**[*’V*’! ’ \CLSID]
@="{8C306064-52F3-4724-A485-3C44005E7ACA}"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(804)
c:\windows\System32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(2044)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\windows\system32\libusbd-nt.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
.
**************************************************************************
.
Completion time: 2009-08-14 10:11 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-14 14:11
Pre-Run: 71,444,819,968 bytes free
Post-Run: 72,648,830,976 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
273 --- E O F --- 2009-08-12 21:24