Firefox -> BSOD
Napsal: 19 kvě 2012 12:51
Zdravím,
prohlížet web lze jen z nouzového režimu s prácí v síti. V tomto režimu nelze ani spustit Firefox (chyba "0xc0000005)". V běžném režimu se nenačte jakýkoliv prohlížeč (Chrome selže, Firefox hodí BSOD, Explorer se nenačítá...) Téměř jistě tu bude nějaká havěť, protože to není poprvé, co tento pc odvirovávám. Avast nemá ani spuštěné štíty (nelze opravit).
Děkuji za odpověď.
Logfile of random's system information tool 1.09 (written by random/random)
Run by Kohoutovi at 2012-05-19 13:39:27
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 353 GB (74%) free of 477 GB
Total RAM: 3583 MB (83% free)
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\Explorer.EXE
ctfmon.exe
C:\PROGRA~2\INTERN~1\iexplore.exe
"C:\PROGRA~2\INTERN~1\iexplore.exe" SCODEF:1724 CREDAT:145409
"C:\PROGRA~2\INTERN~1\iexplore.exe" SCODEF:1724 CREDAT:79893
"C:\PROGRA~2\INTERN~1\iexplore.exe" SCODEF:1724 CREDAT:145410
C:\Windows\system32\wbem\wmiprvse.exe
"C:\PROGRA~2\INTERN~1\iexplore.exe" SCODEF:1724 CREDAT:145413
C:\Users\KOHOUT~1\DOWNLO~1\RSITx64.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\PROGRA~1\TRENDM~1\KOHOUT~1.EXE /silentautolog
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Kohoutovi\AppData\Roaming\Mozilla\Firefox\Profiles\zeihg06l.default
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.2.202.235 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.2.202.235 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_2_202_235.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
C:\Program Files (x86)\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
C:\Users\Kohoutovi\AppData\Roaming\Mozilla\Firefox\Profiles\zeihg06l.default\extensions\
battlefieldplay4free@ea.com
toolbar@ask.com
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-04-04 63912]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Nero Toolbar - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll [2010-12-20 1244040]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-04-01 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Nero Toolbar - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll [2010-12-20 1244040]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"MRT"=C:\Windows\system32\MRT.exe [2012-05-11 57848688]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"EA Core"=C:\Program Files (x86)\Electronic Arts\EADM\Core.exe [2012-05-19 2897408]
""= []
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-11-28 3744552]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-05-19 968128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.exe - open - C:\Windows\svchost.com "%1" %*
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2012-05-19 13:39:27 ----D---- C:\rsit
2012-05-19 13:39:27 ----D---- C:\Program Files\trend micro
2012-05-16 06:37:37 ----A---- C:\Windows\SYSWOW64\FlashPlayerInstaller.exe
2012-05-16 06:31:57 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2012-05-15 18:24:00 ----D---- C:\Users\Kohoutovi\AppData\Roaming\Nokia
2012-05-13 14:26:47 ----A---- C:\Windows\ntbtlog.txt
2012-05-13 14:20:55 ----D---- C:\Windows\Minidump
2012-05-11 17:51:06 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2012-05-11 17:51:06 ----A---- C:\Windows\system32\DWrite.dll
2012-05-11 17:50:59 ----A---- C:\Windows\system32\ntoskrnl.exe
2012-05-11 17:50:58 ----A---- C:\Windows\system32\win32k.sys
2012-05-11 17:50:57 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2012-05-11 17:50:57 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2012-05-11 17:50:11 ----A---- C:\Windows\system32\drivers\partmgr.sys
2012-05-11 17:49:46 ----A---- C:\Windows\system32\drivers\tcpip.sys
2012-05-10 14:32:08 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2012-05-10 14:32:08 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2012-05-10 14:32:08 ----A---- C:\Windows\system32\d3dx10_40.dll
2012-05-10 14:32:08 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2012-05-10 14:32:07 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2012-05-10 14:32:07 ----A---- C:\Windows\system32\D3DX9_40.dll
2012-05-10 14:26:35 ----D---- C:\Program Files (x86)\1C Company
2012-05-07 20:37:03 ----D---- C:\Users\Kohoutovi\AppData\Roaming\Need for Speed World
2012-05-06 18:56:47 ----A---- C:\Windows\directx.sys
2012-05-06 18:56:14 ----A---- C:\Windows\svchost.com
2012-05-05 20:38:03 ----D---- C:\Program Files (x86)\G5 Software
2012-05-05 19:54:59 ----D---- C:\Users\Kohoutovi\AppData\Roaming\.minecraft
2012-04-21 22:03:18 ----D---- C:\Program Files (x86)\GIANTS Software
2012-04-21 19:10:41 ----D---- C:\Program Files (x86)\Glest_2.0.0
2012-04-20 19:51:38 ----D---- C:\Program Files (x86)\Hunting Unlimited 3
======List of files/folders modified in the last 1 month======
2012-05-19 13:39:27 ----RD---- C:\Program Files
2012-05-19 13:30:49 ----D---- C:\Windows\System32
2012-05-19 13:30:49 ----D---- C:\Windows\inf
2012-05-19 13:30:49 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-05-19 13:24:13 ----D---- C:\Windows\Prefetch
