ComboFix 09-07-23.04 - smits 24-07-2009 15:03.1.2 - NTFSx86 NETWORK Microsoft Windows XP Professional 5.1.2600.3.1252.31.1043.18.3070.2817 [GMT 2:00] Gestart vanuit: F:\ComboFix.exe AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} . (((((((((((((((((((((((((((((((((( Andere Verwijderingen ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\All Users\Application Data\18788594 c:\documents and settings\All Users\Application Data\18788594\18788594 c:\documents and settings\All Users\Application Data\18788594\18788594.exe c:\documents and settings\smits\Application Data\bcrypt.html C:\fgewkbsf.exe C:\mlvvh.exe c:\program files\sFX c:\recycler\S-1-5-21-0108322918-1303894731-438587923-2998 c:\recycler\S-1-5-21-0964530687-5032553650-172999673-3815 c:\recycler\S-1-5-21-1449749925-3019132387-696873226-3169 c:\recycler\S-1-5-21-1503447788-2866294581-238428385-8367 c:\recycler\S-1-5-21-2465101006-8115273752-962461781-8932 c:\recycler\S-1-5-21-2469561978-9005656993-060227656-5479 c:\recycler\S-1-5-21-3630273397-9535881120-193705901-4185 c:\recycler\S-1-5-21-3929961959-2987973504-990351025-5157 c:\recycler\S-1-5-21-4080262077-0609840192-881749190-8051 c:\recycler\S-1-5-21-4368792823-5441737073-916284183-5999 c:\recycler\S-1-5-21-4543759325-5902436934-671472412-1185 c:\recycler\S-1-5-21-5803395658-1365728765-577389735-8939 c:\recycler\S-1-5-21-6737726784-3218631373-155646460-1351 c:\recycler\S-1-5-21-7752198975-9803067863-653890969-4477 c:\recycler\S-1-5-21-8376247226-2656446710-786451261-4965 c:\recycler\S-1-5-21-8500562283-3086778509-545140357-7326 c:\recycler\S-1-5-21-8777965836-5966780811-830016697-5176 c:\recycler\S-1-5-21-9059420387-9244081691-525587850-6225 c:\recycler\S-1-5-21-9999813463-7757847906-988426698-5860 . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_GLAIDE32 -------\Legacy_SFX -------\Legacy_SFXDRV (((((((((((((((((((( Bestanden Gemaakt van 2009-06-24 to 2009-07-24 )))))))))))))))))))))))))))))) . 2009-07-24 10:49 . 2009-07-24 10:49 209 ----a-w- c:\windows\prxid93ps.dat 2009-07-24 10:49 . 2009-07-24 10:55 203956 ----a-w- C:\bijhf.exe 2009-07-23 13:06 . 2009-07-23 13:06 -------- d-----w- c:\documents and settings\smits\Application Data\Malwarebytes 2009-07-23 13:06 . 2009-07-13 11:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-07-23 13:06 . 2009-07-23 13:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-07-23 13:06 . 2009-07-23 13:06 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-07-23 13:06 . 2009-07-13 11:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-07-22 18:46 . 2009-07-22 18:46 -------- d-----w- c:\documents and settings\smits\Application Data\Nero 2009-07-22 18:44 . 2009-07-22 18:44 -------- d-----w- c:\program files\Windows Sidebar 2009-07-22 18:37 . 2009-07-22 18:43 -------- d-----w- c:\program files\Nero 2009-07-22 18:36 . 2009-07-22 18:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Nero 2009-07-22 18:36 . 2009-07-22 18:39 -------- d-----w- c:\program files\Common Files\Nero 2009-07-22 18:09 . 2003-01-31 14:33 1134592 ------w- c:\windows\Unnero.exe 2009-07-22 18:09 . 2002-04-21 14:26 49152 ------w- c:\windows\system32\MultiSZ.dll 2009-07-22 18:08 . 2000-09-27 15:15 532480 ----a-r- c:\windows\system32\imagx5.dll 2009-07-22 18:08 . 2000-09-21 16:02 507904 ----a-r- c:\windows\system32\imagr5.dll 2009-07-22 18:08 . 2000-09-21 11:53 275312 ----a-r- c:\windows\system32\ImagXpr5.dll 2009-07-22 18:08 . 2001-07-09 10:50 155648 ----a-r- c:\windows\system32\NeroCheck.exe 2009-07-22 17:36 . 2009-07-22 17:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Ahead 2009-07-22 17:35 . 2009-07-22 18:08 -------- d-----w- c:\program files\Ahead 2009-07-22 17:33 . 2000-09-21 06:47 35328 ----a-r- c:\windows\system32\picn20.dll 2009-07-22 17:33 . 2000-06-26 09:45 106496 ----a-r- c:\windows\system32\TwnLib20.dll 2009-07-22 17:32 . 2009-07-22 17:32 -------- d-----w- c:\program files\Common Files\Ahead 2009-07-22 08:31 . 2001-09-06 19:27 5632 ----a-w- c:\windows\system32\ptpusb.dll 2009-07-22 08:31 . 