thanks for your help,
this is the combofix log
ComboFix 09-12-28.06 - Liam 29/12/2009 15:37:03.1.2 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2550.1816 [GMT 0:00]
Running from: c:\documents and settings\Liam\Desktop\ComboFix.exe
AV: AVG Anti-Virus *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
The following files were disabled during the run:
c:\program files\Common Files\Logitech\LVMVFM\LVPrcInj.dll
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\Liam\LOCALS~1\Temp\tmp2.tmp
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\program files\WinPCap
c:\program files\WinPCap\daemon_mgm.exe
c:\program files\WinPCap\npf_mgm.exe
c:\program files\WinPCap\rpcapd.exe
C:\Thumbs.db
c:\windows\dat.txt
c:\windows\EventSystem.log
c:\windows\search_res.txt
c:\windows\system32\drivers\npf.sys
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\srcr.dat
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll
----- BITS: Possible infected sites -----
hxxp://updates.swarmcast.net
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
((((((((((((((((((((((((( Files Created from 2009-11-28 to 2009-12-29 )))))))))))))))))))))))))))))))
.
2009-12-28 11:59 . 2009-12-28 11:59 -------- d-----w- c:\documents and settings\Liam\Application Data\Malwarebytes
2009-12-28 11:58 . 2009-12-03 16:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-28 11:58 . 2009-12-28 11:58 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-12-28 11:58 . 2009-12-28 11:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-28 11:58 . 2009-12-03 16:13 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-28 00:41 . 2009-12-28 00:41 -------- d-----w- C:\FOUND.005
2009-12-27 00:57 . 2009-12-27 00:57 10686001 ----a-w- c:\documents and settings\Liam\Application Data\Azureus\plugins\azump\mplayer.exe
2009-12-26 18:03 . 2009-12-16 14:42 872960 ----a-w- c:\documents and settings\Liam\Application Data\Mozilla\Firefox\Profiles\5h1n0mz6.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
2009-12-26 18:03 . 2009-12-16 14:42 43008 ----a-w- c:\documents and settings\Liam\Application Data\Mozilla\Firefox\Profiles\5h1n0mz6.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2009-12-26 18:03 . 2009-12-16 14:42 340480 ----a-w- c:\documents and settings\Liam\Application Data\Mozilla\Firefox\Profiles\5h1n0mz6.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2009-12-26 18:03 . 2009-12-16 14:41 346624 ----a-w- c:\documents and settings\Liam\Application Data\Mozilla\Firefox\Profiles\5h1n0mz6.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2009-12-25 19:02 . 2009-12-25 19:02 -------- d-----w- c:\program files\MSXML 4.0
2009-12-10 18:06 . 2009-12-10 18:05 2065688 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
2009-12-10 18:06 . 2009-12-26 10:18 3514648 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgui.exe
2009-12-10 18:06 . 2009-12-26 10:18 2029336 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgtray.exe
2009-12-06 22:15 . 2009-12-06 22:15 -------- d-----w- C:\FOUND.004
2009-12-02 18:23 . 2006-07-13 13:15 73728 ----a-w- c:\windows\system32\lxczpwr.dll
2009-12-02 18:23 . 2002-11-13 15:40 40960 ----a-w- c:\windows\system32\lxczvs.dll
2009-12-02 18:23 . 2006-07-13 13:28 69632 ----a-w- c:\windows\system32\LXCZCU.DLL
2009-12-02 18:23 . 2006-07-13 13:22 90112 ----a-w- c:\windows\system32\LXCZCUR.DLL
2009-12-02 18:23 . 2006-04-18 01:48 200704 ----a-w- c:\windows\system32\LEXLMPM.DLL
2009-12-02 18:23 . 2006-04-18 01:45 155648 ----a-w- c:\windows\system32\LEXPING.EXE
2009-12-02 18:23 . 2006-04-18 01:42 198144 ----a-w- c:\windows\system32\LEX2KUSB.DLL
2009-12-02 18:23 . 2006-04-18 01:42 311296 ----a-w- c:\windows\system32\LEXBCES.EXE
2009-12-02 18:23 . 2006-04-18 01:41 147456 ----a-w- c:\windows\system32\LEXBCE.DLL
2009-12-02 18:23 . 2006-04-18 01:41 174592 ----a-w- c:\windows\system32\LEXPPS.EXE
2009-12-02 18:23 . 2006-04-18 01:41 201216 ----a-w- c:\windows\system32\LEXP2P32.DLL
2009-12-02 18:23 . 2006-01-19 12:33 78336 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\LXCZPP5C.DLL
2009-12-02 18:23 . 2001-01-19 15:50 40960 ----a-w- c:\windows\system32\INSTMON.EXE
2009-12-02 18:22 . 2009-12-02 18:22 -------- d-----w- c:\program files\Lexmark 1200 Series
2009-12-02 18:22 . 2006-07-13 13:45 57344 ----a-w- c:\windows\system32\lxczcinf.dll
