Anonim / 8 lat, 7 miesięcy temu | Download | Plaintext | Odpowiedz |

  1
  2
  3
  4
  5
  6
  7
  8
  9
 10
 11
 12
 13
 14
 15
 16
 17
 18
 19
 20
 21
 22
 23
 24
 25
 26
 27
 28
 29
 30
 31
 32
 33
 34
 35
 36
 37
 38
 39
 40
 41
 42
 43
 44
 45
 46
 47
 48
 49
 50
 51
 52
 53
 54
 55
 56
 57
 58
 59
 60
 61
 62
 63
 64
 65
 66
 67
 68
 69
 70
 71
 72
 73
 74
 75
 76
 77
 78
 79
 80
 81
 82
 83
 84
 85
 86
 87
 88
 89
 90
 91
 92
 93
 94
 95
 96
 97
 98
 99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
ComboFix 09-05-02.4 - Roman 2009-05-02 15:53.1 - NTFSx86
Microsoft Windows XP Home Edition  5.1.2600.3.1250.48.1045.18.1023.569 [GMT 2:00]
Uruchomiony z: c:\documents and settings\Roman\Pulpit\ComboFix.exe
AV: ESET Smart Security 3.0 *On-access scanning disabled* (Updated)
FW: COMODO Firewall Pro *enabled*
FW: Zapora osobista *enabled*
.

(((((((((((((((((((((((((   Pliki utworzone od 2009-04-02 do 2009-05-02  )))))))))))))))))))))))))))))))
.

