ComboFix 10-06-15.02 - Administrator 2010-06-15 20:48:02.1.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1250.48.1045.18.895.246 [GMT 2:00] Uruchomiony z: c:\documents and settings\Administrator\Pulpit\ComboFix.exe AV: AVG Anti-Virus *On-access scanning enabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} AV: BullGuard Antivirus *On-access scanning enabled* (Updated) {7A9BB333-8EDF-4FDC-A2A5-1A30FA021913} AV: ClamAV for Windows *On-access scanning enabled* (Updated) {F1220F1F-7E2E-48CD-846D-B98C6F85CD37} AV: Microsoft Security Essentials *On-access scanning enabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF} AV: Panda Cloud Antivirus *On-access scanning disabled* (Updated) {5AD27692-540A-464E-B625-78275FA38393} FW: BullGuard Firewall *disabled* {2AEF4CB6-61B5-4E60-AF22-D95E75B63FA1} . ((((((((((((((((((((((((((((((((((((((( Usunięto ))))))))))))))))))))))))))))))))))))))))))))))))) . E:\Autorun.inf . ((((((((((((((((((((((((( Pliki utworzone od 2010-05-15 do 2010-06-15 ))))))))))))))))))))))))))))))) . 2010-06-15 17:13 . 2010-06-15 18:51 -------- d-----w- c:\windows\system32\wbem\Logs 2010-06-15 17:07 . 2010-06-15 17:07 -------- d-----w- c:\documents and settings\Administrator\Dane aplikacji\SampleView 2010-06-15 17:04 . 2008-12-13 13:47 40496 ----a-w- c:\windows\system32\drivers\hotcore3.sys 2010-06-15 17:04 . 2010-06-15 17:04 -------- d-----w- c:\program files\Paragon Software 2010-06-15 16:46 . 2010-06-15 16:46 -------- d--h--w- c:\windows\system32\GroupPolicy 2010-06-15 16:22 . 2008-04-13 19:19 75264 ----a-w- c:\windows\system32\drivers\ipsec.sys 2010-06-15 16:22 . 2008-04-13 19:19 75264 ----a-w- c:\windows\system32\dllcache\ipsec.sys 2010-06-13 19:10 . 2010-06-13 19:10 39956 ------w- c:\windows\system32\drivers\irbus.sys 2010-06-13 15:02 . 2010-06-13 15:02 -------- d-----w- c:\documents and settings\Administrator\Ustawienia lokalne\Dane aplikacji\PCHealth 2010-06-13 14:59 . 2010-06-13 14:59 39956 ------w- c:\windows\system32\drivers\ipfltdrv.sys 2010-06-13 14:10 . 2010-06-13 14:10 -------- d-----w- c:\windows\system32\wbem\Repository 2010-06-13 13:49 . 2008-04-13 22:49 39956 ----a-w- c:\windows\system32\ipsec.sys 2010-06-13 07:40 . 2010-06-13 14:09 -------- d--h--w- c:\documents and settings\Administrator\Recent(2) 2010-06-12 04:27 . 2009-01-23 13:48 55504 ----a-w- c:\windows\system32\drivers\BdFileSpy.sys 2010-06-11 18:29 . 2010-06-11 18:29 -------- d-----w- c:\documents and settings\Administrator\Moje dokumenty 2010-06-11 18:26 . 2010-06-11 18:26 -------- d-----w- c:\windows\Twain32 2010-06-11 17:50 . 2010-06-11 17:50 3584 ----a-r- c:\documents and settings\Administrator\Dane aplikacji\Microsoft\Installer\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}\Icon386ED4E3.exe 2010-06-10 16:37 . 2010-06-11 17:50 -------- d-----w- c:\program files\Windows Installer Clean Up 2010-06-10 16:13 . 2010-06-12 03:45 -------- d-----w- c:\windows\system32\NtmsData 2010-06-08 18:53 . 2010-06-08 18:53 503808 ----a-w- c:\documents and settings\Administrator\Dane aplikacji\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-7b397e17-n\msvcp71.dll 2010-06-08 18:53 . 2010-06-08 18:53 499712 ----a-w- c:\documents and settings\Administrator\Dane aplikacji\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-7b397e17-n\jmc.dll 2010-06-08 18:53 . 2010-06-08 18:53 348160 ----a-w- c:\documents and settings\Administrator\Dane aplikacji\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-7b397e17-n\msvcr71.dll 2010-06-08 18:53 . 2010-06-08 18:53 12800 ----a-w- c:\documents and settings\Administrator\Dane aplikacji\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-36257692-n\decora-d3d.dll 2010-06-08 18:53 . 2010-06-08 18:53 61440 ----a-w- c:\documents and settings\Administrator\Dane aplikacji\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-36257692-n\decora-sse.dll 2010-06-08 18:53 . 2010-06-08 18:52 411368 ----a-w- c:\windows\system32\deployJava1.dll 2010-06-06 11:08 . 2010-06-15 18:47 -------- d-----w- c:\windows\system32\CatRoot2 2010-06-05 16:20 . 2010-06-10 16:37 -------- d-----w- c:\program files\MSECache 2010-05-30 14:38 . 2010-06-15 18:20 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\BullGuard 2010-05-30 14:38 . 