Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 20-12-2013 02 Ran by mato at 2013-12-22 11:50:33 Run:1 Running from C:\Users\mato\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** (Cherished Technololgy LIMITED) C:\ProgramData\WPM\wprotectmanager.exe (Microsoft Corporation) C:\Windows\System32\schtasks.exe () C:\Windows\Temp\svchost.exe (Electronic Arts) C:\Program Files (x86)\Origin\Origin.exe (Electronic Arts) C:\Program Files (x86)\Origin\OriginClientService.exe Task: {55C1F2C0-4434-40ED-804D-DD1FDF54A945} - System32\Tasks\Origin => C:\Users\mato\AppData\Roaming\Origin\update.vbe [2013-12-05] () R2 Wpm; C:\ProgramData\WPM\wprotectmanager.exe [499856 2013-12-05] (Cherished Technololgy LIMITED) S3 FairplayKD; \??\C:\ProgramData\MTA San Andreas All\Common\temp\FairplayKD.sys [x] HKLM\...\Run: [Windows Defender] - [x] HKCU\...\Run: [Audio HD Driver] - C:\Users\mato\AppData\Local\Temp\HDAudio.exe HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.aartemis.com/web/?type=ds&ts=1386272332&from=cor&uid=HitachiXHTS547550A9E384_J2170052GZE24DGZE24DX&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.aartemis.com/web/?type=ds&ts=1386272332&from=cor&uid=HitachiXHTS547550A9E384_J2170052GZE24DGZE24DX&q={searchTerms} FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll No File FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll No File FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll No File FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll No File CHR HKLM-x32\...\Chrome\Extension: [dnllcmllkjofnojidnaknldfehfhehoo] - C:\Program Files (x86)\HDvidCodec.com\HDvidCodec10.crx C:\Windows\Temp\*.dll C:\Windows\Temp\*.exe C:\Users\mato\AppData\Local\Temp\*.dll C:\Users\mato\AppData\Local\Temp\*.exe C:\Users\mato\AppData\Local\cache C:\Users\mato\AppData\Local\Mobogenie C:\Users\mato\AppData\Roaming\Origin\update.vbe C:\Users\mato\Documents\Mobogenie C:\Users\wangzhisong C:\Program Files (x86)\Mobogenie Folder: C:\Users\mato\AppData\Roaming\Origin ***************** [1324] C:\ProgramData\WPM\wprotectmanager.exe => Process closed successfully. [3852] C:\Windows\System32\schtasks.exe => Process closed successfully. [3996] C:\Windows\Temp\svchost.exe => Process closed successfully. [2496] C:\Program Files (x86)\Origin\Origin.exe => Process closed successfully. C:\Program Files (x86)\Origin\OriginClientService.exe => No running process found HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{55C1F2C0-4434-40ED-804D-DD1FDF54A945} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{55C1F2C0-4434-40ED-804D-DD1FDF54A945} => Key deleted successfully. C:\Windows\System32\Tasks\Origin => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Origin => Key deleted successfully. Wpm => Service deleted successfully. FairplayKD => Service deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Windows Defender => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Audio HD Driver => Value deleted successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.45.2 => Key deleted successfully. C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll not found. HKLM\Software\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2 => Key deleted successfully. C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll not found. HKLM\Software\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision => Key deleted successfully. C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll not found. HKLM\Software\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming => Key deleted successfully. C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll not found. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\dnllcmllkjofnojidnaknldfehfhehoo => Unable to delete key "C:\Program Files (x86)\HDvidCodec.com\HDvidCodec10.crx" => File/Directory not found. C:\Windows\Temp\*.dll => Moved successfully. C:\Windows\Temp\*.exe => Moved successfully. C:\Users\mato\AppData\Local\Temp\*.dll => Moved successfully. C:\Users\mato\AppData\Local\Temp\*.exe => Moved successfully. C:\Users\mato\AppData\Local\cache => Moved successfully. C:\Users\mato\AppData\Local\Mobogenie => Moved successfully. C:\Users\mato\AppData\Roaming\Origin\update.vbe => Moved successfully. C:\Users\mato\Documents\Mobogenie => Moved successfully. C:\Users\wangzhisong => Moved successfully. C:\Program Files (x86)\Mobogenie => Moved successfully. ========================= Folder: C:\Users\mato\AppData\Roaming\Origin ======================== 2013-12-05 21:57 - 2013-12-21 22:12 - 0000000 ____D () C:\Users\mato\AppData\Roaming\Origin\Cloud Saves 2013-12-05 21:59 - 2013-12-20 17:12 - 0000000 ____D () C:\Users\mato\AppData\Roaming\Origin\CommonTitles 2013-12-05 21:57 - 2013-12-22 11:22 - 0000000 ____D () C:\Users\mato\AppData\Roaming\Origin\Web Storage 2013-12-05 21:57 - 2013-12-05 21:57 - 0000000 ____D () C:\Users\mato\AppData\Roaming\Origin\Widget Updates 2013-12-05 21:57 - 2013-12-21 18:53 - 0000628 _____ () C:\Users\mato\AppData\Roaming\Origin\local.xml 2013-12-05 21:59 - 2013-12-06 17:20 - 0000807 _____ () C:\Users\mato\AppData\Roaming\Origin\local_47d154a075aead7dd50150096dd60ae5.xml 2013-12-20 17:12 - 2013-12-21 18:53 - 0001017 _____ () C:\Users\mato\AppData\Roaming\Origin\local_f6750ea7e44ccc68fbf81cfa8f7b87a5.xml 2013-12-05 21:57 - 2013-12-22 11:22 - 0542720 _____ () C:\Users\mato\AppData\Roaming\Origin\Web Storage\WebpageIcons.db 2013-12-20 17:12 - 2013-12-20 17:12 - 0000267 _____ () C:\Users\mato\AppData\Roaming\Origin\CommonTitles\d480f9e48da675f907353ddb96364371b52383db 2013-12-21 22:12 - 2013-12-21 22:12 - 0000082 _____ () C:\Users\mato\AppData\Roaming\Origin\Cloud Saves\3b0494e917d4e5cad1e6433fa8083c048e743f01.usage 2013-12-05 21:57 - 2013-12-05 21:57 - 0000481 _____ () C:\Users\mato\AppData\Roaming\Origin\Cloud Saves\blacklist ====== End of Folder: ====== ==== End of Fixlog ====