############################## | UsbFix V 7.097 | [Listing] User: Kaper (Administrator) # KAPER-PC Updated 02/09/2012 by El Desaparecido Started at 18:59:19 | 16/10/2012 Website: http://eldesaparecido.com Forum: http://forum.eldesaparecido.com Suspicious file ? : http://eldesaparecido.com/upload.php Contact: contact@eldesaparecido.com PC: LENOVO (20017 ) (X86-based PC CPU: Pentium(R) Dual-Core CPU T4200 @ 2.00GHz (2000) RAM -> [Total : 3066 | Free : 814] BIOS: Ver 1.00PARTTBL9 BOOT: Normal boot OS: Microsoft® Windows Vista™ Home Premium (6.0.6002 32-Bit) # Service Pack 2 WB: Windows Internet Explorer 9.0.8112.16421 SC: Security Center Service [Enabled] WU: Windows Update Service [Enabled] AV: Lavasoft Ad-Aware [Enabled | Updated] FW: Windows FireWall Service [Enabled] C:\ (%systemdrive%) -> Fixed drive # 138 Gb (53 Mb free - 39%) [] # NTFS D:\ -> Fixed drive # 30 Gb (12 Mb free - 38%) [Lenovo] # NTFS E:\ -> Fixed drive # 115 Gb (23 Mb free - 20%) [] # NTFS F:\ -> Fixed drive # 15 Gb (6 Mb free - 41%) [] # NTFS G:\ -> CD-ROM M:\ -> Removable drive # 4 Gb (3 Mb free - 83%) [] # FAT32 ################## | Listing | [19/10/2011 - 21:23:37 | SHD ] C:\$Recycle.Bin [29/12/2011 - 14:55:01 | D ] C:\ADAKO [12/04/2012 - 04:58:24 | D ] C:\afa1975d84fd4da370ad80b9981076f1 [18/09/2006 - 23:43:36 | A | 24] C:\autoexec.bat [19/10/2011 - 22:09:54 | SHD ] C:\Boot [11/04/2009 - 15:18:38 | RASH | 333257] C:\bootmgr [19/10/2011 - 22:09:57 | RAS | 8192] C:\BOOTSECT.BAK [16/10/2012 - 18:15:05 | SHD ] C:\Config.Msi [18/09/2006 - 23:43:37 | A | 10] C:\config.sys [11/01/2012 - 20:03:04 | D ] C:\DigitalVideoConverter [02/11/2006 - 15:02:03 | SHD ] C:\Documents and Settings [19/10/2011 - 19:33:33 | D ] C:\Drivers [30/11/2011 - 18:14:15 | SHD ] C:\found.000 [05/08/2012 - 11:23:18 | SHD ] C:\found.001 [14/10/2012 - 13:18:38 | ASH | 3213479936] C:\hiberfil.sys [25/12/2008 - 15:52:00 | A | 90112] C:\ImgRes.dll [19/10/2011 - 17:35:24 | D ] C:\Intel [04/09/2012 - 21:01:50 | RASH | 0] C:\IO.SYS [10/08/2012 - 17:10:33 | D ] C:\MCS7830_Logs [04/09/2012 - 21:01:50 | RASH | 0] C:\MSDOS.SYS [20/10/2011 - 22:52:49 | RHD ] C:\MSOCache [04/11/2011 - 11:33:28 | D ] C:\NVIDIA [26/01/2012 - 09:08:56 | D ] C:\OP-COM [14/10/2012 - 13:18:36 | ASH | 3529363456] C:\pagefile.sys [21/01/2008 - 04:32:31 | D ] C:\PerfLogs [05/05/2012 - 14:39:00 | D ] C:\PFiles [16/10/2012 - 18:15:43 | RD ] C:\Program Files [14/10/2012 - 23:04:02 | HD ] C:\ProgramData [04/11/2011 - 11:27:38 | A | 4536] C:\shared.log [16/10/2012 - 18:15:40 | A | 13874373] C:\sysiclog.txt [16/01/2012 - 23:01:06 | A | 20145744] C:\sysiclog.txt.bak [16/10/2012 - 18:45:36 | SHD ] C:\System Volume Information [11/03/2012 - 18:42:47 | D ] C:\totalcmd [16/10/2012 - 18:59:22 | D ] C:\UsbFix [16/10/2012 - 18:58:53 | A | 2875] C:\UsbFix.txt [06/08/2012 - 21:35:45 | A | 1795] C:\user.js [03/03/2012 - 19:02:05 | RD ] C:\Users [10/10/2012 - 11:20:01 | SHD ] C:\Windows [14/10/2012 - 13:19:18 | ASH | 76] C:\_PartitionInfo [19/10/2011 - 21:23:37 | SHD ] D:\$RECYCLE.BIN [13/11/2010 - 17:37:08 | HD ] D:\Boot [21/01/2008 - 04:24:42 | RASH | 333203] D:\bootmgr [28/07/2009 - 07:05:11 | D ] D:\drivers [04/11/2011 - 11:28:04 | D ] D:\Games [03/12/2009 - 11:09:02 | HD ] D:\Lenovo [13/11/2010 - 17:37:08 | HD ] D:\program files [19/05/2009 - 05:34:59 | SHD ] D:\System Volume Information [13/11/2010 - 17:37:08 | HD ] D:\Users [13/11/2010 - 17:39:14 | HD ] D:\Windows [19/10/2011 - 21:23:37 | SHD ] E:\$RECYCLE.BIN [24/03/2012 - 17:32:31 | D ] E:\eldcr [07/11/2007 - 09:00:40 | A | 17734] E:\eula.1028.txt [07/11/2007 - 09:00:40 | A | 17734] E:\eula.1031.txt [07/11/2007 - 09:00:40 | A | 10134] E:\eula.1033.txt [07/11/2007 - 09:00:40 | A | 17734] E:\eula.1036.txt [07/11/2007 - 09:00:40 | A | 17734] E:\eula.1040.txt [07/11/2007 - 09:00:40 | A | 118] E:\eula.1041.txt [07/11/2007 - 09:00:40 | A | 17734] E:\eula.1042.txt [07/11/2007 - 09:00:40 | A | 17734] E:\eula.2052.txt [07/11/2007 - 09:00:40 | A | 17734] E:\eula.3082.txt [30/09/2012 - 21:41:12 | D ] E:\faraon [04/09/2012 - 17:38:30 | D ] E:\frontpage [07/11/2007 - 09:00:40 | A | 1110] E:\globdata.ini [07/08/2012 - 23:05:50 | D ] E:\HIII [04/09/2012 - 21:01:29 | D ] E:\hitman [04/09/2012 - 21:03:45 | D ] E:\Hitman 2 Silent Assassin [07/11/2007 - 09:03:18 | A | 562688] E:\install.exe [07/11/2007 - 09:00:40 | A | 843] E:\install.ini [07/11/2007 - 09:03:18 | A | 76304] E:\install.res.1028.dll [07/11/2007 - 09:03:18 | A | 96272] E:\install.res.1031.dll [07/11/2007 - 09:03:18 | A | 91152] E:\install.res.1033.dll [07/11/2007 - 09:03:18 | A | 97296] E:\install.res.1036.dll [07/11/2007 - 09:03:18 | A | 95248] E:\install.res.1040.dll [07/11/2007 - 09:03:18 | A | 81424] E:\install.res.1041.dll [07/11/2007 - 09:03:18 | A | 79888] E:\install.res.1042.dll [07/11/2007 - 09:03:18 | A | 75792] E:\install.res.2052.dll [07/11/2007 - 09:03:18 | A | 96272] E:\install.res.3082.dll [07/10/2012 - 11:51:42 | D ] E:\leagueoflegends [07/10/2012 - 04:17:00 | D ] E:\LOL [12/03/2012 - 19:18:37 | D ] E:\shogun 21 [07/05/2012 - 12:32:25 | D ] E:\shogun total war 2 [28/03/2012 - 02:47:26 | D ] E:\Star Wars-The Old Republic [24/03/2012 - 17:33:06 | D ] E:\starcraft [15/10/2012 - 23:04:53 | D ] E:\Steam [19/10/2011 - 21:13:13 | SHD ] E:\System Volume Information [13/03/2012 - 12:28:44 | D ] E:\The Elder Scrolls V Skyrim cala [08/10/2012 - 16:53:20 | D ] E:\utorrent [07/11/2007 - 09:00:40 | A | 5686] E:\vcredist.bmp [07/11/2007 - 09:09:22 | A | 1442522] E:\VC_RED.cab [07/11/2007 - 09:12:28 | A | 232960] E:\VC_RED.MSI [06/08/2012 - 23:43:39 | D ] E:\World_of_Tanks [19/10/2011 - 21:23:37 | SHD ] F:\$RECYCLE.BIN [27/07/2009 - 23:14:36 | AD ] F:\boot [05/06/2007 - 00:08:56 | A | 438840] F:\bootmgr [21/05/2009 - 17:31:14 | A | 291021] F:\copyunattend.exe [13/06/2009 - 12:05:26 | A | 292203] F:\CsilderbarPE.exe [08/06/2009 - 04:41:42 | A | 292215] F:\delstartupcmd.exe [19/05/2009 - 17:31:36 | AD ] F:\EFI [12/09/2008 - 07:40:06 | A | 31] F:\extdisk.txt [19/05/2009 - 17:31:53 | AD ] F:\Factory [27/07/2009 - 23:34:34 | A | 104919724] F:\factory.000 [27/07/2009 - 23:15:29 | N | 104876510] F:\factory.001 [27/07/2009 - 23:15:41 | N | 104869880] F:\factory.002 [27/07/2009 - 23:15:54 | N | 104913799] F:\factory.003 [27/07/2009 - 23:16:07 | N | 104921724] F:\factory.004 [27/07/2009 - 23:16:19 | N | 104866712] F:\factory.005 [27/07/2009 - 23:16:31 | N | 104920456] F:\factory.006 [27/07/2009 - 23:16:43 | N | 104884970] F:\factory.007 [27/07/2009 - 23:16:55 | N | 104890873] F:\factory.008 [27/07/2009 - 23:17:10 | N | 104889820] F:\factory.009 [27/07/2009 - 23:17:23 | N | 104894411] F:\factory.010 [27/07/2009 - 23:17:35 | N | 104862358] F:\factory.011 [27/07/2009 - 23:17:51 | N | 104883875] F:\factory.012 [27/07/2009 - 23:18:07 | N | 104918773] F:\factory.013 [27/07/2009 - 23:18:21 | N | 104902743] F:\factory.014 [27/07/2009 - 23:18:37 | N | 104875256] F:\factory.015 [27/07/2009 - 23:18:50 | N | 104912784] F:\factory.016 [27/07/2009 - 23:19:04 | N | 104906829] F:\factory.017 [27/07/2009 - 23:19:17 | N | 104876569] F:\factory.018 [27/07/2009 - 23:19:30 | N | 104911858] F:\factory.019 [27/07/2009 - 23:19:44 | N | 104896220] F:\factory.020 [27/07/2009 - 23:19:57 | N | 104858713] F:\factory.021 [27/07/2009 - 23:20:15 | N | 104878304] F:\factory.022 [27/07/2009 - 23:20:32 | N | 104889942] F:\factory.023 [27/07/2009 - 23:20:46 | N | 104889646] F:\factory.024 [27/07/2009 - 23:21:00 | N | 104884344] F:\factory.025 [27/07/2009 - 23:21:13 | N | 104871461] F:\factory.026 [27/07/2009 - 23:21:28 | N | 104874849] F:\factory.027 [27/07/2009 - 23:21:43 | N | 104883707] F:\factory.028 [27/07/2009 - 23:21:57 | N | 104878748] F:\factory.029 [27/07/2009 - 23:22:11 | N | 104875970] F:\factory.030 [27/07/2009 - 23:22:27 | N | 104858883] F:\factory.031 [27/07/2009 - 23:22:44 | N | 104861002] F:\factory.032 [27/07/2009 - 23:22:59 | N | 104919989] F:\factory.033 [27/07/2009 - 23:23:12 | N | 104877920] F:\factory.034 [27/07/2009 - 23:23:28 | N | 104876477] F:\factory.035 [27/07/2009 - 23:23:43 | N | 104866915] F:\factory.036 [27/07/2009 - 23:23:58 | N | 104864690] F:\factory.037 [27/07/2009 - 23:24:14 | N | 104870591] F:\factory.038 [27/07/2009 - 23:24:27 | N | 104889016] F:\factory.039 [27/07/2009 - 23:24:40 | N | 104873834] F:\factory.040 [27/07/2009 - 23:24:57 | N | 104904562] F:\factory.041 [27/07/2009 - 23:25:09 | N | 104905740] F:\factory.042 [27/07/2009 - 23:25:23 | N | 104873923] F:\factory.043 [27/07/2009 - 23:25:36 | N | 104869017] F:\factory.044 [27/07/2009 - 23:25:51 | N | 104883289] F:\factory.045 [27/07/2009 - 23:26:07 | N | 104898894] F:\factory.046 [27/07/2009 - 23:26:24 | N | 104896396] F:\factory.047 [27/07/2009 - 23:26:40 | N | 104872504] F:\factory.048 [27/07/2009 - 23:26:57 | N | 104860941] F:\factory.049 [27/07/2009 - 23:27:11 | N | 104874220] F:\factory.050 [27/07/2009 - 23:27:25 | N | 104875484] F:\factory.051 [27/07/2009 - 23:27:39 | N | 104872794] F:\factory.052 [27/07/2009 - 23:27:53 | N | 104861347] F:\factory.053 [27/07/2009 - 23:28:08 | N | 104858570] F:\factory.054 [27/07/2009 - 23:28:21 | N | 104886977] F:\factory.055 [27/07/2009 - 23:28:35 | N | 104870741] F:\factory.056 [27/07/2009 - 23:28:47 | N | 104874511] F:\factory.057 [27/07/2009 - 23:29:02 | N | 104899994] F:\factory.058 [27/07/2009 - 23:29:16 | N | 104869574] F:\factory.059 [27/07/2009 - 23:29:29 | N | 104858780] F:\factory.060 [27/07/2009 - 23:29:42 | N | 104864932] F:\factory.061 [27/07/2009 - 23:29:57 | N | 104867243] F:\factory.062 [27/07/2009 - 23:30:11 | N | 104894975] F:\factory.063 [27/07/2009 - 23:30:24 | N | 104894990] F:\factory.064 [27/07/2009 - 23:30:37 | N | 104900372] F:\factory.065 [27/07/2009 - 23:30:51 | N | 104900159] F:\factory.066 [27/07/2009 - 23:31:05 | N | 104870575] F:\factory.067 [27/07/2009 - 23:31:18 | N | 104873896] F:\factory.068 [27/07/2009 - 23:31:31 | N | 104902572] F:\factory.069 [27/07/2009 - 23:31:42 | N | 104860689] F:\factory.070 [27/07/2009 - 23:31:57 | N | 104869275] F:\factory.071 [27/07/2009 - 23:32:08 | N | 104877636] F:\factory.072 [27/07/2009 - 23:32:21 | N | 104864466] F:\factory.073 [27/07/2009 - 23:32:36 | N | 104869433] F:\factory.074 [27/07/2009 - 23:32:51 | N | 104895906] F:\factory.075 [27/07/2009 - 23:33:05 | N | 104885035] F:\factory.076 [27/07/2009 - 23:33:18 | N | 104857909] F:\factory.077 [27/07/2009 - 23:33:31 | N | 104907085] F:\factory.078 [27/07/2009 - 23:33:42 | N | 104905604] F:\factory.079 [27/07/2009 - 23:33:54 | N | 104888713] F:\factory.080 [27/07/2009 - 23:34:08 | N | 104863619] F:\factory.081 [27/07/2009 - 23:34:22 | N | 104897524] F:\factory.082 [27/07/2009 - 23:34:33 | N | 76665682] F:\factory.083 [27/07/2009 - 23:34:34 | A | 682] F:\factory.wsi [27/07/2009 - 23:34:34 | A | 2491872] F:\factory0000.DSI [05/06/2007 - 00:08:56 | A | 381440] F:\imagex.exe [22/03/2009 - 14:30:00 | A | 19] F:\listvolume.txt [05/06/2007 - 00:08:56 | A | 1301504] F:\msxml6.dll [05/06/2007 - 00:08:56 | A | 86728] F:\msxml6r.dll [13/06/2009 - 11:33:58 | A | 725] F:\okopr.bat [02/11/2008 - 08:32:41 | A | 1651] F:\okopr_1.bat [07/04/2009 - 07:12:11 | A | 711] F:\okopr_2.bat [19/05/2009 - 17:32:17 | AD ] F:\OneKey Recovery [05/11/2008 - 22:49:56 | A | 188416] F:\pass.exe [12/08/2005 - 14:21:48 | A | 40960] F:\peshutdown.exe [21/05/2009 - 17:40:00 | A | 291047] F:\replaceunattend.exe [19/05/2009 - 17:32:23 | AD ] F:\Servicing [13/01/2008 - 14:18:26 | A | 76] F:\Setup.cmd [19/05/2009 - 17:22:33 | A | 89] F:\sn.txt [19/05/2009 - 17:32:24 | AD ] F:\sources [19/05/2009 - 05:34:59 | SHD ] F:\System Volume Information [19/05/2009 - 20:13:48 | RA | 552] F:\unattend.xml [05/06/2007 - 00:08:56 | A | 3116] F:\wimfltr.inf [05/06/2007 - 00:08:56 | A | 128104] F:\wimfltr.sys [05/06/2007 - 00:08:56 | A | 318464] F:\wimgapi.dll [05/06/2007 - 00:08:56 | A | 178] F:\Wimscript.ini [24/09/2012 - 02:32:48 | SHD ] M:\DCIM [30/09/2012 - 19:21:34 | A | 307] M:\New Folder.lnk [30/09/2012 - 19:21:34 | A | 307] M:\Passwords.lnk [30/09/2012 - 19:21:34 | A | 307] M:\Documents.lnk [30/09/2012 - 19:21:34 | A | 307] M:\Pictures.lnk [30/09/2012 - 19:21:34 | A | 307] M:\Music.lnk [30/09/2012 - 19:21:34 | A | 307] M:\Video.lnk [30/09/2012 - 19:29:46 | A | 364] M:\DCIM.lnk ################## | E.O.F |