2009-04-26 05:23 . 2005-01-31 10:19	7104	----a-r	c:\windows\system32\drivers\lv302af.sys
2009-04-26 04:57 . 2005-01-31 10:00	106496	----a-r	c:\windows\system32\lvcoinst.dll
2009-04-26 04:57 . 2005-01-31 10:12	22016	----a-r	c:\windows\system32\drivers\LVUSBSta.sys
2009-04-26 04:57 . 2005-01-31 10:18	372736	----a-r	c:\windows\system32\LVUI2RC.dll
2009-04-26 04:57 . 2005-01-31 10:10	204800	----a-r	c:\windows\system32\LVUI2.dll
2009-04-26 04:57 . 2005-01-31 10:08	204800	----a-r	c:\windows\system32\lvcodec2.dll
2009-04-26 04:57 . 2005-01-31 10:04	2180096	----a-r	c:\windows\system32\drivers\LVSVF2.sys
2009-04-26 04:57 . 2005-01-31 10:26	912768	----a-r	c:\windows\system32\drivers\LV302AV.SYS
2009-04-26 04:56 . 2009-04-26 04:56	--------	d-----w	c:\documents and settings\Roman\Ustawienia lokalne\Dane aplikacji\Logitech-LS
2009-04-25 08:35 . 2004-10-08 10:46	53248	----a-r	c:\windows\system32\InstMed.exe
2009-04-16 08:19 . 2008-04-21 21:16	218112	-c----w	c:\windows\system32\dllcache\wordpad.exe
2009-04-16 08:16 . 2009-02-06 10:10	227840	-c----w	c:\windows\system32\dllcache\wmiprvse.exe
2009-04-16 08:16 . 2009-03-06 14:22	285696	-c----w	c:\windows\system32\dllcache\pdh.dll
2009-04-16 08:16 . 2009-02-09 11:25	111104	-c----w	c:\windows\system32\dllcache\services.exe
2009-04-16 08:16 . 2009-02-09 10:53	401408	-c----w	c:\windows\system32\dllcache\rpcss.dll
2009-04-16 08:16 . 2009-02-09 10:53	473600	-c----w	c:\windows\system32\dllcache\fastprox.dll
2009-04-16 08:16 . 2009-02-09 10:53	686592	-c----w	c:\windows\system32\dllcache\advapi32.dll
2009-04-16 08:16 . 2009-02-09 10:53	731136	-c----w	c:\windows\system32\dllcache\lsasrv.dll
2009-04-16 08:16 . 2009-02-09 10:53	453120	-c----w	c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-16 08:16 . 2009-02-09 10:53	722944	-c----w	c:\windows\system32\dllcache\ntdll.dll
2009-04-13 18:45 . 2009-05-02 13:52	--------	d-----w	c:\documents and settings\Roman\Dane aplikacji\Skype
2009-04-13 18:45 . 2009-04-13 18:45	--------	d-----r	c:\program files\Skype
2009-04-13 18:33 . 2009-04-26 05:47	--------	d-----w	c:\program files\Logitech
2009-04-13 18:31 . 2006-12-08 10:02	251672	----a-w	c:\windows\system32\xactengine2_5.dll
2009-04-13 18:31 . 2006-11-29 11:06	3426072	----a-w	c:\windows\system32\d3dx9_32.dll
2009-04-13 18:31 . 2006-09-28 14:05	237848	----a-w	c:\windows\system32\xactengine2_4.dll
2009-04-13 18:31 . 2007-03-05 10:42	15128	----a-w	c:\windows\system32\x3daudio1_1.dll
2009-04-13 18:31 . 2006-09-28 14:05	2414360	----a-w	c:\windows\system32\d3dx9_31.dll
2009-04-13 18:31 . 2009-04-14 22:01	--------	d-----w	c:\windows\Logs
2009-04-02 17:54 . 2009-04-02 17:57	--------	d-----w	c:\documents and settings\Roman\Dane aplikacji\Nikon
2009-04-02 17:47 . 2009-05-02 10:46	20	---h--w	c:\documents and settings\All Users\Dane aplikacji\PKP_DLdw.DAT
2009-04-02 17:42 . 2009-04-02 17:42	--------	d-----w	c:\program files\Common Files\muvee Technologies
2009-04-02 17:42 . 2009-04-02 17:42	--------	d-----w	c:\documents and settings\All Users\Dane aplikacji\Nikon
2009-04-02 17:42 . 2009-04-02 17:56	--------	d-----w	c:\program files\Common Files\Nikon
2009-04-02 17:41 . 2009-04-02 17:48	--------	d-----w	c:\program files\Nikon
2009-04-02 17:41 . 2009-05-02 10:46	20	---h--w	c:\documents and settings\All Users\Dane aplikacji\PKP_DLdu.DAT
2009-04-02 17:41 . 2009-04-02 17:47	--------	d-----w	c:\documents and settings\All Users\Dane aplikacji\Ultima_T15
2009-04-02 17:41 . 2009-04-02 17:47	--------	d-----w	c:\documents and settings\All Users\Dane aplikacji\EnterNHelp
2009-04-02 17:38 . 2009-04-05 14:38	--------	d-----w	c:\program files\QuickTime

