ComboFix 11-04-30.06 - Administrator 05/01/2011 8:28.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3323.2756 [GMT -6:00]
Running from: c:\documents and settings\Administrator.BRIANS\My Documents\Downloads\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Crack
c:\program files\Crack\groupmanager.exe
c:\program files\Internet Explorer\SET5F1.tmp
c:\program files\Internet Explorer\SET5F6.tmp
.
.
((((((((((((((((((((((((( Files Created from 2011-04-01 to 2011-05-01 )))))))))))))))))))))))))))))))
.
.
2011-04-22 03:09 . 2011-04-22 03:09 -------- d-----w- c:\documents and settings\Administrator.BRIANS\Application Data\Foxit Software
2011-04-22 02:55 . 2011-04-22 02:56 -------- d-----w- c:\program files\WhoCrashed2
2011-04-22 02:39 . 2011-04-08 05:14 2074216 ----a-w- c:\windows\system32\nvcuvenc.dll
2011-04-22 02:30 . 2011-04-18 17:17 307288 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-04-22 02:30 . 2011-04-18 17:12 19544 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-04-22 02:30 . 2011-04-18 17:17 441176 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-04-22 02:30 . 2011-04-18 17:16 49240 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-04-22 02:30 . 2011-04-18 17:13 25432 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-04-22 02:30 . 2011-04-18 17:16 102488 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-04-22 02:30 . 2011-04-18 17:16 96344 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-04-22 02:30 . 2011-04-18 17:13 30680 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-04-22 02:29 . 2011-04-18 17:25 40112 ----a-w- c:\windows\avastSS.scr
2011-04-22 02:29 . 2011-04-18 17:25 199304 ----a-w- c:\windows\system32\aswBoot.exe
2011-04-22 02:18 . 2011-04-22 02:18 -------- d-sh--w- c:\documents and settings\Administrator.BRIANS\IECompatCache
2011-04-22 02:16 . 2011-04-22 02:16 -------- d-----w- c:\windows\system32\Adobe
2011-04-22 02:07 . 2011-04-22 02:07 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\NVIDIA Corporation
2011-04-22 02:06 . 2011-04-08 05:14 944232 ----a-w- c:\windows\system32\nvdispco3220140.dll
2011-04-22 02:06 . 2011-04-08 05:14 855656 ----a-w- c:\windows\system32\nvgenco322060.dll
2011-04-20 03:12 . 2011-04-20 03:12 -------- d-----w- c:\program files\Western Digital Corporation
2011-04-16 19:55 . 2011-04-22 02:29 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\AVAST Software
2011-04-16 19:55 . 2011-04-16 19:55 -------- d-----w- c:\program files\AVAST Software
2011-04-16 18:09 . 2001-08-18 04:36 50688 -c--a-w- c:\windows\system32\dllcache\umaxscan.dll
2011-04-16 18:08 . 2008-04-14 11:42 27648 -c--a-w- c:\windows\system32\dllcache\rw430ext.dll
2011-04-16 18:07 . 2008-04-14 06:09 5504 -c--a-w- c:\windows\system32\dllcache\mstee.sys
2011-04-16 18:06 . 2001-08-18 04:36 372824 -c--a-w- c:\windows\system32\dllcache\iconf32.dll
2011-04-16 18:05 . 2001-08-17 18:10 44103 -c--a-w- c:\windows\system32\dllcache\el515.sys
2011-04-16 18:04 . 2001-08-17 19:51 13824 -c--a-w- c:\windows\system32\dllcache\bulltlp3.sys
2011-04-16 17:44 . 2011-04-22 02:40 259604 ----a-w- c:\windows\system32\nvdrsdb0.bin
2011-04-16 16:49 . 2000-10-05 22:01 602244 ----a-w- c:\program files\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe
2011-04-16 16:49 . 2000-10-05 21:55 77824 ----a-w- c:\program files\Common Files\InstallShield\Engine\6\Intel 32\ctor.dll
2011-04-16 16:49 . 2000-10-05 21:55 221184 ----a-w- c:\program files\Common Files\InstallShield\IScript\iscript.dll
2011-04-16 16:49 . 2000-10-05 21:50 221184 ----a-w- c:\program files\Common Files\InstallShield\Engine\6\Intel 32\iuser.dll
2011-04-16 16:49 . 2000-10-05 21:49 32768 ----a-w- c:\program files\Common Files\InstallShield\Engine\6\Intel 32\objectps.dll
2011-04-16 16:49 . 2011-04-16 16:49 -------- d-----w- c:\documents and settings\ADMINI~1~BRI
