Hello,
The first message I got was:
ComboFix needs to submit files for further analysis.
Please ensure that you're connected to the internet before clicking ok.
After clicking 'ok', inside the ComboFix window it eventually read:
Uploading files to server... 100%
Then, i received an Upload Failed!! message saying:
Web server appears to be temporarily inaccessible. For your convenience, ComboFix created a submissions form located at
*C:\CF-Submit.htm
Please use that to manually upload it later.
Here is the log:
ComboFix 11-01-13.01 - Steven 01/14/2011 0:33.9.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.958.567 [GMT -8:00]
Running from: c:\documents and settings\Steven\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Steven\Desktop\CFScript.txt
AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
FW: COMODO Firewall *Enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
file zipped: c:\windows\system32\netstat4.dll
.
((((((((((((((((((((((((( Files Created from 2010-12-14 to 2011-01-14 )))))))))))))))))))))))))))))))
.
2011-01-08 05:23 . 2011-01-08 05:24 -------- d-----w- c:\program files\ERUNT
2011-01-05 11:06 . 2005-04-29 23:18 201484 ----a-w- c:\windows\system32\drivers\umss.sys
2011-01-04 10:45 . 2011-01-04 10:44 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-01-03 01:23 . 2010-02-27 03:39 116224 ----a-w- c:\windows\system32\drivers\ubohci.sys
2011-01-03 01:23 . 2010-02-27 03:38 46592 ----a-w- c:\windows\system32\drivers\UBUMAPI.sys
2011-01-03 01:23 . 2010-02-27 03:38 17408 ----a-w- c:\windows\system32\drivers\UBSBM.sys
2011-01-03 01:23 . 2010-02-27 03:38 127488 ----a-w- c:\windows\system32\drivers\UB1394.sys
2011-01-01 11:45 . 2011-01-01 11:45 0 ----a-w- c:\windows\ativpsrm.bin
2011-01-01 11:42 . 2009-07-22 02:55 442368 ----a-w- c:\windows\system32\ATIDEMGX.dll
2011-01-01 11:42 . 2009-04-29 11:06 155648 ----a-w- c:\windows\system32\Oemdspif.dll
2011-01-01 11:42 . 2009-04-29 10:20 45056 ----a-w- c:\windows\system32\aticalrt.dll
2011-01-01 11:42 . 2009-04-29 10:18 3280896 ----a-w- c:\windows\system32\aticaldd.dll
2011-01-01 11:42 . 2009-02-26 12:44 49664 ----a-w- c:\windows\system32\amdpcom32.dll
2011-01-01 11:42 . 2008-10-22 10:51 118784 ----a-w- c:\windows\system32\atibrtmon.exe
2011-01-01 11:42 . 2009-04-29 10:20 45056 ----a-w- c:\windows\system32\aticalcl.dll
2011-01-01 11:42 . 2009-04-29 10:20 135168 ----a-w- c:\windows\system32\atiadlxx.dll
2011-01-01 11:42 . 2009-04-29 10:17 303104 ----a-w- c:\windows\system32\atiok3x2.dll
2010-12-31 01:11 . 2009-04-23 10:24 258048 ----a-w- c:\windows\system32\UCI32M40.dll
2010-12-31 01:11 . 2009-04-29 11:21 410624 ----a-r- c:\windows\system32\XAudio32.dll
2010-12-31 01:11 . 2009-04-29 11:20 8704 ----a-r- c:\windows\system32\drivers\XAudio32.sys
2010-12-31 00:55 . 2010-12-31 00:55 -------- d-----w- c:\documents and settings\Steven\Local Settings\Application Data\Innovative Solutions
2010-12-31 00:55 . 2010-12-31 00:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Innovative Solutions
2010-12-31 00:55 . 2010-12-31 00:55 -------- d-----w- c:\program files\Innovative Solutions
2010-12-31 00:14 . 2009-03-03 12:18 73728 ----a-w- c:\windows\system32\RtNicProp32.dll
2010-12-31 00:14 . 2008-02-25 20:54 105088 ----a-w- c:\windows\system32\drivers\Rtnicxp.sys
2010-12-31 00:07 . 2010-12-31 00:07 -------- d-----w- c:\windows\system32\wbem\Repository
2010-12-30 23:57 . 2010-12-31 00:07 -------- d-----w- c:\program files\Apoint2K
2010-12-30 23:38 . 2010-12-30 23:38 -------- d-----w- c:\program files\Realtek
2010-12-30 23:14 . 2010-12-30 23:14 -------- d-----w- c:\program files\Realtek AC97
2010-12-30 23:14 . 2006-02-07 23:45 757760 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iKernel.dll
2010-12-30 23:14 . 2006-02-07 23:40 204800 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iuser.dll
2010-12-30 23:14 . 2006-02-07 23:40 69715 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ctor.dll
2010-12-30 23:14 . 2006-02-07 23:40 274432 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iscript.dll
