ComboFix 08-07-29.1 - Owner 2008-07-29 23:12:35.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.407 [GMT -5:00]
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\WinXP_EN_HOM_BF.EXE
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Herbert Magombe\Application Data\macromedia\Flash Player\#SharedObjects\HRFSNHCE\interclick.com
C:\Documents and Settings\Herbert Magombe\Application Data\macromedia\Flash Player\#SharedObjects\HRFSNHCE\interclick.com\ud.sol
C:\Documents and Settings\Herbert Magombe\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\Herbert Magombe\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\WINDOWS\BM57247bb3.txt
C:\WINDOWS\BM57247bb3.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\hosts
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\dcIilnnn.ini
C:\WINDOWS\system32\dcIilnnn.ini2
C:\WINDOWS\system32\FeddKkkj.ini
C:\WINDOWS\system32\FeddKkkj.ini2
C:\WINDOWS\system32\hjknmnnn.ini
C:\WINDOWS\system32\hjknmnnn.ini2
C:\WINDOWS\system32\hoveqseg.ini
C:\WINDOWS\system32\hqdwqogw.ini
C:\WINDOWS\system32\iahpflxt.ini
C:\WINDOWS\system32\igtumswj.ini
C:\WINDOWS\system32\ihradkww.ini
C:\WINDOWS\system32\jSAJlnpo.ini
C:\WINDOWS\system32\jSAJlnpo.ini2
C:\WINDOWS\system32\khfDwVOH.dll
C:\WINDOWS\system32\khfFXpnm.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\nnnliIcd.dll
C:\WINDOWS\system32\opnlJASj.dll
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\rajvwkld.ini
C:\WINDOWS\system32\rbvostvg.ini
C:\WINDOWS\system32\vhsjiabb.ini
L:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-06-28 to 2008-07-30 )))))))))))))))))))))))))))))))
.
2008-07-29 21:40 . 2008-07-29 21:40 83,456 --a------ C:\WINDOWS\system32\wgoqwdqh.dll
2008-07-29 21:38 . 2008-07-29 21:38 105,472 --a------ C:\WINDOWS\system32\vpuctlou.dll
2008-07-29 21:38 . 2008-07-29 21:38 105,472 --a------ C:\WINDOWS\system32\egsyql.dll
2008-07-29 21:38 . 2008-07-29 21:38 91,648 --a------ C:\WINDOWS\system32\bnqqjgrh.dll
2008-07-29 21:33 . 2008-07-29 21:33 83,456 --a------ C:\WINDOWS\system32\gvtsovbr.dll
2008-07-29 21:30 . 2008-07-29 21:30 105,472 --a------ C:\WINDOWS\system32\xgpvsbwu.dll
2008-07-29 21:30 . 2008-07-29 21:30 105,472 --a------ C:\WINDOWS\system32\bwrecx.dll
2008-07-29 21:28 . 2008-07-29 21:28 91,648 --a------ C:\WINDOWS\system32\vrsdvnen.dll
2008-07-29 21:27 . 2008-07-29 21:27 314,880 --a------ C:\WINDOWS\system32\geBtSKCt.dll
2008-07-29 19:59 . 2008-07-29 19:59 83,456 --a------ C:\WINDOWS\system32\bbaijshv.dll
2008-07-29 19:56 . 2008-07-29 19:56 105,472 --a------ C:\WINDOWS\system32\nlruvu.dll
2008-07-29 19:56 . 2008-07-29 19:56 105,472 --a------ C:\WINDOWS\system32\jnchiwed.dll
2008-07-29 19:54 . 2008-07-29 19:54 91,648 --a------ C:\WINDOWS\system32\erdocybo.dll
2008-07-29 19:53 . 2008-07-29 19:53 314,880 --a------ C:\WINDOWS\system32\jkkKddeF.dll
2008-07-29 18:44 . 2008-07-29 18:45 <DIR> d-------- C:\Program Files\Windows Defender
2008-07-28 23:52 . 2008-07-29 07:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Google Updater
2008-07-28 23:32 . 2008-07-28 23:32 105,472 --a------ C:\WINDOWS\system32\ymdhfuhl.dll
2008-07-28 23:32 . 2008-07-28 23:32 105,472 --a------ C:\WINDOWS\system32\nyvhwr.dll
2008-07-28 23:28 . 2008-07-28 23:29 83,456 --a------ C:\WINDOWS\system32\dlkwvjar.dll