.
((((((((((((((((((((((((((((((((((((((((   Sekcja Find3M   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-02 13:51 . 2007-06-01 16:54	6	---ha-w	c:\windows\Tasks\SA.DAT
2009-05-02 11:21 . 2009-02-08 20:18	882	----a-w	c:\windows\Tasks\GoogleUpdateTaskMachine.job
2009-05-02 08:01 . 2007-06-02 21:22	--------	d-----w	c:\program files\Kalendarz XP
2009-05-02 07:50 . 2008-12-16 13:43	310	----a-w	c:\windows\Tasks\GlaryInitialize.job
2009-05-01 15:15 . 2007-10-29 11:48	390	----a-w	c:\windows\Tasks\1-Click Maintenance.job
2009-04-25 08:35 . 2007-06-05 20:23	--------	d-----w	c:\program files\Common Files\LogiShrd
2009-04-25 08:34 . 2009-03-29 12:15	--------	d-----w	c:\program files\Common Files\Logitech
2009-04-25 08:34 . 2007-06-02 19:23	--------	d--h--w	c:\program files\InstallShield Installation Information
2009-04-24 04:38 . 2007-06-02 20:16	284	----a-w	c:\windows\Tasks\AppleSoftwareUpdate.job
2009-04-17 05:13 . 2003-04-16 12:00	76324	----a-w	c:\windows\system32\perfc015.dat
2009-04-17 05:13 . 2003-04-16 12:00	454512	----a-w	c:\windows\system32\perfh015.dat
2009-04-15 17:05 . 2007-09-06 13:42	--------	d-----w	c:\program files\Spybot - Search & Destroy
2009-04-12 18:58 . 2009-03-04 16:56	--------	d-----w	c:\program files\Malwarebytes' Anti-Malware
2009-04-06 13:32 . 2009-03-04 16:57	38496	----a-w	c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-06 13:32 . 2009-03-04 16:57	15504	----a-w	c:\windows\system32\drivers\mbam.sys
2009-03-16 12:18 . 2009-04-13 18:32	69448	----a-w	c:\windows\system32\XAPOFX1_3.dll
2009-03-16 12:18 . 2009-04-13 18:32	517448	----a-w	c:\windows\system32\XAudio2_4.dll
2009-03-16 12:18 . 2009-04-13 18:32	235352	----a-w	c:\windows\system32\xactengine3_4.dll
2009-03-16 12:18 . 2009-04-13 18:32	22360	----a-w	c:\windows\system32\X3DAudio1_6.dll
2009-03-10 13:11 . 2007-06-02 20:13	--------	d-----w	c:\program files\Java
2009-03-09 13:27 . 2009-04-13 18:32	453456	----a-w	c:\windows\system32\d3dx10_41.dll
2009-03-09 13:27 . 2009-04-13 18:32	1846632	----a-w	c:\windows\system32\D3DCompiler_41.dll
2009-03-09 13:27 . 2009-04-13 18:32	4178264	----a-w	c:\windows\system32\D3DX9_41.dll
2009-03-06 14:22 . 2003-04-16 12:00	285696	----a-w	c:\windows\system32\pdh.dll
2009-03-03 00:10 . 2003-04-16 12:00	826368	----a-w	c:\windows\system32\wininet.dll
2009-02-20 17:13 . 2007-06-01 18:15	78336	----a-w	c:\windows\system32\ieencode.dll
2009-02-10 17:09 . 2002-09-20 17:12	2067328	----a-w	c:\windows\system32\ntkrnlpa.exe
2009-02-09 14:07 . 2003-04-16 12:00	1847040	----a-w	c:\windows\system32\win32k.sys
2009-02-09 11:26 . 2003-04-16 12:00	2190336	----a-w	c:\windows\system32\ntoskrnl.exe
2009-02-09 11:25 . 2003-04-16 12:00	111104	----a-w	c:\windows\system32\services.exe
2009-02-09 10:53 . 2003-04-16 12:00	731136	----a-w	c:\windows\system32\lsasrv.dll
2009-02-09 10:53 . 2003-04-16 12:00	686592	----a-w	c:\windows\system32\advapi32.dll
2009-02-09 10:53 . 2003-04-16 12:00	401408	----a-w	c:\windows\system32\rpcss.dll
2009-02-09 10:53 . 2003-04-16 12:00	722944	----a-w	c:\windows\system32\ntdll.dll
2009-02-06 10:39 . 2003-04-16 12:00	35328	----a-w	c:\windows\system32\sc.exe
2009-02-03 19:58 . 2003-04-16 12:00	56832	----a-w	c:\windows\system32\secur32.dll
.

