this is abbreviated combofix log
ComboFix 09-09-13.04 - Owner 13/09/2009 20:11.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.3070.2338 [GMT 1:00]
Running from: c:\documents and settings\Owner\Desktop\Combo-Fix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Custom Settings\TaskBarCmd v1.1.exe
c:\documents and settings\Owner\Application Data\drivers\111wfs1intwq.sys
c:\documents and settings\Owner\Application Data\Drivers\11s11ro1s1a2.sys
c:\documents and settings\Owner\Application Data\drivers\downld
c:\documents and settings\Owner\Application Data\drivers\downld\1004140.exe
c:\documents and settings\Owner\Application Data\drivers\downld\1005218.exe
---
THOUSANDS OF THESE
---
c:\documents and settings\Owner\Application Data\drivers\downld\980759921.exe
c:\documents and settings\Owner\Application Data\drivers\downld\980761046.exe
c:\documents and settings\Owner\Application Data\drivers\downld\980761531.exe
c:\documents and settings\Owner\Application Data\drivers\downld\980770734.exe
c:\documents and settings\Owner\Application Data\drivers\downld\980771562.exe
c:\documents and settings\Owner\Application Data\drivers\downld\980780906.exe
c:\documents and settings\Owner\Application Data\drivers\downld\980781812.exe
c:\documents and settings\Owner\Application Data\drivers\downld\980782171.exe
c:\documents and settings\Owner\Application Data\drivers\downld\980815921.exe
c:\documents and settings\Owner\Application Data\drivers\downld\980837828.exe
c:\documents and settings\Owner\Application Data\drivers\downld\981006906.exe
c:\documents and settings\Owner\Application Data\drivers\downld\981007140.exe
c:\documents and settings\Owner\Application Data\drivers\downld\981007156.exe
c:\documents and settings\Owner\Application Data\drivers\downld\981093625.exe
c:\documents and settings\Owner\Application Data\drivers\downld\981094078.exe
c:\documents and settings\Owner\Application Data\drivers\downld\981094109.exe
c:\documents and settings\Owner\Application Data\drivers\downld\981094437.exe
c:\documents and settings\Owner\Application Data\drivers\downld\981095250.exe
c:\documents and settings\Owner\Application Data\drivers\downld\985953.exe
c:\documents and settings\Owner\Application Data\drivers\downld\986359.exe
c:\documents and settings\Owner\Application Data\drivers\downld\986375.exe
c:\documents and settings\Owner\Application Data\drivers\downld\989343.exe
c:\documents and settings\Owner\Application Data\drivers\downld\990546.exe
c:\documents and settings\Owner\Application Data\drivers\downld\991015.exe
c:\documents and settings\Owner\Application Data\drivers\downld\99253859.exe
c:\documents and settings\Owner\Application Data\drivers\downld\99276000.exe
c:\documents and settings\Owner\Application Data\drivers\downld\99279671.exe
c:\documents and settings\Owner\Application Data\drivers\downld\99387031.exe
c:\documents and settings\Owner\Application Data\drivers\downld\99387703.exe
c:\documents and settings\Owner\Application Data\drivers\downld\99388140.exe
c:\documents and settings\Owner\Application Data\drivers\downld\99421125.exe
c:\documents and settings\Owner\Application Data\drivers\downld\99422046.exe
c:\documents and settings\Owner\Application Data\drivers\downld\99476921.exe
c:\documents and settings\Owner\Application Data\drivers\downld\99476968.exe
c:\documents and settings\Owner\Application Data\drivers\downld\99537265.exe
c:\documents and settings\Owner\Application Data\drivers\downld\99538312.exe
c:\documents and settings\Owner\Application Data\drivers\downld\99538828.exe
c:\documents and settings\Owner\Application Data\drivers\downld\99545062.exe
c:\documents and settings\Owner\Application Data\drivers\downld\99545078.exe
c:\documents and settings\Owner\Application Data\drivers\downld\99545359.exe
c:\documents and settings\Owner\Application Data\drivers\downld\995496281.exe
c:\documents and settings\Owner\Application Data\drivers\downld\99549640.exe
c:\documents and settings\Owner\Application Data\drivers\downld\99550375.exe
c:\documents and settings\Owner\Application Data\drivers\downld\99550734.exe
c:\documents and settings\Owner\Application Data\drivers\downld\995526640.exe
c:\documents and settings\Owner\Application Data\drivers\downld\995633484.exe
c:\documents and settings\Owner\Application Data\drivers\downld\995634000.exe
