Also noticed that 3 sites were entered as "Always Allow" in my Internet Options/cookie handling..I removed them....
ArchiveData(auto-quarantine- 2005-07-29 10-36-49.bckp)
Referencefile : SE1R58 28.07.2005
======================================================
MRU LIST
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[0]=MRU FileReference : C:\Documents and Settings\rfl\Application Data\microsoft\office\recent\ Rapist flees with victims vehicle.doc.LNK
obj[1]=MRU FileReference : C:\Documents and Settings\rfl\recent\??rvices.exe.lnk
obj[2]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\adobe\adobe acrobat\5.0\avgeneral\crecentfiles\c1
obj[3]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\adobe\adobe acrobat\5.0\avgeneral\crecentfiles\c2
obj[4]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\adobe\adobe acrobat\5.0\avgeneral\crecentfiles\c3
obj[5]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\adobe\adobe acrobat\5.0\avgeneral\crecentfiles\c4
obj[6]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\adobe\adobe acrobat\5.0\avgeneral\crecentfiles\c5
obj[7]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\adobe\adobe acrobat\5.0\avgeneral\crecentfiles\c6
obj[8]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\adobe\adobe acrobat\5.0\avgeneral\crecentfiles\c7
obj[9]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\adobe\adobe acrobat\5.0\avgeneral\crecentfiles\c8
obj[10]=MRU FileReference : C:\Documents and Settings\rfl\Application Data\microsoft\office\recent\ASAP Utilities.LNK
obj[11]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\direct3d\mostrecentapplication name
obj[12]=MRU RegReference : software\microsoft\direct3d\mostrecentapplication name
obj[13]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\direct3d\mostrecentapplication name
obj[14]=MRU RegReference : software\microsoft\direct3d\mostrecentapplication name
obj[15]=MRU RegReference : software\microsoft\directdraw\mostrecentapplication name
obj[16]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\frontpage\editor default add image directory
obj[17]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\frontpage\editor\per-web image save directories
obj[18]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\frontpage\editor\recent templates
obj[19]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\frontpage\explorer last import file path
obj[20]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\frontpage\explorer\frontpage explorer\recent file list
obj[21]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\frontpage\explorer\frontpage explorer\recent page list
obj[22]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\frontpage\explorer\frontpage explorer\recent publish list
obj[23]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\frontpage\explorer\frontpage explorer\recent web list
obj[24]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\frontpage\explorer\frontpage explorer\recently created servers
obj[25]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\frontpage\webs\opened
obj[26]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\frontpage\webs\published
obj[27]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\internet explorer download directory
obj[28]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\internet explorer\main save directory
obj[29]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\mediaplayer\medialibraryui mllastselectednode
obj[30]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\mediaplayer\player\recentfilelist
obj[31]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\mediaplayer\player\settings opendir
obj[32]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\mediaplayer\preferences lastplaylistindex
obj[33]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\mediaplayer\preferences lastplaylist
obj[34]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\mediaplayer\preferences searchpath
obj[35]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\microsoft management console\recent file list
obj[36]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\ntbackup\log files
obj[37]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\office\10.0\clip organizer\search\last query
obj[38]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\office\10.0\common\open find\microsoft document imaging\settings\save as\file name mru value
obj[39]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\office\10.0\common\open find\microsoft frontpage\settings\link to file\file name mru
obj[40]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\office\10.0\common\open find\microsoft powerpoint\settings\insert picture\file name mru value
obj[41]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\office\10.0\common\open find\microsoft powerpoint\settings\save as\file name mru value
obj[42]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\office\10.0\common\open find\microsoft word\settings\open\file name mru value
obj[43]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\office\10.0\common\open find\microsoft word\settings\save as\file name mru value
obj[44]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\office\10.0\common\search\last query
obj[45]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\office\10.0\excel\recent files
obj[46]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\office\10.0\powerpoint\recent file list
