ComboFix 08-12-26.03 - Dean 2008-12-28 0:23:35.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2047.1564 [GMT 0:00]
Running from: c:\documents and settings\Dean\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Dean\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\Grant\Local Settings\Temporary Internet Files\fbk.sts
c:\documents and settings\LocalService\Application Data\twain_32
c:\documents and settings\LocalService\Application Data\twain_32\user.ds
c:\documents and settings\NetworkService\Application Data\twain_32
c:\documents and settings\NetworkService\Application Data\twain_32\user.ds
c:\windows\system32\btkcrgrc.dll
c:\windows\system32\gtwkeyri.dll
c:\windows\system32\mijrbdho.dll
c:\windows\system32\nevhhqhp.dll
c:\windows\system32\ozbhib.dll
c:\windows\system32\pthreadGC2.dll
c:\windows\system32\ykeeoeei.dll
----- BITS: Possible infected sites -----
hxxp://childhe.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_OREANS32
-------\Service_oreans32
((((((((((((((((((((((((( Files Created from 2008-11-28 to 2008-12-28 )))))))))))))))))))))))))))))))
.
2008-12-27 23:57 . 2008-12-27 23:57 0 --a------ c:\windows\LCDMedia.INI
2008-12-26 20:10 . 2008-12-26 20:10 <DIR> d-------- c:\program files\backups
2008-12-25 03:27 . 2008-12-25 03:27 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-12-25 03:27 . 2008-12-25 03:27 <DIR> d-------- c:\documents and settings\Dean\Application Data\Malwarebytes
2008-12-25 03:27 . 2008-12-25 03:27 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-25 03:27 . 2008-12-03 19:53 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-25 03:27 . 2008-12-03 19:53 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-12-22 23:01 . 2008-12-22 23:01 95 --a------ c:\windows\wininit.ini
2008-12-18 15:27 . 2008-12-18 15:27 <DIR> d-------- c:\documents and settings\Dean\Application Data\Leadertech
2008-12-18 15:26 . 2008-12-18 15:26 0 --ah----- c:\windows\system32\drivers\MsftWdf_Kernel_01005_C oinstaller_Critical.Wdf
2008-12-18 15:26 . 2008-12-18 15:26 0 --ah----- c:\windows\system32\drivers\Msft_Kernel_LMouFilt_0 1005.Wdf
2008-12-18 15:25 . 2008-12-18 15:27 <DIR> d-------- c:\program files\Common Files\Logishrd
2008-12-18 15:24 . 2008-12-18 15:25 <DIR> d-------- c:\documents and settings\All Users\Application Data\LogiShrd
2008-12-14 15:39 . 2007-12-24 13:47 7,680 --a------ c:\windows\system32\ff_vfw.dll
2008-12-14 15:39 . 2007-11-29 12:52 547 --a------ c:\windows\system32\ff_vfw.dll.manifest
2008-12-14 15:39 . 2008-12-28 00:26 370 --a------ c:\windows\system32\tversity.cookies
2008-12-14 15:38 . 2008-12-14 15:39 <DIR> d-------- c:\program files\TVersity Codec Pack
2008-12-14 15:35 . 2008-12-14 15:35 <DIR> d-------- c:\program files\TVersity
2008-12-13 01:24 . 2008-12-13 04:24 <DIR> d-------- c:\documents and settings\NetworkService\Application Data\FinalBurner DATA
2008-12-11 20:37 . 2008-12-11 20:37 42,320 --a------ c:\windows\system32\xfcodec.dll
2008-12-09 23:59 . 2008-12-24 23:15 <DIR> d-------- c:\documents and settings\Dean\Application Data\FinalBurner DATA
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-12-28 00:26 --------- d-----w c:\program files\Steam
2008-12-28 00:26 --------- d-----w c:\documents and settings\Dean\Application Data\Skype
2008-12-28 00:01 --------- d-----w c:\documents and settings\Dean\Application Data\Xfire
2008-12-27 18:04 --------- d-----w c:\documents and settings\Dean\Application Data\skypePM
2008-12-27 00:34 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2008-12-26 20:14 8,306 ----a-w c:\program files\hijackthis.log
2008-12-26 20:07 413 ----a-w c:\program files\Shortcut to HijackThis.lnk
2008-12-21 19:33 --------- d-----w c:\documents and settings\Grant\Application Data\uTorrent
2008-12-21 02:40 --------- d-----w c:\documents and settings\Grant\Application Data\FinalBurner DATA
2008-12-19 16:38 --------- d-----w c:\documents and settings\Grant\Application Data\LimeWire
2008-12-18 15:25 --------- d-----w c:\program files\Logitech
2008-12-17 16:33 --------- d-----w c:\program files\World of Warcraft
2008-12-17 16:25 --------- d-----w c:\program files\Xfire
2008-12-12 18:27 --------- d-----w c:\documents and settings\All Users\Application Data\TrackMania
2008-12-12 17:50 --------- d-----w c:\program files\Common Files\Blizzard Entertainment
2008-12-11 01:19 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-12-06 21:13 --------- d-----w c:\documents and settings\Dean\Application Data\uTorrent
2008-12-05 22:11 138,464 ----a-w c:\windows\system32\drivers\PnkBstrK.sys
2008-11-30 23:08 --------- d-----w c:\program files\Azureus
2008-11-30 23:08 --------- d-----w c:\documents and settings\Dean\Application Data\Azureus
2008-11-29 01:48 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-11-20 23:30 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-20 23:30 --------- d-----w c:\program files\Electronic Arts