c:\documents and settings\Owner\Application Data\drivers\downld\995634437.exe
c:\documents and settings\Owner\Application Data\drivers\downld\995672390.exe
c:\documents and settings\Owner\Application Data\drivers\downld\995673171.exe
c:\documents and settings\Owner\Application Data\drivers\downld\995721906.exe
c:\documents and settings\Owner\Application Data\drivers\downld\995729375.exe
c:\documents and settings\Owner\Application Data\drivers\downld\995729406.exe
c:\documents and settings\Owner\Application Data\drivers\downld\995729468.exe
c:\documents and settings\Owner\Application Data\drivers\downld\99573578.exe
c:\documents and settings\Owner\Application Data\drivers\downld\995791140.exe
c:\documents and settings\Owner\Application Data\drivers\downld\995793109.exe
c:\documents and settings\Owner\Application Data\drivers\downld\995793859.exe
c:\documents and settings\Owner\Application Data\drivers\downld\995801828.exe
c:\documents and settings\Owner\Application Data\drivers\downld\995909296.exe
c:\documents and settings\Owner\Application Data\drivers\downld\995910250.exe
c:\documents and settings\Owner\Application Data\drivers\downld\995910625.exe
c:\documents and settings\Owner\Application Data\drivers\downld\995911234.exe
c:\documents and settings\Owner\Application Data\drivers\downld\995931750.exe
c:\documents and settings\Owner\Application Data\drivers\downld\996304453.exe
c:\documents and settings\Owner\Application Data\drivers\downld\996304468.exe
c:\documents and settings\Owner\Application Data\drivers\downld\996408093.exe
c:\documents and settings\Owner\Application Data\drivers\downld\996411812.exe
c:\documents and settings\Owner\Application Data\drivers\downld\996412062.exe
c:\documents and settings\Owner\Application Data\drivers\downld\996412109.exe
c:\documents and settings\Owner\Application Data\drivers\downld\996412437.exe
c:\documents and settings\Owner\Application Data\drivers\downld\996412453.exe
c:\documents and settings\Owner\Application Data\drivers\downld\996412468.exe
c:\documents and settings\Owner\Application Data\drivers\downld\99737156.exe
c:\documents and settings\Owner\Application Data\drivers\downld\99737187.exe
c:\documents and settings\Owner\Application Data\drivers\downld\99737468.exe
c:\documents and settings\Owner\Application Data\drivers\downld\998343.exe
c:\documents and settings\Owner\Application Data\drivers\downld\99864562.exe
c:\documents and settings\Owner\Application Data\drivers\downld\99866718.exe
c:\documents and settings\Owner\Application Data\drivers\downld\99867109.exe
c:\documents and settings\Owner\Application Data\drivers\downld\99881656.exe
c:\documents and settings\Owner\Application Data\drivers\downld\99884109.exe
c:\documents and settings\Owner\Application Data\drivers\downld\99884281.exe
c:\documents and settings\Owner\Application Data\drivers\downld\99884312.exe
c:\documents and settings\Owner\Application Data\drivers\downld\99884640.exe
c:\documents and settings\Owner\Application Data\drivers\downld\999156.exe
c:\documents and settings\Owner\Application Data\drivers\winupgro.exe
c:\documents and settings\Owner\Application Data\m
c:\documents and settings\Owner\Application Data\m\data.oct
c:\documents and settings\Owner\Application Data\m\flec006.exe
c:\documents and settings\Owner\Application Data\m\list.oct
c:\documents and settings\Owner\Application Data\m\shared\#1_Evidence_Killer_2.0.zip
c:\documents and settings\Owner\Application Data\m\shared\1-More PhotoManager 1.20.zip
c:\documents and settings\Owner\Application Data\m\shared\3-D Box Icons.zip
c:\documents and settings\Owner\Application Data\m\shared\3D GIF Designer 2.21.zip
c:\documents and settings\Owner\Application Data\m\shared\3D_Christmas_Cookies_2.3.zip
c:\documents and settings\Owner\Application Data\m\shared\Abandoned_Well_1.15.zip
c:\documents and settings\Owner\Application Data\m\shared\Aberration 1.02.zip
c:\documents and settings\Owner\Application Data\m\shared\Address_Magic_Personal_Edition_4.0.372.zip
c:\documents and settings\Owner\Application Data\m\shared\Advanced Renamer Portable 2.57.zip
c:\documents and settings\Owner\Application Data\m\shared\Al's_RSS_Ticker_1.0.zip
c:\documents and settings\Owner\Application Data\m\shared\Alkatraz_1.08.zip