2008-07-28 23:23 . 2008-07-28 23:23 91,648 --a------ C:\WINDOWS\system32\odutbuta.dll
2008-07-28 23:22 . 2008-07-28 23:22 314,880 --a------ C:\WINDOWS\system32\nnnmnkjh.dll
2008-07-28 19:54 . 2008-07-28 19:54 83,456 --a------ C:\WINDOWS\system32\jwsmutgi.dll
2008-07-28 19:52 . 2008-07-28 19:52 105,472 --a------ C:\WINDOWS\system32\rtjcebib.dll
2008-07-28 19:52 . 2008-07-28 19:52 105,472 --a------ C:\WINDOWS\system32\rnpxea.dll
2008-07-28 19:52 . 2008-07-28 19:52 91,648 --a------ C:\WINDOWS\system32\pokmmyil.dll
2008-07-28 19:39 . 2008-07-28 19:39 113,880 --a------ C:\WINDOWS\system32\qgjyoknt.exe
2008-07-28 19:36 . 2008-07-28 19:36 105,472 --a------ C:\WINDOWS\system32\jnrhxb.dll
2008-07-28 19:36 . 2008-07-28 19:36 105,472 --a------ C:\WINDOWS\system32\fibwgvjt.dll
2008-07-28 19:33 . 2008-07-28 19:33 83,456 --a------ C:\WINDOWS\system32\wwkdarhi.dll
2008-07-28 19:30 . 2008-07-28 19:30 91,648 --a------ C:\WINDOWS\system32\uadljbvl.dll
2008-07-27 23:57 . 2008-07-29 22:45 303 --a------ C:\WINDOWS\wininit.ini
2008-07-27 21:21 . 2008-07-27 23:24 <DIR> d-------- C:\WINDOWS\system32\RTCOM
2008-07-27 21:21 . 2005-05-12 14:00 14,396,416 --a------ C:\WINDOWS\RTHDCPL.EXE
2008-07-27 21:21 . 2008-07-27 21:21 294,912 --a------ C:\WINDOWS\HideWin.exe
2008-07-27 21:21 . 2005-05-12 14:00 262,144 --a------ C:\WINDOWS\system32\RTSndMgr.Cpl
2008-07-27 21:21 . 2005-05-12 14:00 40,960 --a------ C:\WINDOWS\system32\ChCfg.exe
2008-07-27 21:20 . 2008-07-27 21:20 <DIR> d-------- C:\cabs
2008-07-27 21:20 . 2005-05-12 14:00 487,424 --------- C:\WINDOWS\RtlExUpd.dll
2008-07-27 20:48 . 2008-07-27 20:48 105,472 --a------ C:\WINDOWS\system32\netrwrxy.dll
2008-07-27 20:48 . 2008-07-27 20:48 105,472 --a------ C:\WINDOWS\system32\kujcxh.dll
2008-07-27 20:48 . 2008-07-27 20:48 91,648 --a------ C:\WINDOWS\system32\gxhxmelh.dll
2008-07-27 20:48 . 2008-07-27 20:48 83,456 --a------ C:\WINDOWS\system32\txlfphai.dll
2008-07-27 14:40 . 2008-07-27 14:43 <DIR> d-------- C:\WINDOWS\system32\kBin19
2008-07-27 14:40 . 2008-07-27 14:40 <DIR> d-------- C:\Temp\epr1
2008-07-08 21:10 . 2008-07-17 20:01 <DIR> d-------- C:\Documents and Settings\Herbert Magombe\Application Data\U3
2008-06-30 15:45 . 2008-06-30 15:45 0 --a------ C:\Application Data\wklnhst.dat
2008-06-20 12:41 . 2008-06-20 12:41 245,248 -----c--- C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 05:44 . 2008-06-20 05:44 138,368 -----c--- C:\WINDOWS\system32\dllcache\afd.sys
2008-06-11 12:06 . 2008-06-13 08:10 272,128 --a------ C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 12:06 . 2008-06-13 08:10 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-07 21:33 . 2008-06-07 21:33 268 --ah----- C:\sqmdata02.sqm
2008-06-07 21:33 . 2008-06-07 21:33 244 --ah----- C:\sqmnoopt02.sqm
2008-06-06 20:25 . 2008-06-06 20:25 268 --ah----- C:\sqmdata01.sqm
2008-06-06 20:25 . 2008-06-06 20:25 244 --ah----- C:\sqmnoopt01.sqm
2008-06-06 20:18 . 2008-06-06 20:18 <DIR> d-------- C:\Program Files\MSECache
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-30 00:51 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-07-29 12:43 --------- d-----w C:\Program Files\Google
2008-07-29 00:09 --------- d-----w C:\Program Files\Norton AntiVirus
2008-07-28 05:00 --------- d-----w C:\Documents and Settings\Herbert Magombe\Application Data\Yahoo!
