Stránka 1 z 1

prosím o pomoc - častý BSOD

Napsal: 11 črc 2012 09:39
od pepino
...prosím o radu . Co mám opravit a jak podle tohoto výpisu z dmp souboru. Nějak nejsem z toho chytrý. PC padá čím dál častěji. PROCES_NAME je pokaždé jiný. Buď explorer.exe , chrome.exe nebo firefox.exe. Chybu způsobuje win32k.sys, ale jak toopravit?

Podpis problému:
Název události problému: BlueScreen
Verze operačního systému: 6.1.7601.2.1.0.768.3
ID národního prostředí: 1029

Další informace o problému:
BCCode: 3b
BCP1: 00000000C0000005
BCP2: FFFFF960002364F9
BCP3: FFFFF8800BB5BA60
BCP4: 0000000000000000
OS Version: 6_1_7601
Service Pack: 1_0
Product: 768_1

Soubory, které popisují problém:
C:\Windows\Minidump\071112-16656-01.dmp
C:\Users\Pepino\AppData\Local\Temp\WER-61484-0.sysdata.xml

Přečtěte si prohlášení o zásadách ochrany osobních údajů online:
http://go.microsoft.com/fwlink/?linkid= ... cid=0x0405

Pokud není k dispozici Prohlášení o zásadách ochrany osobních údajů online, přečtěte si toto prohlášení offline:
C:\Windows\system32\cs-CZ\erofflps.txt

Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Windows\Minidump\071112-16656-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7601.17835.amd64fre.win7sp1_gdr.120503-2030
Machine Name:
Kernel base = 0xfffff800`02e51000 PsLoadedModuleList = 0xfffff800`03095670
Debug session time: Wed Jul 11 08:29:49.284 2012 (GMT+2)
System Uptime: 0 days 0:19:11.706
Loading Kernel Symbols
...............................................................
................................................................
.............................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 3B, {c0000005, fffff960002364f9, fffff8800bb5ba60, 0}

Probably caused by : win32k.sys ( win32k!GreSelectVisRgnInternal+39 )

Followup: MachineOwner
---------

3: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff960002364f9, Address of the exception record for the exception that caused the bugcheck
Arg3: fffff8800bb5ba60, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.

Debugging Details:
------------------


EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - Instrukce na adrese 0x%08lx odkazovala na adresu pam

FAULTING_IP:
win32k!GreSelectVisRgnInternal+39
fffff960`002364f9 e85a4efdff call win32k!GreAcquireSemaphore (fffff960`0020b358)

CONTEXT: fffff8800bb5ba60 -- (.cxr 0xfffff8800bb5ba60)
rax=fffff900c078a630 rbx=fffffa8006fa2ef0 rcx=fffffa8006fa2ef0
rdx=0000000079040f44 rsi=fffff8800bb5c4e0 rdi=0000000000000001
rip=fffff960002364f9 rsp=fffff8800bb5c440 rbp=0000000079040f44
r8=0000000000000001 r9=000000000000018c r10=fffff900000007c0
r11=fffff8800bb5c4b8 r12=00000000753db42c r13=00000000000dfd20
r14=00000000000dd310 r15=00000000753b2450
iopl=0 nv up ei ng nz na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00210286
win32k!GreSelectVisRgnInternal+0x39:
fffff960`002364f9 e85a4efdff call win32k!GreAcquireSemaphore (fffff960`0020b358)
Resetting default scope

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT

BUGCHECK_STR: 0x3B

PROCESS_NAME: firefox.exe

CURRENT_IRQL: 0

LAST_CONTROL_TRANSFER: from 0000000000000000 to fffff960002364f9

STACK_TEXT:
fffff880`0bb5c440 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : win32k!GreSelectVisRgnInternal+0x39


FOLLOWUP_IP:
win32k!GreSelectVisRgnInternal+39
fffff960`002364f9 e85a4efdff call win32k!GreAcquireSemaphore (fffff960`0020b358)