c:\documents and settings\Owner\Application Data\m\shared\AlterDesk_0.0.6a.zip
c:\documents and settings\Owner\Application Data\m\shared\Antares_PasSafe_Password_Manager_2.0.zip
c:\documents and settings\Owner\Application Data\m\shared\Any media To Sony Erricsson 5.0.zip
c:\documents and settings\Owner\Application Data\m\shared\Aspose.Pdf For Java 2.2.2.0.zip
c:\documents and settings\Owner\Application Data\m\shared\avast!.Home.4.6.exe.zip
c:\documents and settings\Owner\Application Data\m\shared\Bangarsoft FoxFix 1.0.zip
c:\documents and settings\Owner\Application Data\m\shared\Bass Masters Classic Tournament Edition.zip
c:\documents and settings\Owner\Application Data\m\shared\Battlefield_1942_Desert_Combat_Mission_Angel_of_Death_map.zip
c:\documents and settings\Owner\Application Data\m\shared\BlogBridge_3.0.1.zip
c:\documents and settings\Owner\Application Data\m\shared\CeledyDraw_2.zip
c:\documents and settings\Owner\Application Data\m\shared\CeSync_Activex_1.2.zip
c:\documents and settings\Owner\Application Data\m\shared\Compact AutoRunner 1.0.1 Build 100.zip
c:\documents and settings\Owner\Application Data\m\shared\CoverMe! 1.2.zip
c:\documents and settings\Owner\Application Data\m\shared\CPXCoding_Process_Xlerator_5.3.5.zip
c:\documents and settings\Owner\Application Data\m\shared\CrossFont_4.1.zip
c:\documents and settings\Owner\Application Data\m\shared\CyberSieve 2.7.3.zip
c:\documents and settings\Owner\Application Data\m\shared\Danzania_-_Land_of_Wonder_Screensaver_1.0.zip
c:\documents and settings\Owner\Application Data\m\shared\Data_Entry_Test_2004_5.0_(Patch).zip
c:\documents and settings\Owner\Application Data\m\shared\Data_Protection_Software_1.46.zip
c:\documents and settings\Owner\Application Data\m\shared\Diamond_Calculator_3.0.zip
c:\documents and settings\Owner\Application Data\m\shared\DIRECTORS_SCRIPT_1.0_(Key).zip
c:\documents and settings\Owner\Application Data\m\shared\Duchess_ESML_Librarian_1.0.6.1_(With_Crack).zip
c:\documents and settings\Owner\Application Data\m\shared\DVDConvert_Professional_3.0.45.zip
c:\documents and settings\Owner\Application Data\m\shared\EarMaster Pro 5.0 build 601P.zip
c:\documents and settings\Owner\Application Data\m\shared\Elterm 24 Emulator 1.01.zip
c:\documents and settings\Owner\Application Data\m\shared\Email Audit 3.2.zip
c:\documents and settings\Owner\Application Data\m\shared\EMS_Data_Comparer_for_PostgreSQL_2.0.0.1_Patch.zip
c:\documents and settings\Owner\Application Data\m\shared\Feedreader_3.10_Final.zip
c:\documents and settings\Owner\Application Data\m\shared\FileBackup 1.0.zip
c:\documents and settings\Owner\Application Data\m\shared\FolderSecure_6.0_Crack.zip
c:\documents and settings\Owner\Application Data\m\shared\Free_ProxyWay_anonymous_surfing_2.6.zip
c:\documents and settings\Owner\Application Data\m\shared\FreeVoice_1.2_Beta.zip
c:\documents and settings\Owner\Application Data\m\shared\Google_Maps_With_GPS_Tracker_5.0_Crack.zip
c:\documents and settings\Owner\Application Data\m\shared\Iman_Random_Password_Generator_1.0.zip
c:\documents and settings\Owner\Application Data\m\shared\Immedirate_1.0.0.0.zip
c:\documents and settings\Owner\Application Data\m\shared\ImplantViewer_1.901B.zip
c:\documents and settings\Owner\Application Data\m\shared\Inzomia_Image_Encrypt_1.02.zip
c:\documents and settings\Owner\Application Data\m\shared\Jaguar Calc add-in 1.0.2.zip
c:\documents and settings\Owner\Application Data\m\shared\Java_DeObfuscator_1.6b.zip
c:\documents and settings\Owner\Application Data\m\shared\Jlint 1.20.zip
c:\documents and settings\Owner\Application Data\m\shared\JMesa 2.4.1.zip
c:\documents and settings\Owner\Application Data\m\shared\Joost.zip
c:\documents and settings\Owner\Application Data\m\shared\Kalvyn_Workgroup_Software_Access_Edition_2006_1.0_Key.zip
c:\documents and settings\Owner\Application Data\m\shared\Klick-N-View_Business_Cards_4.5.2.1.zip
c:\documents and settings\Owner\Application Data\m\shared\Klonsoft_MP3_to_WAV_Converter_2.5_[Crack].zip
c:\documents and settings\Owner\Application Data\m\shared\LuxRiot DVR 1.6.12.zip
c:\documents and settings\Owner\Application Data\m\shared\Magic Blog 1.00.zip
c:\documents and settings\Owner\Application Data\m\shared\Marbles+ - The Cross Puzzle 1.1.zip