2008-07-28 04:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-28 04:30 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-07-28 02:21 --------- d-----w C:\Program Files\Realtek
2008-07-28 02:15 --------- d-----w C:\Program Files\BigFix
2008-06-27 03:26 --------- d-----w C:\Program Files\CMATP44
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-04 03:03 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-06-04 03:03 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-06-04 03:03 10,671 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-06-04 03:03 --------- d-----w C:\Program Files\Symantec
2007-11-07 14:56 0 ----a-w C:\Documents and Settings\Ted Stewart\Application Data\wklnhst.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:00 15360]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-12-11 11:56 286720]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 21:05 204288]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-07 09:42 2156368]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-12 18:49 68856]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"SpybotDeletingB7520"="command" [X]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunKistEM"="C:\Program Files\Digital Media Reader\shwiconem.exe" [2004-03-11 17:18 135168]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 22:59 115816]
"osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [2006-09-05 21:22 26248]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-12-15 11:18 49152]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-11-28 20:51 583048]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-12-11 11:56 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-12-11 13:10 267048]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-02-15 21:41 185896]
"5417482f"="C:\DOCUME~1\HERBER~1\LOCALS~1\Temp\cabepxvp.dll" [2008-07-29 20:48 83456]
"BM57247bb3"="C:\WINDOWS\system32\bnqqjgrh.dll" [2008-07-29 21:38 91648]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 17:07 61952 C:\WINDOWS\system32\HdAShCut.exe]
"SoundMan"="SOUNDMAN.EXE" [2005-05-12 14:00 90112 C:\WINDOWS\SOUNDMAN.EXE]
"AlcWzrd"="ALCWZRD.EXE" [2005-05-12 14:00 2805248 C:\WINDOWS\ALCWZRD.EXE]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-12-15 11:40:44 282624]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BigFix.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BigFix.lnk
backup=C:\WINDOWS\pss\BigFix.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-10-13 11:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 13:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CHotkey]
--a--c--- 2004-05-17 20:30 543232 C:\WINDOWS\zHotkey.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]
--a------ 2004-03-17 17:10 61952 C:\WINDOWS\system32\Hdaudpropshortcut.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ShowWnd]
--a--c--- 2003-09-19 11:09 36864 C:\WINDOWS\ShowWnd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
S3 MN710-51;Microsoft® Wireless USB 2.0 Adapter;C:\WINDOWS\system32\DRIVERS\MN710-51.sys [2004-01-07 19:04]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d5366560-fdc2-11db-b15c-834cd9b8cd43}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
2008-03-01 C:\WINDOWS\Tasks\Disk Cleanup.job
- C:\WINDOWS\system32\cleanmgr.exe [2004-08-04 07:00]
2008-07-30 C:\WINDOWS\Tasks\MP Scheduled Scan.job
- C:\Program Files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
2008-07-05 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Owner.job
- C:\PROGRA~1\NORTON~1\Navw32.exe [2006-09-07 01:38]
.
- - - - ORPHANS REMOVED - - - -
BHO-{42BFABD3-B070-4053-9485-30D7E000D3D3} - (no file)
BHO-{6CBB4252-CE26-420C-B9B4-C8758CDD8E34} - (no file)
HKCU-Run-ccleaner - C:\Program Files\CCleaner\ccleaner.exe
MSConfigStartUp-AOL Spyware Protection - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
MSConfigStartUp-mmtask - c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.rwandajb2008.blogspot.com/
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
R1 -: HKCU-Internet Settings,ProxyOverride = *.local
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s
O8 -: &AOL Toolbar search - C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-29 23:28:12
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe
-> C:\DOCUME~1\HERBER~1\LOCALS~1\Temp\cabepxvp.dll
-> C:\WINDOWS\system32\bnqqjgrh.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\LxrJD31s.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\Program Files\Symantec\LiveUpdate\AUPDATE.EXE
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\WINDOWS\system32\verclsid.exe
.
**************************************************************************
.
Completion time: 2008-07-29 23:32:55 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-30 04:32:47
Pre-Run: 186,796,769,280 bytes free
Post-Run: 187,003,281,408 bytes free
WinXP_EN_HOM_BF.EXE
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
274 --- E O F --- 2008-07-09 08:02:59