Did not encounter any problem this time.
aswMBR version 0.9.5.232 Copyright© 2011 AVAST Software
Run date: 2011-05-01 13:15:11
-----------------------------
13:15:11.187 OS Version: Windows 5.1.2600 Service Pack 3
13:15:11.187 Number of processors: 2 586 0x403
13:15:11.187 ComputerName: JANJOSH UserName:
13:15:11.734 Initialize success
13:15:24.953 Disk 0 Windows 501 MBR fixed successfully
13:15:38.500 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-17
13:15:38.500 Disk 0 Vendor: ST3200826AS 3.03 Size: 190782MB BusType: 3
13:15:40.515 Disk 0 MBR read successfully
13:15:40.531 Disk 0 MBR scan
13:15:40.531 Disk 0 Windows XP default MBR code
13:15:42.531 Disk 0 scanning sectors +390700800
13:15:42.562 Disk 0 scanning C:\WINDOWS\system32\drivers
13:15:48.593 Service scanning
13:15:49.546 Disk 0 trace - called modules:
13:15:49.562 ntkrnlpa.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll intelide.sys PCIIDEX.SYS
13:15:49.578 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86d1aab8]
13:15:49.578 3 CLASSPNP.SYS[f751dfd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-17[0x86d81b00]
13:15:49.578 Scan finished successfully
13:17:25.546 Disk 0 Windows 501 MBR fixed successfully
13:18:30.437 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\HP_Administrator\Desktop\MBR.dat"
13:18:30.453 The log file has been saved successfully to "C:\Documents and Settings\HP_Administrator\Desktop\aswMBR2.txt"
aswMBR version 0.9.5.232 Copyright© 2011 AVAST Software
Run date: 2011-05-01 13:15:11
-----------------------------
13:15:11.187 OS Version: Windows 5.1.2600 Service Pack 3
13:15:11.187 Number of processors: 2 586 0x403
13:15:11.187 ComputerName: JANJOSH UserName:
13:15:11.734 Initialize success
13:15:24.953 Disk 0 Windows 501 MBR fixed successfully
13:15:38.500 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-17
13:15:38.500 Disk 0 Vendor: ST3200826AS 3.03 Size: 190782MB BusType: 3
13:15:40.515 Disk 0 MBR read successfully
13:15:40.531 Disk 0 MBR scan
13:15:40.531 Disk 0 Windows XP default MBR code
13:15:42.531 Disk 0 scanning sectors +390700800
13:15:42.562 Disk 0 scanning C:\WINDOWS\system32\drivers
13:15:48.593 Service scanning
13:15:49.546 Disk 0 trace - called modules:
13:15:49.562 ntkrnlpa.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll intelide.sys PCIIDEX.SYS
13:15:49.578 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86d1aab8]
13:15:49.578 3 CLASSPNP.SYS[f751dfd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-17[0x86d81b00]
13:15:49.578 Scan finished successfully
13:17:25.546 Disk 0 Windows 501 MBR fixed successfully
13:18:30.437 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\HP_Administrator\Desktop\MBR.dat"
13:18:30.453 The log file has been saved successfully to "C:\Documents and Settings\HP_Administrator\Desktop\aswMBR2.txt"
ComboFix 11-04-28.02 - HP_Administrator 01/05/2011 12:52:30.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.2.1033.18.1015.582 [GMT -7:00]
Running from: c:\documents and settings\HP_Administrator\Desktop\ComboFix.exe
AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\confin.sys
c:\documents and settings\Administrator\WINDOWS
c:\documents and settings\Default User\WINDOWS
c:\documents and settings\HP_Administrator\Application Data\SystemProc
c:\documents and settings\HP_Administrator\Start Menu\Programs\Windows Recovery
c:\documents and settings\HP_Administrator\Start Menu\Programs\Windows Recovery\Uninstall Windows Recovery.lnk
c:\documents and settings\HP_Administrator\Start Menu\Programs\Windows Recovery\Windows Recovery.lnk
c:\documents and settings\HP_Administrator\WINDOWS
c:\program files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}
c:\program files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\chrome.manifest
c:\program files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\install.rdf
c:\windows\system32\config\systemprofile\WINDOWS
c:\windows\system32\driVERs\zhtwpxof.sys
D:\Autorun.inf
.