c:\documents and settings\Owner\Application Data\m\shared\MB3-214_-_Great_Plains_8.0_Installations_&_Configuration_Practice_Exam_Questions_1.0_(KeyGen).zip
c:\documents and settings\Owner\Application Data\m\shared\Metronome HistoryMaker 1.5a.zip
c:\documents and settings\Owner\Application Data\m\shared\MHT Quick Saver 3.23.zip
c:\documents and settings\Owner\Application Data\m\shared\Microsoft Semblio SDK 1.0.zip
c:\documents and settings\Owner\Application Data\m\shared\MP3 Filename Formatter 5.112.zip
c:\documents and settings\Owner\Application Data\m\shared\MP3DVU 1.02.zip
c:\documents and settings\Owner\Application Data\m\shared\MS_Word_Extract_Phone_Numbers_From_Multiple_Documents_Software_7.0.zip
c:\documents and settings\Owner\Application Data\m\shared\My Properties 1.0.zip
c:\documents and settings\Owner\Application Data\m\shared\MY_ENCRYPTED_DISK_1.10_Key.zip
c:\documents and settings\Owner\Application Data\m\shared\My3DEngine 1.0.18.zip
c:\documents and settings\Owner\Application Data\m\shared\Nero_7_Premium_7.10.1.0.zip
c:\documents and settings\Owner\Application Data\m\shared\NetWalk_2.2.zip
c:\documents and settings\Owner\Application Data\m\shared\Newsgroup_Image_Collector_1.6_[Serial].zip
c:\documents and settings\Owner\Application Data\m\shared\NOD32.2.51.20.Ita.Windows.NT2000XP2003x64.zip
c:\documents and settings\Owner\Application Data\m\shared\Norton.Antivirus.2006.BR.-.por.bard666.F!N4LShare.zip
c:\documents and settings\Owner\Application Data\m\shared\Note_2.12_(Cracked).zip
c:\documents and settings\Owner\Application Data\m\shared\OrgCalendar (WEB) 1.3.zip
c:\documents and settings\Owner\Application Data\m\shared\Origramy 1.12.zip
c:\documents and settings\Owner\Application Data\m\shared\OSS_Audio_Converter_Pro_5.6.0.5_Key.zip
c:\documents and settings\Owner\Application Data\m\shared\PC_Countdown_1.0.zip
c:\documents and settings\Owner\Application Data\m\shared\PDFreactor 1.0.800.zip
c:\documents and settings\Owner\Application Data\m\shared\PetraSell_Scheduler_2004.zip
c:\documents and settings\Owner\Application Data\m\shared\Photoinstrument 2.5 Build 219.zip
c:\documents and settings\Owner\Application Data\m\shared\PhotoPulse 1.3.1.zip
c:\documents and settings\Owner\Application Data\m\shared\Phutboyslim 1.2.zip
c:\documents and settings\Owner\Application Data\m\shared\PolyEdit 5.2.zip
c:\documents and settings\Owner\Application Data\m\shared\Power_Video_Converter_1.5.26.zip
c:\documents and settings\Owner\Application Data\m\shared\PowerTOC_1.2_With_Crack.zip
c:\documents and settings\Owner\Application Data\m\shared\Prefling_2.0.zip
c:\documents and settings\Owner\Application Data\m\shared\PutAFile 2.0.zip
c:\documents and settings\Owner\Application Data\m\shared\Quick_Run_1.4.zip
c:\documents and settings\Owner\Application Data\m\shared\RailwayStation Art Gallery 1 1.0.6.2634.zip
c:\documents and settings\Owner\Application Data\m\shared\Replay_Screencast_1.21.zip
c:\documents and settings\Owner\Application Data\m\shared\RSS_To_Speech_1.1_(Key).zip
c:\documents and settings\Owner\Application Data\m\shared\sendSMS 0.3.0.zip
c:\documents and settings\Owner\Application Data\m\shared\Server Spy 0.1.6.zip
c:\documents and settings\Owner\Application Data\m\shared\Shutdown_Utility_1.03.zip
c:\documents and settings\Owner\Application Data\m\shared\Smart MP3 Renamer 1.4.1.1.zip
c:\documents and settings\Owner\Application Data\m\shared\SmartPlugin Professional 2.2.05-rc1.zip
c:\documents and settings\Owner\Application Data\m\shared\Snotra Tech Oracle Data Components 2.3.zip
c:\documents and settings\Owner\Application Data\m\shared\Sokoban 1.2.zip
c:\documents and settings\Owner\Application Data\m\shared\SuperPro Client Manager 5.0.zip
c:\documents and settings\Owner\Application Data\m\shared\SwisSQL - Sybase to Oracle Migration Tool 3.0.zip
c:\documents and settings\Owner\Application Data\m\shared\Synesthesia_IR_library_WAV_1.1.3.zip
c:\documents and settings\Owner\Application Data\m\shared\SystemInfo_1.0.zip
c:\documents and settings\Owner\Application Data\m\shared\Targa to Extended BMP.zip
c:\documents and settings\Owner\Application Data\m\shared\TechFeeder_1.0.zip
c:\documents and settings\Owner\Application Data\m\shared\Terminal Server Console TSCon 2.7.zip
c:\documents and settings\Owner\Application Data\m\shared\Thunderbird Backup4all Plugin.zip