2008-11-20 23:30 --------- d-----w c:\program files\Common Files\InstallShield
2008-11-20 23:26 --------- d-----w c:\documents and settings\All Users\Application Data\Blizzard
2008-11-15 01:37 --------- d-----w c:\documents and settings\Dean\Application Data\dyyno-vlc
2008-11-15 01:35 --------- d-----w c:\program files\Dyyno
2008-11-13 13:18 --------- d-----w c:\program files\AGEIA Technologies
2008-11-13 13:17 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-11-09 03:39 --------- d-----w c:\documents and settings\All Users\Application Data\TVU Networks
2008-11-07 03:22 --------- d-----w c:\program files\MSXML 6.0
2008-11-06 03:23 --------- d-----w c:\program files\MSBuild
2008-11-06 03:21 --------- d-----w c:\program files\Reference Assemblies
2008-10-28 23:14 --------- d-----w c:\program files\Topaz Labs LLC
2008-10-28 22:56 --------- d-----w c:\program files\Topaz Labs
2008-08-28 13:42 24 ----a-w c:\documents and settings\Dean\jagex_runescape_preferences.dat
2008-08-14 01:00 396,288 ----a-w c:\program files\HijackThis.exe
2008-06-10 15:28 9 ----a-w c:\documents and settings\Dean\status.bin
2008-04-28 15:10 32 ----a-w c:\documents and settings\All Users\Application Data\ezsid.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\shelliconoverlayidentifiers\1T ortoiseSVN]
@="{30351346-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{30351346-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 11:35 536576 --a------ c:\program files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\shelliconoverlayidentifiers\2T ortoiseSVN]
@="{30351347-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{30351347-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 11:35 536576 --a------ c:\program files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\shelliconoverlayidentifiers\3T ortoiseSVN]
@="{30351348-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{30351348-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 11:35 536576 --a------ c:\program files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\shelliconoverlayidentifiers\4T ortoiseSVN]
@="{3035134B-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134B-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 11:35 536576 --a------ c:\program files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\shelliconoverlayidentifiers\5T ortoiseSVN]
@="{3035134C-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134C-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 11:35 536576 --a------ c:\program files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\shelliconoverlayidentifiers\6T ortoiseSVN]
@="{3035134D-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134D-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 11:35 536576 --a------ c:\program files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\shelliconoverlayidentifiers\7T ortoiseSVN]
@="{3035134E-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134E-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 11:35 536576 --a------ c:\program files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2006-02-28 15360]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-04-03 21898024]
"Steam"="c:\program files\steam\steam.exe" [2008-12-20 1410296]
"NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 81920]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-07-24 490952]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"Launch LGDCore"="c:\program files\Logitech\G-series Software\LGDCore.exe" [2006-03-06 1122304]
"Launch LCDMon"="c:\program files\Logitech\G-series Software\LCDMon.exe" [2006-03-06 497152]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-11-27 1261336]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-09-10 289576]
"NvMediaCenter"="c:\windows\system32\NvMcTray. dll" [2008-10-07 86016]
"RTHDCPL"="RTHDCPL.EXE" [2007-03-21 c:\windows\RTHDCPL.exe]
"nwiz"="nwiz.exe" [2008-10-07 c:\windows\system32\nwiz.exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-07-17 c:\windows\KHALMNPR.Exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2006-02-28 15360]
c:\documents and settings\Dean\Start Menu\Programs\Startup\
Product Registration.lnk - c:\program files\Common Files\Logishrd\eReg\SetPoint\eReg.exe [2007-08-02 2979080]
Xfire.lnk - c:\program files\Xfire\xfire.exe [2008-12-11 2990416]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
SetPointII.lnk - c:\program files\Logitech\SetPoint II\SetpointII.exe [2007-08-30 319488]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll kxvbzr.dll ozbhib.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Xfire\\xfire.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Documents and Settings\\Dean\\Desktop\\glider\\hfymaipugz.exe"=
"c:\\Program Files\\Softnyx\\Rakion\\Bin\\rakion.bin"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\Steam\\steamapps\\d3ath1234\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\Steam\\steamapps\\d3ath1234\\team fortress 2\\hl2.exe"=
