Hi, thanks again. Please find the Combo scan below.
ComboFix 08-10-29.07 - homey 2008-10-29 19:59:06.1 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2008-09-28 to 2008-10-29 )))))))))))))))))))))))))))))))
.
2008-10-27 22:30 . 2008-10-27 22:32 d——– C:\Documents and Settings\All Users\Application Data\Watermark Factory
2008-10-27 22:29 . 2008-10-27 22:30 d——– C:\Program Files\Watermark Factory 2
2008-10-26 07:13 . 2008-10-26 07:15 d——– C:\rsit
2008-10-25 20:48 . 2008-10-25 20:48 d——– C:\_OTScanIt
2008-10-25 01:21 . 2008-10-25 01:22 d——– C:\Documents and Settings\All Users\Application Data\WinZip
2008-10-24 08:37 . 2008-10-24 08:37 d——– C:\Program Files\Trend Micro
2008-10-23 19:41 . 2008-10-15 16:34 337,408 —–c— C:\WINDOWS\system32\dllcache\netapi32.dll
2008-10-21 15:14 . 2008-10-21 15:14 d——– C:\Documents and Settings\staff\Application Data\InterVideo
2008-10-21 11:39 . 2008-10-21 11:39 d——– C:\Documents and Settings\staff\Application Data\Malwarebytes
2008-10-16 13:38 . 2008-10-16 14:38 d——– C:\Documents and Settings\staff\Contacts
2008-10-15 20:51 . 2008-10-15 21:00 d——– C:\Documents and Settings\homey\Contacts
2008-10-15 20:18 . 2008-10-15 20:30 d——– C:\Program Files\Windows Live
2008-10-15 20:18 . 2008-10-15 20:23 d–hsc— C:\Program Files\Common Files\WindowsLiveInstaller
2008-10-15 20:09 . 2008-10-15 20:25 d——– C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-10-15 06:09 . 2008-09-08 10:41 333,824 —–c— C:\WINDOWS\system32\dllcache\srv.sys
2008-10-15 06:07 . 2008-08-14 10:11 2,189,184 —–c— C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-10-15 06:07 . 2008-08-14 10:09 2,145,280 —–c— C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-10-15 06:07 . 2008-08-14 09:33 2,023,936 —–c— C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-10-15 06:07 . 2008-09-15 12:12 1,846,400 —–c— C:\WINDOWS\system32\dllcache\win32k.sys
2008-10-15 06:06 . 2008-08-14 09:33 2,066,048 —–c— C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-10-08 10:12 . 2008-10-08 10:12 d——– C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-10-05 22:14 . 2008-10-05 22:14 d——– C:\Documents and Settings\homey\Application Data\Malwarebytes
2008-10-05 22:13 . 2008-10-24 08:06 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-10-05 22:13 . 2008-10-05 22:13 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-05 22:13 . 2008-10-22 15:10 38,496 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-05 22:13 . 2008-10-22 15:10 15,504 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-10-05 21:40 . 2008-10-05 21:40 578,560 –a–c— C:\WINDOWS\system32\dllcache\user32.dll
2008-10-05 21:35 . 2008-10-05 21:35 d——– C:\WINDOWS\ERUNT
2008-10-05 20:56 . 2008-10-05 20:58 d——– C:\Program Files\PDF to Text
2008-09-30 06:01 . 2004-05-14 15:53 462,848 –a—— C:\WINDOWS\system32\ltkrn13n.dll
2008-09-30 06:01 . 2004-05-14 15:53 450,560 –a—— C:\WINDOWS\system32\ltimg13n.dll
2008-09-30 06:01 . 2004-05-14 15:53 401,408 –a—— C:\WINDOWS\system32\lfcmp13n.dll
2008-09-30 06:01 . 2004-05-14 15:53 299,008 –a—— C:\WINDOWS\system32\ltdis13n.dll
2008-09-30 06:01 . 2004-01-12 01:09 206,336 –a—— C:\WINDOWS\system32\ltefx13n.dll
2008-09-30 06:01 . 2004-05-14 15:53 163,840 –a—— C:\WINDOWS\system32\ltfil13n.dll
2008-09-30 06:01 . 2003-11-04 14:10 69,632 –a—— C:\WINDOWS\system32\lfgif13n.dll
2008-09-30 06:01 . 2004-05-14 15:53 57,344 –a—— C:\WINDOWS\system32\lfbmp13n.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-19 19:15 ——— d—–w C:\Program Files\Norton Security Scan
2008-10-19 19:15 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-10-15 09:16 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-10-05 16:20 ——— d—–w C:\Documents and Settings\All Users\Application Data\Cyberlink
2008-10-03 20:42 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-09-29 19:44 ——— d—–w C:\Documents and Settings\homey\Application Data\CyberLink
2008-09-29 13:55 ——— d—–w C:\Documents and Settings\staff\Application Data\Sony Corporation
