ComboFix 09-09-09.01 - Nadine 09/09/2009 16:52.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3061.2609 [GMT -4:00]
Running from: c:\documents and settings\Nadine\Desktop\ComboFix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Outdated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Christine\Application Data\alot
c:\documents and settings\Christine\Application Data\none
c:\documents and settings\Nadine\Application Data\alot
c:\documents and settings\Nadine\Application Data\alot\BrowserSearch\BrowserSearch.xml
c:\documents and settings\Nadine\Application Data\alot\BrowserSearch\BrowserSearch.xml.backup
c:\documents and settings\Nadine\Application Data\alot\Button_0\Button_0.xml
c:\documents and settings\Nadine\Application Data\alot\Button_0\Button_0.xml.backup
c:\documents and settings\Nadine\Application Data\alot\Button_1\Button_1.xml
c:\documents and settings\Nadine\Application Data\alot\Button_1\Button_1.xml.backup
c:\documents and settings\Nadine\Application Data\alot\Button_2\Button_2.xml
c:\documents and settings\Nadine\Application Data\alot\Button_2\Button_2.xml.backup
c:\documents and settings\Nadine\Application Data\alot\Button_3\Button_3.xml
c:\documents and settings\Nadine\Application Data\alot\Button_3\Button_3.xml.backup
c:\documents and settings\Nadine\Application Data\alot\Button_4\Button_4.xml
c:\documents and settings\Nadine\Application Data\alot\Button_4\Button_4.xml.backup
c:\documents and settings\Nadine\Application Data\alot\Button_5\Button_5.xml
c:\documents and settings\Nadine\Application Data\alot\Button_5\Button_5.xml.backup
c:\documents and settings\Nadine\Application Data\alot\Button_6\Button_6.xml
c:\documents and settings\Nadine\Application Data\alot\Button_6\Button_6.xml.backup
c:\documents and settings\Nadine\Application Data\alot\Button_7\Button_7.xml
c:\documents and settings\Nadine\Application Data\alot\Button_7\Button_7.xml.backup
c:\documents and settings\Nadine\Application Data\alot\Button_8\Button_8.xml
c:\documents and settings\Nadine\Application Data\alot\Button_8\Button_8.xml.backup
c:\documents and settings\Nadine\Application Data\alot\Button_9\Button_9.xml
c:\documents and settings\Nadine\Application Data\alot\Button_9\Button_9.xml.backup
c:\documents and settings\Nadine\Application Data\alot\configurator\configurator.xml
c:\documents and settings\Nadine\Application Data\alot\configurator\configurator.xml.backup
c:\documents and settings\Nadine\Application Data\alot\contextMenu\contextMenu.xml
c:\documents and settings\Nadine\Application Data\alot\contextMenu\contextMenu.xml.backup
c:\documents and settings\Nadine\Application Data\alot\ErrorSearch\ErrorSearch.xml
c:\documents and settings\Nadine\Application Data\alot\ErrorSearch\ErrorSearch.xml.backup
c:\documents and settings\Nadine\Application Data\alot\postInstallLayout\postInstallLayout.xml
c:\documents and settings\Nadine\Application Data\alot\postInstallLayout\postInstallLayout.xml.backup
c:\documents and settings\Nadine\Application Data\alot\preferencesLayout\preferencesLayout.xml
c:\documents and settings\Nadine\Application Data\alot\preferencesLayout\preferencesLayout.xml.backup
c:\documents and settings\Nadine\Application Data\alot\products\products.xml
c:\documents and settings\Nadine\Application Data\alot\products\products.xml.backup
c:\documents and settings\Nadine\Application Data\alot\Resources\BrowserSearch\alot_search_defend.html
c:\documents and settings\Nadine\Application Data\alot\Resources\BrowserSearch\images\favicon.ico
c:\documents and settings\Nadine\Application Data\alot\Resources\Button_0\images\alot_logo_button.bmp
c:\documents and settings\Nadine\Application Data\alot\Resources\Button_0\images\alot_logo_button.png
c:\documents and settings\Nadine\Application Data\alot\Resources\Button_1\images\alot_image_search.bmp
c:\documents and settings\Nadine\Application Data\alot\Resources\Button_1\images\alot_image_search.png
c:\documents and settings\Nadine\Application Data\alot\Resources\Button_1\images\alot_news_search.bmp
c:\documents and settings\Nadine\Application Data\alot\Resources\Button_1\images\alot_news_search.png
c:\documents and settings\Nadine\Application Data\alot\Resources\Button_1\images\alot_search_button.bmp
