View Single Post
Old 12-16-2008, 05:41 AM   #13 (permalink)
tanger
Registered User
 
Join Date: Aug 2007
Posts: 62
OS: XP SP3


Re: Does this HJT log look suspicious?

I did as instructed...recovery console was installed without problems and here is the log file.


ComboFix 08-12-15.01 - Warren 2008-12-16 7:37:30.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1533 [GMT -5:00]
Running from: c:\documents and settings\Warren\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Warren\Desktop\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
--------------- FCopy ---------------

c:\windows\ServicePackFiles\i386\winlogon.exe --> c:\windows\system32\winlogon.exe
.
((((((((((((((((((((((((( Files Created from 2008-11-16 to 2008-12-16 )))))))))))))))))))))))))))))))
.

2008-12-13 01:06 . 2008-12-13 01:06 <DIR> d-------- c:\program files\Nobilis
2008-12-12 11:52 . 2008-12-12 11:54 <DIR> d-------- c:\program files\MathType
2008-12-11 16:02 . 2008-12-11 16:02 <DIR> d-------- c:\windows\nview
2008-12-11 16:02 . 2008-11-12 13:45 453,152 --a------ c:\windows\system32\NVUNINST.EXE
2008-12-11 16:02 . 2008-11-12 14:54 453,152 --a------ c:\windows\system32\nvudisp.exe
2008-12-11 16:02 . 2008-12-15 10:37 203,520 --a------ c:\windows\system32\nvapps.xml
2008-12-11 16:02 . 2008-11-12 14:54 18,537 --a------ c:\windows\system32\nvdisp.nvu
2008-12-11 16:01 . 2008-12-11 16:01 <DIR> d-------- C:\NVIDIA
2008-12-11 14:08 . 2008-12-11 14:08 <DIR> d-------- c:\program files\Microsoft Works
2008-12-11 14:05 . 2008-12-11 15:06 <DIR> d-------- c:\windows\SHELLNEW
2008-12-11 13:43 . 2008-12-11 13:43 <DIR> d-------- c:\windows\Downloaded Installations
2008-12-11 13:37 . 2008-12-11 13:37 <DIR> d-------- c:\documents and settings\Administrator
2008-12-10 15:20 . 2008-12-10 15:20 <DIR> d-------- c:\documents and settings\Warren\Application Data\vlc
2008-12-10 14:03 . 2008-12-11 12:46 <DIR> d-------- c:\windows\SxsCaPendDel
2008-12-04 00:47 . 2008-12-04 00:47 250 --a------ c:\windows\gmer.ini
2008-12-02 22:50 . 2008-12-02 22:50 79 --a------ c:\windows\wininit.ini
2008-12-02 14:34 . 2008-12-02 14:34 <DIR> d-------- c:\program files\Foxit Software
2008-12-02 11:15 . 2008-12-02 11:15 <DIR> d-------- c:\documents and settings\Warren\Application Data\Kaspersky_Key_Finder_(KKF
2008-11-28 00:34 . 2008-11-28 00:34 <DIR> d-------- c:\documents and settings\Warren\Application Data\Design Science
2008-11-28 00:29 . 2008-11-28 14:45 <DIR> d-------- c:\documents and settings\Warren\Application Data\gtk-2.0
2008-11-28 00:22 . 2008-11-28 00:22 <DIR> d-------- c:\documents and settings\Warren\Application Data\Inkscape
2008-11-28 00:21 . 2008-11-28 00:22 <DIR> d-------- c:\program files\Inkscape
2008-11-27 19:10 . 2008-11-27 19:10 <DIR> d-------- c:\documents and settings\All Users\Application Data\Alias
2008-11-26 21:24 . 2008-11-26 21:24 21,035 --a------ c:\windows\system32\drivers\AegisP.sys
2008-11-26 21:23 . 2008-11-26 21:23 <DIR> d-------- c:\program files\ASUS WiFi-AP Solo
2008-11-26 21:23 . 2006-06-16 15:30 176,128 --a------ c:\windows\system32\drivers\RTL8187.sys
2008-11-26 21:23 . 2006-03-31 04:39 13,532 --a------ c:\windows\system32\drivers\SjyPkt.sys
2008-11-26 17:35 . 2008-11-26 17:35 <DIR> d-------- c:\documents and settings\Warren\Application Data\pdf995
2008-11-26 17:35 . 2008-11-26 17:35 28 --a------ c:\windows\pdf995.ini
2008-11-26 17:34 . 2008-11-26 17:35 <DIR> d-------- c:\program files\pdf995
2008-11-26 17:34 . 2008-12-02 14:17 <DIR> d-------- c:\documents and settings\All Users\Application Data\pdf995
2008-11-26 17:34 . 2008-11-26 17:34 249,856 --a------ c:\windows\system32\pdfmona.dll
2008-11-26 17:34 . 2008-11-26 17:34 51,716 --a------ c:\windows\system32\pdf995mon.dll
2008-11-26 17:34 . 2008-12-02 14:17 59 --a------ c:\windows\wpd99.drv
2008-11-21 23:10 . 2008-11-21 23:10 <DIR> d-------- c:\windows\Sun
2008-11-21 23:08 . 2008-11-10 05:43 410,984 --a------ c:\windows\system32\deploytk.dll
2008-11-21 23:08 . 2008-11-10 03:39 73,728 --a------ c:\windows\system32\javacpl.cpl
2008-11-21 23:07 . 2008-12-03 09:05 <DIR> d-------- c:\program files\Java