2010-12-30 23:14 . 2005-11-14 07:19 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\DotNetInstaller.exe
2010-12-30 23:14 . 2010-12-30 23:14 331908 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\setup.dll
2010-12-30 23:14 . 2010-12-30 23:14 200836 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iGdi.dll
2010-12-30 22:56 . 2010-12-30 22:56 -------- d-----w- c:\documents and settings\Steven\Application Data\DeviceDoctorSoftware
2010-12-30 22:34 . 2010-12-30 22:34 -------- d-----w- c:\documents and settings\All Users\Uniblue
2010-12-30 22:14 . 2010-12-30 22:21 -------- d-----w- c:\documents and settings\Steven\Application Data\MSNInstaller
2010-12-29 08:16 . 2011-01-14 07:58 -------- d-----w- c:\windows\system32\CatRoot2
2010-12-15 10:35 . 2010-11-06 00:26 5959168 -c----w- c:\windows\system32\dllcache\mshtml.dll
2010-12-15 10:35 . 2010-11-06 00:26 11080704 -c----w- c:\windows\system32\dllcache\ieframe.dll
2010-12-15 10:35 . 2010-10-11 14:59 45568 -c----w- c:\windows\system32\dllcache\wab.exe
2010-12-15 10:26 . 2010-11-02 15:17 40960 -c----w- c:\windows\system32\dllcache\ndproxy.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-12 01:27 . 2010-09-11 07:41 285480 ----a-w- c:\windows\system32\guard32.dll
2011-01-12 01:26 . 2010-09-11 07:40 94784 ----a-w- c:\windows\system32\drivers\inspect.sys
2011-01-12 01:26 . 2010-09-11 07:40 27576 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2011-01-12 01:26 . 2010-09-11 07:40 15592 ----a-w- c:\windows\system32\drivers\cmderd.sys
2011-01-12 01:26 . 2010-09-11 07:40 239368 ----a-w- c:\windows\system32\drivers\cmdGuard.sys
2011-01-04 10:44 . 2010-09-18 02:37 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-12-31 04:33 . 2009-07-13 12:22 520192 ----a-w- c:\windows\system32\ati2sgag.exe
2010-12-22 12:48 . 2010-12-02 08:01 135096 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-12-21 02:09 . 2010-08-29 04:51 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-21 02:08 . 2010-08-29 04:51 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-05 02:48 . 2010-12-02 08:01 61960 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-11-30 01:38 . 2010-11-30 01:38 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2010-11-30 01:38 . 2010-11-30 01:38 69632 ----a-w- c:\windows\system32\QuickTime.qts
2010-11-18 18:12 . 2009-07-13 11:45 81920 ----a-w- c:\windows\system32\isign32.dll
2010-11-09 14:52 . 2004-08-04 12:00 249856 ----a-w- c:\windows\system32\odbc32.dll
2010-11-06 00:26 . 2004-08-04 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2010-11-06 00:26 . 2004-08-04 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-11-06 00:26 . 2004-08-04 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-11-03 12:25 . 2004-08-04 12:00 385024 ----a-w- c:\windows\system32\html.iec
2010-11-02 15:17 . 2004-08-04 12:00 40960 ----a-w- c:\windows\system32\drivers\ndproxy.sys
2010-10-28 13:13 . 2004-08-04 12:00 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-10-26 13:25 . 2004-08-04 12:00 1853312 ----a-w- c:\windows\system32\win32k.sys
2010-10-19 20:51 . 2010-11-26 12:17 222080 ------w- c:\windows\system32\MpSigStub.exe
2009-11-08 00:00 . 2009-11-08 00:00 28488 ----a-w- c:\program files\mozilla firefox\plugins\atgpcdec.dll
2009-11-08 00:00 . 2009-11-08 00:00 185240 ----a-w- c:\program files\mozilla firefox\plugins\atgpcext.dll
2009-11-08 00:00 . 2009-11-08 00:00 99224 ----a-w- c:\program files\mozilla firefox\plugins\ieatgpc.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinPatrol System Monitor"="c:\program files\BillP Studios\WinPatrol\WinPatrol.exe" [2010-05-31 323976]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-08-03 281768]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2011-01-12 2548040]
c:\documents and settings\Steven\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoPopUpsOnBoot"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\guard32.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\rootrepeal.sys]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
2004-09-07 21:47 57344 ------w- c:\windows\Alcxmntr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