SYMBOL_STACK_INDEX: 0

SYMBOL_NAME: win32k!GreSelectVisRgnInternal+39

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: win32k

IMAGE_NAME: win32k.sys

DEBUG_FLR_IMAGE_TIMESTAMP: 4fd6b298

STACK_COMMAND: .cxr 0xfffff8800bb5ba60 ; kb

FAILURE_BUCKET_ID: X64_0x3B_win32k!GreSelectVisRgnInternal+39

BUCKET_ID: X64_0x3B_win32k!GreSelectVisRgnInternal+39

Followup: MachineOwner

Re: prosím o pomoc - častý BSOD

Napsal: 11 črc 2012 19:22
od Rudy
Problém může způsobovat jak hardware, tak systém. Začněte tím, že dejte log RSIT: http://www.viry.cz/forum/viewtopic.php?f=13&t=105895 .

Re: prosím o pomoc - častý BSOD

Napsal: 11 črc 2012 21:32
od pepino
zde je příslušný log:

Logfile of random's system information tool 1.09 (written by random/random)
Run by Pepino at 2012-07-11 22:30:16
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 59 GB (19%) free of 316 GB
Total RAM: 6142 MB (73% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:30:33, on 11.7.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16447)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\Pepino.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.vacovsky.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bigseekpro.com/picpick/{9D02 ... 5CFE6DB616}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [BCU] "C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe"
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKCU\..\Run: [Active Desktop Calendar] C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe
O4 - Startup: Spamihilator.lnk = C:\Program Files\Spamihilator\spamihilator.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Převést cíl vazby do Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Převést do Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Připojit cíl vazby k existujícímu PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Připojit k existujícímu PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Přizpůsobit Menu - file://C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: RF Nástrojová lišta - file://C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Uložit formuláře - file://C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Vyplnit formulář - file://C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{ACC0F182-9917-4E97-8049-E8998873233E}: NameServer = 192.168.0.251,192.168.178.51
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Browser Configuration Utility Service (BCUService) - DeviceVM, Inc. - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Game Mouse Communication And Update Service V1 (KmGameMouseServiceV1) - UASSOFT.COM - C:\Program Files (x86)\Trust\GXT14 Mouse\GameMouseServiceApp.exe
O23 - Service: KMService - Unknown owner - C:\Windows\system32\srvany.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: Protexis Licensing V2 x64 (PSI_SVC_2_x64) - arvato digital services llc - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TabletServicePen - Wacom Technology, Corp. - C:\Program Files\Tablet\Pen\Pen_Tablet.exe
O23 - Service: Wacom Consumer Touch Service (TouchServicePen) - Wacom Technology, Corp. - C:\Program Files\Tablet\Pen\Pen_TouchService.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.2.21\bin\httpd.exe
O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.5.20\bin\mysqld.exe
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9584 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
"C:\Program Files\Tablet\Pen\Pen_TouchService.exe"
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
/QuitInfo:00000000000001D0;0000000000000250; /AddRef;
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
/QuitInfo:0000000000000194;00000000000001A0; /AddRef;
"C:\Windows\system32\Dwm.exe"
"C:\Program Files\Tablet\Pen\Pen_TouchUser.exe"
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe"
"taskhost.exe"
"C:\Program Files (x86)\Bonjour\mDNSResponder.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe"
"C:\Program Files\Spamihilator\spamihilator.exe"
"C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe"
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe"
"c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe"
"C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files\Tablet\Pen\Pen_Tablet.exe"
"C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe"
"C:\Program Files\Tablet\Pen\Pen_TabletUser.exe"
"c:\wamp\bin\apache\apache2.2.21\bin\httpd.exe" -k runservice
"C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesApp64.exe" /TUStart /pid:2848
C:\wamp\bin\apache\apache2.2.21\bin\httpd.exe -d C:/wamp/bin/apache/Apache2.2.21
"C:\Program Files\Tablet\Pen\Pen_Tablet.exe" au
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -requestPending -osint -url "http://forum.viry.cz/viewtopic.php?f=13 ... &e=1127858"
"C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe"
C:\Windows\system32\sppsvc.exe
"C:\Users\Pepino\Desktop\RSITx64.exe"

