Błąd rejestru sysmenu.dll


(Michal1498) #1

Witam od jakiegoś czasu wyskakuję mi taki błąd  0qK2P5j.png

Nie mam pojęcia jak z nim sobie poradzić. Z reguły wyskakują 2 okienka pod rząd i za chwilę następne 2. Proszę o pomoc :slight_smile:


(Acorus) #2

http://forum.dobreprogramy.pl/farbar-recovery-scan-tool-raport-obowiązkowy-t478727/


(Michal1498) #3

http://www.wklej.org/id/1719843/ - FRST

 

http://www.wklej.org/id/1719844/ - Addition

 

http://wklej.org/id/1719846/  - Shortcut


(Acorus) #4

Odinstaluj Akamai NetSession Interface,Update for PriceFountain.Otwórz notatnik systemowy i wklej:

Task: {22759920-9C99-4CBA-AAE1-CCC32CFAC926} - System32\Tasks\Microsoft\Windows\Maintenance\SMupdate2 = Rundll32.exe C:\PROGRA~1\COMMON~1\System\SysMenu.dll ,Command701 update2 ==== ATTENTION
Task: {C881BC03-9D31-4F7E-A81B-D24864CE042E} - System32\Tasks\Microsoft\Windows\Multimedia\SMupdate3 = Rundll32.exe C:\PROGRA~1\COMMON~1\System\SysMenu.dll ,Command701 update3 ==== ATTENTION
AlternateDataStreams: C:\ProgramData:NT
AlternateDataStreams: C:\ProgramData:NT2
AlternateDataStreams: C:\Users\All Users:NT
AlternateDataStreams: C:\Users\All Users:NT2
AlternateDataStreams: C:\ProgramData\Application Data:NT
AlternateDataStreams: C:\ProgramData\Application Data:NT2
AlternateDataStreams: C:\ProgramData\Dane aplikacji:NT
AlternateDataStreams: C:\ProgramData\Dane aplikacji:NT2
AlternateDataStreams: C:\ProgramData\MTA San Andreas All:NT
AlternateDataStreams: C:\ProgramData\MTA San Andreas All:NT2
AlternateDataStreams: C:\Users\Tomek\Dane aplikacji:NT
AlternateDataStreams: C:\Users\Tomek\Dane aplikacji:NT2
AlternateDataStreams: C:\Users\Tomek\AppData\Roaming:NT
AlternateDataStreams: C:\Users\Tomek\AppData\Roaming:NT2
GroupPolicy: Group Policy on Chrome detected ======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction ======= ATTENTION
HKU\S-1-5-21-2180720950-3201666908-3798353860-1000\Software\Microsoft\Internet Explorer\Main,Start Page = https://mysearch.avg.com/?cid={C8A721BD-7414-4EFF-820E-EFC36A757512}mid=5367f0bec0e747cdbfe5d15dc3d51423-764aa49ea078fe42d31d046b3051eb1801a03ea2lang=plds=AVGcoid=avgtbavgcmpid=0215piipr=frd=2015-03-20 10:06:12v=4.1.0.411pid=wtusg=sap=hp
SearchScopes: HKU\.DEFAULT - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2180720950-3201666908-3798353860-1000 - {szukaj.gazeta.pl} URL = http://szukaj.gazeta.pl/internet/0,0.html?slowo={searchTerms}
Toolbar: HKU\S-1-5-21-2180720950-3201666908-3798353860-1000 - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
FF Plugin HKU\S-1-5-21-2180720950-3201666908-3798353860-1000: @hola.org/vlc,version=1.6.344 - C:\Users\Tomek\AppData\Local\Hola\firefox\app\vlc No File
FF Extension: 338e0b9622854424b4c8e25560750fa3 - C:\Users\Tomek\AppData\Roaming\Mozilla\Firefox\Profiles\tfnfyrd4.default\Extensions\{338e0b96-2285-4424-b4c8-e25560750fa3} [2014-12-29]
FF Extension: Quiknowledge - C:\Program Files (x86)\Mozilla Firefox\extensions\quiknowledge@quiknowledge.com [2014-05-29]
FF Extension: Click Caption - C:\Program Files (x86)\Mozilla Firefox\extensions\{190bc294-c8e5-471c-9466-3eb945b09542} [2014-11-27]
FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [not found]
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\browser\defaults\preferences\!vitruvian-csp.js [2014-11-27]
S3 EagleX64; \\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 xhunter1; \\C:\Windows\xhunter1.sys [X]
2014-12-16 22:19 - 2014-12-16 22:19 - 2031584 _____ (Object Browser) C:\Users\Tomek\AppData\Roaming\ALWSRFOJ.exe
2014-12-17 11:08 - 2014-12-17 11:08 - 2031584 _____ (Cinema HDV15.12) C:\Users\Tomek\AppData\Roaming\BVFD.exe
2014-12-16 22:22 - 2014-12-16 22:22 - 1545696 _____ (Object Browser) C:\Users\Tomek\AppData\Roaming\TF.exe
2014-12-17 11:10 - 2014-12-17 11:10 - 1545696 _____ (Cinema HDV15.12) C:\Users\Tomek\AppData\Roaming\XLBRHIF.exe
C:\ProgramData\pclunst.exe
EmptyTemp:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.

Odinstaluj Chrome zaznaczając usunięcie danych przeglądania.


(Michal1498) #5

Dziękuje serdecznie :slight_smile:


(Acorus) #6

Skasuj folder C:\FRST.