2009-12-02 18:22 . 2006-07-13 13:45 69632 ----a-w- c:\windows\system32\lxczscin.dll
2009-12-02 18:22 . 2006-07-13 13:45 49152 ----a-w- c:\windows\system32\lxczcoin.dll
2009-12-02 18:22 . 2006-07-13 13:22 458752 ----a-w- c:\windows\system32\LXCZJSWR.DLL
2009-12-02 18:22 . 2006-07-13 13:17 356352 ----a-w- c:\windows\system32\LXCZUTIL.DLL
2009-12-02 18:22 . 2006-01-12 12:32 983107 ----a-w- c:\windows\system32\LXCZGF.DLL
2009-12-02 18:21 . 2009-12-02 18:21 -------- d-----w- C:\Lexmark
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-27 22:40 . 2006-09-08 17:28 90112 ----a-w- c:\windows\DUMP926c.tmp
2009-12-27 22:12 . 2006-09-08 17:28 90112 ----a-w- c:\windows\DUMP41db.tmp
2009-12-19 23:27 . 2006-09-11 01:20 2048 ----a-w- c:\windows\system32\Tr_sttool.dat
2009-10-16 15:50 . 2009-11-10 18:18 2520888 ----a-w- c:\documents and settings\Liam\Application Data\Mozilla\Firefox\Profiles\5h1n0mz6.default\extensions\
[email protected]\plugins\npTVUAx.dll
2009-10-15 21:32 . 2009-10-15 21:32 409600 ----a-w- c:\windows\system32\lxducoin.dll
2009-10-13 10:30 . 2004-08-04 05:00 270336 ----a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2004-08-04 05:00 149504 ----a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2004-08-04 05:00 79872 ----a-w- c:\windows\system32\raschap.dll
2009-10-11 04:17 . 2009-04-16 23:50 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-08-12 16:27 . 2009-08-12 16:27 6910288 ----a-w- c:\program files\AutobahnAcceleratorInstall.exe
2009-04-19 22:30 . 2009-04-19 22:28 16509288 ----a-w- c:\program files\LimeWireWin.exe
2007-11-21 13:09 . 2007-11-21 13:09 24 --sh--w- c:\windows\S13A353B3.tmp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\Steam\Steam.exe" [2009-10-24 1217808]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" [X]
"AGRSMMSG"="AGRSMMSG.exe" [2006-03-16 88204]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2005-01-08 102491]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-01-08 692315]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-28 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-28 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-28 118784]
"ntiMUI"="c:\program files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe" [2005-05-11 45056]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2006-04-06 225280]
"eRecoveryService"="c:\acer\Empowering Technology\eRecovery\eRAgent.exe" [2006-04-28 401408]
"LogitechCameraAssistant"="c:\program files\Acer\OrbiCam\CameraAssistant.exe" [2006-04-06 331776]
"LogitechVideo[inspector]"="c:\program files\Acer\OrbiCam\InstallHelper.exe" [2006-04-06 19:06 73728]
"LogitechCameraService(E)"="c:\windows\system32\ElkCtrl.exe" [2004-11-01 262144]
"ImageItEncrypt"="c:\windows\system32\ImageItEncrypt.exe" [2005-12-30 40960]
"LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2006-03-30 471040]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-12-10 2043160]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"NSLauncher"="c:\program files\Nokia\Nokia Software Launcher\NSLauncher.exe" [2007-09-07 3100672]
"RTHDCPL"="RTHDCPL.EXE" [2006-02-27 16005120]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-28 141600]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"Lexmark 1200 Series"="c:\program files\Lexmark 1200 Series\lxczbmgr.exe" [2006-07-13 57344]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Liam\Start Menu\Programs\Startup\
autobahn.lnk - c:\documents and settings\Liam\Local Settings\Application Data\Autobahn\autobahn.exe [2009-4-2 710360]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 13:41 294912 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-07-30 18:00 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Steam\\SteamApps\\COMMON\\football manager 2009\\fm.exe"=
"c:\\WINDOWS\\System32\\lxducoms.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [27/03/2009 21:23 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [27/03/2009 21:23 335240]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [27/03/2009 21:23 108552]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [10/10/2006 13:53 5632]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [27/02/2007 12:39 32256]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [27/03/2009 21:23 297752]
R2 lxdu_device;lxdu_device;c:\windows\system32\lxducoms.exe -service --> c:\windows\system32\lxducoms.exe -service [?]