c:\documents and settings\Owner\Application Data\m\shared\Twilight Utilities Address Monitor 2.1.2.zip
c:\documents and settings\Owner\Application Data\m\shared\UFO_Light_1.zip
c:\documents and settings\Owner\Application Data\m\shared\USB_Modem_1.50.zip
c:\documents and settings\Owner\Application Data\m\shared\VBAcodePrint_6.13.98.zip
c:\documents and settings\Owner\Application Data\m\shared\Vikrant's PC Glossary 3 Build 555.zip
c:\documents and settings\Owner\Application Data\m\shared\visKeeper_3.0.2.zip
c:\documents and settings\Owner\Application Data\m\shared\Vista Live Shell Pack - Grey 2.5.1.zip
c:\documents and settings\Owner\Application Data\m\shared\Warcraft_III_The_Frozen_Throne_v1.15_patch.zip
c:\documents and settings\Owner\Application Data\m\shared\WAV to MP3 Plus 1.0.zip
c:\documents and settings\Owner\Application Data\m\shared\Web_Chart_Creator_3.0_(KeyGen).zip
c:\documents and settings\Owner\Application Data\m\shared\Web_Weaver_EZ_Plus_2.06.zip
c:\documents and settings\Owner\Application Data\m\shared\wList 2.0.0.2.zip
c:\documents and settings\Owner\Application Data\m\shared\WordConverterExe.zip
c:\documents and settings\Owner\Application Data\m\shared\World Geography Games 1.0.zip
c:\documents and settings\Owner\Application Data\m\shared\YFakeMusicStatus_1.0.zip
c:\documents and settings\Owner\Application Data\m\srvlist.oct
c:\windows\AppPatch\Custom\{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb
c:\windows\system32\drivers\down
c:\windows\system32\drivers\down\1098578.exe
c:\windows\system32\lsprst7.dll
c:\windows\system32\mdelk.exe
c:\windows\system32\nsprs.dll
c:\windows\system32\serauth1.dll
c:\windows\system32\serauth2.dll
c:\windows\system32\ssprs.dll
c:\windows\system32\wintems.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_111111S1RO1S1A
-------\Legacy_111111S1RO1S1A
-------\Legacy_SK9OU0S
-------\Service_sK9Ou0s
((((((((((((((((((((((((( Files Created from 2009-08-13 to 2009-09-13 )))))))))))))))))))))))))))))))
.
2009-09-13 19:51 . 2009-09-13 19:51 -------- d-----w- c:\windows\system32\xircom
2009-09-13 19:51 . 2009-09-13 19:51 -------- d-----w- c:\windows\system32\wbem\snmp
2009-09-13 19:51 . 2009-09-13 19:51 -------- d-----w- c:\windows\system32\oobe
2009-09-13 19:51 . 2009-09-13 19:51 -------- d-----w- c:\program files\microsoft frontpage
2009-09-13 18:42 . 2009-09-13 18:42 211893 ----a-w- c:\windows\system32\drivers\ynogwbzj.sys
2009-09-13 18:41 . 2009-09-13 18:41 -------- d---a-w- C:\Ice
2009-09-13 03:18 . 2009-09-13 03:18 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-09-13 03:18 . 2009-09-13 03:18 -------- d-----w- c:\documents and settings\Owner\Application Data\SUPERAntiSpyware.com
2009-09-13 02:55 . 2009-09-13 02:55 -------- d-----w- c:\program files\Panda Security
2009-09-13 02:24 . 2009-09-13 02:24 -------- d-----w- C:\rsit
2009-09-13 01:58 . 2009-09-13 01:58 -------- d-----w- c:\program files\ESET
2009-09-13 01:12 . 2009-09-13 11:40 -------- d-----w- c:\program files\Trend Micro
2009-09-13 00:52 . 2009-09-13 00:52 -------- d-----w- c:\program files\Alwil Software
2009-09-12 21:47 . 2008-04-25 18:41 218624 ----a-w- c:\windows\system32\dllcache\uxtheme.dll
2009-09-12 07:17 . 2009-09-12 07:17 -------- d--h--w- c:\windows\PIF
2009-09-12 07:14 . 2009-09-12 07:14 -------- d-----w- c:\documents and settings\Owner\Application Data\Windows Search
2009-09-06 22:26 . 2009-09-06 22:26 -------- d-----w- c:\program files\Acoustica MP3 Audio Mixer
2009-09-03 21:25 . 2009-09-03 21:42 -------- d-----w- c:\program files\Easy h10
2009-08-19 01:55 . 2009-08-19 01:55 -------- d-----w- c:\documents and settings\Owner\Application Data\Sibelius Software
2009-08-19 01:50 . 2009-08-19 01:50 -------- d-----w- c:\program files\Sibelius Software
2009-08-17 00:27 . 2009-08-17 00:27 -------- d-----w- c:\documents and settings\Owner\Application Data\AVG8
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-13 19:49 . 2009-08-05 16:00 -------- d--h--w- c:\documents and settings\Owner\Application Data\drivers
2009-09-13 03:18 . 2009-07-29 01:42 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-09-13 01:29 . 2009-07-29 01:24 -------- d-----w- c:\program files\Java
2009-09-10 09:52 . 2009-09-10 09:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Hewlett-Packard
