Ok, I downloaded Ewido. The network card on the PC is 'jacked, too, so I manually downloaded and installed the entire virus definition package.
Here is the scan log:
[quote]
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 4:45:45 PM, 12/13/2005
+ Report-Checksum: EFC39556
+ Scan result:
HKLM\SOFTWARE\Classes\AppID\{0DC5CD7C-F653-4417-AA43-D457BE3A9622} -> Spyware.BookedSpace : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{205FF73B-CA67-11D5-99DD-444553540006} -> Spyware.CnsMin : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{417386C3-8D4A-4611-9B91-E57E89D603AC} -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{10D7DB96-56DC-4617-8EAB-EC506ABE6C7E} -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{6CDC3337-01F7-4A79-A4AF-0B19303CC0BE} -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{795398D0-DC2F-4118-A69C-592273BA9C2B} -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{B288F21C-A144-4CA2-9B70-8AFA1FAE4B06} -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\PopOops2.PopOops -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\PopOops2.PopOops\Clsid -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\SWLAD1.SWLAD -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\SWLAD1.SWLAD\Clsid -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{D0C29A75-7146-4737-98EE-BC4D7CF44AF9} -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{E0D3B292-A0B0-4640-975C-2F882E039F52} -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Hotbar -> Spyware.HotBar : Cleaned with backup
HKLM\SOFTWARE\Hotbar\Hotbar -> Spyware.HotBar : Cleaned with backup
HKLM\SOFTWARE\Hotbar\Hotbar\Install -> Spyware.HotBar : Cleaned with backup
HKLM\SOFTWARE\Hotbar\Hotbar\MachineInfo -> Spyware.HotBar : Cleaned with backup
HKLM\SOFTWARE\Hotbar\Hotbar\PI -> Spyware.HotBar : Cleaned with backup
HKLM\SOFTWARE\Hotbar\Hotbar\PI\3.2 -> Spyware.HotBar : Cleaned with backup
HKLM\SOFTWARE\Mvu -> Spyware.Delfin : Cleaned with backup
HKLM\SYSTEM\CurrentControlSet\Services\ISEXEng -> Spyware.BargainBuddy : Cleaned with backup
HKLM\SYSTEM\CurrentControlSet\Services\ISEXEng\Security -> Spyware.BargainBuddy : Cleaned with backup
HKLM\SYSTEM\CurrentControlSet\Services\ISEXEng\Enum -> Spyware.BargainBuddy : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Larry Hathcock\Application Data\Mozilla\Profiles\default\3dc6024g.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Larry Hathcock\Application Data\Mozilla\Profiles\default\3dc6024g.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Larry Hathcock\Application Data\Mozilla\Profiles\default\3dc6024g.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Larry Hathcock\Application Data\Mozilla\Profiles\default\3dc6024g.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Larry Hathcock\Application Data\Mozilla\Profiles\default\3dc6024g.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Larry Hathcock\Application Data\Mozilla\Profiles\default\3dc6024g.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Larry Hathcock\Application Data\Mozilla\Profiles\default\3dc6024g.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Larry Hathcock\Application Data\Mozilla\Profiles\default\3dc6024g.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Larry Hathcock\Local Settings\Temporary Internet Files\Content.IE5\CDNZQKPY\tb[1].txt -> Spyware.ToolBand : Cleaned with backup
C:\Program Files\Common Files\system32.dll/gui.exe -> Downloader.Agent.rv : Error during cleaning
C:\WINDOWS\bs7beta.exe -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\cfgmgr52\EECH1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\cfgmgr52\SPZ3.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\NDNuninstall6_30.exe -> Spyware.NewDotNet : Cleaned with backup
C:\WINDOWS\NDNuninstall6_38.exe -> Spyware.NewDotNet : Cleaned with backup
C:\WINDOWS\offun.exe -> Downloader.VB.hw : Cleaned with backup
C:\WINDOWS\system\QBUninstaller.exe -> Downloader.Small.aly : Cleaned with backup
C:\WINDOWS\system32\ixendo.exe -> Trojan.Poler.a : Cleaned with backup
C:\WINDOWS\system32\yunguyo.exe -> Dropper.Agent.hl : Cleaned with backup
C:\WINDOWS\Vielqbiw.dll -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\winadvt.dll -> Spyware.ToolBand : Cleaned with backup
D:\WINDOWS\Temporary Internet Files\Content.IE5\SD0CYOK8\exitpop[1].htm -> Trojan.NoClose.i : Cleaned with backup
D:\WINDOWS\Temporary Internet Files\Content.IE5\QV4XKBMN\consumerinfo2[1].htm -> Spyware.BookedSpace : Cleaned with backup
D:\WINDOWS\Cookies\frontdesk@ads.link4ads[1].txt -> Spyware.Cookie.Link4ads : Cleaned with backup
D:\WINDOWS\Cookies\frontdesk@ads.link4ads[3].txt -> Spyware.Cookie.Link4ads : Cleaned with backup
D:\WINDOWS\Cookies\frontdesk@preferences[1].txt -> Spyware.Cookie.Preferences : Cleaned with backup
D:\WINDOWS\Cookies\frontdesk@ads15.hyperbanner[1].txt -> Spyware.Cookie.Hyperbanner : Cleaned with backup
D:\WINDOWS\Cookies\frontdesk@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
D:\WINDOWS\Cookies\frontdesk@www.hightrafficads[1].txt -> Spyware.Cookie.Hightrafficads : Cleaned with backup
D:\WINDOWS\Cookies\frontdesk@spms.bpath[2].txt -> Spyware.Cookie.Bpath : Cleaned with backup
D:\WINDOWS\Cookies\frontdesk@www.myaffiliateprogram[1].txt -> Spyware.Cookie.Myaffiliateprogram : Cleaned with backup
D:\WINDOWS\Cookies\frontdesk@www.myaffiliateprogram[2].txt -> Spyware.Cookie.Myaffiliateprogram : Cleaned with backup
::Report End
[/quote]
Then I ran HJT.