2008-09-26 22:35 ——— d—–w C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-09-26 21:58 ——— d—–w C:\Program Files\FLV Player
2008-09-26 13:46 ——— d—–w C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-09-26 13:45 ——— d—–w C:\Program Files\iPod
2008-09-26 13:42 ——— d—–w C:\Program Files\QuickTime
2008-09-26 13:41 ——— d—–w C:\Program Files\Common Files\Apple
2008-09-26 13:26 ——— d—–w C:\Program Files\Bonjour
2008-09-21 09:19 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-09-21 09:19 ——— d—–w C:\Program Files\EPSON
2008-09-14 17:59 ——— d—–w C:\Documents and Settings\homey\Application Data\AdobeUM
2008-09-09 12:00 ——— d—–w C:\Documents and Settings\staff\Application Data\AdobeUM
2008-09-08 19:28 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-08 10:41 333,824 —-a-w C:\WINDOWS\system32\drivers\srv.sys
2008-08-31 22:43 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2008-08-28 21:15 ——— d—–w C:\Documents and Settings\homey\Application Data\Apple Computer
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-08-24 437160]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"NWTRAY"="NWTRAY.EXE" [2002-03-12 C:\WINDOWS\system32\nwtray.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
"CompatibleRUPSecurity"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"wave1"= c_511980.nls
"aux2"= c_511980.nls
"wave2"= c_511980.nls
"mixer2"= c_511980.nls
"midi1"= c_511980.nls
"midi2"= c_511980.nls
"aux1"= c_511980.nls
"mixer1"= c_511980.nls
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwv1_0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
backup=C:\WINDOWS\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
–a—— 2004-12-14 01:12 483328 C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Version Cue CS2]
–a—— 2005-04-04 17:58 856064 C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
–a—— 2004-11-17 11:47 118784 C:\Program Files\Apoint\Apoint.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
–a—— 2008-09-03 19:12 111936 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
–a—— 2007-11-26 12:53 115560 C:\Program Files\Common Files\Symantec Shared\ccApp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
–a—— 2008-04-14 00:12 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
–a—— 2005-08-05 13:56 64512 C:\WINDOWS\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus C64 Series]
–a—— 2003-05-27 03:08 99840 C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S10IC2.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
–a—— 2007-08-24 06:00 33648 C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
–a—— 2006-11-14 14:01 50736 C:\Program Files\Common Files\aol\1219490642\ee\aolsoftware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iPrint Tray]
–a—— 2006-10-18 14:14 40960 C:\WINDOWS\system32\iprntctl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISBMgr.exe]
–a—— 2004-02-20 14:12 32768 C:\Program Files\Sony\ISB Utility\ISBMgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
–a—— 2005-08-11 14:30 249856 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2008-09-10 16:40 289576 D:\itunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
——— 2008-04-14 00:12 1695232 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
–a—— 2007-10-18 10:34 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a—— 2006-03-06 08:33 7557120 C:\WINDOWS\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-09-06 14:09 413696 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SonyPowerCfg]
–a—— 2005-12-13 22:43 217088 C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs—- 2008-09-16 11:16 1833296 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SsAAD.exe]
–a—— 2006-01-07 01:36 81920 C:\PROGRA~1\Sony\SONICS~1\SSAAD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
–a—— 2008-07-02 20:13 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Switcher.exe]
–a—— 2006-02-14 12:11 176128 C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NWTRAY]