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-15 21:43 33,764 -csha-w c:\windows\system32\drivers\fidbox.idx
2008-12-15 21:43 3,781,152 -csha-w c:\windows\system32\drivers\fidbox.dat
2008-12-15 16:04 712,736 -csha-w c:\windows\system32\drivers\fidbox2.dat
2008-12-15 16:04 5,612 -csha-w c:\windows\system32\drivers\fidbox2.idx
2008-12-15 15:37 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2008-12-14 16:28 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-12-13 03:38 --------- d-----w c:\documents and settings\Warren\Application Data\uTorrent
2008-12-11 21:03 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-12-11 21:02 --------- d-----w c:\program files\AGEIA Technologies
2008-12-11 20:06 --------- d-----w c:\program files\MSBuild
2008-12-10 20:14 --------- d-----w c:\program files\VideoLAN
2008-12-02 19:32 --------- d-----w c:\program files\Common Files\Adobe
2008-11-28 00:10 --------- d-----w c:\program files\Common Files\InstallShield
2008-11-28 00:10 --------- d-----w c:\documents and settings\Warren\Application Data\Autodesk
2008-11-28 00:01 --------- d-----w c:\documents and settings\All Users\Application Data\Autodesk
2008-11-27 02:23 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-18 14:08 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-11-17 06:10 --------- d-----w c:\program files\WorldOfGoo
2008-11-05 21:41 --------- d-----w c:\program files\iTunes
2008-11-05 21:41 --------- d-----w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-05 21:40 --------- d-----w c:\program files\QuickTime
2008-11-05 21:40 --------- d-----w c:\program files\iPod
2008-11-05 21:40 --------- d-----w c:\program files\Common Files\Apple
2008-11-05 21:40 --------- d-----w c:\program files\Bonjour
2008-11-05 21:40 --------- d-----w c:\program files\Apple Software Update
2008-11-05 05:02 --------- d-----w c:\program files\VS Revo Group
2008-11-05 03:34 --------- d-----w c:\program files\Microsoft Visual Studio 9.0
2008-11-05 01:03 --------- d-----w c:\program files\Common Files\Logitech
2008-11-05 01:03 --------- d-----w c:\program files\Common Files\Logishrd
2008-11-05 00:42 --------- d-----w c:\program files\Microsoft SQL Server Compact Edition
2008-11-05 00:39 --------- d-----w c:\program files\Microsoft SDKs
2008-11-03 22:17 --------- d-----w c:\program files\Common Files\Macrovision Shared
2008-11-02 00:01 --------- d-----w c:\program files\THQ
2008-11-01 23:34 --------- d-----w c:\program files\Steam
2008-10-30 01:46 --------- d-----w c:\program files\Curve Expert