(((((((((((((((((((((((((((((((((((((   Wpisy startowe rejestru   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyœlne, prawid³owe wpisy nie s¹ pokazane  
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-03-27 24103720]
"LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" [2005-01-18 196608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SiSUSBRG"="c:\windows\SiSUSBrg.exe" [2002-04-26 102400]
"WheelMouse"="c:\program files\A4Tech\Mouse\Amoumain.exe" [2006-12-26 196608]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2007-11-23 1410304]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2004-10-08 221184]
"LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2005-01-18 458752]
"LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2005-01-18 217088]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\Roman\Menu Start\Programy\Autostart\
Nikon Monitor.lnk - c:\program files\Common Files\Nikon\Monitor\NkMonitor.exe [2007-10-18 479232]

c:\documents and settings\All Users\Menu Start\Programy\Autostart\
Kalendarz XP.lnk - c:\program files\Kalendarz XP\Kalendarz.exe [2009-1-30 882176]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute	REG_MULTI_SZ   	autocheck autochk *\[u]0[/u]OODBS

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Logitech Desktop Messenger.lnk]
path=c:\documents and settings\All Users\Menu Start\Programy\Autostart\Logitech Desktop Messenger.lnk
backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AntiSpyWare2Guard
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CafeNews
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R2 gupdate1c98a2a5e97c110;Google Update Service (gupdate1c98a2a5e97c110);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-08 133104]
R3 GT680xNT;715 USB Scanner Driver;c:\windows\system32\drivers\gt680x.sys [2003-02-27 17376]
S0 AFPAnsi;G-DATA Ukrywacz Ansi;c:\windows\System32\Drivers\AFPAnsi.sys [2002-10-09 43904]
S0 FO_PAnt;FotoOffice VirtualDisc Driver;c:\windows\System32\Drivers\FO_PAnt.sys [2003-07-17 89216]
S2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2007-11-23 455936]
S3 Amps2prt;A4Tech PS/2 Port Mouse Driver;c:\windows\system32\DRIVERS\Amps2prt.sys [2006-05-09 13824]


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs
UxTuneUp

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9e4fa8a0-23c1-11dc-bcdd-000e2e2a659b}]
\Shell\Auto\command - G:\Cn911.exe
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Cn911.exe

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
ZawartoϾ folderu 'Zaplanowane zadania'

2009-05-01 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe [2007-04-26 20:51]

2009-04-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 13:42]

2009-05-02 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-08 20:18]
.
- - - - USUNIÊTO PUSTE WPISY - - - -

BHO-{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - (no file)


.
------- Skan uzupe³niaj¹cy -------
.
uStart Page = hxxp://www.wp.pl/
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&ksportuj do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: microsoft.com\windowsupdate
Trusted Zone: mks.com.pl\www
Trusted Zone: windowsupdate.com
TCP: {97A3C926-957C-44E7-AAF4-A8EC1B0A6288} = 217.30.129.149 217.30.137.200
DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} - hxxp://downloads.ewido.net/ewidoOnlineScan.cab
DPF: {3D8700FB-86A4-4CB4-B738-6F0FC016AC7D} - hxxp://slimak.onet.pl/_m/wirusy/ArcaOnline.cab
DPF: {68282C51-9459-467B-95BF-3C0E89627E55} - hxxp://www.mks.com.pl/skaner/SkanerOnline.cab
FF - ProfilePath - c:\documents and settings\Roman\Dane aplikacji\Mozilla\Firefox\Profiles\irlebw65.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.wp.pl/
FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=10615&gct=&gc=1&q=
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPAskSBr.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npcnmozillainterface.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-02 15:56
Windows 5.1.2600 Dodatek Service Pack 3 NTFS

skanowanie ukrytych procesów ...  

skanowanie ukrytych wpisów autostartu ... 

skanowanie ukrytych plików ...  

skanowanie pomyœlnie ukoñczone
ukryte pliki: 0

**************************************************************************
.
--------------------- ZABLOKOWANE KLUCZE REJESTRU ---------------------

