Using RootkitRevealer
1. Please study the RKR web page carefully. (TechNet/Systernals link above)
2. Don't use your computer while RKR is scanning.
Start RKR, wait about 10 seconds, click Scan, then leave computer untouched until it completes. An idle machine will minimise the possibility of false positive reports caused by changes to the system during the scan. Background processes may still make intermittent changes, but resulting discrepancies tend to be obvious from their registry or filesystem branch; on a re-scan many may not recur.
3. Save the discrepancy list to text file as needed.
Using the File->Save dialog, select "My Computer" and work down to a suitable folder. The "My Documents" and "Desktop" buttons point to a System user's folders.
4. Use the search feature in the RKR forums.
For questionable discrepancies, search using a distinctive part of the registry key or path name. Very frequently the same item has appeared before and been commented upon. Often they turn out to be innocuous.
5. Search Google.
Googling a distinctive part of the registry key, especially the CLSID, can often lead to forum reports of the application responsible. Similarly, googling filenames may lead to removal advice if malicious. If using long strings copied from posts, ensure that no extra blanks have become embedded in the search string.
6. When posting a log, ATTACH either the full text log or a representative subsection if it's too large.