2008-04-14 20:32 159232 ----a-w- c:\windows\system32\ptpusd.dll 2009-07-22 08:31 . 2008-04-13 22:15 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys 2009-07-22 08:31 . 2008-04-13 22:15 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys 2009-07-22 07:50 . 2008-04-14 20:32 26624 ----a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll 2009-07-22 07:49 . 2009-07-22 07:49 -------- d-----w- c:\documents and settings\smits\Application Data\Apple Computer 2009-07-22 07:33 . 2009-07-21 16:10 2052888 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll 2009-07-21 16:35 . 2007-01-11 11:02 113664 ----a-w- c:\documents and settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE 2009-07-21 16:34 . 2009-07-21 16:35 -------- d-----w- c:\documents and settings\All Users\Application Data\EPSON 2009-07-21 16:34 . 2006-12-08 09:04 76800 ----a-w- c:\windows\system32\E_FLBCDE.DLL 2009-07-21 16:34 . 2006-04-19 09:00 62976 ----a-w- c:\windows\system32\E_FD4BCDE.DLL 2009-07-21 16:34 . 2004-09-11 03:12 49152 ----a-w- c:\windows\system32\E_DCINST.DLL 2009-07-21 16:34 . 2009-07-21 16:34 -------- d-----w- c:\program files\EPSON 2009-07-21 16:31 . 2009-07-21 16:31 -------- d-----w- c:\program files\Common Files\Adobe 2009-07-21 16:30 . 2009-07-21 16:32 -------- d-----w- c:\documents and settings\smits\Local Settings\Application Data\Adobe 2009-07-21 16:30 . 2009-07-22 07:31 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS 2009-07-21 16:30 . 2009-07-21 16:43 -------- d-----w- c:\program files\NOS 2009-07-21 16:26 . 2009-07-22 16:09 -------- d--h--w- C:\$AVG8.VAULT$ 2009-07-21 16:25 . 2008-04-13 22:17 25856 -c--a-w- c:\windows\system32\dllcache\usbprint.sys 2009-07-21 16:25 . 2008-04-13 22:17 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys 2009-07-21 16:11 . 2009-07-21 16:11 11952 ----a-w- c:\windows\system32\avgrsstx.dll 2009-07-21 16:11 . 2009-07-21 16:11 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys 2009-07-21 16:11 . 2009-07-21 16:11 327688 ----a-w- c:\windows\system32\drivers\avgldx86.sys 2009-07-21 16:11 . 2009-07-21 16:11 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys 2009-07-21 16:11 . 2009-07-23 07:21 -------- d-----w- c:\windows\system32\drivers\Avg 2009-07-21 16:10 . 2009-07-21 16:10 -------- d-----w- c:\program files\AVG 2009-07-21 16:10 . 2009-07-21 16:43 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8 2009-07-21 13:42 . 2009-07-21 13:42 -------- d-----w- c:\documents and settings\smits\Contacts 2009-07-21 10:22 . 2009-07-21 10:22 -------- d-----w- c:\documents and settings\smits\Local Settings\Application Data\Identities 2009-07-20 19:15 . 2009-07-20 19:16 -------- dcsh--w- c:\program files\Common Files\WindowsLiveInstaller 2009-07-20 19:14 . 2009-07-20 19:16 -------- d-----w- c:\program files\Windows Live 2009-07-20 19:14 . 2009-07-20 19:14 -------- d-----w- c:\documents and settings\All Users\Application Data\WLInstaller 2009-07-20 19:12 . 2008-10-16 12:09 43544 ----a-w- c:\windows\system32\wups2.dll 2009-07-20 11:03 . 2009-07-22 08:00 -------- d-----w- c:\program files\AruaROSE . ((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-07-22 07:48 . 2009-07-22 07:48 -------- d-----w- c:\program files\iTunes 2009-07-22 07:48 . 2009-07-22 07:48 -------- d-----w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} 2009-07-22 07:48 . 2009-07-22 07:48 -------- d-----w- c:\program files\iPod 2009-07-22 07:48 . 2009-07-22 07:48 -------- d-----w- c:\program files\Common Files\Apple 2009-07-22 07:48 . 2009-07-22 07:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer 2009-07-22 07:48 . 2009-07-22 07:48 -------- d-----w- c:\program files\Bonjour 2009-07-22 07:48 . 2009-07-22 07:48 -------- d-----w- c:\program files\QuickTime 2009-07-22 07:48 . 2009-07-22 07:48 -------- d-----w- c:\program files\Apple Software Update 2009-07-22 07:48 . 2009-07-22 07:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple 2009-07-21 10:04 . 