Hi,
Sorry I didn't run earlier in recovery mode.
Find below FRST.txt after running on recovery mode
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 11-04-2013 (ATTENTION: FRST version is 6 days old)
Ran by SYSTEM at 17-04-2013 14:11:24
Running from G:\
Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US)
The current controlset is ControlSet001
==================== Registry (Whitelisted) ===================
HKLM\...\Run: [IntelWireless] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel Wireless Tray [1933584 2010-12-17] (Intel(R) Corporation)
HKLM\...\Run: [BTMTrayAgent] rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp [10228224 2010-11-03] (Intel Corporation)
HKLM\...\Run: [QuickSet] C:\Program Files\Dell\QuickSet\QuickSet.exe [3666800 2011-01-21] (Dell Inc.)
HKLM\...\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe [524800 2010-11-18] (IDT, Inc.)
HKLM\...\Run: [DellStage] "C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe" "C:\Program Files (x86)\Dell Stage\Dell Stage\start.umj" --startup [483424 2012-02-01] ()
HKLM\...\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe [609144 2011-04-12] (Alps Electric Co., Ltd.)
HKLM-x32\...\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey [1527896 2012-06-21] (McAfee, Inc.)
HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-11-05] (Intel Corporation)
HKLM-x32\...\Run: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2 [487562 2010-08-19] (Creative Technology Ltd)
HKLM-x32\...\Run: [Wipro] "C:\Program Files\Settings\WiproRunReg.vbs" [595 2010-05-07] ()
HKLM-x32\...\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe" [74752 2012-06-28] (Nullsoft, Inc.)
HKLM-x32\...\Run: [Sweetpacks Communicator] C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe [231768 2012-08-15] (SweetIM Technologies Ltd.)
HKLM-x32\...\Run: [SweetIM] C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe [115032 2012-10-04] (SweetIM Technologies Ltd.)
HKLM-x32\...\Run: [RoxWatchTray] "c:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" [240112 2010-11-25] (Sonic Solutions)
HKLM-x32\...\Run: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [Desktop Disc Tool] "c:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe" [514544 2010-11-17] ()
HKLM-x32\...\Run: [Dell DataSafe Online] C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe [1117528 2010-08-25] (Dell, Inc.)
HKLM-x32\...\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-03-13] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [35768 2012-07-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [919008 2012-07-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AccuWeatherWidget] "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe" "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\start.umj" --startup [2835443 2012-02-01] ()
HKU\Sanchit\...\Run: [VeohPlugin] "C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2644992 2011-06-13] (Veoh Networks)
HKU\Sanchit\...\Run: [SmartVoip] "C:\Program Files (x86)\SmartVoip.com\SmartVoip\smartvoip.exe" -nosplash -minimized [19071960 2013-02-06] (SmartVoip)
HKU\Sanchit\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [18642024 2013-02-28] (Skype Technologies S.A.)
HKU\Sanchit\...\Run: [Seahaxarak] C:\Users\Sanchit\AppData\Roaming\Saqivu\boop.exe [196608 2012-07-26] ()
HKU\Sanchit\...\Run: [Messenger (Yahoo!)] ~"C:\PROGRA~2\Yahoo!\Messenger\YahooMessenger.exe" -quiet [5252408 2010-06-01] (Yahoo! Inc.)
HKU\Sanchit\...\Run: [Google Update] "C:\Users\Sanchit\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2011-06-15] (Google Inc.)
HKU\Sanchit\...\Run: [Facebook Update] "C:\Users\Sanchit\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver [138096 2012-07-11] (Facebook Inc.)
HKU\Sanchit\...\Winlogon: [Shell] C:\Users\Sanchit\AppData\Roaming\mcafee.ini,explorer.exe
HKLM-x32\...\RunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe" [559616 2011-10-13] (Dell)
HKLM\...D6A79037F57F\InprocServer32: [Default-fastprox] C:\$Recycle.Bin\S-1-5-18\$3b99f81f31d5dbab1bcf87d0107a285a\n. ATTENTION! ====> ZeroAccess
Startup: C:\ProgramData\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files (x86)\McAfee Security Scan\2.0.189\SSScheduler.exe (McAfee, Inc.)
