ComboFix 10-09-09.04 - Worm Jerry 09/10/2010 23:26:09.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.557 [GMT -7:00]
Running from: c:\documents and settings\Worm Jerry\My Documents\Downloads\ComboFix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Worm Jerry\Local Settings\Application Data\Windows Server
c:\documents and settings\Worm Jerry\Local Settings\Application Data\Windows Server\flags.ini
c:\documents and settings\Worm Jerry\Local Settings\Application Data\Windows Server\server.dat
c:\documents and settings\Worm Jerry\Local Settings\Application Data\Windows Server\uses32.dat
c:\windows\Bsizaa.exe
c:\windows\system32\lsp113.dll
c:\windows\system32\winlogon.exe . . . is infected!!
c:\windows\explorer.exe . . . is infected!!
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_6TO4
-------\Service_6to4
((((((((((((((((((((((((( Files Created from 2010-08-11 to 2010-09-11 )))))))))))))))))))))))))))))))
.
2010-09-08 04:18 . 2010-04-29 22:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-08 04:18 . 2010-04-29 22:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-09-08 04:17 . 2010-09-08 04:18 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-09-08 03:03 . 2010-09-08 03:03 388096 ----a-r- c:\documents and settings\Worm Jerry\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-09-08 03:03 . 2010-09-08 03:03 -------- d-----w- c:\program files\Trend Micro
2010-09-04 00:33 . 2010-09-04 16:58 -------- d-----w- c:\program files\Spyware Doctor
2010-09-04 00:33 . 2010-09-04 16:58 -------- d-----w- c:\program files\Common Files\PC Tools
2010-09-04 00:32 . 2010-09-04 16:56 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-09-03 23:36 . 2010-09-03 23:36 -------- d-----w- c:\program files\ESET
2010-09-03 07:31 . 2010-09-03 07:31 -------- d-----w- c:\documents and settings\Worm Jerry\Application Data\Malwarebytes
2010-09-03 07:31 . 2010-09-03 07:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-09-02 05:19 . 2010-09-02 05:19 -------- d-----w- c:\documents and settings\NetworkService\Application Data\Yahoo!
2010-09-01 11:19 . 2010-09-01 11:19 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Identities
2010-09-01 08:22 . 2010-09-01 08:22 79360 --sha-r- c:\windows\system32\atmadmp.dll
2010-09-01 03:19 . 2010-09-01 03:19 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Yahoo
2010-09-01 03:18 . 2010-09-01 03:18 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\Yahoo!
2010-09-01 03:18 . 2010-09-01 03:18 -------- d-----w- c:\documents and settings\LocalService\Application Data\Yahoo!
2010-08-31 21:01 . 2010-08-31 21:01 -------- d-----w- c:\documents and settings\Worm Jerry\Local Settings\Application Data\jlvviflwj
2010-08-31 21:01 . 2010-08-31 21:01 -------- d-----w- c:\documents and settings\Worm Jerry\Local Settings\Application Data\gkswilkdc
2010-08-31 21:01 . 2010-09-01 00:41 -------- d-----w- c:\documents and settings\Worm Jerry\Local Settings\Application Data\atnbhntdr
2010-08-31 21:00 . 2010-08-31 21:00 -------- d-----w- c:\documents and settings\Worm Jerry\Local Settings\Application Data\moxgfsnhf
2010-08-28 08:47 . 2010-09-04 17:06 144696 ----a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.exe
2010-08-25 06:47 . 2008-04-14 12:00 221184 ----a-w- c:\windows\system32\wmpns.dll
2010-08-20 18:57 . 2010-08-20 18:58 -------- d-----w- c:\program files\QuickTime
2010-08-20 18:57 . 2010-08-20 18:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-08 05:12 . 2010-07-03 00:02 -------- d-----w- c:\program files\Microsoft Silverlight
2010-09-04 20:22 . 2010-05-22 01:04 -------- d-----w- c:\program files\McAfee
2010-09-04 17:18 . 2010-03-06 01:23 -------- d-----w- c:\program files\Yahoo!