Here is the log:
[quote]Logfile of HijackThis v1.99.1
Scan saved at 4:47:59 PM, on 12/13/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\All Users\Desktop\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=userinit.exe
O4 - HKLM\..\Run: [WinTask driver] C:\WINDOWS\System32\wintask.exe
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\System32\dlplls.exe reg_run
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [vidctrl] C:\WINDOWS\System32\vidctrl\vidctrl.exe
O4 - HKLM\..\Run: [regsync] C:\WINDOWS\System32\regsync.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [exp.exe] C:\WINDOWS\System32\exp.exe
O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINDOWS\cfgmgr52.dll,DllRun
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [apisvc.exe] C:\WINDOWS\System32\apisvc.exe
O4 - Global Startup: RealSecure® Desktop Protector.lnk = ?
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros...b?1120002357368O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: BlackICE - Internet Security Systems, Inc. - C:\Program Files\ISS\issSensors\DesktopProtection\blackd.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: RapApp - Internet Security Systems, Inc. - C:\Program Files\ISS\issSensors\DesktopProtection\RapApp.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
[/quote]
I fixed each of the items you mention except for the ones which were corrected by Ewido and therefore no longer running. I was unable to locate any of the files you wished to delete after setting all of my folder options to the correct preferences. I noticed before that when I killed certain spyware or virus processes, certain .exe files would disappear from the windows folder. They would then reappear once rebooted. However, I could not locate the files mentioned.
I also downloaded and installed the CCleaner. I ran both the cleaner and the issue scanner.
Here is the log from the cleaner:
[quote]
CLEANING COMPLETE - (89.279 secs)
------------------------------------------------------------------------------------------
591.7MB removed.
Details of files deleted
------------------------------------------------------------------------------------------
IE Temporary Internet Files (1202 files) 8.10MB
C:\Documents and Settings\Larry Hathcock\Cookies\larry hathcock@a[1].txt 0 bytes
C:\Documents and Settings\Larry Hathcock\Local Settings\History\History.IE5\desktop.ini 113 bytes
Marked for deletion: C:\Documents and Settings\Larry Hathcock\Local Settings\Temporary Internet Files\Content.IE5\index.dat
Marked for deletion: C:\Documents and Settings\Larry Hathcock\Cookies\index.dat
Marked for deletion: C:\Documents and Settings\Larry Hathcock\Local Settings\History\History.IE5\index.dat
C:\WINDOWS\TEMP\CONEXANT_INSTALL.LOG 43.64KB
C:\WINDOWS\TEMP\HP000000.IDX 0.25MB
C:\WINDOWS\TEMP\HP000001.PDL 6 bytes
C:\WINDOWS\TEMP\hpdbglog.txt 680 bytes
C:\WINDOWS\TEMP\hpdj00srv00.log 3.20KB
C:\WINDOWS\TEMP\hpzcoi00.log 596 bytes
C:\WINDOWS\TEMP\hpzcoi01.log 596 bytes
C:\WINDOWS\TEMP\hpzcoi02.log 756 bytes
C:\WINDOWS\TEMP\hpzcoi03.log 694 bytes
C:\WINDOWS\TEMP\hpzcoi04.log 596 bytes
C:\WINDOWS\TEMP\hpzcoi05.log 596 bytes
C:\WINDOWS\TEMP\hpzcoi06.log 757 bytes
C:\WINDOWS\TEMP\hpzcoi07.log 694 bytes
C:\WINDOWS\TEMP\hpzcoi08.log 596 bytes
C:\WINDOWS\TEMP\hpzcoi09.log 596 bytes
C:\WINDOWS\TEMP\hpzcoi10.log 596 bytes
C:\WINDOWS\TEMP\hpzcoi11.log 596 bytes
C:\WINDOWS\TEMP\hpzcoi12.log 596 bytes
C:\WINDOWS\TEMP\hpzcoi13.log 596 bytes
C:\WINDOWS\TEMP\hpzcoi14.log 596 bytes
C:\WINDOWS\TEMP\hpzcoi15.log 596 bytes
C:\WINDOWS\TEMP\hpzcoi16.log 596 bytes
C:\WINDOWS\TEMP\hpzcoi17.log 596 bytes
C:\WINDOWS\TEMP\hpzcoi18.log 596 bytes
C:\WINDOWS\TEMP\hpzcoi19.log 596 bytes
C:\WINDOWS\TEMP\hpzcoi20.log 596 bytes
C:\WINDOWS\TEMP\hpzcoi21.log 596 bytes
C:\WINDOWS\TEMP\hpzcoi22.log 596 bytes
C:\WINDOWS\TEMP\hpzcoi23.log 596 bytes
C:\WINDOWS\TEMP\hpzcoi24.log 596 bytes
C:\WINDOWS\TEMP\hpzcoi25.log 596 bytes
C:\WINDOWS\TEMP\hpzcoi26.log 596 bytes
C:\WINDOWS\TEMP\hpzcoi27.log 596 bytes
C:\WINDOWS\TEMP\hpzcoi28.log 596 bytes
C:\WINDOWS\TEMP\hpzcoi29.log 596 bytes
C:\WINDOWS\TEMP\hpzcoi30.log 596 bytes
C:\WINDOWS\TEMP\hpzcoi31.log 596 bytes
C:\WINDOWS\TEMP\hpzcoi32.log 596 bytes
C:\WINDOWS\TEMP\hpzcoi33.log 596 bytes
C:\WINDOWS\TEMP\hpzcoi34.log 596 bytes
C:\WINDOWS\TEMP\hpzcoi35.log 596 bytes
C:\WINDOWS\TEMP\hpzcoi36.log 596 bytes
C:\WINDOWS\TEMP\hpzcoi37.log 596 bytes
C:\WINDOWS\TEMP\hpzcoi38.log 596 bytes
C:\WINDOWS\TEMP\hpzcoi39.log 596 bytes
C:\WINDOWS\TEMP\hpzcoi40.log 596 bytes
C:\WINDOWS\TEMP\hpzcoi41.log 596 bytes
C:\WINDOWS\TEMP\hpzcoi42.log 596 bytes
C:\WINDOWS\TEMP\hpzcoi43.log 596 bytes
C:\WINDOWS\TEMP\hpzcoi44.log 596 bytes
C:\WINDOWS\TEMP\hpzcoi45.log 596 bytes
C:\WINDOWS\TEMP\hpzcoi46.log 757 bytes
C:\WINDOWS\TEMP\hpzcoi47.log 685 bytes
C:\WINDOWS\TEMP\hpzglue00.log 337 bytes
C:\WINDOWS\TEMP\HPZset000.log 664 bytes
C:\WINDOWS\TEMP\HPZset001.log 664 bytes
C:\WINDOWS\TEMP\IECE.tmp 0.33MB
C:\WINDOWS\TEMP\Perflib_Perfdata_51c.dat 16.00KB
C:\WINDOWS\TEMP\Perflib_Perfdata_5e4.dat 16.00KB
C:\WINDOWS\TEMP\Perflib_Perfdata_5e8.dat 16.00KB
C:\WINDOWS\TEMP\Perflib_Perfdata_610.dat 16.00KB
C:\WINDOWS\TEMP\Perflib_Perfdata_628.dat 16.00KB
C:\WINDOWS\TEMP\Perflib_Perfdata_638.dat 16.00KB
C:\WINDOWS\TEMP\Perflib_Perfdata_65c.dat 16.00KB
C:\WINDOWS\TEMP\Perflib_Perfdata_660.dat 16.00KB
C:\WINDOWS\TEMP\Perflib_Perfdata_914.dat 16.00KB
C:\WINDOWS\TEMP\Perflib_Perfdata_f64.dat 16.00KB
