ComboFix 11-12-13.03 - MIstrz 2011-12-14 12:34:42.1.4 - x86 Microsoft Windows XP Professional 5.1.2600.3.1250.48.1045.18.3326.2666 [GMT 1:00] Uruchomiony z: i:\programy windows\Naprawa sysyemu\ComboFix.exe . . ((((((((((((((((((((((((((((((((((((((( Usunięto ))))))))))))))))))))))))))))))))))))))))))))))))) . . C:\CEPx202C.tmp C:\CEPx5256.tmp C:\CEPx6599.tmp C:\CEPx8F48.tmp C:\CEPxBBF4.tmp c:\documents and settings\All Users\Dane aplikacji\TEMP c:\program files\codec c:\program files\codec\AC3Filter\ac3config.exe c:\program files\codec\AC3Filter\ac3filter_reg_presets.reg c:\program files\codec\AC3Filter\ac3filter_reg_renderers_win2k.reg c:\program files\codec\AC3Filter\ac3filter_reg_reset.reg c:\program files\codec\CoreAVC\coreavc.ico c:\program files\codec\Divx6\config.exe c:\program files\codec\Haali\avi.dll c:\program files\codec\Haali\dxr.dll c:\program files\codec\Haali\mkunicode.dll c:\program files\codec\Haali\mkx.dll c:\program files\codec\Haali\mkzlib.dll c:\program files\codec\Haali\mp4.dll c:\program files\codec\Haali\ogm.dll c:\program files\codec\Haali\splitter.ax c:\program files\codec\Haali\ts.dll c:\program files\codec\history.txt c:\program files\codec\readme.txt c:\program files\codec\Uninstall\unins000.dat c:\program files\codec\Uninstall\unins000.exe c:\program files\codec\XviD\xvid.ico c:\windows\msmqinst.log c:\windows\system32\lsprst7.dll c:\windows\system32\ssprs.dll . . ((((((((((((((((((((((((( Pliki utworzone od 2011-11-14 do 2011-12-14 ))))))))))))))))))))))))))))))) . . 2029-09-07 11:31 . 2029-09-07 11:31 28714 ----a-w- c:\windows\system32\codec.dat 2011-12-13 16:14 . 2011-12-13 16:14 -------- d-----w- c:\program files\XPRepairPro2006 2011-12-13 13:26 . 2011-12-13 13:26 1409 ----a-w- c:\windows\QTFont.for 2011-12-11 11:20 . 2011-12-14 10:16 -------- d-----w- c:\program files\Steam 2011-12-10 11:09 . 2011-12-13 15:40 -------- d-----w- c:\program files\GameSpy Arcade 2011-12-07 05:43 . 2011-12-09 19:43 215128 ----a-w- c:\windows\system32\PnkBstrB.xtr 2011-12-07 05:41 . 2011-12-09 15:17 -------- d-----w- c:\documents and settings\MIstrz\Ustawienia lokalne\Dane aplikacji\PunkBuster 2011-12-07 04:50 . 2011-12-09 15:13 138056 ----a-r- c:\documents and settings\MIstrz\Dane aplikacji\PnkBstrK.sys 2011-12-07 04:50 . 2011-12-09 18:32 270240 ----a-w- c:\windows\system32\PnkBstrB.ex0 2011-12-07 04:27 . 2011-12-13 15:42 -------- d-----w- c:\program files\EA Games 2011-12-04 07:35 . 2011-12-04 07:35 2106216 ----a-w- c:\program files\Mozilla Firefox\D3DCompiler_43.dll 2011-12-04 07:35 . 2011-12-04 07:35 1998168 ----a-w- c:\program files\Mozilla Firefox\d3dx9_43.dll 2011-12-01 22:01 . 2011-12-02 02:52 -------- d-----w- c:\program files\Midifile Optimizer 7 DEMO 2011-11-25 00:42 . 2011-11-25 00:47 -------- d-----w- c:\documents and settings\MIstrz\Dane aplikacji\wargaming.net 2011-11-21 22:43 . 1998-04-24 16:06 96256 ----a-w- c:\windows\system32\aspiCtr.dll 2011-11-21 22:43 . 1997-08-08 14:57 160768 ----a-w- c:\windows\system32\CBXFirm.dll 2011-11-18 03:46 . 2011-12-10 12:48 -------- d-----w- c:\documents and settings\MIstrz\.gstreamer-0.10 2011-11-18 03:45 . 2011-12-12 06:32 -------- d-----w- c:\documents and settings\MIstrz\Ustawienia lokalne\Dane aplikacji\ChomikBox 2011-11-18 03:45 . 2011-11-18 03:45 -------- d-----w- c:\program files\ChomikBox . . . (((((((((((((((((((((((((((((((((((((((( Sekcja Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-12-14 10:15 . 2010-09-18 13:47 17488 ----a-w- c:\windows\gdrv.sys 2011-10-31 10:53 . 2011-10-31 10:53 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2004-06-21 12:23 . 2003-12-27 12:05 1319424 ----a-w- c:\program files\MysticalTTC.exe 2003-12-04 16:01 . 2003-12-27 12:05 1419264 ----a-w- c:\program files\Mystical_PlugIn_TTC.8bf 2011-12-04 07:35 . 