2012-05-19 13:23:44 ----D---- C:\Windows\system32\config
2012-05-19 13:22:54 ----D---- C:\Windows\Temp
2012-05-19 13:20:39 ----D---- C:\Windows
2012-05-18 21:44:27 ----SHD---- C:\System Volume Information
2012-05-18 21:44:04 ----SHD---- C:\Windows\Installer
2012-05-16 06:37:37 ----D---- C:\Windows\SysWOW64
2012-05-16 06:31:58 ----D---- C:\Windows\Tasks
2012-05-16 06:31:58 ----D---- C:\Windows\system32\Tasks
2012-05-15 20:48:41 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2012-05-15 18:22:47 ----D---- C:\Windows\system32\drivers
2012-05-15 18:16:01 ----D---- C:\ProgramData\Nokia
2012-05-15 18:16:01 ----D---- C:\Program Files (x86)\Nokia
2012-05-15 18:15:12 ----D---- C:\Program Files (x86)\PC Connectivity Solution
2012-05-15 18:15:03 ----D---- C:\Windows\system32\DriverStore
2012-05-15 18:15:03 ----D---- C:\Windows\system32\catroot
2012-05-13 14:40:40 ----D---- C:\Windows\system32\catroot2
2012-05-12 23:08:33 ----A---- C:\Windows\SYSWOW64\PnkBstrA.exe
2012-05-12 21:52:58 ----D---- C:\Program Files (x86)\Army Rage
2012-05-12 16:06:35 ----D---- C:\Program Files (x86)\Mozilla Firefox
2012-05-11 23:30:14 ----D---- C:\Windows\Microsoft.NET
2012-05-11 23:30:13 ----RSD---- C:\Windows\assembly
2012-05-11 21:17:18 ----D---- C:\Windows\winsxs
2012-05-11 18:06:40 ----A---- C:\Windows\system32\MRT.INI
2012-05-11 18:01:32 ----A---- C:\Windows\system32\MRT.exe
2012-05-10 17:55:55 ----D---- C:\Program Files (x86)\EA Games
2012-05-10 14:26:35 ----RD---- C:\Program Files (x86)
2012-05-06 18:56:15 ----A---- C:\install.exe
2012-05-05 23:47:44 ----SD---- C:\Users\Kohoutovi\AppData\Roaming\Microsoft
2012-05-05 22:22:59 ----D---- C:\ProgramData\Electronic Arts
2012-05-05 22:22:59 ----D---- C:\Program Files (x86)\Electronic Arts
2012-05-05 22:19:23 ----HD---- C:\ProgramData
2012-05-05 20:45:45 ----D---- C:\Program Files (x86)\Activision
2012-04-21 20:58:36 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2012-04-20 21:30:22 ----D---- C:\Program Files (x86)\GameSpy Arcade
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2009-05-05 16440]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2011-11-28 42328]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C62x64.sys [2009-11-27 67072]
R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys [2009-12-22 38456]
S1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2011-11-28 591192]
S1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2011-11-28 304472]
S1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2011-11-28 58712]
S2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2011-11-28 24408]
S2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2011-11-28 66904]
S2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2011-12-24 314016]
S2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2011-12-24 43680]
S3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atipmdag.sys [2010-02-10 6368256]
S3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2010-02-10 188416]
S3 EagleX64;EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys []
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmbx64.sys [2011-11-01 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\Windows\system32\drivers\ccdcmbox64.sys [2011-11-01 27136]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys [2008-08-28 25600]
S3 RTHDMIAzAudService;Service for HDMI; C:\Windows\system32\drivers\RtHDMIVX.sys [2009-04-14 208672]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys [2011-11-01 9216]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2010-11-20 32768]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltjx64.sys [2011-11-01 9216]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service; C:\Windows\system32\drivers\viahduaa.sys [2010-10-02 1349232]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
S2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2010-02-10 202752]
S2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-11-28 44768]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-05-13 177648]
S2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2012-05-12 76888]
S2 PowerManager;Power Manager; C:\Windows\svchost.exe [2001-08-24 36352]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-16 257696]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-05-13 177648]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2012-05-06 111104]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2012-05-06 130608]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2012-05-17 801832]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-04-02 1255736]
-----------------EOF-----------------
prohlížet web lze jen z nouzového režimu s prácí v síti. V tomto režimu nelze ani spustit Firefox (chyba "0xc0000005)". V běžném režimu se nenačte jakýkoliv prohlížeč (Chrome selže, Firefox hodí BSOD, Explorer se nenačítá...) Téměř jistě tu bude nějaká havěť, protože to není poprvé, co tento pc odvirovávám. Avast nemá ani spuštěné štíty (nelze opravit).