C:\WINDOWS\TEMP\servic000.log 344 bytes
C:\WINDOWS\TEMP\servic001.log 516 bytes
C:\WINDOWS\TEMP\servic002.log 172 bytes
C:\WINDOWS\TEMP\servic003.log 510 bytes
C:\WINDOWS\TEMP\SPL27.tmp 0.75MB
C:\WINDOWS\TEMP\SPL2D.tmp 0.25MB
C:\WINDOWS\TEMP\T30DebugLogFile.txt 0 bytes
C:\WINDOWS\TEMP\Temporary Internet Files\Content.IE5\index.dat 0 bytes
C:\WINDOWS\TEMP\_ISTMP0.DIR\Projects.ini 6.06KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\131266_1116_188_1808_62.41.tmp1 5.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\131380_2688_1852_2740_62.41.tmp1 5.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\131402_2688_1852_2732_62.41.tmp1 5.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\GLM4D.tmp 12.50KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\History\History.IE5\desktop.ini 113 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\IEC1.tmp 0.32MB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\IEC12.tmp 0.32MB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\IEC2B.tmp 0.33MB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\IEC7.tmp 0.32MB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\InstHelp.dll 56.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\IUCheck.log 587 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\me_0debMU7JNL6DQBE 0 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\me_3az9zbrmB9DH3FX 0 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\me_48ZSLyz5ZK81kfn 0 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\me_4IRVntRbXyL8vjT 0 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\me_72Hjx6Fvwandedh 0 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\me_7iq3x9OjnY83eP3 0 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\me_8UXSQsGmqStVhjr 0 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\me_bBzIq21xFCEt0Uj 0 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\me_BGARlp4uY2xsaV 0 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\me_Bot 0 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\me_bqmcc8ie4RchP2k 2.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\me_c3vPTyZQLgg 0 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\me_cE0qgXRlVoEbKmW 0 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\me_Cy7RY5qGBE53tJu 0 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\me_D1ESy8sTBfqyacQ 0 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\me_D43m6HRloDNk2wM 0 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\me_dfr8j9tta3s3vnI 0 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\me_DtOVhWybUnsWouY 0 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\me_EXlso622kpFZYqA 0 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\me_eYMR89YIS4MSBKw 0 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\me_GvzH5V1fuE8nr5 2.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\me_HmRa6zKh24qUVED 2.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\me_lELTFKyXJq8iCM1 0 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\me_mav7m38qWl5M 2.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\me_nqrSb8hQotIiRWD 0 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\me_P2c3wfoXjn1pNT1 2.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\me_PUs5kp00Zo2hIjK 2.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\me_RKE2Eln3xWWV3Ml 0 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\me_RtDgewcaxXxzXsG 0 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\me_RVouKjcBF4yuKQG 0 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\me_rytXkyOkGFOfHJy 0 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\me_T8MFN3LsN57hckj 0 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\me_wpcyRAlJUvKYvJv 2.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\me_XHmj 0 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\me_yVfiXe6cZYiWqCq 0 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\me_zjZxaRCiYqMNilc 0 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\MSSVPN32.TMP 0.38MB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Abcpy.ini 2.96KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\DATA.TAG 103 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\data1.cab 6.50KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\data1.hdr 28.66KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Help\ENU\ACROBAT.PDF 27.78KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Help\ENU\DocBox.pdf 3.99KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Help\ENU\MiniReader.pdf 75.21KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Help\ENU\Reader.pdf 0.96MB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\lang.dat 22.99KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\layout.bin 609 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\os.dat 450 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\AceLite.dll 0.38MB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\ACROFX32.DLL 52.