2011-06-01 20:40 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ------- Sigcheck ------- Note: Unsigned files aren't necessarily malware. . [-] 2008-05-17 12:35 . 9994E5A07D951FC1B0F5FB18501090FC . 1526784 . . [2001.12.4414.700] . . c:\windows\system32\comres.dll . [-] 2008-05-17 . 5F1CCDF37F28A88D0473B0C9EA1E0D58 . 487424 . . [5.1.2600.5512] . . c:\windows\system32\user32.dll . [-] 2008-05-17 . 67EACB65FBB0997DD3BE8E4F1A5FE069 . 1503232 . . [6.00.2900.5512] . . c:\windows\explorer.exe . [-] 2008-05-17 . 3122DAF86B33ED8AC4662D07593025D7 . 501760 . . [1.0626.6001.18000] . . c:\windows\system32\usp10.dll . [-] 2008-05-17 . 0277E1A3E8B337555A45943808451981 . 40448 . . [5.1.2600.5512] . . c:\windows\system32\ctfmon.exe . . [-] 2008-05-16 . C8BDAD4065118558B3DC360FC96D81DB . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll . . [-] 2008-05-16 12:10 . C51B4A5C05A5475708E3C81C7765B71D . 27136 . . [11.0.5721.5145] . . c:\windows\system32\mspmsnsv.dll . . c:\windows\System32\wscntfy.exe ... - brak elementu !! c:\windows\System32\regsvc.dll ... - brak elementu !! . ((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2011-02-23 14:04 122512 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TaskSwitchXP"="c:\program files\TaskSwitchXP\TaskSwitchXP.exe" [2006-08-04 62976] "VisualTaskTips"="c:\program files\Utilities\VisualTaskTips\VisualTaskTips.exe" [2007-09-05 36352] "GAINWARD"="c:\program files\EXPERTool\TBPanel.exe" [2009-10-05 2174976] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-09-03 94208] "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-11-29 39408] "Odkurzacz-MCD"="c:\program files\Odkurzacz 12\odk_mcd.exe" [2009-12-12 349184] "Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-10-13 17351304] "TomTomHOME.exe"="c:\program files\TomTom HOME 2\TomTomHOMERunner.exe" [2011-04-22 247728] "ChomikBox"="c:\program files\ChomikBox\ChomikBox.exe" [2011-11-07 5758976] "Steam"="c:\program files\Steam\Steam.exe" [2011-12-11 1242448] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BCU"="c:\program files\DeviceVM\Browser Configuration Utility\BCU.exe" [2009-08-04 346320] "RTHDCPL"="RTHDCPL.EXE" [2009-08-14 18702336] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-09-27 86016] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-09-27 13918208] "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672] "H2O"="c:\program files\SyncroSoft\Pos\H2O\cledx.exe" [2005-12-18 307200] "avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2011-02-23 3451496] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040] "SearchSettings"="c:\program files\Common Files\Spigot\Search Settings\SearchSettings.exe" [2011-09-27 894304] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "TaskSwitchXP"="c:\program files\TaskSwitchXP\TaskSwitchXP.exe" [2006-08-04 62976] "VisualTaskTips"="c:\program files\Utilities\VisualTaskTips\VisualTaskTips.exe" [2007-09-05 36352] "Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-10-13 17351304] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "nltide_2"="shell32" [X] "nltide_3"="advpack.dll" [2010-11-06 124928] . c:\documents and settings\MIstrz\Menu Start\Programy\Autostart\ Microsoft Office Groove.lnk - c:\program files\Microsoft Office\Office12\GROOVE.EXE [2006-10-27 338216] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "SynchronousMachineGroupPolicy"= 0 (0x0) "SynchronousUserGroupPolicy"= 0 (0x0) . [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "NoSMHelp"= 1 (0x1) "NoSMConfigurePrograms"= 1 (0x1) "NoResolveTrack"= 1 (0x1) . [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer] "NoSMHelp"= 1 (0x1) "NoSMConfigurePrograms"= 1 (0x1) "NoResolveTrack"= 1 (0x1) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "midi2"=xgusb.cpl "midi7"=xgusb.cpl . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0autocheck OODBS\0OODBS . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) "DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0) . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= "g:\\GRY\\Electronic Arts\\Battlefield Bad Company 2\\BFBC2Updater.exe"= "c:\\Program Files\\Steam\\Steam.exe"= . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "3591:TCP"= 3591:TCP:kmikawm . R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2010-09-21 691696] R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-04-13 371544] R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-02-16 301528] R1 kl2;kl2;c:\windows\system32\drivers\kl2.sys [2010-06-09 11352] R1 VBoxDrv;VirtualBox Service;c:\windows\system32\drivers\VBoxDrv.sys [2010-09-09 55424] R1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\drivers\VBoxUSBMon.sys [2010-09-09 42048] R2 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [2011-09-27 745880] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-02-16 19544] R2 BCUService;Browser Configuration Utility Service;c:\program files\DeviceVM\Browser Configuration Utility\BCUService.exe [2010-09-10 219360] R2 ES lite Service;ES lite Service for program management.;c:\program files\Gigabyte\EasySaver\essvr.exe [2010-09-10 68136] R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [2011-04-22 92592] R3 CLEDX;Team H2O CLEDX service;c:\windows\system32\drivers\cledx.sys [2010-10-10 33792] R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2010-05-07 32856] R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2009-11-02 19472] R3 WsAudioDevice_383;WsAudioDevice_383;c:\windows\system32\drivers\WsAudioDevice_383.sys [2010-10-04 16640] S2 cgrbylja;Microsoft Monitor;c:\windows\system32\svchost.exe -k netsvcs [2008-04-14 14336] S2 gupdate;Usługa Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-11-29 136176] S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2010-09-10 1684736] S3 gupdatem;Usługa Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-11-29 136176] . --- Inne Usługi/Sterowniki w Pamięci --- . *NewlyCreated* - SRSERVICE . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs phomybzml wjrmbotia . Zawartość folderu 'Zaplanowane zadania' . 2011-12-14 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 15:57] . 2011-12-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-11-29 04:26] . 2011-12-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-11-29 04:26] . 2011-12-14 c:\windows\Tasks\WGASetup.job - c:\windows\system32\KB905474\wgasetup.exe [2010-11-23 21:18] . . ------- Skan uzupełniający ------- . uStart Page = hxxp://www.google.com/ uSearchMigratedDefaultURL = hxxp://www.google.com/custom?client=pub-3794288947762788&forid=1&channel=1975384696&ie=UTF-8&oe=UTF-8&safe=active&cof=GALT%3A%23008000%3BGL%3A1%3BDIV%3A%23336699%3BVLC%3A663399%3BAH%3Acenter%3BBGC%3AFFFFFF%3BLBGC%3A336699%3BALC%3A0000FF%3BLC%3A0000FF%3BT%3A000000%3BGFNT%3A0000FF%3BGIMP%3A0000FF%3BFORID%3A1&hl=pl&q={searchTerms} uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://www.google.com/keyword/%s IE: E&ksportuj do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 Trusted Zone: google.com\mail TCP: DhcpNameServer = 192.168.1.1 FF - ProfilePath - c:\documents and settings\MIstrz\Dane aplikacji\Mozilla\Firefox\Profiles\pp5wu3nh.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.pl/ FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=937811&p= . . ------- Skojarzenia plików ------- . inifile=c:\windows\system32\Notepad2.exe %1 txtfile=c:\windows\system32\Notepad2.exe %1 . - - - - USUNIĘTO PUSTE WPISY - - - - . HKLM-Run-NWEReboot - (no file) HKLM-Run-Ulead Quick-Drop - c:\program files\Ulead Systems\Ulead DVD MovieFactory 5 Plus\Ulead DVD MovieFactory 5\Quick-Drop.exe HKU-Default-Run-Komunikator - c:\program files\Tlen.pl\tlen.exe AddRemove-Codec_is1 - c:\program files\Codec\Uninstall\unins000.exe AddRemove-NVIDIA nView Desktop Manager - c:\program files\NVIDIA Corporation\nView\nViewSetup.exe . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2011-12-14 12:52 Windows 5.1.2600 Dodatek Service Pack 3 NTFS . skanowanie ukrytych procesów ... . skanowanie ukrytych wpisów autostartu ... . skanowanie ukrytych plików ... . skanowanie pomyślnie ukończone ukryte pliki: 0 . ************************************************************************** . [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{95808DC4-FA4A-4C74-92FE-5B863F82066B}] "ImagePath"="\??\c:\program files\CyberLink\PowerDVD\000.fcl" . [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\cgrbylja] "ServiceDll"="c:\windows\system32\sxlpa.dll" . --------------------- ZABLOKOWANE KLUCZE REJESTRU --------------------- . [HKEY_USERS\S-1-5-21-1844237615-1770027372-1417001333-1002\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{405AE1A4-27F9-536B-2266-AC0267E377B2}*] @Allowed: (Read) (RestrictedCode) @Allowed: (Read) (RestrictedCode) "bbomjhjdanibkicabakhpdhejodgphnioekm"=hex:62,61,70,6b,00,00 . [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*] "OODEFRAG10.00.00.01WORKSTATION"="968D2243AB8975F8C5A8009D2C16FA7BDA0F569411D0AB62DCFE6BD0791A3350F81872000131AFDB2078AE6B83584160FBEEEE173A0E68EEA734497427D1B0444C3A35A8447CAE57F3906DD81422C86FC64AA692788FD953018390BA564A17FD496B2FFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B9808BA7FD869164D6794A9C6AECB7A5D1407A6A0AC4980AC79339C2CD9A62F354769F06A0EF56E25511602095C85D2CA5F9682EEB7A7E18FB78EAF622EE8C87F0DE54A3E747A9217101F93E07771F3E28B79E3FB03CFA87314694A257CE0589A4858C04626E9187D9CBCED5275246DF5397BF7CB7B87EEC06B9FE622D96AEB00245F17D5496CA50983693C7431B11E0A7613F25C4C736D74EC48645BE1D6B1C110CC76130B9E040014D611328525073A156FF0FCA2A97E1D8A2B07A634E87E823FA76BF899139FBB63E6E2CCD47CCC34A9707053AF34A0DEF946752E71594A7D28A965562A4D0929C83109D783A93C398D2852D7A813F67035CA3B6E42542F7B85C2B94D73C6F549E002C2BAF8124121DD62DE57493AC89BFA1F48B950796FDE5894205531EBBE310DD8AF31A190EC55FB9A3F734C8F00C1CC5C6FB6C9DCED1C62F635B8A39F600AEEE757CAF0F277D48C00819E76EE2CD571D068DEE10733BA2B71F9170E357B92EF19A1EB58FAB9B178F899A38B25005E72FBCE7FCEF1E9577E4552E2B777D59A3C055CCBD25E31116D9CDC1FD4F853779F9622B94D90E221EAE487E16CA05887C4FDB8F6DBC8802E5DB80601A09D9F4F8886C40619C5125D43F5C3AF7CE38ED3BD854BCC7356EDD87BCC338FC1C004AA846C00AA77698E641ED29ABBBA662A8B1C548F80209AE16FC20EE6610C80C45F2E977CC7ABC615A2D70AFCC77F3F0150A055E29B6999EAEB6FE38764D9EEC6D9E30E4C4D849E061810DE466BA6FD0A5748298477DB4FBAD7036CDFD988151797C689E083CD266358A846B0108EA26469D7219A45872A29CFC2F69D56FAECE32EBD7893025A83568C496D5E761BA0CFE5D8462F088389AC07378953C294E4FD43737C1EB70253ABF0DC3053AFB4E230BB15552F19664566C4AD5AF85A41DF5F1354E821661F2651D51323F623C74610F09FBB6D22CCA816E1B7D766B06EB6A16C93499EA38F7F5D9FDD0B960BC29B1C9F499D9CA5586E234EAAA25CA70C338333275AFE5937570645766462F798A7A4F3ADD1D8F3AC4B96899E0DFAF99015E75EC98E8DC37B9AA655D65CEE4AC2239E2FA6E59DB7F2E49D2CF122CAB3F68ED5F7F80979F6C728416E3D55B3BA3C3B232854974DEBD8530C60C59D34B43AC678A177A656570AD4F8C4AE660E538312EE461CDAAD5F8D2756E37EEE08345F581E8C4A721B9FB56715A070D93EF29EBB63" . --------------------- Pliki DLL ładowane pod uruchomionymi procesami --------------------- . - - - - - - - > 'winlogon.exe'(1264) c:\windows\system32\SETUPAPI.dll c:\windows\system32\sfc_os.dll c:\windows\system32\cscui.dll . - - - - - - - > 'lsass.exe'(1320) c:\windows\system32\setupapi.dll . Czas ukończenia: 2011-12-14 12:58:56 ComboFix-quarantined-files.txt 2011-12-14 11:58 . Przed: 31 890 587 648 bajtów wolnych Po: 35 445 633 024 bajtów wolnych . WindowsXP-KB310994-SP2-Pro-BootDisk-PLK.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons UnsupportedDebug="do not select this" /debug multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer . - - End Of File - - 0352399FFB6B3E871B9AABA2A20AA540