Startup: C:\ProgramData\Start Menu\Programs\Startup\Monitor Apache Servers.lnk
ShortcutTarget: Monitor Apache Servers.lnk -> C:\Program Files (x86)\Apache Software Foundation\Apache2.2\bin\ApacheMonitor.exe (Apache Software Foundation)
==================== Services (Whitelisted) ===================
4 Apache2.2; "C:\Program Files (x86)\Apache Software Foundation\Apache2.2\bin\httpd.exe" -k runservice [20549 2012-01-28] (Apache Software Foundation)
4 BrlAPI; C:\cygwin\bin\cygrunsrv.exe [68096 2008-03-18] ()
4 Giraffic; C:\Program Files (x86)\Giraffic\Veoh_GirafficWatchdog.exe --service [2232504 2012-07-02] (Giraffic)
4 HitmanProScheduler; C:\Program Files\HitmanPro\hmpsched.exe [109352 2013-04-09] (SurfRight B.V.)
4 McAWFwk; C:\PROGRA~1\mcafee\msc\mcawfwk.exe [220528 2010-08-30] (McAfee, Inc.)
4 McComponentHostService; "C:\Program Files (x86)\McAfee Security Scan\2.0.189\McCHSvc.exe" [227232 2010-09-02] (McAfee, Inc.)
2 McMPFSvc; "C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [200728 2012-05-10] (McAfee, Inc.)
4 mcmscsvc; "C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [200728 2012-05-10] (McAfee, Inc.)
4 McNaiAnn; "C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [200728 2012-05-10] (McAfee, Inc.)
4 McNASvc; "C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [200728 2012-05-10] (McAfee, Inc.)
4 McODS; "C:\Program Files\mcafee\VirusScan\mcods.exe" [383608 2012-08-24] (McAfee, Inc.)
4 McOobeSv; "C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [200728 2012-05-10] (McAfee, Inc.)
4 McProxy; "C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [200728 2012-05-10] (McAfee, Inc.)
2 McShield; "C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe" [237920 2012-06-22] (McAfee, Inc.)
2 mfefire; "C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe" [218320 2012-06-22] (McAfee, Inc.)
2 mfevtp; "C:\Windows\system32\mfevtps.exe" [177144 2012-06-22] (McAfee, Inc.)
4 MSK80Service; "C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [200728 2012-05-10] (McAfee, Inc.)
4 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2010-12-17] ()
==================== Drivers (Whitelisted) =====================
3 cfwids; C:\Windows\System32\Drivers\cfwids.sys [69672 2012-06-22] (McAfee, Inc.)
3 HipShieldK; C:\Windows\System32\Drivers\HipShieldK.sys [196440 2012-04-20] (McAfee, Inc.)
3 hitmanpro37; C:\Windows\System32\Drivers\hitmanpro37.sys [32152 2013-04-09] ()
3 mfeapfk; C:\Windows\System32\Drivers\mfeapfk.sys [169320 2012-06-22] (McAfee, Inc.)
3 mfeavfk; C:\Windows\System32\Drivers\mfeavfk.sys [300392 2012-06-22] (McAfee, Inc.)
3 mfefirek; C:\Windows\System32\Drivers\mfefirek.sys [513456 2012-06-22] (McAfee, Inc.)
0 mfehidk; C:\Windows\System32\Drivers\mfehidk.sys [752672 2012-06-22] (McAfee, Inc.)
3 mferkdet; C:\Windows\System32\Drivers\mferkdet.sys [106112 2012-06-22] (McAfee, Inc.)
0 mfewfpk; C:\Windows\System32\Drivers\mfewfpk.sys [335784 2012-06-22] (McAfee, Inc.)