2010-09-04 17:18 . 2010-03-06 01:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2010-09-04 17:14 . 2009-03-12 06:06 -------- d-----w- c:\program files\Google
2010-09-04 17:10 . 2010-07-03 23:18 -------- d-----w- c:\documents and settings\All Users\Application Data\DivX
2010-09-04 17:10 . 2010-01-22 20:52 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-09-04 17:09 . 2010-01-22 20:52 -------- d-----w- c:\program files\DivX
2010-09-04 16:47 . 2001-08-17 13:57 11648 ----a-w- c:\windows\system32\drivers\acpiec.sys
2010-09-03 08:47 . 2009-03-12 06:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Acer GameZone Console
2010-08-28 09:52 . 2010-08-03 08:17 57344 ----a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-08-25 22:48 . 2010-03-24 06:06 400 ----a-w- c:\documents and settings\Worm Jerry\Application Data\wklnhst.dat
2010-08-25 06:45 . 2009-12-13 08:42 -------- d-----w- c:\program files\Windows Media Connect 2
2010-08-13 22:32 . 2010-05-06 04:52 76112 ----a-w- c:\documents and settings\Guest\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-08-12 18:34 . 2009-03-12 06:01 -------- d-----w- c:\program files\Microsoft Works
2010-08-12 18:13 . 2009-03-12 05:59 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-08-09 04:00 . 2010-08-09 03:17 -------- d-----w- c:\program files\Magestorm
2010-08-09 03:22 . 2010-08-09 03:22 33824 ----a-w- c:\windows\system32\drivers\oreans32.sys
2010-08-08 18:43 . 2009-08-24 21:56 -------- d-----w- c:\documents and settings\LocalService\Application Data\SACore
2010-08-03 17:08 . 2010-08-03 01:34 -------- d-----w- c:\program files\AVS4YOU
2010-08-03 17:08 . 2010-08-03 01:34 -------- d-----w- c:\program files\Common Files\AVSMedia
2010-08-03 08:17 . 2010-01-22 20:57 -------- d-----w- c:\documents and settings\Worm Jerry\Application Data\DivX
2010-08-03 01:49 . 2010-08-03 01:49 -------- d-----w- c:\program files\InterLok
2010-08-03 01:36 . 2010-08-03 01:36 -------- d-----w- c:\documents and settings\All Users\Application Data\AVS4YOU
2010-08-03 01:36 . 2010-08-03 01:36 -------- d-----w- c:\documents and settings\Worm Jerry\Application Data\AVS4YOU
2010-08-03 01:36 . 2009-08-24 21:09 76112 ----a-w- c:\documents and settings\Worm Jerry\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-07-31 21:37 . 2010-07-31 21:38 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-07-31 21:37 . 2010-07-31 21:37 -------- d-----w- c:\program files\Java
2010-07-31 21:37 . 2010-07-31 21:37 152576 ----a-w- c:\documents and settings\Worm Jerry\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2010-07-31 21:36 . 2010-07-31 21:35 79488 ----a-w- c:\documents and settings\Worm Jerry\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-07-22 03:58 . 2010-07-13 23:23 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-07-16 19:34 . 2010-07-16 19:30 -------- d-----w- c:\program files\Common Files\Adobe
2010-07-15 22:18 . 2010-05-22 01:04 120136 ----a-w- c:\windows\system32\drivers\Mpfp.sys
2010-07-14 09:03 . 2010-07-14 09:03 -------- d-----w- c:\documents and settings\NetworkService\Application Data\DivX
2010-06-30 12:31 . 2009-03-11 12:53 149504 ----a-w- c:\windows\system32\schannel.dll
2010-06-24 12:15 . 2009-03-11 12:53 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-06-24 12:15 . 2009-03-11 12:52 17408 ----a-w- c:\windows\system32\corpol.dll
2010-06-24 12:10 . 2009-03-11 12:53 667136 ----a-w- c:\windows\system32\wininet.dll
2010-06-23 13:44 . 2009-03-11 12:53 1851904 ----a-w- c:\windows\system32\win32k.sys
2010-06-21 15:27 . 2009-03-11 12:53 354304 ----a-w- c:\windows\system32\drivers\srv.sys
2010-06-17 14:03 . 2009-03-11 12:53 80384 ----a-w- c:\windows\system32\iccvid.dll
2010-06-14 14:31 . 2009-03-12 05:06 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-14 07:41 . 2009-03-11 12:53 1172480 ----a-w- c:\windows\system32\msxml3.dll
2010-07-06 22:38 . 2010-07-06 22:38 119808 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
------- Sigcheck -------
[-] 2008-04-14 . 77F4BE7A778F6330779784D64F0DE94D . 507904 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe
[-] 2008-04-14 . 08F7661C81DA72EF96B31217C211BC40 . 1033728 . . [6.00.2900.5512] . . c:\windows\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-06-24 1840424]
"Messenger (Yahoo!)"="c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe" [2010-02-17 5244216]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-17 3872080]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2009-01-31 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"M3000Mnt"="M3000Rmv.dll " [X]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-04-16 178712]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]
