ComboFix 09-01-19.03 - Proprio 2009-01-19 18:57:14.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.2.1036.18.1023.708 [GMT -5:00]
Lancé depuis: c:\documents and settings\Proprio\Bureau\combo-fix.exe
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\cookies.ini
c:\windows\system32\avhoslmb.dll
c:\windows\system32\BJlSBJlm.ini
c:\windows\system32\bvidmr.dll
c:\windows\system32\cjpdmnxi.dll
c:\windows\system32\Drivers\TDSSpqlt.sys
c:\windows\system32\gvhebdt.dll
c:\windows\system32\IkRuCfhk.ini
c:\windows\system32\jhwygvnb.ini
c:\windows\system32\jQpYacfe.ini
c:\windows\system32\kdpkzv.dll
c:\windows\system32\mcrh.tmp
c:\windows\system32\mdm.exe
c:\windows\system32\setup.ini
c:\windows\system32\TDSSbrsr.dll
c:\windows\system32\TDSScfum.dll
c:\windows\system32\TDSSofxh.dll
c:\windows\system32\TDSSosvd.dat
c:\windows\system32\TDSSriqp.dll
c:\windows\system32\TDSStkdv.log
c:\windows\system32\tuibis.dll
c:\windows\system32\vjhwvrnx.dll
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
-------\Legacy_TDSSSERV.SYS
-------\Service_TDSSserv.sys
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-19 au 2009-01-19 ))))))))))))))))))))))))))))))))))))
.
2009-01-18 13:58 . 2009-01-19 07:00 <REP> d-------- c:\program files\UsbFix
2009-01-18 00:11 . 2009-01-18 00:11 <REP> d-------- c:\program files\CCleaner
2009-01-17 15:36 . 2009-01-19 18:20 2,192 --a------ c:\windows\system32\TDSSlxwp.dll
2009-01-17 15:00 . 2009-01-17 15:00 <REP> d-------- c:\program files\TeaTimer (Spybot - Search & Destroy)
2009-01-17 15:00 . 2009-01-17 15:00 <REP> d-------- c:\program files\SDHelper (Spybot - Search & Destroy)
2009-01-17 15:00 . 2009-01-17 15:00 <REP> d-------- c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2009-01-17 15:00 . 2009-01-17 15:00 <REP> d-------- c:\program files\File Scanner Library (Spybot - Search & Destroy)
2009-01-17 14:38 . 2009-01-17 14:38 579,584 --a--c--- c:\windows\system32\dllcache\user32.dll
2009-01-17 14:24 . 2008-06-21 05:35 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage réseau
2009-01-17 14:24 . 2008-06-21 05:35 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage d'impression
2009-01-17 14:24 . 2008-06-21 09:49 <REP> d--h----- c:\documents and settings\Administrateur\Modèles
2009-01-17 14:24 . 2008-06-21 05:35 <REP> d-------- c:\documents and settings\Administrateur\Mes documents
2009-01-17 14:24 . 2008-06-21 05:35 <REP> dr------- c:\documents and settings\Administrateur\Menu Démarrer
2009-01-17 14:24 . 2008-06-21 05:35 <REP> d-------- c:\documents and settings\Administrateur\Favoris
2009-01-17 14:24 . 2009-01-18 08:47 <REP> d-------- c:\documents and settings\Administrateur\Bureau
2009-01-17 14:24 . 2009-01-18 08:42 <REP> d-------- c:\documents and settings\Administrateur
2009-01-17 14:16 . 2009-01-17 14:16 <REP> d-------- c:\windows\ERUNT
2009-01-17 14:13 . 2009-01-17 14:53 <REP> d-------- C:\SDFix
2009-01-17 10:55 . 2009-01-17 10:55 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-17 10:55 . 2009-01-14 16:11 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-17 10:55 . 2009-01-14 16:11 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-01-17 09:35 . 2009-01-17 09:35 <REP> d-------- c:\program files\Malwarebytes' Anti-Malwaree
2009-01-17 09:33 . 2009-01-17 09:33 685,056 --a------ c:\windows\is-J0VPR.exe
2009-01-17 09:33 . 2009-01-17 09:33 13,753 --a------ c:\windows\is-J0VPR.msg
2009-01-17 09:33 . 2009-01-17 09:33 470 --a------ c:\windows\is-J0VPR.lst
2009-01-17 09:15 . 2009-01-18 10:11 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-01-16 19:42 . 2009-01-16 19:42 254,976 --a------ c:\documents and settings\Proprio\msiexec.exe
2009-01-16 18:56 . 2009-01-16 18:58 <REP> d-------- c:\program files\Windows Live Safety Center
2009-01-16 18:52 . 2009-01-16 18:52 <REP> d-------- c:\windows\system32\hi
2009-01-16 18:52 . 2009-01-16 18:52 <REP> d-------- c:\documents and settings\Proprio\Application Data\cogad