c:\documents and settings\Nadine\Application Data\alot\Resources\Button_1\images\alot_search_button.png
c:\documents and settings\Nadine\Application Data\alot\Resources\Button_1\images\alot_shop_search.bmp
c:\documents and settings\Nadine\Application Data\alot\Resources\Button_1\images\alot_shop_search.png
c:\documents and settings\Nadine\Application Data\alot\Resources\Button_1\images\alot_videos_search.bmp
c:\documents and settings\Nadine\Application Data\alot\Resources\Button_1\images\alot_videos_search.png
c:\documents and settings\Nadine\Application Data\alot\Resources\Button_1\images\alot_web_search.bmp
c:\documents and settings\Nadine\Application Data\alot\Resources\Button_1\images\alot_web_search.png
c:\documents and settings\Nadine\Application Data\alot\Resources\Button_2\images\default_1030_alot_cel_search.bmp
c:\documents and settings\Nadine\Application Data\alot\Resources\Button_2\images\default_1030_alot_cel_search.png
c:\documents and settings\Nadine\Application Data\alot\Resources\Button_3\images\default_2334_default_2301_hulu.bmp
c:\documents and settings\Nadine\Application Data\alot\Resources\Button_3\images\default_2334_default_2301_hulu.png
c:\documents and settings\Nadine\Application Data\alot\Resources\Button_4\images\default_1153_alot_cel_entcenter.bmp
c:\documents and settings\Nadine\Application Data\alot\Resources\Button_4\images\default_1153_alot_cel_entcenter.png
c:\documents and settings\Nadine\Application Data\alot\Resources\Button_5\images\default_1154_alot_cel_photos.bmp
c:\documents and settings\Nadine\Application Data\alot\Resources\Button_5\images\default_1154_alot_cel_photos.png
c:\documents and settings\Nadine\Application Data\alot\Resources\Button_6\images\default_1151_alot_mrkt_starpulse.bmp
c:\documents and settings\Nadine\Application Data\alot\Resources\Button_6\images\default_1151_alot_mrkt_starpulse.png
c:\documents and settings\Nadine\Application Data\alot\Resources\Button_7\images\2428_icon.png
c:\documents and settings\Nadine\Application Data\alot\Resources\Button_8\images\2554_icon.png
c:\documents and settings\Nadine\Application Data\alot\Resources\Button_9\images\default_1795_default_1795_alot_configure.bmp
c:\documents and settings\Nadine\Application Data\alot\Resources\Button_9\images\default_1795_default_1795_alot_configure.png
c:\documents and settings\Nadine\Application Data\alot\Resources\contextMenu\images\alot_icon.bmp
c:\documents and settings\Nadine\Application Data\alot\Resources\contextMenu\images\alot_icon.png
c:\documents and settings\Nadine\Application Data\alot\Resources\contextMenu\images\alot_logo_button.bmp
c:\documents and settings\Nadine\Application Data\alot\Resources\contextMenu\images\alot_logo_button.png
c:\documents and settings\Nadine\Application Data\alot\Resources\Shared\images\alot_brand.png
c:\documents and settings\Nadine\Application Data\alot\Resources\Shared\images\alot_configure.bmp
c:\documents and settings\Nadine\Application Data\alot\Resources\Shared\images\alot_configure.png
c:\documents and settings\Nadine\Application Data\alot\Resources\Shared\images\alot_splitter.png
c:\documents and settings\Nadine\Application Data\alot\Resources\Shared\images\discover.png
c:\documents and settings\Nadine\Application Data\alot\Resources\Shared\images\intro_popup.png
c:\documents and settings\Nadine\Application Data\alot\TimerManager\TimerManager.xml
c:\documents and settings\Nadine\Application Data\alot\TimerManager\TimerManager.xml.backup
c:\documents and settings\Nadine\Application Data\alot\toolbar.xml
c:\documents and settings\Nadine\Application Data\alot\toolbar.xml.backup
c:\documents and settings\Nadine\Application Data\alot\toolbarContextMenu\toolbarContextMenu.xml
c:\documents and settings\Nadine\Application Data\alot\toolbarContextMenu\toolbarContextMenu.xml.backup
c:\documents and settings\Nadine\Application Data\alot\ToolbarSearch\ToolbarSearch.xml
c:\documents and settings\Nadine\Application Data\alot\ToolbarSearch\ToolbarSearch.xml.backup
c:\documents and settings\Nadine\Application Data\alot\Updater\Updater.xml
c:\documents and settings\Nadine\Application Data\alot\Updater\Updater.xml.backup