obj[47]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\office\10.0\powerpoint\recent templates
obj[48]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\office\10.0\powerpoint\recent typeface list
obj[49]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\office\10.0\powerpoint\recentfolderlist
obj[50]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\office\11.0\access\settings MRUFlags4
obj[51]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\office\11.0\access\settings MRUFlags3
obj[52]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\office\11.0\access\settings MRUFlags2
obj[53]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\office\11.0\access\settings MRU3
obj[54]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\office\11.0\access\settings MRU2
obj[55]=MRU FileReference : C:\Documents and Settings\rfl\Application Data\microsoft\office\recent\invalid.LNK
obj[56]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\office\11.0\access\settings Size of MRU File List
obj[57]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\office\11.0\access\settings Enable MRU File List
obj[58]=MRU FileReference : C:\Documents and Settings\rfl\Application Data\microsoft\office\recent\LWW Pricing Worksheet - eff 070105 - RESALE.xls.LNK
obj[59]=MRU FileReference : C:\Documents and Settings\rfl\Application Data\microsoft\office\recent\LWW Pricing-Eff010105-Domtar Only.xls.LNK
obj[60]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\*
obj[61]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\windows\currentversion\explorer\recentdocs\.ATW
obj[62]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\windows\currentversion\explorer\recentdocs\.bmp
obj[63]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\windows\currentversion\explorer\recentdocs\.doc
obj[64]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\windows\currentversion\explorer\recentdocs\.exe
obj[65]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\windows\currentversion\explorer\recentdocs\.gif
obj[66]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\windows\currentversion\explorer\recentdocs\.htm
obj[67]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\windows\currentversion\explorer\recentdocs\.html
obj[68]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\windows\currentversion\explorer\recentdocs\.inf
obj[69]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\windows\currentversion\explorer\recentdocs\.jpg
obj[70]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\windows\currentversion\explorer\recentdocs\.mdb
obj[71]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\windows\currentversion\explorer\recentdocs\.pdf
obj[72]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\windows\currentversion\explorer\recentdocs\.pot
obj[73]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\windows\currentversion\explorer\recentdocs\.ppt
obj[74]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\windows\currentversion\explorer\recentdocs\.tif
obj[75]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\windows\currentversion\explorer\recentdocs\.txt
obj[76]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\windows\currentversion\explorer\recentdocs\.wav
obj[77]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\windows\currentversion\explorer\recentdocs\.xls
obj[78]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\windows\currentversion\explorer\recentdocs\.zip
obj[79]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\windows\currentversion\explorer\recentdocs\Folder
obj[80]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\windows\currentversion\explorer\recentdocs\NetHood
obj[81]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\mp3
obj[82]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\mpf
obj[83]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\mpg
obj[84]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\realnetworks\realplayer\6.0\preferences\LastLoginTime
obj[85]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\pdf
obj[86]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\realnetworks\realplayer\6.0\preferences\MostRecentClips1
obj[87]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\realnetworks\realplayer\6.0\preferences\MostRecentClips2
obj[88]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\realnetworks\realplayer\6.0\preferences\MostRecentClips3
obj[89]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\realnetworks\realplayer\6.0\preferences\MostRecentClips4
obj[90]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\realnetworks\realplayer\6.0\preferences\MostRecentClips5
obj[91]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\realnetworks\realplayer\6.0\preferences\MostRecentClips6
obj[92]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\realnetworks\realplayer\6.0\preferences\MostRecentClips7
obj[93]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\realnetworks\realplayer\6.0\preferences\MostRecentClips8
obj[94]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\RTO
obj[95]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\stc
obj[96]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\swf
obj[97]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\swi
obj[98]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\tif
obj[99]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\tiff
obj[100]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\txt
