﻿Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 22-02-2015
Ran by Wojtek at 2015-02-22 22:45:42 Run:2
Running from C:\Users\Wojtek\Desktop
Loaded Profiles: Wojtek & UpdatusUser (Available profiles: Wojtek & UpdatusUser)
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
C:\ProgramData\398c0b96-ebd3-4f67-a5c7-1899a15c12be\maintainer.exe
C:\ProgramData\398c0b96-ebd3-4f67-a5c7-1899a15c12be
HKLM\...\Run: [mbot_pl_62] => [X]
Reg: reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f
HKLM\...\Run: [rec_pl_1] => C:\Program Files\rec_pl_1\rec_pl_1.exe [3977384 2014-12-16] ()
C:\Program Files\rec_pl_1
HKLM\...\Policies\Explorer\Run: [2047455250] => C:\ProgramData\msllwzo.exe [102468 2013-08-29] ( ( ))
C:\ProgramData\msllwzo.exe
HKLM\...\Policies\Explorer\Run: [2047455515] => C:\ProgramData\msrcgei.exe [418304 2013-08-29] ( (RonyaSoft))
C:\ProgramData\msrcgei.exe
HKU\S-1-5-21-1300774181-379790519-3807236815-1000\...\Policies\Explorer\Run: [2047455515] => C:\Users\Wojtek\AppData\Roaming\msrcgei.exe
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
CHR DefaultSearchKeyword: Default -> 04FD52EAE3AC9E4206D6B2F5A52CE9E7197B1490BDB9CE73E8FFDF683717C0C5
CHR DefaultSearchURL: Default -> 859FCF4BC12B7E259CF6A1FFFE74F341444C8C881FEC3889F76722C6487BE743
S3 ACPIVPC; system32\DRIVERS\AcpiVpc.sys [X]
C:\ProgramData\InstallMate
C:\Users\Wojtek\AppData\Local\nsb201F.tmp
C:\Users\Wojtek\AppData\Local\nsh5094.tmp
C:\Users\Wojtek\AppData\Local\nsn75FD.tmp
C:\Users\Wojtek\AppData\Local\nsrADED.tmp
EmptyTemp:
*****************

C:\ProgramData\398c0b96-ebd3-4f67-a5c7-1899a15c12be\maintainer.exe => Moved successfully.
C:\ProgramData\398c0b96-ebd3-4f67-a5c7-1899a15c12be => Moved successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\mbot_pl_62 => value deleted successfully.

========= reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f =========

Bť¤D: System nie znalaz w rejestrze okrelonego klucza albo wartoci.


========= End of Reg: =========


========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f =========

Bť¤D: System nie znalaz w rejestrze okrelonego klucza albo wartoci.


========= End of Reg: =========


========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f =========

Bť¤D: System nie znalaz w rejestrze okrelonego klucza albo wartoci.


========= End of Reg: =========


========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f =========

Bť¤D: System nie znalaz w rejestrze okrelonego klucza albo wartoci.


========= End of Reg: =========

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\rec_pl_1 => value deleted successfully.
C:\Program Files\rec_pl_1 => Moved successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\\2047455250 => Value not found.
C:\ProgramData\msllwzo.exe => Moved successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\\2047455515 => value deleted successfully.
C:\ProgramData\msrcgei.exe => Moved successfully.
HKU\S-1-5-21-1300774181-379790519-3807236815-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\\2047455515 => Value not found.
C:\Windows\system32\GroupPolicy\Machine => Moved successfully.
C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully.
"HKLM\SOFTWARE\Policies\Google" => Key deleted successfully.
Chrome DefaultSearchKeyword not detected.
Chrome DefaultSearchURL not detected.
ACPIVPC => Service deleted successfully.
C:\ProgramData\InstallMate => Moved successfully.
C:\Users\Wojtek\AppData\Local\nsb201F.tmp => Moved successfully.
C:\Users\Wojtek\AppData\Local\nsh5094.tmp => Moved successfully.
C:\Users\Wojtek\AppData\Local\nsn75FD.tmp => Moved successfully.
C:\Users\Wojtek\AppData\Local\nsrADED.tmp => Moved successfully.
EmptyTemp: => Removed 163.3 MB temporary data.


The system needed a reboot. 

==== End of Fixlog 22:45:48 ====