2008-10-27 20:27 --------- d-----w c:\documents and settings\All Users\Application Data\2DBoy
2008-10-27 20:23 --------- d-----w c:\documents and settings\Warren\Application Data\My Battle for Middle-earth(tm) II Files
2008-10-27 05:04 --------- d-----w c:\program files\EA GAMES
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-22 21:30 --------- d-----w c:\program files\Microsoft.NET
2008-10-22 20:54 --------- d-----w c:\documents and settings\All Users\Application Data\FLEXnet
2008-10-22 16:11 --------- d-----w c:\program files\Reference Assemblies
2008-10-16 20:38 826,368 ----a-w c:\windows\system32\wininet.dll
2008-10-16 19:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 19:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 19:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 19:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 19:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 19:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 19:09 43,544 -c--a-w c:\windows\system32\wups2.dll
2008-10-16 19:08 34,328 -c--a-w c:\windows\system32\wups.dll
2008-10-16 19:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 19:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-13 14:56 70,936 ----a-w c:\windows\system32\PhysXLoader.dll
2008-10-07 14:13 58,648 ----a-w c:\windows\system32\AgCPanelTraditionalChinese.dll
2008-10-07 14:13 58,648 ----a-w c:\windows\system32\AgCPanelSwedish.dll
2008-10-07 14:13 58,648 ----a-w c:\windows\system32\AgCPanelSpanish.dll
2008-10-07 14:13 58,648 ----a-w c:\windows\system32\AgCPanelSimplifiedChinese.dll
2008-10-07 14:13 58,648 ----a-w c:\windows\system32\AgCPanelPortugese.dll
2008-10-07 14:13 58,648 ----a-w c:\windows\system32\AgCPanelKorean.dll
2008-10-07 14:13 58,648 ----a-w c:\windows\system32\AgCPanelJapanese.dll
2008-10-07 14:13 58,648 ----a-w c:\windows\system32\AgCPanelGerman.dll
2008-10-07 14:13 58,648 ----a-w c:\windows\system32\AgCPanelFrench.dll
2008-10-07 14:13 288,024 ----a-w c:\windows\system32\PhysXCplUI.exe
2008-10-07 14:13 288,024 ----a-w c:\windows\system32\PhysXCompatCplUI.exe
2008-10-07 14:13 23,320 ----a-w c:\windows\system32\PhysXDevice.dll
2008-10-03 10:02 247,326 ----a-w c:\windows\system32\strmdll.dll
2008-07-18 18:06 47,360 -c--a-w c:\documents and settings\Warren\Application Data\pcouffin.sys
2006-06-23 18:48 32,768 -c--a-w c:\windows\inf\UpdateUSB.exe
2004-08-04 12:00 73,728 -csha-w c:\windows\RegisteredPackages\{DD90D410-1823-43EB-9A16-A2331BF08799}$BACKUP$\System\wmplayer.exe
.