2011-04-16 16:36 . 2011-04-16 16:36 -------- d-----w- c:\windows\B9DB4C7601A446D58910F7AA6376DBAF.TMP
2011-04-16 15:58 . 2011-04-16 16:17 -------- d-----w- c:\program files\Driver Cleaner Pro
2011-04-16 01:21 . 2011-04-16 01:21 -------- d-----w- c:\program files\CCleaner
2011-04-16 00:37 . 2008-02-27 04:23 676224 ----a-w- c:\windows\system32\OGACheckControl.dll
2011-04-15 04:07 . 2011-04-15 04:07 -------- d-----w- c:\program files\Common Files\Java
2011-04-15 04:06 . 2011-04-15 04:06 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-04-15 04:03 . 2011-04-15 04:04 -------- d-----w- c:\program files\Registry Cleaner
2011-04-08 04:15 . 2011-04-08 04:15 81920 ----a-w- c:\windows\system32\nvwddi.dll
2011-04-08 04:15 . 2011-04-08 04:15 580200 ----a-w- c:\windows\system32\easyUpdatusAPIU.dll
2011-04-08 04:15 . 2011-04-08 04:15 277608 ----a-w- c:\windows\system32\nvmccs.dll
2011-04-08 04:15 . 2011-04-08 04:15 13891176 ----a-w- c:\windows\system32\nvcpl.dll
2011-04-08 04:15 . 2011-04-08 04:15 111208 ----a-w- c:\windows\system32\nvmctray.dll
2011-04-08 04:15 . 2011-04-08 04:15 155752 ----a-w- c:\windows\system32\nvsvc32.exe
2011-04-08 04:15 . 2011-04-08 04:15 145000 ----a-w- c:\windows\system32\nvcolor.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-15 04:06 . 2010-12-28 00:17 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-04-08 05:14 . 2007-10-25 09:17 4111232 ----a-w- c:\windows\system32\nv4_disp.dll
2011-04-08 05:14 . 2007-10-25 09:17 2027008 ----a-w- c:\windows\system32\nvapi.dll
2011-04-08 05:14 . 2007-10-25 09:17 14856192 ----a-w- c:\windows\system32\nvoglnt.dll
2011-04-08 05:14 . 2007-10-25 09:17 12501600 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2011-03-07 05:33 . 2010-11-10 05:44 692736 ------w- c:\windows\system32\inetcomm.dll
2011-03-04 06:37 . 2006-05-30 07:28 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-03-03 13:21 . 2006-05-30 07:28 1857920 ----a-w- c:\windows\system32\win32k.sys
2011-02-17 13:18 . 2006-05-30 07:28 455936 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-02-17 13:18 . 2006-05-30 07:28 357888 ----a-w- c:\windows\system32\drivers\srv.sys
2011-02-17 12:32 . 2010-11-11 00:09 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2011-02-15 12:56 . 2006-05-30 07:28 290432 ----a-w- c:\windows\system32\atmfd.dll
2011-02-09 13:53 . 2006-05-30 07:28 270848 ----a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53 . 2006-05-30 07:28 186880 ----a-w- c:\windows\system32\encdec.dll
2011-02-08 13:33 . 2006-05-30 07:28 978944 ----a-w- c:\windows\system32\mfc42.dll
2011-02-08 13:33 . 2006-05-30 07:28 974848 ----a-w- c:\windows\system32\mfc42u.dll
2011-02-02 07:58 . 2010-11-10 05:42 2067456 ----a-w- c:\windows\system32\mstscax.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-04-18 17:25 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-04-18 3460784]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2011-04-08 111208]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-04-08 13891176]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2011-02-24 1753192]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^Administrator.BRIANS^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Administrator.SIRSYSTEM^Start Menu^Programs^Startup^Xfire.lnk]
backup=c:\windows\pss\Xfire.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^DualCoreCenter.lnk]
backup=c:\windows\pss\DualCoreCenter.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Windows Search.lnk]
backup=c:\windows\pss\Windows Search.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BtcMaestro
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SysTrayApp
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-11-10 18:49 932288 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-01-30 15:45 35736 ----a-w- c:\program files\Adobe\Reader 10.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast]
