Hello - I am reposting this message because my original did not appear to upload. I sincerely apologize if this message arrives twice.
I have run RogueKiller after encountering frequent "Threat Detected" warnings from Avast (attempts to link to different URLs linking to .dlls).
The scan appears to indicate my computer is clean with the exception of the following two registry PUMs:
¤¤¤ Registry : 2 ¤¤¤
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-2691382955-3789416768-595039784-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_TrackProgs : 0 -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-2691382955-3789416768-595039784-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_TrackProgs : 0 -> Found
I am not experienced with registry items and therefore cannot tell if these indicate an infection or not, and/or whether it is safe to allow RogueKiller to delete them. Can someone please advise?
For reference, the full RogueKiller report is included below.
Thank you very much for your help!
------------------------------------------------------
RogueKiller V10.8.4.0 (x64) [Jun 15 2015] by Adlice Software
mail :
http://www.adlice.com/contact/Feedback :
http://forum.adlice.comWebsite :
http://www.adlice.com/softwares/roguekiller/Blog :
http://www.adlice.comOperating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : <myname> [Administrator]
Started from : C:\Users\<myname>\Downloads\RogueKillerX64.exe
Mode : Scan -- Date : 06/21/2015 09:58:48
¤¤¤ Processes : 0 ¤¤¤
¤¤¤ Registry : 2 ¤¤¤
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-2691382955-3789416768-595039784-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_TrackProgs : 0 -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-2691382955-3789416768-595039784-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_TrackProgs : 0 -> Found
¤¤¤ Tasks : 0 ¤¤¤
¤¤¤ Files : 0 ¤¤¤
¤¤¤ Hosts File : 0 ¤¤¤
¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤
¤¤¤ Web browsers : 0 ¤¤¤
¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: HGST HTS721010A9E630 +++++
--- User ---
[MBR] 294f44b9c5bc231730cbf420e6f7ce8a
[BSP] 87bff97a231e9a9784d276e9e7954f8a : Unknown|VT.Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 372736 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
2 - [XXXXXX] EXTEN-LBA (0xf) [VISIBLE] Offset (sectors): 763570176 | Size: 557520 MB
3 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 1905371136 | Size: 23512 MB
User = LL1 ... OK
User = LL2 ... OK
+++++ PhysicalDrive1: SanDisk iSSD P4 8GB +++++
--- User ---
[MBR] 88920e8157efee4827b2137e18b5ca63
[BSP] 0a9420da5d388cf72c9f5653515471d4 : Empty MBR Code
Partition table:
0 - [XXXXXX] UNKNOWN (0x73) [VISIBLE] Offset (sectors): 2048 | Size: 7639 MB
User = LL1 ... OK
User = LL2 ... OK