obj[101]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\unk
obj[102]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\wav
obj[103]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\wmv
obj[104]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\WPA
obj[105]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\wpd
obj[106]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\wps
obj[107]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\xls
obj[108]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\zip
obj[109]=MRU FileReference : C:\Documents and Settings\rfl\Application Data\microsoft\office\recent\WK.July.3.ppt.LNK
obj[110]=MRU FileReference : C:\Documents and Settings\rfl\Application Data\microsoft\office\recent\World Pac Inquiries-Update 7-28.xls.LNK
obj[111]=MRU FileReference : C:\Documents and Settings\rfl\Application Data\microsoft\office\recent\WorldPacPaper.LNK
obj[112]=MRU FileReference : C:\Documents and Settings\rfl\Application Data\microsoft\office\recent\wwwroot.LNK
obj[113]=MRU RegReference : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\windows media\wmsdk\general computername
WINDUPDATES
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[66]=Regkey : interface\{00ada225-ea6c-4fb3-82e8-68189201ccb9}
obj[67]=Regkey : clsid\{1e5f0d38-214b-4085-ad2a-d2290e6a2d2c}
obj[68]=RegValue : clsid\{1e5f0d38-214b-4085-ad2a-d2290e6a2d2c} "AppID"
obj[69]=Regkey : appid\{735c5a0c-f79f-47a1-8ca1-2a2e482662a8}
obj[70]=Regkey : appid\loaderx.exe
obj[98]=Regkey : software\microsoft\windows\currentversion\uninstall\media access
obj[105]=Regkey : software\microsoft\downloadmanager
obj[106]=Folder : C:\Program Files\Media Access
obj[109]=File : C:\WINNT\system32\ide21201.vxd
obj[110]=File : C:\Program Files\media access\Info.txt
VX2
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[71]=Regkey : S-1-5-21-2134126602-1817933973-825688854-1221\software\aurora
obj[72]=RegValue : S-1-5-21-2134126602-1817933973-825688854-1221\software\aurora "AUC3n5trMsgSDisp"
obj[73]=RegValue : S-1-5-21-2134126602-1817933973-825688854-1221\software\aurora "AUs3t5icky1S"
obj[74]=RegValue : S-1-5-21-2134126602-1817933973-825688854-1221\software\aurora "AUs3t5icky2S"
obj[75]=RegValue : S-1-5-21-2134126602-1817933973-825688854-1221\software\aurora "AUs3t5icky3S"
obj[76]=RegValue : S-1-5-21-2134126602-1817933973-825688854-1221\software\aurora "AUs3t5icky4S"
obj[77]=RegValue : S-1-5-21-2134126602-1817933973-825688854-1221\software\aurora "AUC1o3d5eOfSFinalAd"
obj[78]=RegValue : S-1-5-21-2134126602-1817933973-825688854-1221\software\aurora "AUT3i5m7eOfSFinalAd"
obj[79]=RegValue : S-1-5-21-2134126602-1817933973-825688854-1221\software\aurora "AUD3s5tSSEnd"
obj[80]=RegValue : S-1-5-21-2134126602-1817933973-825688854-1221\software\aurora "AU3N5a7tionSCode"
obj[81]=RegValue : S-1-5-21-2134126602-1817933973-825688854-1221\software\aurora "AUP3D5om"
obj[82]=RegValue : S-1-5-21-2134126602-1817933973-825688854-1221\software\aurora "AUT3h5rshSCheckSIn"
obj[83]=RegValue : S-1-5-21-2134126602-1817933973-825688854-1221\software\aurora "AUT3h5rshSMots"
obj[84]=RegValue : S-1-5-21-2134126602-1817933973-825688854-1221\software\aurora "AUM3o5deSSync"
obj[85]=RegValue : S-1-5-21-2134126602-1817933973-825688854-1221\software\aurora "AUI3n5ProgSCab"
obj[86]=RegValue : S-1-5-21-2134126602-1817933973-825688854-1221\software\aurora "AUI3n5ProgSEx"
obj[87]=RegValue : S-1-5-21-2134126602-1817933973-825688854-1221\software\aurora "AUI3n5ProgSLstest"
obj[88]=RegValue : S-1-5-21-2134126602-1817933973-825688854-1221\software\aurora "AUB3D5om"
obj[89]=RegValue : S-1-5-21-2134126602-1817933973-825688854-1221\software\aurora "AUE3v5nt"
obj[90]=RegValue : S-1-5-21-2134126602-1817933973-825688854-1221\software\aurora "AUT3h5rshSBath"
obj[91]=RegValue : S-1-5-21-2134126602-1817933973-825688854-1221\software\aurora "AUT3h5rshSysSInf"
obj[92]=RegValue : S-1-5-21-2134126602-1817933973-825688854-1221\software\aurora "AUL3n5Title"
obj[93]=RegValue : S-1-5-21-2134126602-1817933973-825688854-1221\software\aurora "AUC3u5rrentSMode"
obj[94]=RegValue : S-1-5-21-2134126602-1817933973-825688854-1221\software\aurora "AUC3n5tFyl"
obj[95]=RegValue : S-1-5-21-2134126602-1817933973-825688854-1221\software\aurora "AUI3g5noreS"
obj[96]=RegValue : S-1-5-21-2134126602-1817933973-825688854-1221\software\aurora "AUL3a5stSSChckin"
obj[107]=RegValue : software\microsoft\internet explorer\toolbar\webbrowser "{0E5CBF21-D15F-11D0-8301-00AA005B4383}"
obj[108]=RegData : software\microsoft\windows nt\currentversion\winlogon "Shell"
PROMULGATE
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[97]=Regkey : software\classes\vccpgdataaccess.pgdataaccessctrl.1
ALEXA
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[99]=RegValue : S-1-5-21-2134126602-1817933973-825688854-1221\software\microsoft\internet explorer\extensions\cmdmapping "{c95fe080-8f5d-11d2-a20b-00aa003c157a}"
POSSIBLE BROWSER HIJACK ATTEMPT
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[100]=Regkey : Software\Microsoft\Windows\CurrentVersion\Uninstall\abi-1
obj[101]=RegValue : Software\Microsoft\Windows\CurrentVersion\Uninstall\abi-1 "URLInfoAbout"
obj[102]=RegValue : Software\Microsoft\Windows\CurrentVersion\Uninstall\abi-1 "Publisher"
obj[103]=RegValue : Software\Microsoft\Windows\CurrentVersion\Uninstall\abi-1 "HelpLink"
obj[104]=RegValue : Software\Microsoft\Windows\CurrentVersion\Uninstall\abi-1 "Contact"