2009-01-16 18:52 . 2009-01-16 19:15 41,984 --a------ C:\mywyxngk.exe
2009-01-16 18:52 . 2009-01-16 19:15 705 --a------ C:\yjqcq.exe
2009-01-15 19:25 . 2009-01-17 15:44 739 --a------ c:\windows\wininit.ini
2009-01-15 19:24 . 2009-01-15 19:24 <REP> d-------- c:\documents and settings\All Users\Application Data\Avg8
2009-01-15 18:24 . 2009-01-19 18:23 <REP> d-------- c:\program files\Spybot - Search & Destroy
2009-01-15 18:24 . 2009-01-19 18:23 <REP> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-13 11:57 . 2009-01-13 11:58 <REP> d-------- c:\program files\Svetlograd
2009-01-12 21:56 . 2009-01-12 21:56 0 --a------ c:\windows\nsreg.dat
2009-01-12 21:55 . 2009-01-12 21:56 <REP> d-------- c:\temp\Real
2009-01-12 21:54 . 2009-01-12 21:54 <REP> d-------- c:\documents and settings\Proprio\Application Data\Skip-Bo
2009-01-12 20:38 . 2009-01-12 20:38 <REP> d-------- c:\program files\Lavasoft
2009-01-12 20:19 . 2009-01-12 20:57 <REP> d-------- c:\program files\NoAdware
2009-01-11 19:54 . 2009-01-11 19:54 <REP> d-------- c:\program files\Dr. Daisy Pet Vet
2009-01-08 18:27 . 2009-01-16 18:52 <REP> d-------- c:\windows\system32\m3V02
2009-01-08 18:27 . 2009-01-16 19:15 <REP> d-------- c:\temp\tmp90
2009-01-07 18:37 . 2009-01-07 18:37 268 --ah----- C:\sqmdata08.sqm
2009-01-07 18:37 . 2009-01-07 18:37 244 --ah----- C:\sqmnoopt08.sqm
2009-01-07 18:20 . 2009-01-07 18:20 <REP> d-------- c:\program files\Fichiers communs\Logitech
2009-01-07 06:46 . 2009-01-07 06:46 268 --ah----- C:\sqmdata07.sqm
2009-01-07 06:46 . 2009-01-07 06:46 244 --ah----- C:\sqmnoopt07.sqm
2009-01-07 00:09 . 2009-01-07 00:09 268 --ah----- C:\sqmdata06.sqm
2009-01-07 00:09 . 2009-01-07 00:09 244 --ah----- C:\sqmnoopt06.sqm
2009-01-06 23:35 . 2009-01-06 23:36 <REP> d-------- c:\documents and settings\Proprio\.java
2009-01-06 23:21 . 2009-01-06 23:21 268 --ah----- C:\sqmdata05.sqm
2009-01-06 23:21 . 2009-01-06 23:21 244 --ah----- C:\sqmnoopt05.sqm
2009-01-06 23:13 . 2009-01-06 23:13 268 --ah----- C:\sqmdata04.sqm
2009-01-06 23:13 . 2009-01-06 23:13 244 --ah----- C:\sqmnoopt04.sqm
2009-01-06 13:02 . 2009-01-06 13:02 268 --ah----- C:\sqmdata03.sqm
2009-01-06 13:02 . 2009-01-06 13:02 244 --ah----- C:\sqmnoopt03.sqm
2009-01-06 07:03 . 2009-01-06 07:03 268 --ah----- C:\sqmdata02.sqm
2009-01-06 07:03 . 2009-01-06 07:03 244 --ah----- C:\sqmnoopt02.sqm
2009-01-05 17:48 . 2009-01-05 22:45 410,984 --a------ c:\windows\system32\deploytk.dll
2009-01-05 14:32 . 2009-01-05 14:32 400 --a------ c:\documents and settings\Proprio\XpoxNnUE.bat
2009-01-05 14:29 . 2009-01-05 14:29 112,640 --a------ c:\documents and settings\Proprio\HCcyfIR.exe
2009-01-05 14:29 . 2009-01-05 14:29 112,364 --a------ c:\documents and settings\Proprio\owOtwSMsd.exe
2009-01-05 07:28 . 2009-01-08 05:39 <REP> d-------- c:\windows\system32\whSLD02
2009-01-05 07:28 . 2009-01-05 07:28 <REP> d-------- c:\temp\REX81
2009-01-04 06:36 . 2009-01-04 06:37 <REP> d-------- c:\program files\Family Restaurant
2009-01-03 06:44 . 2009-01-05 09:46 <REP> d-------- c:\program files\Star Defender 4
2009-01-02 12:58 . 2009-01-02 12:58 64,000 --a------ C:\vkefbog.exe
2009-01-02 06:42 . 2009-01-02 06:42 <REP> d-------- c:\documents and settings\All Users\Application Data\Genimo
2009-01-02 06:37 . 2009-01-02 06:37 <REP> d-------- c:\documents and settings\Proprio\Application Data\Genimo
2009-01-02 01:15 . 2009-01-02 01:15 73,313 --a------ c:\temp\nWE35I.exe
2009-01-02 01:15 . 2009-01-02 01:15 43,520 --a------ c:\windows\system32\whSLD022328.exe
2009-01-01 16:04 . 2009-01-01 16:04 <REP> d-------- c:\documents and settings\Proprio\Application Data\Home Sweet Home
2008-12-29 12:58 . 2008-12-29 12:58 <REP> d-------- c:\documents and settings\All Users\Application Data\Slapdash Games
2008-12-25 17:34 . 2008-12-25 17:34 <REP> d-------- c:\documents and settings\Proprio\Application Data\SPORE