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\AcroRd32.exe 3.69MB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\ActiveX\AcroIEHelper.ocx 36.92KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\ActiveX\pdf.ocx 0.37MB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\ActiveX\pdf.tlb 3.95KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\Agm.dll 1.09MB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\Bib.dll 0.14MB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\Browser\nppdf32.dll 100.89KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\CoolType.dll 1.38MB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\JavaScripts\aform.js 33.78KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\msvcp60.dll 0.38MB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\msvcrt.dll 0.25MB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\oleaut32.dll 0.57MB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\Optional\README.TXT 46 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\plug_ins\AcroFill.api 0.61MB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\plug_ins\EScript.api 0.61MB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\plug_ins\EWH32.api 68.07KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\plug_ins\hls.api 52.06KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\plug_ins\Infusium.api 0.26MB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\plug_ins\InterTrust\DocBox.api 0.39MB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\plug_ins\InterTrust\NPDocBox.dll 0.21MB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\plug_ins\Movie\Movie.api 0.26MB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\plug_ins\Movie\QT2.dll 24.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\plug_ins\Movie\QT3.dll 32.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\plug_ins\Movie\QT4.dll 36.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\plug_ins\MSAA.api 0.10MB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\plug_ins\reflow.api 0.24MB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\plug_ins\search.api 0.20MB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\plug_ins\vdkhome\enu\vdk10.lng 22.74KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\plug_ins\vdkhome\enu\vdk10.rsd 60.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\plug_ins\vdkhome\enu\vdk10.rst 2.30KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\plug_ins\vdkhome\enu\vdk10.stc 3.07KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\plug_ins\vdkhome\enu\vdk10.stp 3.07KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\plug_ins\vdkhome\enu\vdk10.syd 0.77MB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\plug_ins\vdkhome\vdk10.cmp 3.95KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\plug_ins\vdkhome\vdk10.lic 41 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\plug_ins\vdkhome\vdk10.std 2.02KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\plug_ins\vdkhome\vdk10.syx 415 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\plug_ins\vdkhome\vdk10.thd 304 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\plug_ins\WEBBUY\HTML\btn_submit.gif 746 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\plug_ins\WEBBUY\HTML\table_btm.gif 249 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\plug_ins\WEBBUY\HTML\template1.html 2.02KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\plug_ins\WEBBUY\HTML\template2.html 2.93KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\plug_ins\WEBBUY\HTML\template5.html 192 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\plug_ins\WEBBUY\HTML\title_acrobat.gif 742 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\plug_ins\WEBBUY\HTML\title_adobe.gif 806 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\plug_ins\WEBBUY\HTML\title_end.gif 223 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\plug_ins\WEBBUY\HTML\title_mid.gif 300 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\plug_ins\Webbuy.api 0.41MB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\plug_ins\weblink.api 0.10MB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\plug_ins\WHA.api 68.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\RdrENU.xml 198 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\SPPlugins\ADMPlugin.apl 0.85MB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\SPPlugins\ExpressViews.apl 0.19MB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\Uninstall\Uninst.dll 80.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\vdk150.dll 0.84MB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Reader\WHA Library.dll 0.16MB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\ReadMe.html 21.75KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Resource\CMap\Identity-H 6.25KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Resource\CMap\Identity-V 1.17KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Resource\ENUtxt.pdf 1.38KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Resource\Font\AdobeFnt.lst 23 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Resource\Font\cobo____.pfb 49.35KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Resource\Font\cob_____.pfb 34.67KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Resource\Font\com_____.pfb 33.77KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Resource\Font\coo_____.pfb 47.33KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Resource\Font\PFM\COBO____.PFM 686 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Resource\Font\PFM\COB_____.PFM 679 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Resource\Font\PFM\COM_____.PFM 674 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Resource\Font\PFM\COO_____.PFM 682 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Resource\Font\PFM\SY______.PFM 672 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Resource\Font\PFM\ZD______.PFM 