ComboFix 08-11-12.01 - Riccardo Piccoli 2008-11-13 16.35.51.1 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.1585 [GMT 1:00]
Eseguito da: c:\documents and settings\Riccardo Piccoli\Documenti\Software\ComboFix.exe
* Creato nuovo punto di ripristino
.
Os seguintes ficheiros foram desabilitados durante a rodagem:c:\programmi\File comuni\Logitech\LVMVFM\LVPrcInj.dll
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Riccardo Piccoli\Dati applicazioni\inst.exe
c:\windows\system32\cfx32.ocx
c:\windows\system32\drivers\npf.sys
c:\windows\system32\packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\systeminfo3.dll
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll
.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_IPRIP
-------\Legacy_NPF
-------\Service_Iprip
-------\Service_NPF
((((((((((((((((((((((((( Files Creati Da 2008-10-13 al 2008-11-13 )))))))))))))))))))))))))))))))))))
.
2008-11-12 18:55 . 2008-11-12 18:55 <DIR> d-------- c:\programmi\RegCleaner
2008-11-10 11:25 . 2008-11-10 11:25 <DIR> d-------- c:\programmi\CloneDVD
2008-11-10 11:25 . 2008-11-10 11:25 <DIR> d-------- c:\documents and settings\Riccardo Piccoli\Dati applicazioni\Vso
2008-11-10 11:25 . 2008-11-10 11:25 <DIR> d-------- c:\documents and settings\All Users\Dati applicazioni\DVDXStudio
2008-11-10 11:25 . 2008-11-10 11:25 47,360 --a------ c:\windows\system32\drivers\pcouffin.sys
2008-11-10 11:25 . 2008-11-10 11:25 47,360 --a------ c:\documents and settings\Riccardo Piccoli\Dati applicazioni\pcouffin.sys
2008-10-27 19:15 . 1999-09-10 12:06 45,056 --a------ c:\windows\system32\WNASPI32.DLL
2008-10-27 19:15 . 1999-09-10 12:06 25,244 --a------ c:\windows\system32\drivers\ASPI32.SYS
2008-10-27 19:15 . 1999-09-10 12:06 5,600 --a------ c:\windows\system\WINASPI.DLL
2008-10-27 19:15 . 1999-09-10 12:06 4,672 --a------ c:\windows\system\WOWPOST.EXE
2008-10-27 19:10 . 2008-10-27 19:10 <DIR> d-------- c:\programmi\EasyDVDClone
2008-10-24 16:56 . 2008-10-15 18:36 337,408 --------- c:\windows\system32\dllcache\netapi32.dll
2008-10-15 14:35 . 2008-09-08 12:41 333,824 --------- c:\windows\system32\dllcache\srv.sys
2008-10-15 14:34 . 2008-08-14 15:22 2,192,896 --------- c:\windows\system32\dllcache\ntoskrnl.exe
2008-10-15 14:34 . 2008-08-14 15:22 2,148,864 --------- c:\windows\system32\dllcache\ntkrnlmp.exe
2008-10-15 14:34 . 2008-08-14 15:22 2,069,760 --------- c:\windows\system32\dllcache\ntkrnlpa.exe
2008-10-15 14:34 . 2008-08-14 15:22 2,027,520 --------- c:\windows\system32\dllcache\ntkrpamp.exe
2008-10-15 14:34 . 2008-09-15 17:24 1,846,400 --------- c:\windows\system32\dllcache\win32k.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-22 15:10 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2008-10-22 15:10 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2008-10-10 11:24 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\Nokia
2008-10-10 10:57 --------- d-----w c:\programmi\PC Connectivity Solution
2008-10-10 10:57 --------- d-----w c:\programmi\File comuni\PCSuite
2008-10-10 10:57 --------- d-----w c:\programmi\File comuni\Nokia
2008-10-10 10:45 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2008-10-10 10:44 0 ---ha-w c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-10-09 09:58 --------- d-----w c:\programmi\QuickTime
2008-10-09 09:20 --------- d-----w c:\programmi\iTunes
2008-10-09 09:20 --------- d-----w c:\programmi\iPod
2008-10-09 09:20 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-07 13:23 --------- d-----w c:\programmi\MaZZick
2008-10-06 10:34 --------- d-----w c:\documents and settings\Riccardo Piccoli\Dati applicazioni\Windows Search
2008-10-03 17:58 6,066,176 ------w c:\windows\system32\dllcache\ieframe.dll
2008-10-03 14:05 --------- d-----w c:\programmi\GiocoDigitale
2008-10-03 14:05 --------- d-----w c:\documents and settings\All Users\Dati applicazioni\GiocoDigitale