------- Sigcheck -------

2007-10-30 11:53 360832 64798ecfa43d78c7178375fcdd16d8c8 c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2008-06-20 05:44 360960 744e57c99232201ae98c49168b918f48 c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
2008-06-20 06:51 361600 9aefa14bd6b182d61e3119fa5f436d3d c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
2008-06-20 06:59 361600 ad978a1b783b5719720cff204b666c8e c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
2008-07-11 23:10 360320 b3acff769e44cc8ae708ab740a52cf5d c:\windows\$NtServicePackUninstall$\tcpip.sys
2004-08-04 07:00 359040 9f4b36614a0fc234525ba224957de55c c:\windows\$NtUninstallKB941644$\tcpip.sys
2008-04-13 14:20 361344 93ea8d04ec73a85db02eb8805988f733 c:\windows\$NtUninstallKB951748$\tcpip.sys
2008-05-02 17:26 360064 8283a4d489b207991efdc8328733d0bc c:\windows\$NtUninstallKB951748_0$\tcpip.sys
2008-04-13 14:20 361344 93ea8d04ec73a85db02eb8805988f733 c:\windows\ServicePackFiles\i386\TCPIP.SYS
2008-09-28 11:11 361600 cbeebeb899e31ef52b962cb31fc8ca5c c:\windows\system32\dllcache\TCPIP.SYS
2008-09-28 11:11 361600 cbeebeb899e31ef52b962cb31fc8ca5c c:\windows\system32\drivers\TCPIP.SYS
.
((((((((((((((((((((((((((((( snapshot@2008-12-15_16.45.29.45 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-04-14 00:12:39 507,904 -c--a-w c:\windows\system32\dllcache\winlogon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2008-04-25 201992]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-11-12 13672448]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
ASUS WiFi-AP Solo.lnk - c:\program files\ASUS WiFi-AP Solo\RtWLan.exe [2008-11-26 987136]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-11-04 805392]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 02:42 72208 c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ac3filter"= ac3filter.acm

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a--c--- 2006-11-16 18:04 139264 c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus CX4800 Series]
--a--c--- 2005-02-02 03:00 98304 c:\windows\system32\spool\drivers\w32x86\3\E_FATIADA.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelliPoint]
--a------ 2007-08-31 14:01 1037736 c:\program files\Microsoft IntelliPoint\ipoint.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-10-01 18:57 289576 c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a--c--- 2006-01-12 14:40 155648 c:\program files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2008-11-12 14:54 13672448 c:\windows\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2008-11-12 14:54 86016 c:\windows\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
--a--c--- 2008-03-14 18:50 233472 c:\program files\PowerISO\PWRISOVM.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-09-06 15:09 413696 c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAX]
-----c--- 2006-07-13 06:12 729088 c:\program files\Analog Devices\SoundMAX\SMax4.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
--a--c--- 2006-12-18 20:34 868352 c:\program files\Analog Devices\Core\smax4pnp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-11-10 05:43 136600 c:\program files\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2008-11-12 14:54 1630208 c:\windows\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 7.0.1.325\\English\\setup.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\EA GAMES\\The Battle for Middle-earth (tm)\\game.dat"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Steam\\steamapps\\warrenlightning\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\EA GAMES\\The Battle for Middle-earth (tm) II\\game.dat"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 32784]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\DRIVERS\klfltdev.sys [2008-03-13 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2008-03-25 24592]
R3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8187.sys [2008-11-26 176128]
R3 SjyPkt;SjyPkt;\??\c:\windows\System32\Drivers\SjyPkt.sys [2008-11-26 13532]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\autorun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{67b0ce98-414d-11dd-94ec-0015af291d0c}]
\Shell\AutoRun\command - G:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{84b05056-adcd-11dd-9591-0015af291d0c}]
\Shell\Auto\command - sxs2.exe
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL sxs2.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c8532678-8e23-11dd-9552-0015af291d0c}]
\Shell\Auto\command - E:\auto.exe
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL auto.exe
\Shell\explore\Command - E:\t.com
\Shell\open\Command - E:\t.com

*Newly Created Service* - CATCHME
*Newly Created Service* - SJYPKT
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\Microsoft Office\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Warren\Application Data\Mozilla\Firefox\Profiles\po1w7agd.default\
FF - prefs.js: browser.startup.homepage - www.tsn.ca
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-16 07:38:06
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1084)
c:\windows\system32\klogon.dll
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll
.
Completion time: 2008-12-16 7:38:35
ComboFix-quarantined-files.txt 2008-12-16 12:38:33
ComboFix2.txt 2008-12-15 21:45:46

Pre-Run: 177,885,822,976 bytes free
Post-Run: 177,866,371,072 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /noguiboot

265 --- E O F --- 2008-12-14 16:28:37
tanger is offline