I was able to get windows updates yesterday and it seems to be running better, the automatic updates worked. Thank you for all your help
ROOTREPEAL (c) AD, 2007-2009
==================================================
Scan Start Time: 2010/06/08 18:20
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================
Drivers
-------------------
Name: dump_iaStor.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_iaStor.sys
Address: 0xA0EE6000 Size: 851968 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0x9FAAE000 Size: 49152 File Visible: No Signed: -
Status: -
Name: uphcleanhlp.sys
Image Path: C:\WINDOWS\system32\Drivers\uphcleanhlp.sys
Address: 0x9FFEA000 Size: 8960 File Visible: No Signed: -
Status: -
Hidden/Locked Files
-------------------
Path: C:\hiberfil.sys
Status: Locked to the Windows API!
Path: c:\documents and settings\rob\local settings\temp\~df1223.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)
Path: c:\documents and settings\rob\local settings\temp\~df5740.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)
Path: c:\documents and settings\rob\local settings\temp\~dfda73.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\clickonce_bootstrap.exe.manifest
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Interop.IWshRuntimeLibrary.cdf-ms
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Interop.IWshRuntimeLibrary.manifest
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\stdole.cdf-ms
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\stdole.manifest
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Xceed.Compression.cdf-ms
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Xceed.Compression.manifest
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\DellDriverDownloadManager.cdf-ms
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\DellDriverDownloadManager.manifest
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Core.cdf-ms
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Core.manifest
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.ISOImage.cdf-ms
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.ISOImage.manifest
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\DellDriverDownloadManager.exe.manifest
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.cdf-ms
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.manifest
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.manifest
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\Dell.eSupport.DownloadManager.Localization.resources.cdf-ms
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Rob\Local Settings\Apps\2.0\WM1CB0O5.BRL\WMLNLB4M.66W\manifests\DellDriverDownloadManager.exe.cdf-ms
Status: Locked to the Windows API!
SSDT
-------------------
#: 012 Function Name: NtAlertResumeThread
Status: Hooked by "<unknown>" at address 0x8a4b1658
#: 013 Function Name: NtAlertThread
Status: Hooked by "<unknown>" at address 0x89a60390
#: 017 Function Name: NtAllocateVirtualMemory
Status: Hooked by "<unknown>" at address 0x8a4dc1b0
#: 043 Function Name: NtCreateMutant
Status: Hooked by "<unknown>" at address 0x898ba4d0
#: 053 Function Name: NtCreateThread
Status: Hooked by "<unknown>" at address 0x89a64b20
#: 083 Function Name: NtFreeVirtualMemory
Status: Hooked by "<unknown>" at address 0x89a278b8
#: 089 Function Name: NtImpersonateAnonymousToken
Status: Hooked by "<unknown>" at address 0x89a13c28
#: 091 Function Name: NtImpersonateThread
Status: Hooked by "<unknown>" at address 0x8a484f28
#: 108 Function Name: NtMapViewOfSection
Status: Hooked by "<unknown>" at address 0x89a5e210
#: 114 Function Name: NtOpenEvent
Status: Hooked by "<unknown>" at address 0x89a59a90
#: 123 Function Name: NtOpenProcessToken
Status: Hooked by "<unknown>" at address 0x89a32510
#: 129 Function Name: NtOpenThreadToken
Status: Hooked by "<unknown>" at address 0x8a4923f8
#: 206 Function Name: NtResumeThread
Status: Hooked by "<unknown>" at address 0x8a4a7630
#: 213 Function Name: NtSetContextThread
Status: Hooked by "<unknown>" at address 0x89acb350
#: 228 Function Name: NtSetInformationProcess
Status: Hooked by "<unknown>" at address 0x8a4a97a8
#: 229 Function Name: NtSetInformationThread
Status: Hooked by "<unknown>" at address 0x8a494a40
#: 253 Function Name: NtSuspendProcess
Status: Hooked by "<unknown>" at address 0x89a5f700
#: 254 Function Name: NtSuspendThread
Status: Hooked by "<unknown>" at address 0x8a492ab0
#: 257 Function Name: NtTerminateProcess
Status: Hooked by "<unknown>" at address 0x89a53778
#: 258 Function Name: NtTerminateThread
Status: Hooked by "<unknown>" at address 0x89a74568
#: 263 Function Name: NtUnloadKey
Status: Hooked by "C:\WINDOWS\system32\Drivers\uphcleanhlp.sys" at address 0x9ffea6d0
#: 267 Function Name: NtUnmapViewOfSection
Status: Hooked by "<unknown>" at address 0x8a4af9c0
#: 277 Function Name: NtWriteVirtualMemory
Status: Hooked by "<unknown>" at address 0x898ff780
==EOF==
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.netdevice: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
All processes killed
========== REGISTRY ==========
Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ce75a476-d092-11de-996a-00225f54032b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ce75a476-d092-11de-996a-00225f54032b}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\SearchSettings deleted successfully.
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer\\"HonorAutoRunSetting"|dword:00000001 /E : value set successfully!
========== COMMANDS ==========
[EMPTYTEMP]
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 54903170 bytes
->Flash cache emptied: 9890 bytes
User: Rob
->Temp folder emptied: 2726342 bytes
->Temporary Internet Files folder emptied: 121485350 bytes
->Java cache emptied: 4529059 bytes
->Flash cache emptied: 5161 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 150127 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 175.00 mb
OTM by OldTimer - Version 3.1.12.2 log created on 06082010_194527
Files moved on Reboot...
C:\Documents and Settings\Rob\Local Settings\Temporary Internet Files\Content.IE5\VD92ACCU\viewtopic[1].htm moved successfully.
File C:\WINDOWS\temp\Perflib_Perfdata_5a4.dat not found!
Registry entries deleted on Reboot...