2009-07-20 09:57 42168 ----a-w- c:\documents and settings\smits\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-07-20 11:01 . 2001-09-07 14:00 92342 ----a-w- c:\windows\system32\perfc013.dat 2009-07-20 11:01 . 2001-09-07 14:00 512384 ----a-w- c:\windows\system32\perfh013.dat 2009-07-20 10:54 . 2009-07-20 10:54 -------- d-----w- c:\program files\Microsoft.NET 2009-07-20 10:29 . 2009-07-20 09:54 -------- d-----w- c:\program files\Realtek 2009-07-20 10:23 . 2009-07-20 09:52 -------- d-----w- c:\program files\MSI 2009-07-20 10:23 . 2009-07-20 09:51 -------- d--h--w- c:\program files\InstallShield Installation Information 2009-07-20 09:57 . 2009-07-20 09:57 -------- d-----w- c:\documents and settings\smits\Application Data\ATI 2009-07-20 09:57 . 2009-07-20 09:57 -------- d-----w- c:\documents and settings\All Users\Application Data\ATI 2009-07-20 09:56 . 2009-07-20 09:56 0 ----a-w- c:\windows\ativpsrm.bin 2009-07-20 09:53 . 2009-07-20 09:53 -------- d-----w- c:\program files\Intel 2009-07-20 09:52 . 2009-07-20 09:51 -------- d-----w- c:\program files\ATI Technologies 2009-07-20 09:52 . 2009-07-20 09:51 -------- d-----w- c:\program files\Common Files\InstallShield 2009-07-20 09:24 . 2009-07-20 08:52 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat 2009-07-20 08:56 . 2009-07-20 08:56 -------- d-----w- c:\program files\microsoft frontpage 2009-07-20 08:55 . 2009-07-20 08:55 64200 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat 2009-07-20 08:54 . 2009-07-20 08:54 -------- d-----w- c:\program files\MSBuild 2009-07-20 08:54 . 2009-07-20 08:54 -------- d-----w- c:\program files\Reference Assemblies 2009-07-20 08:49 . 2009-07-20 08:49 21748 ----a-w- c:\windows\system32\emptyregdb.dat 2009-07-20 08:49 . 2009-07-20 08:49 -------- d-----w- c:\program files\Windows Media Connect 2 2009-07-13 12:22 . 2009-07-13 12:22 75048 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.1.6\SetupAdmin.exe 2009-05-16 03:58 . 2009-05-16 03:58 4069888 ----a-w- c:\windows\system32\drivers\ati2mtag.sys 2009-05-16 03:39 . 2009-05-16 03:39 442368 ----a-w- c:\windows\system32\ATIDEMGX.dll 2009-05-16 03:38 . 2009-05-16 03:38 335872 ----a-w- c:\windows\system32\ati2dvag.dll 2009-05-16 03:18 . 2009-05-16 03:18 204800 ----a-w- c:\windows\system32\atipdlxx.dll 2009-05-16 03:17 . 2009-05-16 03:17 155648 ----a-w- c:\windows\system32\Oemdspif.dll 2009-05-16 03:17 . 2009-05-16 03:17 26112 ----a-w- c:\windows\system32\Ati2mdxx.exe 2009-05-16 03:17 . 2009-05-16 03:17 43520 ----a-w- c:\windows\system32\ati2edxx.dll 2009-05-16 03:17 . 2009-05-16 03:17 155648 ----a-w- c:\windows\system32\ati2evxx.dll 2009-05-16 03:15 . 2009-05-16 03:15 602112 ----a-w- c:\windows\system32\ati2evxx.exe 2009-05-16 03:14 . 2009-05-16 03:14 53248 ----a-w- c:\windows\system32\ATIDDC.DLL 2009-05-16 03:07 . 2009-05-16 03:07 2987136 ----a-w- c:\windows\system32\ati3duag.dll 2009-05-16 02:55 . 2009-05-16 02:55 11423744 ----a-w- c:\windows\system32\atioglxx.dll 2009-05-16 02:54 . 2009-05-16 02:54 2122624 ----a-w- c:\windows\system32\ativvaxx.dll 2009-05-16 02:54 . 2009-05-16 02:54 887724 ----a-w- c:\windows\system32\ativva6x.dat 2009-05-16 02:54 . 2009-05-16 02:54 3 ----a-w- c:\windows\system32\ativva5x.dat 2009-05-16 02:51 . 2009-05-16 02:51 311296 ----a-w- c:\windows\system32\atiiiexx.dll 2009-05-16 02:38 . 2009-05-16 02:38 49664 ----a-w- c:\windows\system32\atimpc32.dll 2009-05-16 02:38 . 2009-05-16 02:38 49664 ----a-w- c:\windows\system32\amdpcom32.dll 2009-05-16 02:33 . 2009-05-16 02:33 479232 ----a-w- c:\windows\system32\atikvmag.dll 2009-05-16 02:31 . 2009-05-16 02:31 139264 ----a-w- c:\windows\system32\atiadlxx.dll 2009-05-16 02:31 . 2009-05-16 02:31 17408 ----a-w- c:\windows\system32\atitvo32.dll 2009-05-16 02:30 . 2009-05-16 02:30 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll 2009-05-16 02:26 . 2009-05-16 02:26 376832 ----a-w- c:\windows\system32\atiok3x2.dll 2009-05-16 02:24 . 2009-05-16 02:24 651264 ----a-w- c:\windows\system32\ati2cqag.dll 2009-05-16 01:35 . 