"c:\\Program Files\\Steam\\steamapps\\d3ath1234\\garrysmod\\hl2 .exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Program Files\\iMesh Applications\\iMesh\\iMesh.exe"=
"c:\\Program Files\\Steam\\steamapps\\d3ath1234\\source sdk base\\hl2.exe"=
"c:\\Documents and Settings\\Dean\\Desktop\\CabalTemp\\ESTSetupLoader .exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr .exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Documents and Settings\\Dean\\My Documents\\My Music\\RF Online\\RF.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\RndLabs\\BaboViolent 2\\bv2.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Steam\\steamapps\\d3ath1234\\zombie panic! source\\hl2.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\trackmania united\\TmForever.exe"=
"c:\\Program Files\\Steam\\steamapps\\d3ath1234\\diprip warm up\\hl2.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\call of duty 4\\iw3mp.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\fallout 3\\Fallout3.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\left 4 dead demo\\left4dead.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Documents and Settings\\Dean\\Local Settings\\Application Data\\Dyyno Receiver\\DPPM.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\left 4 dead\\left4dead.exe"=
"c:\\Program Files\\TVersity\\Media Server\\MediaServer.exe"=
"c:\\Documents and Settings\\Dean\\Desktop\\Pokemon\\Pokemon Game.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"32937:TCP"= 32937:TCP:u
"32937:UDP"= 32937:UDP:uu
"41431:TCP"= 41431:TCP:utorrent
"41431:UDP"= 41431:UDP:utorrent
"3074:UDP"= 3074:UDP:Xbox
"3074:TCP"= 3074:TCP:Xbox
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-08-10 97928]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-08-10 231704]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"c:\program files\Viewpoint\Common\ViewpointService.exe" [2008-07-19 24652]
S0 NVStrap;NVStrap;c:\windows\system32\drivers\NVStra p.sys [2008-02-22 4224]
S3 BRGSp50;BRGSp50 NDIS Protocol Driver;c:\windows\system32\Drivers\BRGSp50.sys [2008-09-13 20608]
S3 XDva145;XDva145;\??\c:\windows\system32\XDva145.sy s []
S3 ZDCNDIS5;ZDCNDIS5 NDIS Protocol Driver;\??\c:\windows\system32\ZDCNDIS5.SYS [2008-09-13 19072]
.
Contents of the 'Scheduled Tasks' folder
2008-12-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2008-12-28 c:\windows\Tasks\tbuqyhwu.job
- c:\windows\system32\rundll32.exe [2006-02-28 12:00]
.
- - - - ORPHANS REMOVED - - - -
BHO-{2209D0AB-34FC-458B-9D8C-DD785609F236} - (no file)
BHO-{3089261E-71AA-4324-B6A7-CDCE4FA80A9F} - (no file)
BHO-{BA463437-C3DE-47da-8280-87596824388A} - (no file)
BHO-{F9A51CB2-90EA-496A-A998-915D1C9E2A1B} - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.gamerenders.com/forum/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: &Clean Traces
FF - ProfilePath - c:\documents and settings\Dean\Application Data\Mozilla\Firefox\Profiles\cxabp3a8.default\
FF - prefs.
js: browser.search.selectedEngine - DAEMON Search
FF - prefs.
js: browser.startup.homepage - hxxp://www.gamerenders.com/forum/index.php?showforum=9
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\ToolbarFF\components\vmAVGConnector .dll
FF - plugin: c:\documents and settings\Dean\Application Data\Mozilla\Firefox\Profiles\cxabp3a8.default\ext ensions\NPDyyno@dyyno.com\plugins\npDyyno.dll
FF - plugin: c:\program files\Dyyno\Dyyno Player\npvlc.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.
************************************************** ************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-12-28 00:26:31
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
c:\docume~1\Dean\LOCALS~1\Temp\~DF9222.tmp 327680 bytes
c:\docume~1\Dean\LOCALS~1\Temp\~DF99D0.tmp 512 bytes
scan completed successfully
hidden files: 2
************************************************** ************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\program files\NVIDIA Corporation\nTune\nTuneService.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\TVersity\Media Server\MediaServer.exe
c:\program files\TortoiseSVN\bin\TSVNCache.exe
c:\program files\Logitech\G-series Software\Applets\LCDCountdown\LCDCountdown.exe
c:\program files\Logitech\G-series Software\Applets\LCDClock.exe
c:\windows\system32\wscntfy.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Java\jre1.6.0_05\bin\jucheck.exe
c:\program files\AVG\AVG8\avgrsx.exe
.
************************************************** ************************
.
Completion time: 2008-12-28 0:31:38 - machine was rebooted [Dean]
ComboFix-quarantined-files.txt 2008-12-28 00:31:36
Pre-Run: 6,315,077,632 bytes free
Post-Run: 7,079,833,600 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOW S
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Micro soft Windows XP Home Edition" /noexecute=optin /fastdetect
292 --- E O F --- 2008-12-19 06:27:01