2008-10-01 12:01 32,000 ----a-w c:\windows\system32\drivers\usbaapl.sys
2008-09-29 15:25 --------- d-----w c:\programmi\Windows Desktop Search
2008-09-29 15:25 --------- d-----w c:\documents and settings\Riccardo Piccoli\Dati applicazioni\Windows Desktop Search
2008-09-28 15:27 --------- d-----w c:\programmi\Macromedia
2008-09-28 15:27 --------- d-----w c:\programmi\File comuni\Macromedia Shared
2008-09-15 16:24 1,846,400 ----a-w c:\windows\system32\win32k.sys
2008-09-08 19:02 107,888 ----a-w c:\windows\system32\CmdLineExt.dll
2008-08-27 09:57 3,593,216 ------w c:\windows\system32\dllcache\mshtml.dll
2008-08-25 09:39 70,656 ------w c:\windows\system32\dllcache\ie4uinit.exe
2008-08-25 09:38 13,824 ------w c:\windows\system32\dllcache\ieudinit.exe
2008-08-23 06:56 635,848 ------w c:\windows\system32\dllcache\iexplore.exe
2008-08-23 06:54 161,792 ------w c:\windows\system32\dllcache\ieakui.dll
2008-08-14 14:22 2,148,864 ----a-w c:\windows\system32\ntoskrnl.exe
2008-08-14 14:22 2,027,520 ----a-w c:\windows\system32\ntkrnlpa.exe
2008-08-14 11:04 138,496 ------w c:\windows\system32\dllcache\afd.sys
2008-06-07 13:57 22,328 ----a-w c:\documents and settings\Riccardo Piccoli\Dati applicazioni\PnkBstrK.sys
2008-02-13 21:00 32 ----a-w c:\documents and settings\All Users\Dati applicazioni\ezsid.dat
2008-07-28 17:30 32,768 --sha-w c:\windows\system32\config\systemprofile\Impostazioni locali\Cronologia\History.IE5\MSHist012008072820080729\index.dat
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"SweetIM"="c:\programmi\Macrogaming\SweetIM\SweetIM.exe" [2006-12-27 73840]
"updateMgr"="c:\programmi\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" [2006-03-30 313472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" [X]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-03-23 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-03-23 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-03-23 118784]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-17 64512]
"AzMixerSel"="c:\programmi\Realtek\InstallShield\AzMixerSel.exe" [2005-12-21 53248]
"SynTPEnh"="c:\programmi\Synaptics\SynTP\SynTPEnh.exe" [2006-03-03 761946]
"ntiMUI"="c:\programmi\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe" [2006-05-15 45056]
"ADMTray.exe"="c:\acer\Empowering Technology\admtray.exe" [2005-10-24 2462208]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2005-12-27 69632]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-09-07 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-09-07 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-09-07 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-09-07 455168]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-07-20 7581696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-07-20 86016]
"eRecoveryService"="c:\acer\Empowering Technology\eRecovery\Monitor.exe" [2008-03-17 397312]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2006-06-23 225280]
"LogitechCameraAssistant"="c:\programmi\Acer\OrbiCam\CameraAssistant.exe" [2006-06-26 331776]
"LogitechVideo[inspector]"="c:\programmi\Acer\OrbiCam\InstallHelper.exe" [2006-06-26 15:55 73728]
"LogitechCameraService(E)"="c:\windows\system32\ElkCtrl.exe" [2004-11-01 262144]
"SunJavaUpdateSched"="c:\programmi\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2006-07-20 593920]
"ePower_DMC"="c:\acer\Empowering Technology\ePower\ePower_DMC.exe" [2006-04-14 344064]
"Acer ePower Management"="c:\acer\Empowering Technology\ePower\Acer ePower Management.exe" [2006-01-20 3080192]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2008-09-06 413696]
"AppleSyncNotifier"="c:\programmi\File comuni\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-03 111936]
"iTunesHelper"="c:\programmi\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"RTHDCPL"="RTHDCPL.EXE" [2006-06-28 c:\windows\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 c:\windows\SkyTel.exe]