4 mysql; "C:\Program Files\MySQL\MySQL Server 5.5\bin\mysqld" --defaults-file="C:\ProgramData\MySQL\MySQL Server 5.5\my.ini" mysql [9171 2012-02-27] ()
1 NEOFLTR_719_20893; C:\Windows\System32\Drivers\NEOFLTR_719_20893.sys [99152 2012-05-04] (Juniper Networks)
3 hwdatacard; C:\Windows\System32\DRIVERS\ewusbmdm.sys [x]
3 PCDSRVC{1E208CE0-FB7451FF-06020200}_0; \??\c:\program files\dell support center\pcdsrvc_x64.pkms [x]
==================== NetSvcs (Whitelisted) ====================
==================== One Month Created Files and Folders ========
2013-04-17 06:41 - 2013-04-17 06:41 - 00000000 ____D C:\FRST
2013-04-10 07:01 - 2013-04-14 03:22 - 00000000 ____D C:\Windows\pss
2013-04-09 14:50 - 2013-04-14 03:33 - 00001823 ____A C:\Users\Public\Desktop\HitmanPro.lnk
2013-04-09 14:50 - 2013-04-14 03:33 - 00001823 ____A C:\ProgramData\Desktop\HitmanPro.lnk
2013-04-09 14:50 - 2013-04-09 14:50 - 00032152 ____A C:\Windows\System32\Drivers\hitmanpro37.sys
2013-04-09 14:50 - 2013-04-09 14:50 - 00000000 ____D C:\Program Files\HitmanPro
2013-04-09 14:49 - 2013-04-09 14:49 - 00000000 ____D C:\ProgramData\HitmanPro
2013-04-09 14:49 - 2013-04-09 14:49 - 00000000 ____D C:\ProgramData\Application Data\HitmanPro
2013-04-09 14:11 - 2013-04-09 14:11 - 00000000 __SHD C:\found.001
2013-04-09 13:41 - 2013-04-09 13:42 - 09741664 ____A (SurfRight B.V.) C:\Users\Sanchit\Downloads\HitmanPro_x64.exe
2013-04-09 03:40 - 2013-04-09 03:40 - 00006768 ____N C:\bootsqm.dat
2013-04-09 03:37 - 2013-04-09 03:37 - 00000000 __SHD C:\found.000
2013-04-09 01:03 - 2013-04-09 01:03 - 00000000 ____D C:\ProgramData\ltmrj
2013-04-09 01:03 - 2013-04-09 01:03 - 00000000 ____D C:\ProgramData\Application Data\ltmrj
2013-04-03 12:16 - 2013-04-08 02:29 - 00000000 ____D C:\Users\Sanchit\Application Data\Riom
2013-04-03 12:16 - 2013-04-08 02:29 - 00000000 ____D C:\Users\Sanchit\AppData\Roaming\Riom
2013-04-03 12:16 - 2013-04-03 12:16 - 00000000 ____D C:\Users\Sanchit\Application Data\Saqivu
2013-04-03 12:16 - 2013-04-03 12:16 - 00000000 ____D C:\Users\Sanchit\Application Data\Essybe
2013-04-03 12:16 - 2013-04-03 12:16 - 00000000 ____D C:\Users\Sanchit\AppData\Roaming\Saqivu
2013-04-03 12:16 - 2013-04-03 12:16 - 00000000 ____D C:\Users\Sanchit\AppData\Roaming\Essybe
2013-04-03 07:19 - 2013-04-03 07:19 - 00012737 ____A C:\Users\Sanchit\Desktop\hs_err_pid12100.log
2013-03-31 03:33 - 2013-03-31 03:33 - 00000000 ____D C:\Users\Sanchit\Local Settings\Application Data\{56247787-5527-4C84-AFF1-526BFB67A65B}
2013-03-31 03:33 - 2013-03-31 03:33 - 00000000 ____D C:\Users\Sanchit\Local Settings\{56247787-5527-4C84-AFF1-526BFB67A65B}
2013-03-31 03:33 - 2013-03-31 03:33 - 00000000 ____D C:\Users\Sanchit\AppData\Local\{56247787-5527-4C84-AFF1-526BFB67A65B}
2013-03-30 08:57 - 2013-03-30 08:57 - 00000000 ____D C:\Users\Sanchit\Local Settings\Application Data\{FD858EF5-6B23-403E-A310-157FA49C236D}