684 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Resource\Font\PFM\ZX______.MMM 7.08KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Resource\Font\PFM\zx______.pfm 683 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Resource\Font\PFM\ZY______.MMM 7.08KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Resource\Font\PFM\zy______.pfm 684 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Resource\Font\PFM\_ABI____.PFM 5.21KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Resource\Font\PFM\_AB_____.PFM 5.21KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Resource\Font\PFM\_AI_____.PFM 5.68KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Resource\Font\PFM\_A______.PFM 5.67KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Resource\Font\PFM\_ebi____.pfm 4.57KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Resource\Font\PFM\_eb_____.pfm 4.83KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Resource\Font\PFM\_ei_____.pfm 4.70KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Resource\Font\PFM\_er_____.pfm 4.58KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Resource\Font\SY______.PFB 33.89KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Resource\Font\ZD______.PFB 48.43KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Resource\Font\ZX______.PFB 73.80KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Resource\Font\ZY______.PFB 94.16KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Resource\Font\_ABI____.PFB 31.27KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Resource\Font\_AB_____.PFB 31.22KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Resource\Font\_AI_____.PFB 31.36KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Resource\Font\_A______.PFB 31.33KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Resource\Font\_ebi____.pfb 37.64KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Resource\Font\_eb_____.pfb 34.55KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Resource\Font\_ei_____.pfb 36.64KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Resource\Font\_er_____.pfb 34.55KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\Setup.exe 72.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\SETUP.INI 103 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\setup.ins 0.15MB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\setup.lid 49 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\SVG Files\NPSVGVw.dll 0.29MB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\SVG Files\ReadMe.html 18.73KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\SVG Files\SVG Viewer License.txt 22.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\SVG Files\SVGAbout.svg 77.58KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\SVG Files\SVGControl.dll 0.47MB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\SVG Files\SVGHelp.html 2.86KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\SVG Files\SVGRSRC.DLL 12.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\SVG Files\SVGView.dll 1.52MB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\SVG Files\SVGViewer.dict 18.01KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\SVG Files\SVGViewer.ini 0 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\SVG Files\SVGViewer.zip 0.19MB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\_INST32I.EX_ 0.28MB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\_ISDel.exe 27.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\_Setup.dll 34.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\_sys1.cab 0.17MB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\_sys1.hdr 4.95KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\_user1.cab 0.26MB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\pft8~tmp\_user1.hdr 5.65KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\s318.7 0 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\setup.exe 0.21MB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\89ABCDEF\desktop.ini 67 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\8VQD612P\desktop.ini 67 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\desktop.ini 67 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\GLERCLMJ\desktop.ini 67 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OPQRSTUV\desktop.ini 67 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\WER112.tmp.dir00\appcompat.txt 14.55KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\WER5.tmp 0 bytes
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\WER5.tmp.dir00\sysdata.xml 59.42KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\~DF233C.tmp 16.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\~DF26BB.tmp 16.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\~DF27EF.tmp 16.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\~DF29E0.tmp 16.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\~DF53DF.tmp 16.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\~DF6017.tmp 16.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\~DF64.tmp 16.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\~DF64BD.tmp 16.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\~DF6677.tmp 16.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\~DF685B.tmp 16.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\~DF6997.tmp 16.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\~DF7081.tmp 16.