Děkuji za odpověď.
Logfile of random's system information tool 1.09 (written by random/random)
Run by Kohoutovi at 2012-05-19 13:39:27
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 353 GB (74%) free of 477 GB
Total RAM: 3583 MB (83% free)
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\Explorer.EXE
ctfmon.exe
C:\PROGRA~2\INTERN~1\iexplore.exe
"C:\PROGRA~2\INTERN~1\iexplore.exe" SCODEF:1724 CREDAT:145409
"C:\PROGRA~2\INTERN~1\iexplore.exe" SCODEF:1724 CREDAT:79893
"C:\PROGRA~2\INTERN~1\iexplore.exe" SCODEF:1724 CREDAT:145410
C:\Windows\system32\wbem\wmiprvse.exe
"C:\PROGRA~2\INTERN~1\iexplore.exe" SCODEF:1724 CREDAT:145413
C:\Users\KOHOUT~1\DOWNLO~1\RSITx64.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\PROGRA~1\TRENDM~1\KOHOUT~1.EXE /silentautolog
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Kohoutovi\AppData\Roaming\Mozilla\Firefox\Profiles\zeihg06l.default
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.2.202.235 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.2.202.235 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_2_202_235.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
C:\Program Files (x86)\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
C:\Users\Kohoutovi\AppData\Roaming\Mozilla\Firefox\Profiles\zeihg06l.default\extensions\
battlefieldplay4free@ea.com
toolbar@ask.com
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-04-04 63912]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Nero Toolbar - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll [2010-12-20 1244040]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-04-01 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Nero Toolbar - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll [2010-12-20 1244040]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"MRT"=C:\Windows\system32\MRT.exe [2012-05-11 57848688]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"EA Core"=C:\Program Files (x86)\Electronic Arts\EADM\Core.exe [2012-05-19 2897408]
""= []
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-11-28 3744552]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-05-19 968128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.exe - open - C:\Windows\svchost.com "%1" %*
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2012-05-19 13:39:27 ----D---- C:\rsit
2012-05-19 13:39:27 ----D---- C:\Program Files\trend micro
2012-05-16 06:37:37 ----A---- C:\Windows\SYSWOW64\FlashPlayerInstaller.exe
2012-05-16 06:31:57 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2012-05-15 18:24:00 ----D---- C:\Users\Kohoutovi\AppData\Roaming\Nokia
2012-05-13 14:26:47 ----A---- C:\Windows\ntbtlog.txt
2012-05-13 14:20:55 ----D---- C:\Windows\Minidump
2012-05-11 17:51:06 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2012-05-11 17:51:06 ----A---- C:\Windows\system32\DWrite.dll
2012-05-11 17:50:59 ----A---- C:\Windows\system32\ntoskrnl.exe
2012-05-11 17:50:58 ----A---- C:\Windows\system32\win32k.sys
2012-05-11 17:50:57 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2012-05-11 17:50:57 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2012-05-11 17:50:11 ----A---- C:\Windows\system32\drivers\partmgr.sys
2012-05-11 17:49:46 ----A---- C:\Windows\system32\drivers\tcpip.sys
2012-05-10 14:32:08 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2012-05-10 14:32:08 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2012-05-10 14:32:08 ----A---- C:\Windows\system32\d3dx10_40.dll
2012-05-10 14:32:08 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2012-05-10 14:32:07 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2012-05-10 14:32:07 ----A---- C:\Windows\system32\D3DX9_40.dll
2012-05-10 14:26:35 ----D---- C:\Program Files (x86)\1C Company
2012-05-07 20:37:03 ----D---- C:\Users\Kohoutovi\AppData\Roaming\Need for Speed World
2012-05-06 18:56:47 ----A---- C:\Windows\directx.sys
2012-05-06 18:56:14 ----A---- C:\Windows\svchost.com
2012-05-05 20:38:03 ----D---- C:\Program Files (x86)\G5 Software
2012-05-05 19:54:59 ----D---- C:\Users\Kohoutovi\AppData\Roaming\.minecraft
2012-04-21 22:03:18 ----D---- C:\Program Files (x86)\GIANTS Software
2012-04-21 19:10:41 ----D---- C:\Program Files (x86)\Glest_2.0.0
2012-04-20 19:51:38 ----D---- C:\Program Files (x86)\Hunting Unlimited 3
======List of files/folders modified in the last 1 month======
2012-05-19 13:39:27 ----RD---- C:\Program Files
2012-05-19 13:30:49 ----D---- C:\Windows\System32
2012-05-19 13:30:49 ----D---- C:\Windows\inf
2012-05-19 13:30:49 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-05-19 13:24:13 ----D---- C:\Windows\Prefetch