2009-09-10 01:44 . 2009-07-29 05:19 -------- d-----w- c:\program files\SPSSEval
2009-09-07 08:10 . 2009-08-04 11:24 -------- d-----w- c:\documents and settings\Owner\Application Data\Azureus
2009-08-20 12:26 . 2009-07-29 04:46 -------- d-----w- c:\program files\Question Writer - Publisher Edition
2009-08-19 01:55 . 2009-07-29 01:33 112224 ----a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-18 19:39 . 2009-07-29 01:24 -------- d-----w- c:\program files\Unlocker
2009-08-07 23:55 . 2009-08-07 23:55 262144 ----a-w- c:\windows\system32\default_user_class.dat
2009-08-06 18:04 . 2009-08-06 18:04 -------- d-----w- c:\program files\eBay
2009-08-06 13:22 . 2009-08-06 13:22 -------- d-----w- c:\program files\Blue Onion Software
2009-08-05 16:12 . 2009-08-04 11:15 -------- d-----w- c:\program files\eMule
2009-08-05 16:03 . 2009-08-05 16:03 -------- d-----w- c:\documents and settings\Owner\Application Data\GlobalSCAPE
2009-08-05 16:02 . 2009-08-05 16:02 -------- d-----w- c:\program files\GlobalSCAPE
2009-08-05 16:02 . 2009-07-29 01:34 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-05 16:01 . 2009-07-29 01:34 -------- d-----w- c:\program files\Common Files\InstallShield
2009-08-05 11:48 . 2009-07-29 01:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-08-04 11:29 . 2009-08-04 11:24 -------- d-----w- c:\program files\Xobni
2009-08-04 11:24 . 2009-08-04 11:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Azureus
2009-08-04 11:23 . 2009-08-04 11:23 -------- d-----w- c:\program files\Vuze
2009-08-04 10:44 . 2009-08-04 10:44 -------- d-----w- c:\program files\tools
2009-08-04 10:18 . 2009-08-04 10:18 -------- d-----w- c:\program files\MSECache
2009-08-04 09:36 . 2009-07-29 04:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-07-31 09:47 . 2009-07-31 09:47 -------- d-----w- c:\documents and settings\Owner\Application Data\Canon
2009-07-31 09:15 . 2009-07-31 09:15 -------- d-----w- c:\program files\Canon
2009-07-31 09:06 . 2009-07-29 01:14 -------- d-----w- c:\program files\Microsoft Silverlight
2009-07-30 06:48 . 2009-07-30 06:48 -------- d-----w- c:\documents and settings\All Users\Application Data\FLEXnet
2009-07-30 06:35 . 2009-07-29 05:00 -------- d-----w- c:\program files\Common Files\Adobe
2009-07-30 06:35 . 2009-07-30 06:35 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2009-07-30 06:32 . 2009-07-30 06:32 9464 ------w- c:\windows\system32\drivers\cdralw2k.sys
2009-07-30 06:32 . 2009-07-30 06:32 9336 ------w- c:\windows\system32\drivers\cdr4_xp.sys
2009-07-30 05:57 . 2009-07-30 05:35 -------- d-----w- c:\program files\DVBT
2009-07-30 05:54 . 2009-07-30 05:54 -------- d-----w- c:\documents and settings\Owner\Application Data\Logitech
2009-07-30 05:53 . 2009-07-30 05:53 -------- d-----w- c:\documents and settings\All Users\Application Data\LogiShrd
2009-07-30 05:53 . 2009-07-30 05:53 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2009-07-30 05:53 . 2009-07-30 05:53 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_LHidFilt_01005.Wdf
2009-07-30 05:52 . 2009-07-30 05:52 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-07-30 05:52 . 2009-07-30 05:52 -------- d-----w- c:\program files\Common Files\Logishrd
2009-07-30 05:52 . 2009-07-30 05:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Logitech
2009-07-30 05:52 . 2009-07-30 05:52 -------- d-----w- c:\program files\Logitech
2009-07-30 05:04 . 2009-07-30 05:04 -------- d-----w- c:\program files\Microsoft Money
2009-07-30 04:58 . 2009-07-30 04:58 -------- d-----w- c:\program files\Belkin
2009-07-30 02:08 . 2009-07-29 04:39 -------- d-----w- c:\documents and settings\Owner\Application Data\Apple Computer
2009-07-29 13:56 . 2009-07-29 13:53 -------- d-----w- c:\program files\Microsoft Bootvis
2009-07-29 13:52 . 2009-07-29 04:33 -------- d-----w- c:\program files\Windows Desktop Search
2009-07-29 13:48 . 2009-07-29 01:57 -------- d-----w- c:\program files\Microsoft Works
2009-07-29 07:23 . 2009-07-29 07:23 -------- d-----w- c:\program files\CCleaner
2009-07-29 07:22 . 2009-07-29 07:22 -------- d-----w- c:\program files\CDex_150
2009-07-29 06:12 . 2009-07-29 06:07 -------- d-----w- c:\documents and settings\Owner\Application Data\Spotify
2009-07-29 06:07 . 2009-07-29 06:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Last.fm