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\~DF7237.tmp 16.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\~DF72D4.tmp 16.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\~DF747E.tmp 16.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\~DF748A.tmp 16.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\~DF759E.tmp 16.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\~DF776A.tmp 16.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\~DF8717.tmp 16.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\~DF8FBD.tmp 16.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\~DF9547.tmp 16.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\~DFA2B9.tmp 16.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\~DFA860.tmp 16.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\~DFAD04.tmp 16.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\~DFB26F.tmp 16.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\~DFE06E.tmp 16.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\~DFF47.tmp 16.00KB
C:\DOCUME~1\LARRYH~1\LOCALS~1\Temp\~DFFA2A.tmp 16.00KB
C:\WINDOWS\MEMORY.DMP 511.6MB
C:\WINDOWS\MiniDump\Mini102605-01.dmp 64.00KB
C:\WINDOWS\MiniDump\Mini102605-02.dmp 64.00KB
C:\WINDOWS\system32\wbem\Logs\FrameWork.log 61.07KB
C:\WINDOWS\system32\wbem\Logs\mofcomp.log 20.20KB
C:\WINDOWS\system32\wbem\Logs\setup.log 9.39KB
C:\WINDOWS\system32\wbem\Logs\wbemcore.log 238 bytes
C:\WINDOWS\system32\wbem\Logs\wbemess.log 31.59KB
C:\WINDOWS\system32\wbem\Logs\wbemprox.log 8.68KB
C:\WINDOWS\system32\wbem\Logs\WBEMSNMP.log 2 bytes
C:\WINDOWS\system32\wbem\Logs\WinMgmt.log 12.35KB
C:\WINDOWS\system32\wbem\Logs\wmiadap.log 807 bytes
C:\WINDOWS\system32\wbem\Logs\wmiprov.log 780 bytes
C:\WINDOWS\system32\wbem\Logs\wbemess.lo_ 64.03KB
C:\WINDOWS\system32\wbem\Logs\wmiprov.lo_ 0.11MB
C:\WINDOWS\0.log 0 bytes
C:\WINDOWS\COM+.log 1.41KB
C:\WINDOWS\comsetup.log 0.16MB
C:\WINDOWS\dahotfix.log 1.70KB
C:\WINDOWS\DHCPUPG.LOG 403 bytes
C:\WINDOWS\DtcInstall.log 243 bytes
C:\WINDOWS\FaxSetup.log 0.40MB
C:\WINDOWS\IEPatchUninstall.log 40 bytes
C:\WINDOWS\iis6.log 52.10KB
C:\WINDOWS\imsins.log 1.34KB
C:\WINDOWS\KB821557.log 15.90KB
C:\WINDOWS\KB823182.log 28.73KB
C:\WINDOWS\KB823559.log 31.68KB
C:\WINDOWS\KB824105.log 27.51KB
C:\WINDOWS\KB824141.log 26.67KB
C:\WINDOWS\KB825119.log 26.11KB
C:\WINDOWS\KB828035.log 21.23KB
C:\WINDOWS\KB828741.log 0.15MB
C:\WINDOWS\KB835732.log 0.16MB
C:\WINDOWS\KB837001.log 12.14KB
C:\WINDOWS\KB839643.log 8.56KB
C:\WINDOWS\KB839645.log 10.01KB
C:\WINDOWS\KB840315.log 8.57KB
C:\WINDOWS\KB840374.log 22.91KB
C:\WINDOWS\KB840987.log 82.50KB
C:\WINDOWS\KB841356.log 3.58KB
C:\WINDOWS\KB841533.log 3.32KB
C:\WINDOWS\KB841873.log 10.55KB
C:\WINDOWS\KB842773.log 8.79KB
C:\WINDOWS\KB873376.log 3.40KB
C:\WINDOWS\MDACSET.log 22.81KB
C:\WINDOWS\msgsocm.log 20.33KB
C:\WINDOWS\nsw.log 289 bytes
C:\WINDOWS\ntdtcsetup.log 0.10MB
C:\WINDOWS\ocgen.log 0.21MB
C:\WINDOWS\ocmsn.log 18.68KB
C:\WINDOWS\Q306676.log 10.41KB
C:\WINDOWS\Q308387.log 10.41KB
C:\WINDOWS\Q308402.log 10.41KB
C:\WINDOWS\Q308677.log 10.76KB
C:\WINDOWS\Q308928.log 10.53KB
C:\WINDOWS\Q309056.log 10.22KB
C:\WINDOWS\Q309521.log 21.21KB
C:\WINDOWS\Q310051.log 10.26KB
C:\WINDOWS\Q310601.log 10.81KB
C:\WINDOWS\Q311542.log 10.41KB
C:\WINDOWS\Q311822.log 10.20KB
C:\WINDOWS\Q311889.log 10.46KB
C:\WINDOWS\Q311967.log 10.19KB
C:\WINDOWS\Q313450.log 18.97KB
C:\WINDOWS\Q313596.log 10.41KB
C:\WINDOWS\Q314147.log 10.41KB
C:\WINDOWS\Q314862.log 19.52KB
C:\WINDOWS\Q315000.log 10.41KB
C:\WINDOWS\Q315403.log 10.41KB
C:\WINDOWS\Q316134.log 10.41KB
C:\WINDOWS\Q316253.log 10.48KB
C:\WINDOWS\Q317277.log 10.66KB
C:\WINDOWS\Q318138.log 29.81KB
C:\WINDOWS\Q319580.log 11.04KB
C:\WINDOWS\Q321856.log 363 bytes
C:\WINDOWS\Q323172.log 30.39KB
C:\WINDOWS\Q323255.log 12.37KB
C:\WINDOWS\Q324096.log 31.82KB
C:\WINDOWS\Q324380.log 31.41KB
C:\WINDOWS\Q326830.log 13.88KB
C:\WINDOWS\Q328940.log 21.02KB
C:\WINDOWS\Q329048.log 30.60KB
C:\WINDOWS\Q329115.log 13.66KB
C:\WINDOWS\Q329170.log 16.95KB
C:\WINDOWS\Q329390.log 13.09KB
C:\WINDOWS\Q329441.log 19.65KB
C:\WINDOWS\Q329834.log 30.61KB
C:\WINDOWS\Q810577.log 32.42KB
C:\WINDOWS\Q811493.log 38.70KB
C:\WINDOWS\Q811630.log 28.42KB
C:\WINDOWS\Q815021.log 20.17KB
C:\WINDOWS\Q817606.log 28.39KB
C:\WINDOWS\Q818966.log 362 bytes
C:\WINDOWS\Q819696.log 31.80KB
C:\WINDOWS\Q828026.log 22.16KB
C:\WINDOWS\regopt.log 2.93KB
C:\WINDOWS\sessmgr.setup.log 2.09KB
C:\WINDOWS\setupact.log 70.90KB
C:\WINDOWS\setupapi.log 0.38MB
C:\WINDOWS\setuperr.log 0 bytes
C:\WINDOWS\Sti_Trace.log 0 bytes
C:\WINDOWS\svcpack.log 10.68KB
C:\WINDOWS\tsoc.log 0.16MB
C:\WINDOWS\wiadebug.log 216 bytes
C:\WINDOWS\wiaservc.log 49 bytes
C:\WINDOWS\Windows Update.log 0.13MB
C:\WINDOWS\WindowsUpdate.log 0.66MB
C:\WINDOWS\wsdu.log 215 bytes
C:\WINDOWS\xpsp1hfm.log 72.17KB
C:\WINDOWS\imsins.BAK 1.34KB
C:\WINDOWS\ntbtlog.txt 0.27MB
C:\WINDOWS\OEWABLog.txt 1.91KB
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\drwtsn32.log 21.1MB
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp 0.23MB
C:\WINDOWS\Debug\mrt.log 2.29KB
C:\WINDOWS\Debug\NetSetup.LOG 7.42KB
C:\WINDOWS\Debug\oakley.log 0 bytes
C:\WINDOWS\security\logs\backup.log 2.97KB
C:\WINDOWS\security\logs\SceRoot.log 1.73KB
C:\WINDOWS\security\logs\scesetup.log 1.01MB
C:\WINDOWS\security\logs\scecomp.old 24.13KB
C:\Documents and Settings\Larry Hathcock\Application Data\Mozilla\profiles\default\3dc6024g.slt\cache\17B60911d01 48.76KB