2008-12-25 17:00 . 2008-12-25 17:00 <REP> d-------- c:\program files\Electronic Arts
2008-12-22 21:45 . 2008-12-22 21:45 268 --ah----- C:\sqmdata01.sqm
2008-12-22 21:45 . 2008-12-22 21:45 244 --ah----- C:\sqmnoopt01.sqm
2008-12-22 21:38 . 2008-12-22 21:38 268 --ah----- C:\sqmdata00.sqm
2008-12-22 21:38 . 2008-12-22 21:38 244 --ah----- C:\sqmnoopt00.sqm
2008-12-22 09:00 . 2008-12-22 09:30 <REP> d-------- c:\program files\Fairy Treasure
2008-12-21 06:52 . 2008-12-21 06:52 <REP> d-------- c:\documents and settings\Proprio\Application Data\EleFun Games
2008-12-20 22:21 . 2008-12-20 22:21 <REP> d-------- c:\documents and settings\All Users\Application Data\Mushroom Age
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-17 21:27 --------- d-----w c:\program files\Google
2009-01-17 00:24 --------- d-----w c:\documents and settings\Proprio\Application Data\LimeWire
2009-01-13 17:58 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-01-13 16:56 --------- d-----w c:\documents and settings\All Users\Application Data\BigFishGamesCache
2009-01-13 02:54 --------- d-----w c:\program files\Zylom Games
2009-01-06 03:45 --------- d-----w c:\program files\Java
2009-01-05 18:39 --------- d-----w c:\documents and settings\Proprio\Application Data\Zylom
2008-12-25 22:26 --------- d-----w c:\documents and settings\Proprio\Application Data\DivX
2008-12-25 21:58 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-21 15:34 --------- d-----w c:\documents and settings\Proprio\Application Data\HP
2008-12-20 03:37 --------- d-----w c:\documents and settings\Proprio\Application Data\PlayFirst
2008-12-20 03:37 --------- d-----w c:\documents and settings\All Users\Application Data\PlayFirst
2008-12-14 17:00 --------- d-----w c:\documents and settings\Proprio\Application Data\Friday's games
2008-12-14 16:54 --------- d-----w c:\program files\BoontyGames
2008-12-11 10:57 333,952 ----a-w c:\windows\system32\drivers\srv.sys
2008-12-08 13:50 --------- d-----w c:\documents and settings\All Users\Application Data\NeptunesAdve
2008-12-08 13:40 --------- d-----w c:\documents and settings\Proprio\Application Data\Valusoft
2008-12-08 13:40 --------- d-----w c:\documents and settings\All Users\Application Data\Valusoft
2008-12-08 03:33 --------- d-----w c:\program files\Hot Dish 2 - Cross Country Cook Off
2008-12-08 02:26 --------- d-----w c:\documents and settings\Proprio\Application Data\Artogon
2008-12-01 17:39 --------- d-----w c:\documents and settings\Proprio\Application Data\PetShowCraze
2008-11-29 21:11 --------- d-----w c:\documents and settings\Proprio\Application Data\Dragon Altar Games
2008-11-29 14:13 --------- d-----w c:\documents and settings\Proprio\Application Data\Jane s Hotel Family Hero
2008-11-24 22:02 --------- d-----w c:\documents and settings\Proprio\Application Data\Gaijin Ent
2008-11-22 00:39 --------- d-----w c:\documents and settings\Proprio\Application Data\Printer Info Cache
2008-11-22 00:39 --------- d-----w c:\documents and settings\Proprio\Application Data\Image Zone Express
2008-08-25 11:00 23 ----a-w c:\documents and settings\Proprio\jagex_runescape_preferences.dat
1999-04-06 12:27 99,840 ----a-w c:\program files\Fichiers communs\IRAABOUT.DLL
1998-12-09 02:53 70,144 ----a-w c:\program files\Fichiers communs\IRAMDMTR.DLL
1998-12-09 02:53 48,640 ----a-w c:\program files\Fichiers communs\IRALPTTR.DLL
1998-12-09 02:53 31,744 ----a-w c:\program files\Fichiers communs\IRAWEBTR.DLL
1998-12-09 02:53 186,368 ----a-w c:\program files\Fichiers communs\IRAREG.DLL
1998-12-09 02:53 17,920 ----a-w c:\program files\Fichiers communs\IRASRIAL.DLL
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-09-19 68856]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"LogitechCommunicationsManager"="c:\program files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe" [2008-08-14 565008]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-08-14 2407184]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-05 136600]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-01-02 210520]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]