–a—— 2002-03-12 09:37 28672 C:\WINDOWS\system32\nwtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WLSetupSvc"=3 (0x3)
"usnjsvc"=3 (0x3)
"iPod Service"=3 (0x3)
"gusvc"=3 (0x3)
"Bonjour Service"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
"AOL ACS"=2 (0x2)
"Adobe Version Cue CS2"=3 (0x3)
"Adobe LM Service"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Adobe\\Adobe Version Cue CS2\\bin\\VersionCueCS2.exe"=
"C:\\Program Files\\Symantec\\Symantec Endpoint Protection\\Smc.exe"=
"C:\\Program Files\\Symantec\\Symantec Endpoint Protection\\SNAC.EXE"=
"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Novell\\GroupWise\\grpwise.exe"=
"C:\\Novell\\GroupWise\\notify.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"D:\\itunes\\iTunes.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R1 nipplpt2;Novell iCapture Lpt Redirector 2;C:\WINDOWS\system32\drivers\nipplpt.sys [2006-10-18 34671]
R3 ti21sony;ti21sony;C:\WINDOWS\system32\drivers\ti21sony.sys [2006-02-21 226304]
S2 EraserSvc10823;Symantec Eraser Service;C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2007-11-26 108392]
S3 Image Converter video recording monitor for VAIO Entertainment;Image Converter video recording monitor for VAIO Entertainment;C:\Program Files\Sony\Image Converter 2\IcVzMon.exe [2005-07-14 32768]
S3 Smcinst;Symantec Auto-upgrade Agent;C:\Program Files\Symantec\Symantec Endpoint Protection\SmcLU\Setup\smcinst.exe [ ]
S3 SonyImgF;Sony Image Conversion Filter Driver;C:\WINDOWS\system32\DRIVERS\SonyImgF.sys [2005-12-27 29184]
.
Contents of the 'Scheduled Tasks' folder
2008-08-28 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-Symantec Antvirus
MSConfigStartUp-ZoneAlarm Client - C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
.
——- Supplementary Scan ——-
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.co.uk/
R1 -: HKCU-Internet Settings,ProxyOverride = *.local
O8 -: &Google; Search - C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 -: &Translate; English Word - C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 -: Backward Links - C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 -: Cached Snapshot of Page - C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 -: Convert link target to Adobe PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 -: Convert link target to existing PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 -: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 -: Convert selected links to existing PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 -: Convert selection to Adobe PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 -: Convert selection to existing PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 -: Convert to Adobe PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 -: Convert to existing PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 -: E&xport; to Microsoft Excel - C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O8 -: Similar Pages - C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 -: Translate Page into English - C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O15 -: Trusted Zone: *.sony-europe.com
O15 -: Trusted Zone: *.sonystyle-europe.com
O15 -: Trusted Zone: *.vaio-link.com
O16 -: {193C772A-87BE-4B19-A7BB-445B226FE9A1} - hxxp://downloads.ewido.net/ewidoOnlineScan.cab
C:\WINDOWS\Downloaded Program Files\ewidoOnlineScan.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-10-29 20:16:12
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vsdatant]
"ImagePath"="a"
.
———————— Other Running Processes ————————
.
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\scardsvr.exe
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-10-29 20:26:13 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-29 20:26:03
Pre-Run: 2,813,579,264 bytes free
Post-Run: 3,443,957,760 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
269 — E O F — 2008-10-25 01:29:44

thanks