2013-03-30 08:57 - 2013-03-30 08:57 - 00000000 ____D C:\Users\Sanchit\Local Settings\{FD858EF5-6B23-403E-A310-157FA49C236D}
2013-03-30 08:57 - 2013-03-30 08:57 - 00000000 ____D C:\Users\Sanchit\AppData\Local\{FD858EF5-6B23-403E-A310-157FA49C236D}
2013-03-29 04:47 - 2013-03-29 19:10 - 00000000 ____D C:\Users\Sanchit\.android
2013-03-26 15:24 - 2013-03-26 15:24 - 00000000 ____D C:\Users\Public\Juniper Networks
2013-03-26 15:24 - 2012-05-04 20:17 - 00590472 ____A (Juniper Networks) C:\Windows\System32\dsNcSmartCardProv.dll
2013-03-26 15:24 - 2012-05-04 20:17 - 00422024 ____A (Juniper Networks) C:\Windows\System32\dsNcCredProv.dll
2013-03-26 14:29 - 2013-03-26 14:29 - 00262144 ____A C:\Windows\Minidump\032613-30997-01.dmp
2013-03-26 14:25 - 2013-03-26 14:25 - 00200531 ____A C:\Users\Sanchit\Downloads\Sanchit (1).rar
2013-03-26 14:25 - 2013-03-26 12:11 - 00205247 ____A C:\Users\Sanchit\Downloads\Sanchit.apk
2013-03-26 14:23 - 2013-03-26 14:23 - 00200531 ____A C:\Users\Sanchit\Downloads\Sanchit.rar
2013-03-25 18:09 - 2013-03-25 18:09 - 00000018 ____A C:\pending.un
2013-03-25 18:09 - 2012-05-04 20:27 - 00099152 ____A (Juniper Networks) C:\Windows\System32\Drivers\NEOFLTR_719_20893.SYS
2013-03-22 17:27 - 2013-03-22 17:27 - 01633280 ____A C:\Users\Sanchit\Downloads\NGIN SNEC40 Multidomain ATP for TDE(For TMS import)V0.3.xls
2013-03-20 15:48 - 2013-02-11 23:12 - 00019968 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\usb8023.sys
2013-03-20 15:28 - 2013-03-20 15:28 - 00000096 ____A C:\Users\Sanchit\Downloads\Menu.txt
2013-03-20 06:08 - 2013-03-20 06:08 - 00000000 ____D C:\Users\Sanchit\Application Data\Google
2013-03-20 06:08 - 2013-03-20 06:08 - 00000000 ____D C:\Users\Sanchit\AppData\Roaming\Google
2013-03-19 11:42 - 2013-03-19 11:42 - 00262144 ____A C:\Windows\Minidump\031913-30123-01.dmp
2013-03-19 11:41 - 2013-03-26 14:29 - 572101397 ____A C:\Windows\MEMORY.DMP
2013-03-18 17:07 - 2013-03-18 17:07 - 08151705 ____A C:\Users\Sanchit\Downloads\com.goldron.bbfree-1.0.apk
==================== One Month Modified Files and Folders =======
2013-04-17 06:41 - 2013-04-17 06:41 - 00000000 ____D C:\FRST
2013-04-17 03:32 - 2011-06-12 06:52 - 00000000 ____D C:\ProgramData\Sonic
2013-04-17 03:32 - 2011-06-12 06:52 - 00000000 ____D C:\ProgramData\Application Data\Sonic
2013-04-14 03:34 - 2009-07-13 23:45 - 00020928 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-04-14 03:34 - 2009-07-13 23:45 - 00020928 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-04-14 03:33 - 2013-04-09 14:50 - 00001823 ____A C:\Users\Public\Desktop\HitmanPro.lnk
2013-04-14 03:33 - 2013-04-09 14:50 - 00001823 ____A C:\ProgramData\Desktop\HitmanPro.lnk
2013-04-14 03:22 - 2013-04-10 07:01 - 00000000 ____D C:\Windows\pss
2013-04-10 07:57 - 2012-08-24 16:48 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-04-10 07:57 - 2011-06-17 14:15 - 00000000 ____D C:\Program Files (x86)\Giraffic