2010-06-08 18:11 -------- d-----w- c:\documents and settings\Administrator\Dane aplikacji\BullGuard 2010-05-30 14:37 . 2010-05-30 14:37 -------- d-----w- c:\program files\BullGuard Ltd 2010-05-17 12:36 . 2010-05-17 12:36 -------- d-----w- c:\documents and settings\Administrator\Ustawienia lokalne\Dane aplikacji\Identities . (((((((((((((((((((((((((((((((((((((((( Sekcja Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-06-13 14:44 . 2004-09-20 06:20 92980 ----a-w- c:\windows\system32\perfc015.dat 2010-06-13 14:44 . 2004-09-20 06:20 33976 ----a-w- c:\windows\system32\perfh015.dat 2010-06-13 14:44 . 2010-04-24 19:54 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\PrevxCSI 2010-06-13 14:35 . 2010-04-24 19:55 61440 ----a-w- c:\windows\system32\PxSecure.dll 2010-06-13 14:35 . 2010-04-24 19:55 57248 ----a-w- c:\windows\system32\drivers\pxrts.sys 2010-06-13 14:35 . 2010-04-24 19:55 30320 ----a-w- c:\windows\system32\drivers\pxscan.sys 2010-06-13 14:35 . 2010-04-24 19:55 24400 ----a-w- c:\windows\system32\drivers\pxkbf.sys 2010-06-13 13:21 . 2010-05-15 16:29 -------- d-----w- c:\documents and settings\Administrator\Dane aplikacji\XnView 2010-06-13 08:59 . 2008-08-02 06:06 90616 ----a-w- c:\documents and settings\Administrator\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT 2010-06-12 05:34 . 2008-08-02 14:32 -------- d-----w- c:\program files\microsoft frontpage 2010-06-12 05:05 . 2009-10-26 15:23 31640 ----a-r- c:\windows\system32\drivers\Afw.sys 2010-06-10 18:06 . 2008-08-02 14:32 -------- d-----w- c:\program files\Java 2010-06-08 18:53 . 2008-08-02 14:31 -------- d-----w- c:\program files\Common Files\Java 2010-06-06 10:34 . 2008-08-02 14:31 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Microsoft Help 2010-06-06 10:13 . 2010-05-04 15:52 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\IObit 2010-06-06 07:56 . 2008-08-02 16:48 -------- d-----w- c:\documents and settings\Administrator\Dane aplikacji\Roxio 2010-06-06 07:56 . 2008-08-02 14:31 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Roxio 2010-06-06 06:40 . 2010-03-07 16:25 -------- d-----w- c:\documents and settings\Administrator\Dane aplikacji\AIMP 2010-05-30 14:43 . 2009-04-28 10:51 87376 ----a-w- c:\windows\system32\BGLsp.dll 2010-05-30 14:43 . 2009-10-26 15:23 256792 ----a-r- c:\windows\system32\drivers\AfwCore.sys 2010-05-12 17:05 . 2010-04-24 19:54 -------- d-----w- c:\program files\Prevx 2010-05-12 17:05 . 2010-04-26 18:31 1032176 ----a-w- c:\documents and settings\All Users\Dane aplikacji\PrevxCSI\~PrevxCSIUpdate.exe 2010-05-04 15:52 . 2010-05-04 15:52 -------- d-----w- c:\program files\IObit 2010-05-02 08:09 . 2004-08-04 08:00 1851520 ----a-w- c:\windows\system32\win32k.sys 2010-04-29 13:39 . 2009-05-31 17:10 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-04-29 13:39 . 2009-05-31 17:10 20952 ----a-w- c:\windows\system32\drivers\mbam.sys 2010-04-26 20:10 . 2009-06-21 15:20 1718912 ----a-w- c:\windows\system32\BootMan.exe 2010-04-24 17:01 . 2010-04-16 19:13 -------- d-----w- c:\documents and settings\Administrator\Dane aplikacji\Media Player Classic 2010-04-24 16:59 . 2010-04-24 16:56 -------- d-----w- c:\documents and settings\Administrator\Dane aplikacji\Auslogics 2010-04-20 05:34 . 2004-08-04 08:00 285696 ----a-w- c:\windows\system32\atmfd.dll 2010-04-16 19:08 . 2010-04-16 19:07 -------- d-----w- c:\program files\Real Alternative 2010-04-16 16:09 . 2004-08-04 08:00 669696 ----a-w- c:\windows\system32\wininet.dll 2010-04-16 16:08 . 2004-08-04 08:00 81920 ----a-w- c:\windows\system32\ieencode.dll . ((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MsmqIntCert"="mqrt.dll" [2009-06-25 177152] "SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-01-05 872448] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-01-12 827392] "Cpqset"="c:\program files\Hewlett-Packard\Default Settings\cpqset.exe" [2007-05-03 57344] "Recguard"="c:\windows\Sminst\Recguard.exe" [2005-12-20 1187840] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] c:\documents and settings\All Users\Menu Start\Programy\Autostart\ Launchy.lnk - c:\moje programy\Launchy\Launchy.exe [2009-11-19 286720] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OneCard] 2007-02-07 01:30 74240 ----a-r- c:\program files\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\windows\system32\APSHook.