R3 lv321av;Logitech USB PC Camera (VC0321);c:\windows\system32\drivers\lv321av.sys [30/11/2005 20:28 1097472]
S2 eLock2BurnerLockDriver;eLock2BurnerLockDriver;\??\c:\windows\system32\eLock2BurnerLockDriver.sys --> c:\windows\system32\eLock2BurnerLockDriver.sys [?]
S2 eLock2FSCTLDriver;eLock2FSCTLDriver;\??\c:\windows\system32\eLock2FSCTLDriver.sys --> c:\windows\system32\eLock2FSCTLDriver.sys [?]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [16/02/2006 17:51 4096]
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.co.uk/ig?hl=en
uInternet Connection Wizard,ShellNext = hxxp://global.acer.com/
uInternet Settings,ProxyOverride = *.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspx
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {C9386579-3C0F-4713-82C6-5BA8088C7C8D} - hxxps://secure.shared.live.com/Pa6vGqB728AxD-ckvrPc0A/etc/Microsoft.Live.Folders.RichUpload.cab
FF - ProfilePath - c:\documents and settings\Liam\Application Data\Mozilla\Firefox\Profiles\5h1n0mz6.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/ig?hl=en
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?btnI=I%27m+Feeling+Lucky&q=
FF - component: c:\documents and settings\Liam\Application Data\Mozilla\Firefox\Profiles\5h1n0mz6.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\documents and settings\Liam\Application Data\Mozilla\Firefox\Profiles\5h1n0mz6.default\extensions\
[email protected]\plugins\npTVUAx.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-AzMixerSel - c:\program files\Realtek\InstallShield\AzMixerSel.exe
HKLM-Run-eDataSecurity Loader - c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe
HKLM-Run-RevHDD - c:\windows\SYSTEM\RevHDD.exe
HKLM-Run-lxdumon.exe - c:\program files\Lexmark 5600-6600 Series\lxdumon.exe
HKLM-Run-EzPrint - c:\program files\Lexmark 5600-6600 Series\ezprint.exe
SSODL-aswmklt-{3AB6ADA7-3518-4D69-BB7C-9205D29E0DD9} - c:\windows\aswmklt.dll
SSODL-bqxomdo-{C2CFA686-014E-4B1C-A0BC-DBB0CCC3DCAD} - c:\windows\bqxomdo.dll
AddRemove-RealJukebox 1.0 - c:\program files\Common Files\Real\Update_OB\r1puninst.exe
AddRemove-{7B63B2922B174135AFC0E1377DD81EC2} - c:\program files\DivX\DivXCodecUninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-12-29 15:46
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(672)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(4232)
c:\windows\system32\WININET.dll
c:\program files\Common Files\Logitech\LVMVFM\LVPrcInj.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\SUPERAntiSpyware\SASSEH.DLL
c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\program files\Microsoft Office\OFFICE11\msohev.dll
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\lxducoms.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\progra~1\AVG\AVG8\avgam.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\windows\AGRSMMSG.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\igfxext.exe
c:\program files\Lexmark 1200 Series\lxczbmon.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\fxssvc.exe
c:\\?\c:\windows\system32\WBEM\WMIADAP.EXE
.
**************************************************************************
.
Completion time: 2009-12-29 15:48:41 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-29 15:48
Pre-Run: 1,976,008,704 bytes free
Post-Run: 2,878,963,712 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - 1E80D555D18D99E8BFC3332F79855200