2012-05-19 13:23:44 ----D---- C:\Windows\system32\config
2012-05-19 13:22:54 ----D---- C:\Windows\Temp
2012-05-19 13:20:39 ----D---- C:\Windows
2012-05-18 21:44:27 ----SHD---- C:\System Volume Information
2012-05-18 21:44:04 ----SHD---- C:\Windows\Installer
2012-05-16 06:37:37 ----D---- C:\Windows\SysWOW64
2012-05-16 06:31:58 ----D---- C:\Windows\Tasks
2012-05-16 06:31:58 ----D---- C:\Windows\system32\Tasks
2012-05-15 20:48:41 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2012-05-15 18:22:47 ----D---- C:\Windows\system32\drivers
2012-05-15 18:16:01 ----D---- C:\ProgramData\Nokia
2012-05-15 18:16:01 ----D---- C:\Program Files (x86)\Nokia
2012-05-15 18:15:12 ----D---- C:\Program Files (x86)\PC Connectivity Solution
2012-05-15 18:15:03 ----D---- C:\Windows\system32\DriverStore
2012-05-15 18:15:03 ----D---- C:\Windows\system32\catroot
2012-05-13 14:40:40 ----D---- C:\Windows\system32\catroot2
2012-05-12 23:08:33 ----A---- C:\Windows\SYSWOW64\PnkBstrA.exe
2012-05-12 21:52:58 ----D---- C:\Program Files (x86)\Army Rage
2012-05-12 16:06:35 ----D---- C:\Program Files (x86)\Mozilla Firefox
2012-05-11 23:30:14 ----D---- C:\Windows\Microsoft.NET
2012-05-11 23:30:13 ----RSD---- C:\Windows\assembly
2012-05-11 21:17:18 ----D---- C:\Windows\winsxs
2012-05-11 18:06:40 ----A---- C:\Windows\system32\MRT.INI
2012-05-11 18:01:32 ----A---- C:\Windows\system32\MRT.exe
2012-05-10 17:55:55 ----D---- C:\Program Files (x86)\EA Games
2012-05-10 14:26:35 ----RD---- C:\Program Files (x86)
2012-05-06 18:56:15 ----A---- C:\install.exe
2012-05-05 23:47:44 ----SD---- C:\Users\Kohoutovi\AppData\Roaming\Microsoft
2012-05-05 22:22:59 ----D---- C:\ProgramData\Electronic Arts
2012-05-05 22:22:59 ----D---- C:\Program Files (x86)\Electronic Arts
2012-05-05 22:19:23 ----HD---- C:\ProgramData
2012-05-05 20:45:45 ----D---- C:\Program Files (x86)\Activision
2012-04-21 20:58:36 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2012-04-20 21:30:22 ----D---- C:\Program Files (x86)\GameSpy Arcade
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2009-05-05 16440]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2011-11-28 42328]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C62x64.sys [2009-11-27 67072]
R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys [2009-12-22 38456]
S1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2011-11-28 591192]
S1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2011-11-28 304472]
S1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2011-11-28 58712]
S2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2011-11-28 24408]
S2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2011-11-28 66904]
S2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2011-12-24 314016]
S2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2011-12-24 43680]
S3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atipmdag.sys [2010-02-10 6368256]
S3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2010-02-10 188416]
S3 EagleX64;EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys []
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmbx64.sys [2011-11-01 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\Windows\system32\drivers\ccdcmbox64.sys [2011-11-01 27136]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys [2008-08-28 25600]
S3 RTHDMIAzAudService;Service for HDMI; C:\Windows\system32\drivers\RtHDMIVX.sys [2009-04-14 208672]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys [2011-11-01 9216]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2010-11-20 32768]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltjx64.sys [2011-11-01 9216]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service; C:\Windows\system32\drivers\viahduaa.sys [2010-10-02 1349232]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
S2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2010-02-10 202752]
S2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-11-28 44768]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-05-13 177648]
S2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2012-05-12 76888]
S2 PowerManager;Power Manager; C:\Windows\svchost.exe [2001-08-24 36352]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-16 257696]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-05-13 177648]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2012-05-06 111104]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2012-05-06 130608]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2012-05-17 801832]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-04-02 1255736]
-----------------EOF-----------------