Thank you. Here's RK's log-
RogueKiller V9.2.10.0 [Jul 11 2014] by Adlice Software
mail :
http://www.adlice.com/contact/
Feedback :
http://forum.adlice.com
Website :
http://www.adlice.com/softwares/roguekiller/
Blog :
http://www.adlice.com
Operating System : Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User : Karen [Admin rights]
Mode : Remove -- Date : 09/14/2014 23:05:36
¤¤¤ Bad processes : 0 ¤¤¤
¤¤¤ Registry Entries : 8 ¤¤¤
[PUM.Policies] HKEY_USERS\S-1-5-21-4245672646-903908883-2055752331-1006\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableRegistryTools : 0 -> NOT SELECTED
[PUM.Policies] HKEY_USERS\S-1-5-21-4245672646-903908883-2055752331-1006\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableTaskMgr : 0 -> NOT SELECTED
[PUM.Desktop] HKEY_USERS\S-1-5-21-4245672646-903908883-2055752331-1006\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop | NoChangingWallpaper : 0 -> NOT SELECTED
[PUM.StartMenu] HKEY_USERS\S-1-5-21-4245672646-903908883-2055752331-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowRecentDocs : 0 -> NOT SELECTED
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> NOT SELECTED
[PUM.HomePage] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main | Start Page :
http://www.dell4me.com/myway -> NOT SELECTED
[PUM.HomePage] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main | Start Page :
http://www.dell4me.com/myway -> NOT SELECTED
[PUM.SearchPage] HKEY_USERS\S-1-5-21-4245672646-903908883-2055752331-1006\Software\Microsoft\Internet Explorer\Main | Search Page :
http://my.juno.com/s/search?r=minisearch -> NOT SELECTED
¤¤¤ Scheduled tasks : 0 ¤¤¤
¤¤¤ Files : 0 ¤¤¤
¤¤¤ HOSTS File : 0 ¤¤¤
¤¤¤ Antirootkit : 4 (Driver: LOADED) ¤¤¤
[Filter(Kernel.Filter)] \Driver\atapi @ \Device\Ide\IdeDeviceP1T1L0-17 : \Driver\AnyDVD @ Unknown (\SystemRoot\System32\Drivers\AnyDVD.sys)
[Filter(Kernel.Filter)] \Driver\atapi @ Unknown : \Driver\Cdrom @ \Device\CdRom1 (\SystemRoot\System32\DRIVERS\serial.sys)
[Filter(Kernel.Filter)] \Driver\atapi @ \Device\Ide\IdeDeviceP1T0L0-f : \Driver\AnyDVD @ Unknown (\SystemRoot\System32\Drivers\AnyDVD.sys)
[Filter(Kernel.Filter)] \Driver\atapi @ Unknown : \Driver\Cdrom @ \Device\CdRom0 (\SystemRoot\System32\DRIVERS\serial.sys)
¤¤¤ Web browsers : 3 ¤¤¤
[PUM.Proxy][FIREFX:Config] pf4zwblf.default : user_pref("network.proxy.http", "127.0.0.1"); -> NOT SELECTED
[PUM.Proxy][FIREFX:Config] pf4zwblf.default : user_pref("network.proxy.http_port", 50370); -> NOT SELECTED
[PUM.HomePage][FIREFX:Config] pf4zwblf.default : user_pref("browser.startup.homepage", "
www.rr.com"); -> NOT SELECTED
¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: IC35L090AVV207-0 +++++
--- User ---
[MBR] 6b61654af29af97c554fd93638735cc2
[BSP] f0531316a6163d16f4ba254ab3fe3bf4 : Windows XP MBR Code
Partition table:
0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 63 | Size: 31 MB
1 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 64260 | Size: 76253 MB
User = LL1 ... OK
User = LL2 ... OK
============================================
RKreport_DEL_09072014_031239.log - RKreport_SCN_09072014_030702.log - RKreport_SCN_09142014_225904.log
The page for KernelMode RootKits came up again after the scan. Just thought I'd mention it in case it's important. If not, nevermind.
Going to go do the MBAM now.