c:\documents and settings\Nadine\Application Data\none
c:\program files\alot
c:\program files\alot\alotUninst.exe
c:\program files\alot\bin\alot.dll
c:\program files\alot\bin\BHO\alotBHO.dll
c:\windows\COUPON~1.OCX
c:\windows\CouponPrinter.ocx
c:\windows\system32\drivers\hjgruiwswlpuny.sys
c:\windows\system32\drivers\kbiwkmxtxoxyed.sys
c:\windows\system32\hjgruidsvnthvo.dll
c:\windows\system32\hjgruieohfogbr.dat
c:\windows\system32\hjgruilpwcoppt.dat
c:\windows\system32\hjgruiulndjglk.dll
c:\windows\system32\kbiwkmdaevqstp.dll
c:\windows\system32\kbiwkmdkwwhhxk.dat
c:\windows\system32\kbiwkmehkvaaxr.dat
c:\windows\system32\kbiwkmjvynswvk.dll
c:\windows\system32\kbiwkmkyxexmej.dll
c:\windows\Tasks\At1.job
c:\windows\Tasks\At10.job
c:\windows\Tasks\At11.job
c:\windows\Tasks\At12.job
c:\windows\Tasks\At13.job
c:\windows\Tasks\At14.job
c:\windows\Tasks\At15.job
c:\windows\Tasks\At16.job
c:\windows\Tasks\At17.job
c:\windows\Tasks\At18.job
c:\windows\Tasks\At19.job
c:\windows\Tasks\At2.job
c:\windows\Tasks\At20.job
c:\windows\Tasks\At21.job
c:\windows\Tasks\At22.job
c:\windows\Tasks\At23.job
c:\windows\Tasks\At24.job
c:\windows\Tasks\At3.job
c:\windows\Tasks\At4.job
c:\windows\Tasks\At5.job
c:\windows\Tasks\At6.job
c:\windows\Tasks\At7.job
c:\windows\Tasks\At8.job
c:\windows\Tasks\At9.job
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_hjgruiddkjejwy
-------\Legacy_hjgruiddkjejwy
-------\Service_kbiwkmmwxqirfm
-------\Legacy_kbiwkmmwxqirfm
((((((((((((((((((((((((( Files Created from 2009-08-09 to 2009-09-09 )))))))))))))))))))))))))))))))
.
2009-09-08 20:49 . 2009-09-08 20:49 -------- d-----w- c:\documents and settings\Nadine\Application Data\Malwarebytes
2009-09-08 20:49 . 2009-08-03 17:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-08 20:49 . 2009-09-08 20:49 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-08 20:49 . 2009-09-08 20:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-09-08 20:49 . 2009-08-03 17:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-08 19:09 . 2009-09-08 19:09 -------- d-----w- C:\Rooter$
2009-09-07 00:05 . 2009-09-07 00:05 2198 ----a-w- C:\a3VSw.bat
2009-09-06 20:46 . 2009-09-06 20:46 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-09-04 20:16 . 2009-09-04 20:16 -------- d-sh--w- c:\documents and settings\Christine\PrivacIE
2009-09-04 20:15 . 2009-09-04 20:15 -------- d-sh--w- c:\documents and settings\Christine\IETldCache
2009-09-04 15:37 . 2009-09-04 15:37 -------- d-sh--w- c:\documents and settings\Nadine\PrivacIE
2009-09-04 15:36 . 2009-09-04 15:36 -------- d-sh--w- c:\documents and settings\Nadine\IETldCache
2009-09-04 15:33 . 2009-09-04 15:33 -------- d-sh--w- c:\documents and settings\Melissa\IETldCache
2009-09-04 15:32 . 2009-09-04 15:32 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-09-04 15:28 . 2009-08-07 08:48 100352 -c----w- c:\windows\system32\dllcache\iecompat.dll
2009-09-04 15:28 . 2009-09-04 15:28 -------- d-----w- c:\windows\ie8updates
2009-09-04 15:28 . 2009-07-19 22:48 11067392 -c----w- c:\windows\system32\dllcache\ieframe.dll
2009-09-04 15:28 . 2009-07-03 17:09 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-09-04 15:28 . 2009-07-03 17:09 594432 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2009-09-04 15:28 . 2009-07-03 17:09 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-09-04 15:28 . 2009-07-03 17:09 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll
2009-09-04 15:28 . 2009-07-03 17:09 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-09-04 15:27 . 2009-09-04 15:27 -------- dc-h--w- c:\windows\ie8
2009-09-04 04:10 . 2009-09-04 04:10 -------- d-----w- c:\program files\Common Files\TSCUninstall
2009-09-04 04:09 . 2009-09-08 21:11 -------- d-----w- c:\program files\TSC
2009-08-31 15:11 . 2009-08-31 15:11 -------- d-----w- c:\program files\Windows Media Connect 2
2009-08-31 15:10 . 2009-08-31 15:10 -------- d-----w- c:\windows\system32\drivers\UMDF
2009-08-27 05:58 . 2009-08-27 05:58 -------- d-----w- c:\documents and settings\Nadine\Application Data\MSNInstaller
2009-08-26 08:41 . 2009-08-26 08:41 -------- d-----w- c:\windows\Cache
2009-08-26 08:41 . 2009-08-26 08:41 -------- d-----w- c:\program files\Coupons