2013-04-10 07:57 - 2011-06-12 07:02 - 00000000 ____D C:\Program Files (x86)\Dell DataSafe Local Backup
2013-04-10 07:56 - 2013-01-19 08:43 - 00007284 ____A C:\Windows\setupact.log
2013-04-10 07:56 - 2011-06-18 06:48 - 00000896 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-04-10 07:56 - 2011-06-12 07:13 - 00000000 ____D C:\Users\Default\Local Settings\SoftThinks
2013-04-10 07:56 - 2011-06-12 07:13 - 00000000 ____D C:\Users\Default\Local Settings\Application Data\SoftThinks
2013-04-10 07:56 - 2011-06-12 07:13 - 00000000 ____D C:\Users\Default\AppData\Local\SoftThinks
2013-04-10 07:56 - 2011-06-12 07:13 - 00000000 ____D C:\Users\Default User\Local Settings\SoftThinks
2013-04-10 07:56 - 2011-06-12 07:13 - 00000000 ____D C:\Users\Default User\Local Settings\Application Data\SoftThinks
2013-04-10 07:56 - 2011-06-12 07:13 - 00000000 ____D C:\Users\Default User\AppData\Local\SoftThinks
2013-04-10 07:56 - 2009-07-14 00:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-04-10 07:51 - 2011-06-12 06:27 - 01171389 ____A C:\Windows\WindowsUpdate.log
2013-04-10 07:19 - 2009-07-14 00:13 - 00006732 ____A C:\Windows\System32\PerfStringBackup.INI
2013-04-09 14:50 - 2013-04-09 14:50 - 00032152 ____A C:\Windows\System32\Drivers\hitmanpro37.sys
2013-04-09 14:50 - 2013-04-09 14:50 - 00000000 ____D C:\Program Files\HitmanPro
2013-04-09 14:49 - 2013-04-09 14:49 - 00000000 ____D C:\ProgramData\HitmanPro
2013-04-09 14:49 - 2013-04-09 14:49 - 00000000 ____D C:\ProgramData\Application Data\HitmanPro
2013-04-09 14:11 - 2013-04-09 14:11 - 00000000 __SHD C:\found.001
2013-04-09 13:42 - 2013-04-09 13:41 - 09741664 ____A (SurfRight B.V.) C:\Users\Sanchit\Downloads\HitmanPro_x64.exe
2013-04-09 12:28 - 2011-11-19 13:25 - 00000936 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2092152589-3654524724-1465183675-1000UA.job
2013-04-09 12:28 - 2011-06-18 06:48 - 00000900 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-04-09 12:28 - 2011-06-15 13:07 - 00000916 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2092152589-3654524724-1465183675-1000UA.job
2013-04-09 03:40 - 2013-04-09 03:40 - 00006768 ____N C:\bootsqm.dat
2013-04-09 03:37 - 2013-04-09 03:37 - 00000000 __SHD C:\found.000
2013-04-09 01:08 - 2011-11-19 13:25 - 00000914 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2092152589-3654524724-1465183675-1000Core.job
2013-04-09 01:03 - 2013-04-09 01:03 - 00000000 ____D C:\ProgramData\ltmrj
2013-04-09 01:03 - 2013-04-09 01:03 - 00000000 ____D C:\ProgramData\Application Data\ltmrj
2013-04-09 01:01 - 2011-06-18 06:47 - 00000000 ____D C:\Users\Sanchit\Application Data\Skype
2013-04-09 01:01 - 2011-06-18 06:47 - 00000000 ____D C:\Users\Sanchit\AppData\Roaming\Skype
2013-04-08 17:45 - 2011-06-15 06:01 - 00000000 ____D C:\users\Sanchit