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job

=========Mozilla firefox=========

ProfilePath - C:\Users\Pepino\AppData\Roaming\Mozilla\Firefox\Profiles\za8j87vf.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.vacovsky.com/"
prefs.js - "extensions.enabledItems" - "{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3, compatibility@addons.mozilla.org:0.8.1, {3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}:0.9.0.4, {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}:6.0.16, {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20, {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21, {DDC359D1-844A-42a7-9AA1-88A850A938A8}:2.0.2, {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23, {22119944-ED35-4ab1-910B-E619EA06A115}:7.1.8, {AB7308B2-C13C-4eba-AC78-2AD55B96EE09}:3.0.0, {a7c6cf7f-112c-4500-a7ea-39801a327e5f}:1.99.2, {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.16, Strata40@SpewBoy.au:0.6.2, {07b2a769-ed19-4483-87ce-c643914c81bb}:3.0.0.91"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.3.300.262 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_262.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0]
"Description"=DivX Plus Web Player
"Path"=C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0]
"Description"=DivX VOD Helper Plug-in
"Path"=C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_33]
"Description"=
"Path"=C:\Windows\SysWOW64\npdeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@wacom.com/wacom-plugin,version=1.1.0.10]
"Description"=WebTablet Plugin API
"Path"=C:\Program Files (x86)\TabletPlugins\npwacom.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@wacom.com/wacom-plugin,version=1.1.0.4]
"Description"=WebTablet Plugin API
"Path"=C:\Program Files (x86)\TabletPlugins\npwacom.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@wacom.com/wacom-plugin,version=1.1.0.5]
"Description"=WebTablet Plugin API
"Path"=C:\Program Files (x86)\TabletPlugins\npwacom.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@wacom.com/wtPlugin,version=2.0.0.1]
"Description"=WebTablet Plugin API
"Path"=C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Acrobat]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Air\nppdf32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.3.300.262 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_262.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0]
"Description"=DivX VOD Helper Plug-in
"Path"=C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL

C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nsIQTScriptablePlugin.xpt

C:\Program Files (x86)\Mozilla Firefox\plugins\
np-mswmp.dll
nppdf32.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
QuickTimePlugin.class
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt

C:\Program Files (x86)\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-12-21 689040]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2012-07-03 1387952]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-07-03 1160792]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Skytel"=C:\Program Files\Realtek\Audio\HDA\Skytel.exe [2009-06-25 1833504]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Active Desktop Calendar"=C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe [2010-12-15 8626688]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCU]
C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe [2009-08-04 346320]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"BCU"=C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe [2009-08-04 346320]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2012-07-03 4273976]

C:\Users\Pepino\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Spamihilator.lnk - C:\Program Files\Spamihilator\spamihilator.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2011-03-31 249344]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2011-06-12 6721936]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2011-06-12 4221328]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"GreyMSIAds"=0
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"="C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot-S&D 2 Tray Icon"
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe"="C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Disabled:Spybot-S&D 2 Scanner Service"
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe"="C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater"
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe"="C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.ac3filter64"=ac3filter64.acm
"msacm.ac3filter"=ac3filter.acm
"vidc.XVID"=xvidvfw.dll
"vidc.ffds"=ff_vfw.dll
"VIDC.ACDV"=ACDV.dll
"msacm.l3pacm"=l3codecp.acm
"msacm.aacacm"=AACACM.acm
"msacm.ac3acm"=ac3acm.acm
"VIDC.LAGS"=lagarith.dll
"msacm.avis"=ff_acm.acm
"vidc.x264"=x264vfw.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 month======