2009-08-12 18:23 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-04 04:17 . 2009-06-20 20:53 2338 ----a-w- c:\documents and settings\Nadine\Application Data\wklnhst.dat
2009-08-09 20:09 . 2009-02-13 11:11 34776 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-05 09:01 . 2008-04-25 16:16 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-02 21:18 . 2009-02-13 11:14 -------- d-----w- c:\program files\Microsoft Silverlight
2009-07-29 16:58 . 2009-02-13 11:10 -------- d-----w- c:\program files\Dell DataSafe Online
2009-07-28 17:01 . 2009-07-28 17:01 154 ----a-w- c:\documents and settings\Christine\Application Data\wklnhst.dat
2009-07-28 16:59 . 2009-07-28 16:59 -------- d-----w- c:\documents and settings\Christine\Application Data\Template
2009-07-17 19:01 . 2008-04-25 16:16 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-14 03:43 . 2008-04-25 16:16 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-03 17:09 . 2008-04-25 16:16 915456 ----a-w- c:\windows\system32\wininet.dll
2009-06-25 08:25 . 2008-04-25 16:16 54272 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2008-04-25 16:16 56832 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2008-04-25 16:16 147456 ----a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2008-04-25 16:16 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:25 . 2008-04-25 16:16 730112 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2008-04-25 16:16 301568 ----a-w- c:\windows\system32\kerberos.dll
2009-06-24 11:18 . 2008-04-25 16:16 92928 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-18 07:09 . 2009-06-18 07:09 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-06-16 14:36 . 2008-04-25 16:16 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2008-04-25 16:16 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-12 12:31 . 2008-04-25 16:16 80896 ----a-w- c:\windows\system32\tlntsess.exe
2009-06-12 12:31 . 2008-04-25 16:16 76288 ----a-w- c:\windows\system32\telnet.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2008-12-03 3882312]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-07-17 142104]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-07-17 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-07-17 138008]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-02 582992]
"Dell DataSafe Online"="c:\program files\Dell DataSafe Online\DataSafeOnline.exe" [2009-07-07 1779952]
"dldtmon.exe"="c:\program files\Dell V305\dldtmon.exe" [2008-06-24 668912]
"dldtamon"="c:\program files\Dell V305\dldtamon.exe" [2008-06-24 16624]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-10-04 206064]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2007-07-17 16132608]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2009-02-13 11:10 10536 ----a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\WINDOWS\\system32\\dldtcoms.exe"=
"c:\\Program Files\\Dell V305\\dldtmon.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\dldtpswx.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\dldttime.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\dldtjswx.exe"=
R2 dldt_device;dldt_device;c:\windows\system32\dldtcoms.exe -service --> c:\windows\system32\dldtcoms.exe -service [?]
S2 dldtCATSCustConnectService;dldtCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\dldtserv.exe [2/25/2008 12:38 PM 99568]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-07-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-02-13 19:32]
2009-09-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-02-13 19:32]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.aol.com/.
- - - - ORPHANS REMOVED - - - -
AddRemove-alotToolbar - c:\program files\alot\alotUninst.exe
AddRemove-TSC - c:\program files\TSC\tsc.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-09-09 16:59
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(724)
c:\program files\Citrix\GoToAssist\514\G2AWinLogon.dll
.
Completion time: 2009-09-09 16:59
ComboFix-quarantined-files.txt 2009-09-09 20:59
Pre-Run: 307,913,347,072 bytes free
Post-Run: 308,686,225,408 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
292 --- E O F --- 2009-09-08 21:18