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BgMainSvc] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "135:TCP"= 135:TCP:DCOM(135) R0 hotcore3;Hotcore helper;c:\windows\system32\drivers\hotcore3.sys [2010-06-15 40496] R0 pxscan;pxscan;c:\windows\system32\drivers\pxscan.sys [2010-04-24 30320] R0 SafeBoot;SafeBoot;c:\windows\system32\drivers\SafeBoot.sys [2007-02-07 100495] R0 SbAlg;SbAlg;c:\windows\system32\drivers\SbAlg.sys [2006-10-09 44720] R0 SbFsLock;SbFsLock;c:\windows\system32\drivers\SbFsLock.sys [2007-03-29 13696] R1 RsvLock;RsvLock;c:\windows\system32\drivers\rsvlock.sys [2007-02-07 5808] R2 ASBroker;Logon Session Broker;c:\windows\System32\svchost.exe -k Cognizance [2004-08-04 14336] R2 ASChannel;Local Communication Channel;c:\windows\System32\svchost.exe -k Cognizance [2004-08-04 14336] R2 BdFileSpy;BullGuard File Monitor Driver;c:\windows\system32\drivers\BdFileSpy.sys [2010-06-12 55504] R2 BsFileScan;BullGuard File Scan Service;c:\windows\System32\svchost.exe -k BullGuard [2004-08-04 14336] R2 BsFire;BullGuard Firewall Service;c:\windows\System32\svchost.exe -k BullGuard [2004-08-04 14336] R2 BsMailProxy;BullGuard Email Monitoring Service;c:\windows\System32\svchost.exe -k BullGuard [2004-08-04 14336] R2 CSIScanner;CSIScanner;c:\program files\Prevx\prevx.exe [2010-04-24 6348024] R2 pxrts;pxrts;c:\windows\system32\drivers\pxrts.sys [2010-04-24 57248] R3 afw;Agnitum firewall driver;c:\windows\system32\drivers\Afw.sys [2009-10-26 31640] R3 afwcore;afwcore;c:\windows\system32\drivers\AfwCore.sys [2009-10-26 256792] R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [2006-09-19 36608] R3 pxkbf;pxkbf;c:\windows\system32\drivers\pxkbf.sys [2010-04-24 24400] S2 NanoServiceMain;NanoServiceMain; [x] S3 0123231261332943mcinstcleanup;0123231261332943mcinstcleanup; [x] S3 0177991269482521mcinstcleanup;0177991269482521mcinstcleanup; [x] S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2009-06-21 13192] S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2009-06-21 8456] S3 Harmonogram automatycznej usługi LiveUpdate;Harmonogram automatycznej usługi LiveUpdate; [x] S3 HpFkCryptService;Drive Encryption Service;c:\program files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe [2007-03-29 221184] S3 IS360service;IS360service;c:\program files\IObit\IObit Security 360\is360srv.exe [2010-05-04 311568] S3 pdfcDispatcher;PDF Document Manager;c:\program files\PDF Complete\pdfsvc.exe [2007-07-28 540448] S4 PuranDefrag;PuranDefrag;c:\windows\system32\PuranDefragS.exe [2010-03-21 229376] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 Cognizance REG_MULTI_SZ ASBroker ASChannel getPlusHelper REG_MULTI_SZ getPlusHelper BullGuard REG_MULTI_SZ BgMainSvc BsFileScan BsMailProxy BsFire [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}] 2007-04-19 11:23 452136 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe . . ------- Skan uzupełniający ------- . uStart Page = hxxp://www.hp.com uInternet Connection Wizard,ShellNext = hxxp://www.symantec.com/techsupp/servlet/ProductMessages?module=3019&error=7&language=Polish&product=NIS&version=10.2.0.30&build=HPQ_60D uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: E&ksportuj do programu Microsoft Excel IE: Wyślij do urządzenia &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm LSP: c:\windows\system32\BGLsp.dll FF - ProfilePath - c:\documents and settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\igi8qiok.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.pl/ FF - plugin: c:\documents and settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\igi8qiok.