C:\Documents and Settings\Larry Hathcock\Application Data\Mozilla\profiles\default\3dc6024g.slt\cache\182BEA87d01 19.52KB
C:\Documents and Settings\Larry Hathcock\Application Data\Mozilla\profiles\default\3dc6024g.slt\cache\1FC2DCD6d01 87.54KB
C:\Documents and Settings\Larry Hathcock\Application Data\Mozilla\profiles\default\3dc6024g.slt\cache\21F3A5D8d01 15.5MB
C:\Documents and Settings\Larry Hathcock\Application Data\Mozilla\profiles\default\3dc6024g.slt\cache\32955A42d01 82.04KB
C:\Documents and Settings\Larry Hathcock\Application Data\Mozilla\profiles\default\3dc6024g.slt\cache\3EEA6246d01 28.01KB
C:\Documents and Settings\Larry Hathcock\Application Data\Mozilla\profiles\default\3dc6024g.slt\cache\417DB630d01 19.08KB
C:\Documents and Settings\Larry Hathcock\Application Data\Mozilla\profiles\default\3dc6024g.slt\cache\4A9C3D35d01 49.58KB
C:\Documents and Settings\Larry Hathcock\Application Data\Mozilla\profiles\default\3dc6024g.slt\cache\4AF0BC07d01 24.17KB
C:\Documents and Settings\Larry Hathcock\Application Data\Mozilla\profiles\default\3dc6024g.slt\cache\55C32115d01 21.77KB
C:\Documents and Settings\Larry Hathcock\Application Data\Mozilla\profiles\default\3dc6024g.slt\cache\8FE08206d01 21.68KB
C:\Documents and Settings\Larry Hathcock\Application Data\Mozilla\profiles\default\3dc6024g.slt\cache\9BA12749d01 34.42KB
C:\Documents and Settings\Larry Hathcock\Application Data\Mozilla\profiles\default\3dc6024g.slt\cache\9F1E7B58d01 37.26KB
C:\Documents and Settings\Larry Hathcock\Application Data\Mozilla\profiles\default\3dc6024g.slt\cache\C5BCA8AFd01 19.56KB
C:\Documents and Settings\Larry Hathcock\Application Data\Mozilla\profiles\default\3dc6024g.slt\cache\CEF83390d01 34.99KB
C:\Documents and Settings\Larry Hathcock\Application Data\Mozilla\profiles\default\3dc6024g.slt\cache\DE381EF7d01 30.78KB
C:\Documents and Settings\Larry Hathcock\Application Data\Mozilla\profiles\default\3dc6024g.slt\cache\_CACHE_001_ 0.22MB
C:\Documents and Settings\Larry Hathcock\Application Data\Mozilla\profiles\default\3dc6024g.slt\cache\_CACHE_002_ 0.17MB
C:\Documents and Settings\Larry Hathcock\Application Data\Mozilla\profiles\default\3dc6024g.slt\cache\_CACHE_003_ 0.32MB
C:\Documents and Settings\Larry Hathcock\Application Data\Mozilla\profiles\default\3dc6024g.slt\cache\_CACHE_MAP_ 0.13MB
C:\Documents and Settings\Larry Hathcock\Application Data\Mozilla\profiles\default\3dc6024g.slt\history.dat 1.94KB
C:\Documents and Settings\Larry Hathcock\Application Data\Mozilla\profiles\default\3dc6024g.slt\downloads.rdf 2.02KB
Removed Cookie: infospace.com
Removed Cookie: infospace.com
Removed Cookie: infospace.com
Removed Cookie: infospace.com
Removed Cookie: netscape.com
Removed Cookie: atwola.com
Removed Cookie: sun.com
Removed Cookie: sun.com
Removed Cookie: sun.com
Removed Cookie: sun.com
Removed Cookie: sun.com
Removed Cookie: sun.com
Removed Cookie: sun.com
Removed Cookie: sun.com
Removed Cookie: sun.com
Removed Cookie: microsoft.com
C:\Documents and Settings\Larry Hathcock\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol 300 bytes
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Logs\09212005.Log 876 bytes
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Logs\09302005.Log 5.15KB
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Logs\10182005.Log 662 bytes
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Logs\10262005.Log 4.32KB
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Logs\11292005.Log 8.92KB
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Logs\12012005.Log 0.14MB
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Logs\12022005.Log 93.49KB
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Logs\12132005.Log 1.09KB
C:\Documents and Settings\Larry Hathcock\Local Settings\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Logs\08072005.Log 1.47MB
C:\Documents and Settings\Larry Hathcock\Local Settings\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Logs\08082005.Log 0.30MB
C:\Documents and Settings\Larry Hathcock\Local Settings\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Logs\08122005.Log 43.67KB
C:\Documents and Settings\Larry Hathcock\Local Settings\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Logs\09302005.Log 4.08KB
C:\Documents and Settings\Larry Hathcock\Local Settings\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Logs\10262005.Log 3.05KB
C:\Documents and Settings\Larry Hathcock\Local Settings\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Logs\12012005.Log 69.67KB
C:\Documents and Settings\Larry Hathcock\Local Settings\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Logs\12022005.Log 86.04KB
C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\avenge$201.5$20microdefs2$20corp$209_microdefsb.curdefs_symalllanguages_livetri.zip 2.52KB
C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\avenge$201.5$20microdefs2$20corp$209_microdefsb.jul_symalllanguages_livetri.zip 2.52KB
C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\avenge$201.5$20microdefs2$20corp$209_microdefsb.oct_symalllanguages_livetri.zip 2.52KB
C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\avenge$201.5$20microdefs2$20corp$209_microdefsb.old_symalllanguages_livetri.zip 2.57KB
C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\avenge$201.5$20microdefs2$20corp$209_microdefsb.sep_symalllanguages_livetri.zip 2.52KB
C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\liveupdate_2.0_english_livetri.zip 3.33KB