2009-05-16 01:35 45056 ----a-w- c:\windows\system32\aticalrt.dll 2009-05-16 01:34 . 2009-05-16 01:34 45056 ----a-w- c:\windows\system32\aticalcl.dll 2009-05-16 01:33 . 2009-05-16 01:33 3158016 ----a-w- c:\windows\system32\aticaldd.dll 2009-05-15 19:05 . 2009-07-20 09:52 593920 ------w- c:\windows\system32\ati2sgag.exe 2009-05-15 06:02 . 2009-05-15 06:02 2373416 ----a-w- c:\documents and settings\All Users\Application Data\Nero\Nero\DrWeb\DrWeb32.dll 2009-05-15 05:50 . 2009-05-15 05:50 2373416 ----a-w- c:\documents and settings\All Users\Application Data\Nero\Nero 9\DrWeb\DrWeb32.dll 2009-05-05 19:33 . 2009-05-05 19:33 118784 ----a-w- c:\windows\system32\atibtmon.exe . ------- Sigcheck ------- [-] 2008-05-05 20:32 1571840 497BEF5C5FAD126CA16437C1682F64EA c:\windows\system32\sfcfiles.dll . ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten ))))))))))))))))))))))))))))))))))))))))))))))))))) . . *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DiagAP8169"="c:\program files\MSI\LAN Utility\DiagAP8169" [X] "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-05-20 98304] "JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2007-03-20 36864] "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-07-21 1948440] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128] "NeroCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648] "RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-05-04 16206848] "SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2006-04-24 1448960] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "nltide_2"="shell32" [X] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter] 2009-07-21 16:11 11952 ----a-w- c:\windows\system32\avgrsstx.dll [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\AVG\\AVG8\\avgupd.exe"= "c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [21-7-2009 18:11 327688] R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [21-7-2009 18:11 108552] R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [21-7-2009 18:10 298776] R2 LANPkt;Realtek LANPkt Protocol;c:\windows\system32\drivers\LANPkt.sys [20-7-2009 11:52 8440] R3 Diag69xp;Diag69xp;c:\windows\system32\drivers\diag69xp.sys [20-7-2009 12:23 11266] S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [20-7-2009 11:54 1684736] . Inhoud van de 'Gedeelde Taken' map 2009-07-22 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34] . . ------- Bijkomende Scan ------- . uStart Page = hxxp://www.google.nl/ uInternet Settings,ProxyOverride = *.local IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-07-24 15:07 Windows 5.1.2600 Service Pack 3 NTFS scannen van verborgen processen ... scannen van verborgen autostart items ... scannen van verborgen bestanden ... Scan succesvol afgerond verborgen bestanden: 0 ************************************************************************** . --------------------- DLLs Geladen Onder Lopende Processen --------------------- - - - - - - - > 'winlogon.exe'(684) c:\windows\system32\Ati2evxx.dll - - - - - - - > 'explorer.exe'(2896) c:\windows\system32\ieframe.dll c:\windows\system32\wpdshserviceobj.dll c:\windows\system32\portabledevicetypes.dll c:\windows\system32\portabledeviceapi.dll . ------------------------ Andere Aktieve Processen ------------------------ . c:\windows\system32\ati2evxx.exe c:\windows\system32\ati2evxx.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe c:\program files\MSI\LAN Utility\DiagAP8169.exe c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe c:\program files\AVG\AVG8\avgrsx.exe c:\progra~1\AVG\AVG8\avgnsx.exe c:\program files\iPod\bin\iPodService.exe c:\program files\AVG\AVG8\avgupd.exe . ************************************************************************** . Voltooingstijd: 2009-07-24 15:10 - machine werd herstart ComboFix-quarantined-files.txt 2009-07-24 13:10 Pre-Run: 303.858.683.904 bytes beschikbaar Post-Run: 305.836.781.568 bytes beschikbaar WindowsXP-KB310994-SP2-Pro-BootDisk-NLD.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect 267