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG08.00.00.01WORKSTATION"="9AF872E278C6222F15B0CCE8D274DBBBB4ABD83B3516AFEAA6D3811DBE85DE89566603F303D259667D4EEBB81E8089F1C040B1C5DF0FAB2E5B36CC6DFD5A41F0643277E35845FE70994FE274D6B562A9BB2B128ECAE4C40B0195BA9AE5F5097A111AB32541E6D79E9451FDD275CB6508D305D231BE5A4F1CE426C7C5324807D469117F7D0BF5CB555FA2EE6077EBB349FA1AAD9E88A5478F9A51D8E52135AE46433E878803A1E7102D484B7CDC3313B9E4EC401CFA73CC2BF736B6437513982634FADDB57C105E59F6780C5A2A34ED3C8BB08DC1EAE1A0C395FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C8EDD5E5BE2F6E667A6171C11EC38DE3DC038D530D6EB3452FEBC9E127BECC74C80C376EB94223421B8C90943F1B316F9E75C647C459D1AFB3E295E14A57363A317A473D8425DE645DB69D853A8331FF23E8D46BE64238B893620AC8DE872FE2FD926237F50C1437E042BB8C9E76B082CC2EA05CA0BEE21CC21FB9954D0E49E1BB997AE7F0891A3DF9B6B391305F91D587EF6B67E3B92BF39C507DE56AE75DA3C58B098F72830763E43E5BFA34C9BC26CAE1AC4BCEF485E071EF10D88467861AA0E88328CE22BBC3151BD85EDFC34F1A3C41FEB6B916B8BB05AD105E2D36072C1679EA3E75D2E8E184C7B966DC74A33FA67353F7603FA65745B9EFEDF80C6652222526AB6B28A1513F087539FD688A8B56F7024CB179AA0D539B484FEEFE921AFB2EAD3A7EFB78F06B12F7206443E83D8EA48D45E1693861E3D55F5C43628A493C011867117CFCF9CB0A7F9251E5F0CAF1A18DE253C517156E5A28439DB878039A7D1F74B9E8F3BC1C706C809E7801C48731EA299B863D34DE52737E65F31D9D0761EF4727159CDA883440F3D98DD25F321FE583BAFFDB197A44F695EB0F2EACDF1CC9CA8EBB21444A241D0D49BD629C8FE42088DBAF9A18BBBE9C932B43B7FE90F96E330E147314F1DBF68E3CFEC3F2220521015E351D044792D5BFA45A17A20FC1911D296E1DA4618E4810587C8139DC97FA1DE2DA48022E1AF74D42FDCCFB01856C0DD4776DC6AF13C9CD68B33E41DF3FCC3F7083884C62A6F3F5EB24B0921F532E2A1A09B93C03B348F79159D85C64EE0CEF2DE74C31ABC4CBCBB06EC4437DCF5BBF143097214379F039253195F06B8A871E60D63BB46388ABC145167B1814850E029C71F006EDFB2F1CCEADBEA074AB2AD6F6137FC3CEFD16893B18397CD695341A237DCD5A3E0892FD57143B83C4BC2D8A9A1C12A2E6A30386939ADCEB222F11A3F0EEAA2C79A23DF5EF1CC6CDCB97F1DB985FCFD13E115FDC96BF6C4060A0800E24012A7B3A260FA9B6B9B3C6347F4F644B783C2A544D459EBC1947965EDD05B77B33F3C85C0094DC952F5F40C581239F55995D9"
.
--------------------- Pliki DLL ³adowane pod uruchomionymi procesami ---------------------

- - - - - - - > 'winlogon.exe'(612)
c:\windows\SYSTEM32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(3628)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Czas ukoñczenia: 2009-05-02 15:59
ComboFix-quarantined-files.txt  2009-05-02 13:59

Przed: 6 618 152 960 bajtów wolnych
Po: 6 618 894 336 bajtów wolnych

WindowsXP-KB310994-SP2-Home-BootDisk-PLK.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

207	--- E O F ---	2009-04-29 08:02