2013-04-08 16:31 - 2011-06-15 13:07 - 00000864 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2092152589-3654524724-1465183675-1000Core.job
2013-04-08 10:32 - 2011-06-15 07:17 - 00022016 ____A C:\Users\Sanchit\Local Settings\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-04-08 10:32 - 2011-06-15 07:17 - 00022016 ____A C:\Users\Sanchit\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-04-08 10:32 - 2011-06-15 07:17 - 00022016 ____A C:\Users\Sanchit\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-04-08 02:29 - 2013-04-03 12:16 - 00000000 ____D C:\Users\Sanchit\Application Data\Riom
2013-04-08 02:29 - 2013-04-03 12:16 - 00000000 ____D C:\Users\Sanchit\AppData\Roaming\Riom
2013-04-07 01:22 - 2012-07-10 15:54 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-04-07 01:22 - 2011-06-12 06:57 - 00000000 ____D C:\ProgramData\Skype
2013-04-07 01:22 - 2011-06-12 06:57 - 00000000 ____D C:\ProgramData\Application Data\Skype
2013-04-03 12:16 - 2013-04-03 12:16 - 00000000 ____D C:\Users\Sanchit\Application Data\Saqivu
2013-04-03 12:16 - 2013-04-03 12:16 - 00000000 ____D C:\Users\Sanchit\Application Data\Essybe
2013-04-03 12:16 - 2013-04-03 12:16 - 00000000 ____D C:\Users\Sanchit\AppData\Roaming\Saqivu
2013-04-03 12:16 - 2013-04-03 12:16 - 00000000 ____D C:\Users\Sanchit\AppData\Roaming\Essybe
2013-04-03 07:19 - 2013-04-03 07:19 - 00012737 ____A C:\Users\Sanchit\Desktop\hs_err_pid12100.log
2013-04-02 16:21 - 2011-08-05 12:39 - 00000000 ____D C:\Sandeep
2013-04-02 07:31 - 2011-06-15 12:25 - 00000000 ____D C:\Users\Sanchit\Application Data\Mozilla
2013-04-02 07:31 - 2011-06-15 12:25 - 00000000 ____D C:\Users\Sanchit\AppData\Roaming\Mozilla
2013-03-31 08:32 - 2011-11-06 11:34 - 00002384 ____A C:\Users\Sanchit\Desktop\Google Chrome.lnk
2013-03-31 03:33 - 2013-03-31 03:33 - 00000000 ____D C:\Users\Sanchit\Local Settings\Application Data\{56247787-5527-4C84-AFF1-526BFB67A65B}
2013-03-31 03:33 - 2013-03-31 03:33 - 00000000 ____D C:\Users\Sanchit\Local Settings\{56247787-5527-4C84-AFF1-526BFB67A65B}
2013-03-31 03:33 - 2013-03-31 03:33 - 00000000 ____D C:\Users\Sanchit\AppData\Local\{56247787-5527-4C84-AFF1-526BFB67A65B}
2013-03-30 08:57 - 2013-03-30 08:57 - 00000000 ____D C:\Users\Sanchit\Local Settings\Application Data\{FD858EF5-6B23-403E-A310-157FA49C236D}
2013-03-30 08:57 - 2013-03-30 08:57 - 00000000 ____D C:\Users\Sanchit\Local Settings\{FD858EF5-6B23-403E-A310-157FA49C236D}
2013-03-30 08:57 - 2013-03-30 08:57 - 00000000 ____D C:\Users\Sanchit\AppData\Local\{FD858EF5-6B23-403E-A310-157FA49C236D}
2013-03-29 19:10 - 2013-03-29 04:47 - 00000000 ____D C:\Users\Sanchit\.android
2013-03-29 18:14 - 2011-11-16 18:20 - 00000000 ____D C:\Users\Sanchit\workspace
2013-03-28 18:07 - 2012-08-24 16:23 - 00000000 ____D C:\Users\Sanchit\My Documents\Software
2013-03-28 18:07 - 2012-08-24 16:23 - 00000000 ____D C:\Users\Sanchit\Documents\Software