2007-09-14 01:50 1603152 ----a-w- c:\program files\Canon\MyPrinter\BJMYPRT.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu]
2007-10-26 01:10 652624 ----a-w- c:\program files\Canon\SolutionMenu\CNSLMAIN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinPatrol]
2010-05-31 11:18 323976 ------w- c:\program files\BillP Studios\WinPatrol\WinPatrol.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ATI Smart"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"Lavasoft Ad-Aware Service"=2 (0x2)
"VSSERV"=2 (0x2)
"LIVESRV"=2 (0x2)
"idsvc"=3 (0x3)
"JavaQuickStarterService"=2 (0x2)
"ose"=3 (0x3)
"TMWebProtect"=2 (0x2)
"TmProxy"=2 (0x2)
"MatSvc"=3 (0x3)
"IS360service"=2 (0x2)
"sp_rssrv"=2 (0x2)
"AntiVirService"=2 (0x2)
"AntiVirSchedulerService"=2 (0x2)
"gupdate"=2 (0x2)
"ACDaemon"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [9/17/2010 10:49 AM 28552]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [9/10/2010 11:40 PM 239368]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [9/10/2010 11:40 PM 27576]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [7/13/2009 10:41 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [7/13/2009 10:41 AM 74480]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [12/2/2010 12:01 AM 135336]
R2 ubsbm;Unibrain 1394 SBM Driver;c:\windows\system32\drivers\UBSBM.sys [1/2/2011 5:23 PM 17408]
R2 ubumapi;Unibrain 1394 FireAPI Driver;c:\windows\system32\drivers\UBUMAPI.sys [1/2/2011 5:23 PM 46592]
R3 TMPassthruMP;TMPassthruMP;c:\windows\system32\drivers\TMPassthru.sys [1/10/2010 3:58 AM 206608]
R3 ubohci;Unibrain 1394 OHCI Driver;c:\windows\system32\drivers\ubohci.sys [1/2/2011 5:23 PM 116224]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 12:16 PM 130384]
S2 HsfXAudioService;HsfXAudioService;c:\windows\system32\svchost.exe -k HsfXAudioService [8/4/2004 4:00 AM 14336]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [7/13/2009 10:41 AM 7408]
S3 TMPassthru;Trend Micro Passthru Ndis Service;c:\windows\system32\drivers\TMPassthru.sys [1/10/2010 3:58 AM 206608]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [8/4/2004 4:00 AM 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 12:16 PM 753504]
S4 gupdate;Google Update Service (gupdate); [x]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
HsfXAudioService REG_MULTI_SZ HsfXAudioService
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
FF - ProfilePath - c:\documents and settings\Steven\Application Data\Mozilla\Firefox\Profiles\kn5tze51.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.startup.homepage - hxxp://www.aol.com/
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?sourceid=navclient&hl=en&q=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: TVU Web Player: firefox@tvunetworks.com - %profile%\extensions\firefox@tvunetworks.com
FF - Ext: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - %profile%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - user.js: browser.cache.memory.capacity - 16000
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 4095
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 1000000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 1000000
FF - user.js: dom.disable_window_status_change - true
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 1000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-01-14 00:37
Windows 5.1.2600 Service Pack 3 NTFS
detected NTDLL code modification:
ZwClose, ZwOpenFile
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(952)
c:\windows\system32\guard32.dll
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'lsass.exe'(1024)
c:\windows\system32\guard32.dll
- - - - - - - > 'explorer.exe'(456)
c:\windows\system32\WININET.dll
c:\windows\system32\guard32.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
Completion time: 2011-01-14 00:40:08
ComboFix-quarantined-files.txt 2011-01-14 08:40
Pre-Run: 129,413,591,040 bytes free
Post-Run: 129,399,382,016 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - 4C9A829EA07AEBCCFE8F42AE1FA0A01F