2009-07-29 06:07 . 2009-07-29 04:39 -------- d-----w- c:\program files\iTunes
2009-07-29 06:07 . 2009-07-29 06:07 -------- d-----w- c:\program files\Spotify
2009-07-29 06:06 . 2009-07-29 06:06 -------- d-----w- c:\program files\Last.fm
2009-07-29 05:22 . 2009-07-29 05:22 1025 ----a-w- c:\windows\system32\sysprs7.dll
2009-07-29 05:20 . 2009-07-29 05:20 1024 ----a-w- c:\windows\system32\clauth2.dll
2009-07-29 05:20 . 2009-07-29 05:20 1024 ----a-w- c:\windows\system32\clauth1.dll
2009-07-29 05:11 . 2009-07-29 05:11 -------- d-----w- c:\documents and settings\Owner\Application Data\Forte
2009-07-29 05:11 . 2009-07-29 05:10 -------- d-----w- c:\program files\Agent
2009-07-29 05:06 . 2009-07-29 04:58 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-07-29 05:06 . 2009-07-29 04:58 -------- d-----w- c:\program files\NOS
2009-07-29 05:00 . 2009-07-29 04:59 -------- d-----w- c:\program files\Ultra Tag Editor
2009-07-29 04:59 . 2009-07-29 04:59 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-07-29 04:50 . 2009-07-29 04:50 -------- d-----w- c:\program files\Ahead
2009-07-29 04:50 . 2009-07-29 04:50 -------- d-----w- c:\program files\Common Files\Ahead
2009-07-29 04:48 . 2009-07-29 04:48 -------- d-----w- c:\program files\Smart Projects
2009-07-29 04:46 . 2009-07-29 04:46 -------- d-----w- c:\program files\Common Files\Xheo
2009-07-29 04:43 . 2009-07-29 04:42 -------- d-----w- c:\documents and settings\Owner\Application Data\Winamp
2009-07-29 04:42 . 2009-07-29 04:42 -------- d-----w- c:\program files\Winamp
2009-07-29 04:39 . 2009-07-29 04:39 -------- d-----w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-07-29 04:39 . 2009-07-29 04:39 -------- d-----w- c:\program files\iPod
2009-07-29 04:39 . 2009-07-29 01:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-07-29 04:39 . 2009-07-29 04:39 -------- d-----w- c:\program files\Bonjour
2009-07-29 04:39 . 2009-07-29 01:25 -------- d-----w- c:\program files\QuickTime Alternative
2009-07-29 04:38 . 2009-07-29 04:38 -------- d-----w- c:\program files\Apple Software Update
2009-07-29 04:38 . 2009-07-29 04:38 -------- d-----w- c:\documents and settings\Owner\Application Data\Windows Desktop Search
2009-07-29 04:38 . 2009-07-29 04:38 -------- d-----w- c:\program files\Common Files\Apple
2009-07-29 04:38 . 2009-07-29 04:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-07-29 04:29 . 2009-07-29 04:25 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-07-29 02:11 . 2009-07-29 02:11 -------- d-----w- c:\program files\AVG
2009-07-29 01:57 . 2009-07-29 01:57 -------- d-----w- c:\program files\Microsoft.NET
2009-07-29 01:51 . 2009-07-29 01:51 128 ----a-w- c:\documents and settings\Owner\Local Settings\Application Data\fusioncache.dat
2009-07-29 01:51 . 2009-07-29 01:51 -------- d-----w- c:\program files\Pro Imaging Powertoys
2009-07-29 01:51 . 2009-07-29 01:51 -------- d-----w- c:\program files\Common Files\Nikon
2009-07-29 01:42 . 2009-07-29 01:42 -------- d-----w- c:\program files\AGEIA Technologies
2009-07-29 01:42 . 2009-07-29 01:42 -------- d-----w- c:\program files\NVIDIA Corporation
2009-07-29 01:42 . 2009-07-29 01:42 -------- d-----w- c:\documents and settings\All Users\Application Data\NVIDIA Corporation
2009-07-29 01:40 . 2009-07-29 01:40 -------- d-----w- c:\program files\Intel
2009-07-29 01:38 . 2009-07-29 01:38 -------- d-----w- c:\program files\Dell
2009-07-29 01:34 . 2009-07-29 01:34 -------- d-----w- c:\program files\SigmaTel
2009-07-29 01:25 . 2009-07-29 01:25 -------- d-----w- c:\program files\MediaLooks
2009-07-29 01:25 . 2009-07-29 01:25 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-07-29 01:24 . 2009-07-29 01:24 -------- d-----w- c:\program files\7-Zip
2009-07-29 01:24 . 2009-07-29 01:24 -------- d-----w- c:\program files\Foxit Software
2009-07-29 01:24 . 2009-07-29 01:24 -------- d-----w- c:\documents and settings\Owner\Application Data\Foxit
2009-07-29 01:24 . 2009-07-29 01:24 -------- d-----w- c:\program files\UPHClean
2009-07-29 01:24 . 2009-07-29 01:24 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2009-07-29 01:24 . 2009-07-29 01:24 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-07-29 01:22 . 2009-07-29 01:22 94248 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-07-29 01:22 . 2009-07-29 01:22 -------- d-----w- c:\program files\MSBuild
.