2011-04-18 17:25 3460784 ----a-w- c:\program files\AVAST Software\Avast\AvastUI.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 ----a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2010-11-11 15:20 136176 ----atw- c:\documents and settings\Administrator.BRIANS\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 18:44 31072 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2007-09-26 08:35 162584 ----a-r- c:\windows\system32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2007-09-26 08:36 142104 ----a-r- c:\windows\system32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LiveMonitor]
2006-09-05 11:15 497152 ----a-w- c:\program files\MSI\Live Update 3\LMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ------w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2011-04-08 04:15 13891176 ----a-w- c:\windows\system32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2011-04-08 04:15 111208 ----a-w- c:\windows\system32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2011-02-24 08:57 1753192 ----a-w- c:\program files\NVIDIA Corporation\nView\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2007-09-26 08:36 138008 ----a-r- c:\windows\system32\igfxpers.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
2007-09-26 08:33 303104 ----a-w- c:\windows\sttray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2010-12-09 05:10 1242448 ----a-w- c:\program files\Steam\Steam.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-10-29 20:49 249064 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinSys2]
2007-10-30 08:37 208896 ----a-r- c:\windows\system32\WinSys2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"idsvc"=3 (0x3)
"ose"=3 (0x3)
"odserv"=3 (0x3)
"Microsoft Office Groove Audit Service"=3 (0x3)
"iPod Service"=3 (0x3)
"wscsvc"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [11/11/2010 10:04 PM 691696]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [4/21/2011 8:30 PM 441176]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [4/21/2011 8:30 PM 307288]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [4/21/2011 8:30 PM 19544]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 1:46 AM 130384]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [5/30/2006 1:28 AM 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 1:46 AM 753504]
.
--- Other Services/Drivers In Memory ---
.
*Deregistered* - klmd25
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
Contents of the 'Scheduled Tasks' folder
.
2011-04-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1220945662-2025429265-839522115-500Core.job
- c:\documents and settings\Administrator.BRIANS\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-04-11 15:20]
.
2011-05-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1220945662-2025429265-839522115-500UA.job
- c:\documents and settings\Administrator.BRIANS\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-04-11 15:20]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
- - - - ORPHANS REMOVED - - - -
.
MSConfigStartUp-GroupManager - c:\program files\Crack\groupmanager.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-05-01 08:33
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1220945662-2025429265-839522115-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,f6,1d,cc,31,ea,b6,89,41,9e,f9,9d,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,f6,1d,cc,31,ea,b6,89,41,9e,f9,9d,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2011-05-01 08:36:03
ComboFix-quarantined-files.txt 2011-05-01 14:36
.
Pre-Run: 567,011,262,464 bytes free
Post-Run: 567,561,723,904 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="MS WINDOWS XP SP2/SP3 UWin Installer Edition" /noexecute=optin /fastdetect
.
- - End Of File - - 0CF67061108B256C246E249CBAB9046D