Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User : Marco [Admin rights]
Mode : Scan – Date : 11/05/2012 16:35:37
here listpart report:
ListParts by Farbar Version: 30-10-2012
Ran by [removed] (administrator) on 05-11-2012 at 16:39:24
Windows XP (X86)
Running From: C:\Documents and Settings\[removed]\Desktop
Language: 0410
************************************************************
========================= Memory info ======================
Percentage of memory in use: 30%
Total physical RAM: 3455.36 MB
Available physical RAM: 2399.86 MB
Total Pagefile: 5335.94 MB
Available Pagefile: 4289.28 MB
Total Virtual: 2047.88 MB
Available Virtual: 1994.82 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:120.17 GB) (Free:13.75 GB) NTFS ==>[Drive with boot components (Windows XP)]
2 Drive d: (HP_RECOVERY) (Fixed) (Total:7.81 GB) (Free:0.71 GB) FAT32 ==>[Drive with boot components (Windows XP)]
Disco n. Stato Dim. Libera Din Gpt
——– ———- ——- ——- — —
Disco 0 Pronto 596 GB 468 GB
Partitions of Disk 0:
===============
Partizione n. Tipo Dim. Offset
————- —————- ——- ——-
Partizione 1 Primario 120 GB 32 KB
Partizione 2 Primario 8010 MB 120 GB
Partizione 3 Esteso 468 GB 128 GB
================================================================================
======================
Disk: 0
La partizione attualmente selezionata è la partizione 1.
Partizione 1
Tipo : 07
Nascosta: No
Attiva: Sì
Volume n. Lett. Etichetta Fs Tipo Dim. Stato Info
———- — ———– —– ———- ——- ——— ——–
* Volume 1 C NTFS Partizione 120 GB Integro Sistema (partition with boot components)
================================================================================
======================
Disk: 0
La partizione attualmente selezionata è la partizione 2.
Partizione 2
Tipo : 0C
Nascosta: No
Attiva: No
Volume n. Lett. Etichetta Fs Tipo Dim. Stato Info
———- — ———– —– ———- ——- ——— ——–
* Volume 2 D HP_RECOVERY FAT32 Partizione 8010 MB Integro
================================================================================
======================
****** End Of Log ******
I've done with norton disabled (for both) , list part without mark LIST BCD
Extract the contents of the zipped file to desktop.
Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
[external image: Posted Image] Click the image to enlarge it
In the right panel, you will see several boxes that have been checked. Uncheck the following …
IAT/EAT
Drives/Partition other than Systemdrive (typically C:\)
Show All (don't miss this one)
Then click the Scan button & wait for it to finish.
Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries.
———-
Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User : Marco [Admin rights]
Mode : Remove – Date : 11/07/2012 14:23:29