Infected copy of c:\windows\system32\drivers\volsnap.sys was found and disinfected
Restored copy from - Kitty had a snack
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_zhtwpxof
-------\Service_zhtwpxof
.
.
((((((((((((((((((((((((( Files Created from 2011-04-01 to 2011-05-01 )))))))))))))))))))))))))))))))
.
.
2011-05-01 09:54 . 2011-05-01 07:26 16432 ----a-w- c:\windows\system32\lsdelete.exe
2011-05-01 07:26 . 2011-05-01 07:26 98392 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-05-01 07:24 . 2011-04-29 19:12 64512 ----a-w- c:\windows\system32\drivers\Lbd.sys
2011-05-01 07:24 . 2011-05-01 07:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2011-05-01 07:24 . 2011-05-01 07:24 -------- d-----w- c:\program files\Lavasoft
2011-04-28 22:38 . 2011-05-01 05:30 -------- d-----w- c:\windows\system32\NtmsData
2011-04-28 22:37 . 2011-04-28 22:37 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\Avira
2011-04-28 22:28 . 2011-04-02 00:07 61960 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-04-28 22:28 . 2011-04-02 00:07 137656 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-04-28 22:28 . 2010-06-17 22:27 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2011-04-28 22:28 . 2010-06-17 22:27 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2011-04-28 22:28 . 2011-04-28 22:28 -------- d-----w- c:\program files\Avira
2011-04-28 22:28 . 2011-04-28 22:28 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2011-04-26 17:32 . 2011-04-26 23:48 -------- d-----w- c:\documents and settings\All Users\Application Data\STOPzilla!
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-07 05:33 . 2005-11-29 21:24 692736 ---ha-w- c:\windows\system32\inetcomm.dll
2011-03-04 06:45 . 2005-11-29 21:27 434176 ---ha-w- c:\windows\system32\vbscript.dll
2011-03-03 13:21 . 2005-11-29 21:27 1857920 ---ha-w- c:\windows\system32\win32k.sys
2011-02-17 19:00 . 2005-11-29 21:27 832512 ---ha-w- c:\windows\system32\wininet.dll
2011-02-17 19:00 . 2005-11-29 21:24 1830912 ---h--w- c:\windows\system32\inetcpl.cpl
2011-02-17 19:00 . 2005-11-29 21:24 78336 ---ha-w- c:\windows\system32\ieencode.dll
2011-02-17 19:00 . 2005-11-29 21:23 17408 ---ha-w- c:\windows\system32\corpol.dll
2011-02-17 13:18 . 2005-11-29 21:24 455936 ---ha-w- c:\windows\system32\drivers\mrxsmb.sys
2011-02-17 13:18 . 2005-11-29 21:26 357888 ---ha-w- c:\windows\system32\drivers\srv.sys
2011-02-17 12:32 . 2009-04-15 23:20 5120 ---ha-w- c:\windows\system32\xpsp4res.dll
2011-02-17 11:44 . 2005-11-29 21:24 389120 ---ha-w- c:\windows\system32\html.iec
2011-02-15 12:56 . 2005-11-29 21:23 290432 ---ha-w- c:\windows\system32\atmfd.dll
2011-02-11 13:25 . 2005-11-29 23:42 229888 ---ha-w- c:\windows\system32\fxscover.exe
2011-02-08 13:33 . 2005-11-29 21:24 978944 ---h--w- c:\windows\system32\mfc42.dll
2011-02-08 13:33 . 2005-11-29 21:24 974848 ---ha-w- c:\windows\system32\mfc42u.dll
2011-02-02 07:58 . 2005-11-29 21:25 2067456 ---ha-w- c:\windows\system32\mstscax.dll
2009-04-01 05:47 . 2009-01-29 18:17 324976 ---ha-w- c:\program files\mozilla firefox\components\coFFPlgn.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-10 68856]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2004-08-11 59392]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-08 61952]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-06-08 77824]
"Persistence"="c:\windows\system32\igfxpers.exe" [2005-06-08 114688]
"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]
"SMSERIAL"="sm56hlpr.exe" [2005-01-24 544768]
"SoundMan"="SOUNDMAN.EXE" [2005-05-04 90112]
"AlcWzrd"="ALCWZRD.EXE" [2005-05-04 2805248]
"PS2"="c:\windows\system32\ps2.exe" [2004-10-25 90112]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2005-05-11 253952]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-10 208952]
"IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-10 44032]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-01 136600]
"Samsung PanelMgr"="c:\windows\Samsung\PanelMgr\SSMMgr.exe" [2009-08-14 614400]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-11-30 98304]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-03-28 281768]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
"Magnify"="Magnify.exe" [2008-04-14 72704]
.
c:\documents and settings\HP_Administrator\Start Menu\Programs\Startup\
Vancouver, British Columbia - Weather Forecast - The Weather Network.url [2009-1-29 9403]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-12 282624]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [01/05/2011 12:24 AM 64512]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [28/04/2011 3:28 PM 136360]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [29/04/2011 12:11 PM 2146496]
S2 SSPORT;SSPORT;\??\c:\windows\system32\Drivers\SSPORT.sys --> c:\windows\system32\Drivers\SSPORT.sys [?]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\kernexplorer.sys [29/04/2011 12:11 PM 15232]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WUAUSERV
.
Contents of the 'Scheduled Tasks' folder
.
2011-05-01 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2011-04-29 19:11]
.
.
------- Supplementary Scan -------
.
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
uStart Page = hxxp://www.google.com
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\09re9tk6.default\
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: NoScript: {73a6fe31-595d-460b-a920-fcc0f8843232} - %profile%\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: Flashblock: {3d7eb24f-2740-49df-8937-200b1cc08f8a} - %profile%\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
FF - Ext: WOT: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} - %profile%\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
FF - Ext: FoxClocks: {d37dc5d0-431d-44e5-8c91-49419370caa1} - %profile%\extensions\{d37dc5d0-431d-44e5-8c91-49419370caa1}
FF - Ext: Save Image in Folder: {5e594888-3e8e-47da-b2c6-b0b545112f84} - %profile%\extensions\{5e594888-3e8e-47da-b2c6-b0b545112f84}
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-PCDrProfiler - (no file)
Notify-TPSvc - TPSvc.dll
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-05-01 13:00
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-2321429022-972957719-2583767808-1008\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@DACL=(02 0010)
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
@DACL=(02 0010)
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@DACL=(02 0010)
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@DACL=(02 0010)
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@DACL=(02 0010)
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@DACL=(02 0010)
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@DACL=(02 0010)
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'explorer.exe'(3088)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\windows\sm56hlpr.exe
c:\windows\SOUNDMAN.EXE
c:\windows\ALCWZRD.EXE
c:\windows\system32\dllhost.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\eHome\ehmsas.exe
c:\windows\system32\wscntfy.exe
c:\program files\Lavasoft\Ad-Aware\AAWTray.exe
.
**************************************************************************
.
Completion time: 2011-05-01 13:12:30 - machine was rebooted
ComboFix-quarantined-files.txt 2011-05-01 20:12
.
Pre-Run: 161,749,176,320 bytes free
Post-Run: 161,736,396,800 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
.
- - End Of File - - C2D7AD469195A3666C5ACB0886288329
This post has been edited by aloy66: 01 May 2011 - 03:23 PM