2013-03-28 10:25 - 2011-10-26 16:00 - 00000000 ____D C:\Users\Sanchit\Local Settings\Windows Live
2013-03-28 10:25 - 2011-10-26 16:00 - 00000000 ____D C:\Users\Sanchit\Local Settings\Application Data\Windows Live
2013-03-28 10:25 - 2011-10-26 16:00 - 00000000 ____D C:\Users\Sanchit\AppData\Local\Windows Live
2013-03-26 15:24 - 2013-03-26 15:24 - 00000000 ____D C:\Users\Public\Juniper Networks
2013-03-26 15:24 - 2011-11-20 07:22 - 00000000 ____D C:\Program Files (x86)\Juniper Networks
2013-03-26 15:24 - 2011-11-20 07:21 - 00000000 ____D C:\Users\Sanchit\Application Data\Juniper Networks
2013-03-26 15:24 - 2011-11-20 07:21 - 00000000 ____D C:\Users\Sanchit\AppData\Roaming\Juniper Networks
2013-03-26 14:29 - 2013-03-26 14:29 - 00262144 ____A C:\Windows\Minidump\032613-30997-01.dmp
2013-03-26 14:29 - 2013-03-19 11:41 - 572101397 ____A C:\Windows\MEMORY.DMP
2013-03-26 14:29 - 2011-09-14 19:41 - 00000000 ____D C:\Windows\Minidump
2013-03-26 14:25 - 2013-03-26 14:25 - 00200531 ____A C:\Users\Sanchit\Downloads\Sanchit (1).rar
2013-03-26 14:23 - 2013-03-26 14:23 - 00200531 ____A C:\Users\Sanchit\Downloads\Sanchit.rar
2013-03-26 12:11 - 2013-03-26 14:25 - 00205247 ____A C:\Users\Sanchit\Downloads\Sanchit.apk
2013-03-25 18:09 - 2013-03-25 18:09 - 00000018 ____A C:\pending.un
2013-03-22 17:27 - 2013-03-22 17:27 - 01633280 ____A C:\Users\Sanchit\Downloads\NGIN SNEC40 Multidomain ATP for TDE(For TMS import)V0.3.xls
2013-03-20 15:28 - 2013-03-20 15:28 - 00000096 ____A C:\Users\Sanchit\Downloads\Menu.txt
2013-03-20 06:08 - 2013-03-20 06:08 - 00000000 ____D C:\Users\Sanchit\Application Data\Google
2013-03-20 06:08 - 2013-03-20 06:08 - 00000000 ____D C:\Users\Sanchit\AppData\Roaming\Google
2013-03-20 06:08 - 2011-06-15 13:07 - 00000000 ____D C:\Users\Sanchit\Local Settings\Google
2013-03-20 06:08 - 2011-06-15 13:07 - 00000000 ____D C:\Users\Sanchit\Local Settings\Application Data\Google
2013-03-20 06:08 - 2011-06-15 13:07 - 00000000 ____D C:\Users\Sanchit\AppData\Local\Google
2013-03-19 17:59 - 2011-11-21 15:21 - 00000000 ____D C:\Users\Sanchit\Application Data\vlc
2013-03-19 17:59 - 2011-11-21 15:21 - 00000000 ____D C:\Users\Sanchit\AppData\Roaming\vlc
2013-03-19 11:42 - 2013-03-19 11:42 - 00262144 ____A C:\Windows\Minidump\031913-30123-01.dmp
2013-03-18 17:07 - 2013-03-18 17:07 - 08151705 ____A C:\Users\Sanchit\Downloads\com.goldron.bbfree-1.0.apk
ZeroAccess:
C:\$Recycle.Bin\S-1-5-18\$3b99f81f31d5dbab1bcf87d0107a285a
C:\$Recycle.Bin\S-1-5-18\$3b99f81f31d5dbab1bcf87d0107a285a\@
C:\$Recycle.Bin\S-1-5-18\$3b99f81f31d5dbab1bcf87d0107a285a\L
C:\$Recycle.Bin\S-1-5-18\$3b99f81f31d5dbab1bcf87d0107a285a\U
ZeroAccess:
C:\$Recycle.Bin\S-1-5-21-2092152589-3654524724-1465183675-1000\$3b99f81f31d5dbab1bcf87d0107a285a
C:\$Recycle.Bin\S-1-5-21-2092152589-3654524724-1465183675-1000\$3b99f81f31d5dbab1bcf87d0107a285a\@