------- Sigcheck -------
[-] 2009-04-20 . BA8C046D98345129723E6BCAA1E8AB99 . 361600 . . [5.1.2600.5649] . . c:\windows\system32\drivers\tcpip.sys
c:\windows\system32\wscntfy.exe ... is missing !!
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2009-07-09 1657376]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-07-14 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-07-14 13877248]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]
"CoolSwitch"="c:\windows\system32\taskswitch.exe" [2002-03-19 45632]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2006-03-20 282624]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2008-12-18 76304]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2009-04-20 128512]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
FreeSnap.lnk - c:\windows\Installer\{93A5E75B-4E28-4F0F-9006-D19522776993}\_5C685E6D2772ED439F4846.exe [2009-8-6 1078]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-7-30 809488]
Rupsmon Daemon.lnk - c:\program files\Belkin\Belkin Power Management Software\Monw32.exe [2009-7-30 32768]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-27 123904]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
"MaxRecentDocs"= 18 (0x12)
"NoSMConfigurePrograms"= 1 (0x1)
"NoRecentDocsNetHood"= 1 (0x1)
"MemCheckBoxInRunDlg"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 14:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-02-18 23:30 72208 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"NeroFilterCheck"=c:\windows\system32\NeroCheck.exe
"QuickTime Task"="c:\program files\QuickTime Alternative\QTTask.exe" -atboottime
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Elements 6.0\apdproxy.exe"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Spotify\\spotify.exe"=
"c:\\Program Files\\eMule\\eMule.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;c:\program files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [11/09/2007 00:45 124832]
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [30/07/2009 06:53 10384]
R3 EC168BDA;EC168BDA service;c:\windows\system32\drivers\EC168BDA.sys [11/09/2007 14:20 87296]
S0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys --> c:\windows\system32\drivers\pavboot.sys [?]
--- Other Services/Drivers In Memory ---
*Deregistered* - uphcleanhlp
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
2009-09-11 c:\windows\Tasks\FP backup.job
- c:\windows\system32\ntbackup.exe [2008-04-14 12:00]
2009-09-12 c:\windows\Tasks\mydocs backup.job
- c:\windows\system32\ntbackup.exe [2008-04-14 12:00]
2009-09-10 c:\windows\Tasks\Outlook Backup.job
- c:\windows\system32\ntbackup.exe [2008-04-14 12:00]
2009-09-07 c:\windows\Tasks\Spybot - Search & Destroy.job
- c:\progra~1\SPYBOT~1\SpybotSD.exe [2009-07-29 20:31]
2009-09-13 c:\windows\Tasks\User_Feed_Synchronization-{9C9DF633-BCA1-4280-B27E-51FA64BA62DF}.job
- c:\windows\system32\msfeedssync.exe [2009-04-20 18:22]
2009-09-13 c:\windows\Tasks\weekly home backup.job
- c:\windows\system32\ntbackup.exe [2008-04-14 12:00]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.com/uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {53D8FB9F-E3EA-4313-94FB-49868EC4D01B} = 192.168.0.1
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} -
hxxp://download.eset.com/special/eos/OnlineScanner.cab.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-09-13 20:53
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(740)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll
- - - - - - - > 'explorer.exe'(3912)
c:\windows\system32\WININET.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3079_x-ww_b811a94e\MSVCR80.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Belkin\Belkin Power Management Software\RupsMon.exe
c:\program files\UPHClean\uphclean.exe
c:\windows\system32\searchindexer.exe
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\rundll32.exe
c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
c:\program files\Blue Onion Software\FreeSnap\FreeSnap.exe
c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
c:\program files\Logitech\SetPoint\LU\LuLnchr.exe
c:\program files\Logitech\SetPoint\LU\LogitechUpdate.exe
c:\windows\system32\searchfilterhost.exe
c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\Download\{BE462510-1DBC-4D81-9CB9-74F373596630}\chrome_installer.exe
c:\documents and settings\Owner\Local Settings\temp\CR_19.tmp\setup.exe
.
**************************************************************************
.
Completion time: 2009-09-13 20:56 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-13 19:56
Pre-Run: 344,095,006,720 bytes free
Post-Run: 344,018,919,424 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
5427 --- E O F --- 2009-07-31 08:58