"RTHDCPL"="RTHDCPL.EXE" [2009-02-24 17529856]
"AzMixerSel"="c:\program files\Realtek\Audio\Drivers\AzMixerSel.exe" [2006-01-25 53248]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-02-05 1430824]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2008-12-30 875016]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-07-06 30192]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-14 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2008-07-09 570664]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-06-08 2221352]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2008-03-07 236016]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2010-02-11 1218008]
"McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2009-07-08 1176808]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-08-10 421888]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Acer VCM.lnk - c:\program files\Acer\Acer VCM\AcerVCM.exe [2009-3-11 565248]
InterVideo WinCinema Manager.lnk - c:\program files\InterVideo\Common\Bin\WinCinemaMgr.exe [2009-8-27 114688]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26666:TCP"= 26666:TCP:spport
"24027:TCP"= 24027:TCP:spport
"15825:TCP"= 15825:TCP:spport
"24262:TCP"= 24262:TCP:spport
"24152:TCP"= 24152:TCP:spport
"11508:TCP"= 11508:TCP:spport
R1 oreans32;oreans32;c:\windows\system32\drivers\oreans32.sys [8/8/2010 8:22 PM 33824]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [5/21/2010 6:07 PM 203280]
R2 RS_Service;Raw Socket Service;c:\program files\Acer\Acer VCM\RS_Service.exe [3/11/2009 11:32 PM 237568]
R3 L1c;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1c51x86.sys [3/3/2009 8:03 PM 38912]
R3 M3000Srv;WebCam Driver;c:\windows\system32\drivers\M3000KNT.sys [6/22/2009 4:28 PM 145408]
S0 axcrng;axcrng; [x]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [4/23/2010 1:39 AM 135664]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [3/11/2009 10:56 PM 1684736]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [3/11/2009 11:06 PM 30192]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RtsUStor.sys [3/11/2009 10:54 PM 162816]
S3 Rts516xIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys --> c:\windows\system32\DRIVERS\Rts516xIR.sys [?]
.
Contents of the 'Scheduled Tasks' folder
2010-08-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 20:34]
2010-09-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-23 08:38]
2010-09-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-23 08:38]
2010-06-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2010-05-22 19:22]
2010-09-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2010-05-22 19:22]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://search.entru.com/?s=21982
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
LSP: c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
FF - ProfilePath - c:\documents and settings\Worm Jerry\Application Data\Mozilla\Firefox\Profiles\bz5lle5a.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\documents and settings\Worm Jerry\Application Data\Facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\windows\system32\TVUAx\npTVUAx.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-klmdb.sys
AddRemove-{7B63B2922B174135AFC0E1377DD81EC2} - c:\program files\DivX\DivXCodecUninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-09-10 23:36
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(744)
c:\windows\system32\l3codeca.acm
- - - - - - - > 'explorer.exe'(1720)
c:\program files\McAfee\SiteAdvisor\saHook.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\rundll32.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\progra~1\McAfee\VIRUSS~1\mcshield.exe
c:\program files\McAfee\MPF\MPFSrv.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\system32\IoctlSvc.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\progra~1\mcafee.com\agent\mcagent.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\igfxsrvc.exe
c:\windows\WebCam\M3000\M3000Mnt.exe
c:\program files\Common Files\Nero\Lib\NMIndexingService.exe
c:\windows\system32\igfxext.exe
c:\progra~1\Yahoo!\Messenger\ymsgr_tray.exe
c:\program files\Windows Live\Contacts\wlcomm.exe
.
**************************************************************************
.
Completion time: 2010-09-10 23:42:30 - machine was rebooted
ComboFix-quarantined-files.txt 2010-09-11 06:42
Pre-Run: 103,295,287,296 bytes free
Post-Run: 103,161,827,328 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - 710852E4ABC619D9437FCF8938D2C30B