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ ---- FIREFOX - SPOSÓB POSTĘPOWANIA ---- pref(dom.disable_open_during_load, false); FF - user.js: browser.cache.memory.capacity - 16000 FF - user.js: browser.chrome.favicons - false FF - user.js: browser.display.show_image_placeholders - true FF - user.js: browser.turbo.enabled - true FF - user.js: browser.urlbar.autocomplete.enabled - true FF - user.js: browser.urlbar.autoFill - false FF - user.js: content.max.tokenizing.time - 3000000 FF - user.js: content.maxtextrun - 4095 FF - user.js: content.notify.backoffcount - 5 FF - user.js: content.notify.interval - 1000000 FF - user.js: content.notify.ontimer - true FF - user.js: content.switch.threshold - 1000000 FF - user.js: dom.disable_window_status_change - true FF - user.js: network.http.max-connections - 48 FF - user.js: network.http.max-connections-per-server - 16 FF - user.js: network.http.max-persistent-connections-per-proxy - 16 FF - user.js: network.http.max-persistent-connections-per-server - 8 FF - user.js: network.http.pipelining - true FF - user.js: network.http.pipelining.firstrequest - true FF - user.js: network.http.pipelining.maxrequests - 8 FF - user.js: network.http.proxy.pipelining - true FF - user.js: network.http.request.max-start-delay - 0 FF - user.js: nglayout.initialpaint.delay - 250 FF - user.js: plugin.expose_full_path - true FF - user.js: ui.submenuDelay - 0 FF - user.js: browser.blink_allowed - true FF - user.js: network.prefetch-next - true FF - user.js: layout.spellcheckDefault - 1 FF - user.js: browser.search.openintab - false FF - user.js: browser.tabs.closeButtons - 1 FF - user.js: browser.tabs.opentabfor.middleclick - true FF - user.js: browser.tabs.tabMinWidth - 100 FF - user.js: browser.urlbar.hideGoButton - false c:\moje programy\Firefox 3.0.1\greprefs\all.js - pref("ui.use_native_colors", true); c:\moje programy\Firefox 3.0.1\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\moje programy\Firefox 3.0.1\greprefs\all.js - pref("svg.smil.enabled", false); c:\moje programy\Firefox 3.0.1\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true); c:\moje programy\Firefox 3.0.1\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\moje programy\Firefox 3.0.1\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\moje programy\Firefox 3.0.1\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\moje programy\Firefox 3.0.1\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\moje programy\Firefox 3.0.1\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\moje programy\Firefox 3.0.1\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); . - - - - USUNIĘTO PUSTE WPISY - - - - ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - (no file) ShellExecuteHooks-{4F07DA45-8170-4859-9B5F-037EF2970034} - (no file) ActiveSetup-ccc-core-static - msiexec AddRemove-{E2883E8F-472F-4fb0-9522-AC9BF37916A7} - c:\program files\NOS\bin\getPlus_Helper.dll ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-06-15 20:53 Windows 5.1.2600 Dodatek Service Pack 3 NTFS skanowanie ukrytych procesów ... skanowanie ukrytych wpisów autostartu ... HKLM\Software\Microsoft\Windows\CurrentVersion\Run Cpqset = c:\program files\Hewlett-Packard\Default Settings\cpqset.exe????????T??????????????|?M?|?????M?|&?@ skanowanie ukrytych plików ... skanowanie pomyślnie ukończone ukryte pliki: 0 ************************************************************************** Binary file raw_enum.dat matches . --------------------- Pliki DLL ładowane pod uruchomionymi procesami --------------------- - - - - - - - > 'winlogon.exe'(892) c:\windows\system32\Ati2evxx.dll c:\program files\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll c:\program files\Hewlett-Packard\IAM\bin\ItMsg.dll - - - - - - - > 'explorer.exe'(252) c:\windows\system32\APSHook.dll c:\windows\system32\msi.dll c:\windows\system32\WPDShServiceObj.dll c:\program files\BullGuard Ltd\BullGuard\BackupShellHook.dll c:\windows\system32\btncopy.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Pozostałe uruchomione procesy ------------------------ . c:\windows\system32\Ati2evxx.exe c:\windows\system32\Ati2evxx.exe c:\program files\Hewlett-Packard\IAM\bin\asghost.exe c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe c:\windows\system32\msdtc.exe c:\windows\System32\SCardSvr.exe c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe . ************************************************************************** . Czas ukończenia: 2010-06-15 20:56:43 - komputer został uruchomiony ponownie ComboFix-quarantined-files.txt 2010-06-15 18:56 Przed: 11 848 843 264 bajtów wolnych Po: 11 720 441 856 bajtów wolnych WindowsXP-KB310994-SP2-Pro-BootDisk-PLK.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer - - End Of File - - F7CD785672CE2129B3D90590979139B1