"nwiz"="nwiz.exe" [2006-07-20 c:\windows\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= c:\windows\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= c:\windows\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 0 (0x0)
"NoFileAssociate"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\programmi\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Maple 10\\JRE\\BIN\\MAPLE.EXE"=
"c:\\Programmi\\MATLAB\\R2006b\\bin\\win32\\MATLAB.exe"=
"d:\\COD4\\iw3mp.exe"=
"c:\\Programmi\\ANSYS Inc\\v110\\RSM\\bin\\JobManagerService.exe"=
"c:\\Programmi\\ANSYS Inc\\v110\\RSM\\bin\\JMAdmin.exe"=
"c:\\Programmi\\ANSYS Inc\\v110\\RSM\\bin\\JMPassword.exe"=
"c:\\Programmi\\ANSYS Inc\\v110\\AISOL\\CommonFiles\\intel\\AnsysWBU.exe"=
"c:\\Programmi\\ANSYS Inc\\v110\\ANSYS\\bin\\intel\\ANSYS.exe"=
"c:\\Programmi\\ANSYS Inc\\v110\\AISOL\\CAD Integration\\intel\\ActivePIMgrU.exe"=
"c:\\Programmi\\ANSYS Inc\\v110\\AISOL\\CAD Integration\\intel\\ReaderHostU.exe"=
"c:\\Programmi\\ANSYS Inc\\v110\\CommonFiles\\TCL\\bin\\intel\\tclsh.exe"=
"c:\\Programmi\\ANSYS Inc\\v110\\CommonFiles\\TCL\\bin\\intel\\wish.exe"=
"c:\\Programmi\\Ansys Inc\\V110\\AISOL\\AUTODYN\\intel\\autodyn.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\livecall.exe"=
"c:\\WINDOWS\\System32\\PnkBstrB.exe"=
"c:\\Programmi\\ANSYS Inc\\v110\\RSM\\bin\\ScriptHostService.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
"c:\\Programmi\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"c:\\Programmi\\File comuni\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3587:TCP"= 3587:TCP:Gruppi peer-to-peer Windows
"3540:UDP"= 3540:UDP:Peer Name Resolution Protocol (PNRP)
"135:TCP"= 135:TCP:*:Disabled:porta135
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-07-19 78416]
R1 OsaFsLoc;OsaFsLoc;c:\windows\system32\drivers\OsaFsLoc.sys [2005-10-15 12106]
R2 ANSYS FLEXlm license manager;ANSYS FLEXlm license manager;c:\programmi\Ansys Inc\Shared Files\Licensing\intel\lmgrd.exe [2006-03-24 1294336]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 EpmPsd;Acer EPM Power Scheme Driver;c:\windows\system32\drivers\epm-psd.sys [2006-01-23 4096]
R2 EpmShd;Acer EPM System Hardware Driver;c:\windows\system32\drivers\epm-shd.sys [2006-01-23 78208]
R2 Flexlm Service 1;Flexlm Service 1;c:\programmi\vNFlexnt\Lmgrd.exe [2003-07-08 659456]
R2 JobManagerService110;Ansys JobManager Service V11;c:\programmi\ANSYS Inc\v110\RSM\bin\JobManagerService.exe [2007-01-16 20480]
R2 osaio;osaio;c:\windows\system32\drivers\osaio.sys [2005-06-30 7296]
R2 osanbm;osanbm;c:\windows\system32\drivers\osanbm.sys [2005-01-14 4010]
R2 ScriptHostService110;Ansys ScriptHost Service V11;c:\programmi\ANSYS Inc\v110\RSM\bin\ScriptHostService.exe [2007-01-16 20480]
R3 lv321av;Logitech USB PC Camera (VC0321);c:\windows\system32\DRIVERS\lv321av.sys [2006-06-19 1097728]
R3 NdisFilt;OSA NdisFilter Protocol;c:\windows\system32\Drivers\NdisFilt.sys [2005-09-13 4392]
S2 FLEXlm Service for vNDesktop;FLEXlm Service for vNDesktop;c:\programmi\vNFlexnt\lmgrd.exe [2003-07-08 659456]
S3 MSSQL$AUTODESKVAULT;SQL Server (AUTODESKVAULT);c:\programmi\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2008-02-26 29183504]
S3 p2pgasvc;Autenticazione gruppo rete peer;c:\windows\system32\svchost.exe [2008-04-14 14336]
S3 p2pimsvc;Gestione identità rete peer;c:\windows\system32\svchost.exe [2008-04-14 14336]
S3 p2psvc;Rete peer;c:\windows\system32\svchost.exe [2008-04-14 14336]
S3 PNRPSvc;Peer Name Resolution Protocol (PNRP);c:\windows\system32\svchost.exe [2008-04-14 14336]
S3 USBSTOR;Driver archiviazione di massa USB;c:\windows\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{88B2E5C0-5FCB-11QQ-BAX5-114016608589}]
c:\recycler\S-1-5-21-1482476501-1644491937-682003330-1113\crss.exe
.