Symantec Fax Starter Edition Port.lnk - c:\program files\Microsoft Office\Office\1036\OLFSNT40.EXE [1999-04-06 46080]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ c:\windows\system32\zonldnus.exe c:\windows\system32\zonldnus.exe:changelist\
0autocheck autochk *
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati0ikxx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati2psxx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati3bexx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 21:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ALi5289]
--------- 2005-03-10 13:56 405504 c:\program files\ULI5289\ALi5289.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
--a------ 2007-05-15 14:55 1057328 c:\program files\Nero\Nero 7\InCD\InCD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
--a------ 2006-12-05 21:55 54832 c:\program files\CyberLink\PowerDVD\Language\Language.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2007-03-01 14:57 153136 c:\program files\Fichiers communs\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--------- 2006-11-23 14:10 56928 c:\program files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SecurDisc]
--a------ 2007-05-15 14:55 1628208 c:\program files\Nero\Nero 7\InCD\NBHGui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
--a------ 2004-07-27 16:01 68096 c:\windows\SOUNDMAN.EXE
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R0 aliidex;aliidex;c:\windows\system32\drivers\aliidex.sys [2008-06-21 7040]
R0 aliperf;aliperf;c:\windows\system32\drivers\aliperf.sys [2008-06-21 7168]
R0 m5289;m5289;c:\windows\system32\drivers\m5289.sys [2008-06-21 51840]
R0 uliagpkx;ULi AGP Bus Filter Driver;c:\windows\system32\drivers\AGPKX.SYS [2008-06-21 45056]
R3 ULI5261;ULi Based Ethernet NT Driver;c:\windows\system32\drivers\ULILAN.SYS [2008-06-21 29696]
S0 ati0ikxx;ati0ikxx;c:\windows\system32\Drivers\ati0ikxx.sys --> c:\windows\system32\Drivers\ati0ikxx.sys [?]
S0 ati2psxx;ati2psxx;c:\windows\system32\Drivers\ati2psxx.sys --> c:\windows\system32\Drivers\ati2psxx.sys [?]
S0 ati3bexx;ati3bexx;c:\windows\system32\Drivers\ati3bexx.sys --> c:\windows\system32\Drivers\ati3bexx.sys [?]
S1 20083107;20083107;c:\windows\system32\drivers\20083107.sys --> c:\windows\system32\drivers\20083107.sys [?]
S1 e39f7dde;e39f7dde;c:\windows\system32\drivers\e39f7dde.sys --> c:\windows\system32\drivers\e39f7dde.sys [?]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d8d2fe7a-5062-11dd-b7bb-000b6a7be87f}]
\Shell\AutoRun\command - G:\start.exe
.
.
------- Examen supplémentaire -------
.
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} -
hxxp://game02.zylom.com/activex/zylomgamesplayer.cab
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-19 18:59:36
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\WgaTray.exe
c:\program files\Nero\Nero 7\InCD\InCDsrv.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Fichiers communs\logishrd\LVCOMSER\LVComSer.exe
c:\program files\Fichiers communs\logishrd\LVMVFM\LVPrcSrv.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\windows\system32\wscntfy.exe
c:\program files\Fichiers communs\logishrd\LVCOMSER\LVComSer.exe
c:\program files\Fichiers communs\logishrd\LQCVFX\COCIManager.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\windows\system32\wbem\wmiapsrv.exe
.
**************************************************************************
.
Heure de fin: 2009-01-19 19:05:37 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-01-20 00:05:34
Avant-CF: 80,399,671,296 octets libres
Après-CF: 80,334,897,152 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect
267 --- E O F --- 2009-01-17 20:33:18