C:\$Recycle.Bin\S-1-5-21-2092152589-3654524724-1465183675-1000\$3b99f81f31d5dbab1bcf87d0107a285a\L
C:\$Recycle.Bin\S-1-5-21-2092152589-3654524724-1465183675-1000\$3b99f81f31d5dbab1bcf87d0107a285a\U
ZeroAccess:
C:\$Recycle.Bin\S-1-5-18\$3b99f81f31d5dbab1bcf87d0107a285a
==================== Known DLLs (Whitelisted) =================
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
==================== Memory info ===========================
Percentage of memory in use: 18%
Total physical RAM: 4003.18 MB
Available physical RAM: 3276.63 MB
Total Pagefile: 4001.38 MB
Available Pagefile: 3267.28 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
==================== Partitions =============================
1 Drive c: (OS) (Fixed) (Total:451.01 GB) (Free:44.94 GB) NTFS
3 Drive e: (Recovery) (Fixed) (Total:14.65 GB) (Free:7.44 GB) NTFS ==>[System with boot components (obtained from reading drive)]
5 Drive g: () (Removable) (Total:29.8 GB) (Free:12.95 GB) FAT32
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 465 GB 0 B
Disk 1 No Media 0 B 0 B
Disk 2 Online 29 GB 0 B
Partitions of Disk 0:
===============
Disk ID: 825589A0
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 100 MB 1024 KB
Partition 2 Primary 14 GB 101 MB
Partition 3 Primary 451 GB 14 GB
==================================================================================
Disk: 0
Partition 1
Type : DE
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 DELLUTILITY FAT Partition 100 MB Healthy Hidden
=========================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 E Recovery NTFS Partition 14 GB Healthy
=========================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C OS NTFS Partition 451 GB Healthy
=========================================================
Partitions of Disk 2:
===============
Disk ID: 00000000
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 29 GB 16 KB
==================================================================================
Disk: 2
Partition 1
Type : 0C
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G FAT32 Removable 29 GB Healthy
=========================================================
============================== MBR Partition Table ==================
==============================
Partitions of Disk 0:
===============
Disk ID: 825589A0
Partition 1:
=========
Hex: 00202100DEDF130C0008000000200300
Active: NO
Type: DE
Size: 100 MB
Partition 2:
=========
Hex: 80DF140C07FEFFFF0028030000C0D401
Active: YES
Type: 07 (NTFS)
Size: 15 GB
Partition 3:
=========
Hex: 00FEFFFF07FEFFFF00E8D70130706038
Active: NO
Type: 07 (NTFS)
Size: 451 GB
==============================
Partitions of Disk 2:
===============
Disk ID: 00000000
Partition 1:
=========
Hex: 000021000CFEFFFF200000002024BA03
Active: NO
Type: 0C
Size: 30 GB
Last Boot: 2013-04-04 01:46
==================== End Of Log =============================