C:\Program Files\Lavasoft\Ad-Aware SE Professional\defs.ref.old 0.48MB
C:\Documents and Settings\Larry Hathcock\Application Data\Lavasoft\Ad-Aware\Logs\Ad-Aware log2005-08-07 19-09-34.txt 34.97KB
C:\Documents and Settings\Larry Hathcock\Application Data\Lavasoft\Ad-Aware\Logs\Ad-Aware log2005-12-01 15-56-21.txt 7.06KB
C:\Documents and Settings\Larry Hathcock\Application Data\Lavasoft\Ad-Aware\Logs\Ad-Aware log2005-12-01 16-03-48.txt 4.39KB
C:\Documents and Settings\Larry Hathcock\Application Data\Lavasoft\Ad-Aware\Logs\Ad-Aware log2005-12-01 16-12-29.txt 30.66KB
C:\Documents and Settings\Larry Hathcock\Application Data\Lavasoft\Ad-Aware\Logs\Ad-Aware log2005-12-02 21-03-47.txt 51.34KB
C:\Documents and Settings\Larry Hathcock\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\BorderPanel.class-3c14a8ad-1ad32ebe.class 5.81KB
C:\Documents and Settings\Larry Hathcock\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\BorderPanel.class-3c14a8ad-1ad32ebe.idx 286 bytes
C:\Documents and Settings\Larry Hathcock\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\click.au-7319cf46-3d69aa0b.au 1.54KB
C:\Documents and Settings\Larry Hathcock\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\click.au-7319cf46-3d69aa0b.idx 257 bytes
C:\Documents and Settings\Larry Hathcock\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\facade.gif-74370c38-4521b360.gif 2.15KB
C:\Documents and Settings\Larry Hathcock\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\facade.gif-74370c38-4521b360.idx 305 bytes
C:\Documents and Settings\Larry Hathcock\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\Fader.class-2537fda5-1cda10f8.class 12.18KB
C:\Documents and Settings\Larry Hathcock\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\Fader.class-2537fda5-1cda10f8.idx 292 bytes
C:\Documents and Settings\Larry Hathcock\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\FixFontHeadline.class-153c6e13-4660ec99.class 2.83KB
C:\Documents and Settings\Larry Hathcock\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\FixFontHeadline.class-153c6e13-4660ec99.idx 272 bytes
C:\Documents and Settings\Larry Hathcock\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\FixFontHeadlines.class-151d4f90-36f28b48.class 7.32KB
C:\Documents and Settings\Larry Hathcock\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\FixFontHeadlines.class-151d4f90-36f28b48.idx 273 bytes
C:\Documents and Settings\Larry Hathcock\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\ImageCanvas.class-31d4f1c8-68d29853.class 821 bytes
C:\Documents and Settings\Larry Hathcock\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\ImageCanvas.class-31d4f1c8-68d29853.idx 285 bytes
C:\Documents and Settings\Larry Hathcock\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\logo.gif-9a58a0a-46b56128.gif 1.46KB
C:\Documents and Settings\Larry Hathcock\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\logo.gif-9a58a0a-46b56128.idx 262 bytes
C:\Documents and Settings\Larry Hathcock\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\MD5.class-29fca593-6f7b8154.class 5.42KB
C:\Documents and Settings\Larry Hathcock\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\MD5.class-29fca593-6f7b8154.idx 278 bytes
C:\Documents and Settings\Larry Hathcock\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\MD5State.class-243d6746-2fc7aa77.class 644 bytes
C:\Documents and Settings\Larry Hathcock\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\MD5State.class-243d6746-2fc7aa77.idx 282 bytes
C:\Documents and Settings\Larry Hathcock\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\shallwedance2004-150.jpg-464b53ba-458fa4fd.idx 284 bytes
C:\Documents and Settings\Larry Hathcock\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\shallwedance2004-150.jpg-464b53ba-458fa4fd.jpg 8.36KB
C:\Documents and Settings\Larry Hathcock\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\SizeablePanel.class-35cdfc5e-7d0ebce2.class 554 bytes
C:\Documents and Settings\Larry Hathcock\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\SizeablePanel.class-35cdfc5e-7d0ebce2.idx 287 bytes
C:\Documents and Settings\Larry Hathcock\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\slipper.class-5c1c49bf-4b44721e.class 7.87KB
C:\Documents and Settings\Larry Hathcock\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\slipper.class-5c1c49bf-4b44721e.idx 272 bytes
C:\Documents and Settings\Larry Hathcock\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\speed.class-7db2195c-47ec41f9.class 8.46KB
C:\Documents and Settings\Larry Hathcock\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\speed.class-7db2195c-47ec41f9.idx 280 bytes
C:\Documents and Settings\Larry Hathcock\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\teamamericaworldpolice150.jpg-6bd44977-5bb10a17.idx 289 bytes
C:\Documents and Settings\Larry Hathcock\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\teamamericaworldpolice150.jpg-6bd44977-5bb10a17.jpg 5.93KB
C:\Documents and Settings\Larry Hathcock\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\thedustfactory150.jpg-172c19ef-2a7e6c3d.idx 281 bytes
C:\Documents and Settings\Larry Hathcock\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\thedustfactory150.jpg-172c19ef-2a7e6c3d.jpg 8.82KB
C:\Documents and Settings\Larry Hathcock\Application Data\Sun\Java\Deployment\cache\javapi\v1.0