Contenuto della cartella 'Scheduled Tasks'
2008-10-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
- - - - ORFÃOS REMOVIDOS - - - -
HKCU-RunServicesOnce-washindex - c:\program files\Washer\washidx.exe
HKLM-Run-EoEngine - (no file)
HKLM-Run-EoNet - (no file)
HKU-Default-Run-Nokia.PCSync - c:\programmi\Nokia\Nokia PC Suite 6\PcSync2.exe
.
------- Supplementare di scansione -------
.
R0 -: HKCU-Main,Start Page =
hxxp://www.google.it/R0 -: HKCU-Main,SearchMigratedDefaultURL =
hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
R0 -: HKLM-Main,Start Page =
hxxp://it.intl.acer.yahoo.comR1 -: HKCU-Internet Settings,ProxyServer = proxy.ing.unitn.it:80
O8 -: Convert link target to Adobe PDF - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 -: Convert link target to existing PDF - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 -: Convert selected links to Adobe PDF - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 -: Convert selected links to existing PDF - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 -: Convert selection to Adobe PDF - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 -: Convert selection to existing PDF - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 -: Convert to Adobe PDF - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 -: Convert to existing PDF - c:\programmi\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 -: E&sporta in Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O16 -: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-11-13 16:40:39
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\Intel\Wireless\Bin\EvtEng.exe
c:\programmi\Intel\Wireless\Bin\S24EvMon.exe
c:\programmi\file comuni\logitech\lvmvfm\LVPrcSrv.exe
c:\programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\programmi\Alwil Software\Avast4\aswUpdSv.exe
c:\programmi\Ansys Inc\Shared Files\Licensing\intel\ansyslmd.exe
c:\programmi\Autodesk\Data Management Server 2008\Server\Dispatch\Connectivity.WindowsService.JobDispatch.exe
c:\programmi\Autodesk\Data Management Server 2008\Server\Webserver\Connectivity.EDMWS.Server.exe
c:\programmi\Alwil Software\Avast4\ashServ.exe
c:\acer\Empowering Technology\admServ.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\programmi\vNFlexnt\MSC.exe
c:\programmi\File comuni\LightScribe\LSSrvc.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\programmi\Intel\Wireless\Bin\RegSrvc.exe
c:\windows\system32\tcpsvcs.exe
c:\programmi\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\system32\SearchIndexer.exe
c:\windows\ehome\mcrdsvc.exe
c:\programmi\Alwil Software\Avast4\ashMaiSv.exe
c:\programmi\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\dllhost.exe
c:\windows\eHome\ehmsas.exe
c:\windows\system32\rundll32.exe
c:\docume~1\RICCAR~1\IMPOST~1\Temp\RtkBtMnt.exe
c:\windows\system32\wbem\unsecapp.exe
c:\programmi\iPod\bin\iPodService.exe
.
**************************************************************************
.
Ora fine scansione: 2008-11-13 16:45:55 - macchina è stato riavviato
ComboFix-quarantined-files.txt 2008-11-13 15:45:52
Pre-Run: 9.340.583.936 byte disponibili
Post-Run: 9,782,525,952 byte disponibili
WindowsXP-KB310994-SP2-Pro-BootDisk-ITA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
274 --- E O F --- 2008-10-24 15:00:42