2012-07-11 18:46:14 ----A---- C:\Windows\ntbtlog.txt
2012-07-11 17:37:39 ----SD---- C:\ComboFix
2012-07-11 16:00:54 ----A---- C:\Windows\system32\nvvsvc.exe
2012-07-11 16:00:54 ----A---- C:\Windows\system32\nvsvcr.dll
2012-07-11 16:00:54 ----A---- C:\Windows\system32\nvsvc64.dll
2012-07-11 16:00:54 ----A---- C:\Windows\system32\nvshext.dll
2012-07-11 16:00:54 ----A---- C:\Windows\system32\nvmctray.dll
2012-07-11 16:00:54 ----A---- C:\Windows\system32\nvcpl.dll
2012-07-11 16:00:18 ----D---- C:\ProgramData\NVIDIA Corporation
2012-07-11 08:46:26 ----D---- C:\Program Files (x86)\Debugging Tools for Windows (x86)
2012-07-11 00:33:34 ----A---- C:\Windows\system32\win32k.sys
2012-07-11 00:29:30 ----A---- C:\Windows\system32\mshtmled.dll
2012-07-11 00:29:29 ----A---- C:\Windows\SYSWOW64\url.dll
2012-07-11 00:29:29 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2012-07-11 00:29:29 ----A---- C:\Windows\system32\url.dll
2012-07-11 00:29:28 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2012-07-11 00:29:28 ----A---- C:\Windows\SYSWOW64\ieui.dll
2012-07-11 00:29:28 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2012-07-11 00:29:28 ----A---- C:\Windows\system32\urlmon.dll
2012-07-11 00:29:28 ----A---- C:\Windows\system32\iertutil.dll
2012-07-11 00:29:27 ----A---- C:\Windows\SYSWOW64\wininet.dll
2012-07-11 00:29:27 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2012-07-11 00:29:27 ----A---- C:\Windows\system32\ieUnatt.exe
2012-07-11 00:29:27 ----A---- C:\Windows\system32\ieui.dll
2012-07-11 00:29:26 ----A---- C:\Windows\system32\wininet.dll
2012-07-11 00:29:26 ----A---- C:\Windows\system32\jsproxy.dll
2012-07-11 00:29:25 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2012-07-11 00:29:25 ----A---- C:\Windows\SYSWOW64\jscript.dll
2012-07-11 00:29:25 ----A---- C:\Windows\system32\jscript9.dll
2012-07-11 00:29:25 ----A---- C:\Windows\system32\jscript.dll
2012-07-11 00:29:24 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2012-07-11 00:29:23 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2012-07-11 00:29:22 ----A---- C:\Windows\system32\mshtml.dll
2012-07-11 00:29:21 ----A---- C:\Windows\system32\ieframe.dll
2012-07-11 00:29:20 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2012-07-11 00:28:38 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2012-07-11 00:28:38 ----A---- C:\Windows\SYSWOW64\schannel.dll
2012-07-11 00:28:38 ----A---- C:\Windows\SYSWOW64\secur32.dll
2012-07-11 00:28:38 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2012-07-11 00:28:38 ----A---- C:\Windows\system32\schannel.dll
2012-07-11 00:28:38 ----A---- C:\Windows\system32\ncrypt.dll
2012-07-11 00:28:37 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2012-07-11 00:28:37 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2012-07-11 00:28:37 ----A---- C:\Windows\system32\drivers\cng.sys
2012-07-11 00:28:34 ----A---- C:\Windows\system32\shell32.dll
2012-07-11 00:28:32 ----A---- C:\Windows\SYSWOW64\shell32.dll
2012-07-11 00:28:24 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2012-07-11 00:28:24 ----A---- C:\Windows\system32\msxml6.dll
2012-07-11 00:28:24 ----A---- C:\Windows\system32\msxml3.dll
2012-07-11 00:28:23 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2012-07-11 00:28:23 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2012-07-11 00:28:23 ----A---- C:\Windows\system32\msxml3r.dll
2012-07-11 00:28:20 ----A---- C:\Windows\SYSWOW64\cdosys.dll
2012-07-11 00:28:19 ----A---- C:\Windows\system32\cdosys.dll
2012-07-11 00:08:21 ----SHD---- C:\$RECYCLE.BIN
2012-07-11 00:04:53 ----D---- C:\Windows\temp
2012-07-10 21:45:19 ----D---- C:\rsit
2012-07-10 21:45:19 ----D---- C:\Program Files\trend micro
2012-07-10 15:48:04 ----A---- C:\Windows\zip.exe
2012-07-10 15:48:04 ----A---- C:\Windows\SWSC.exe
2012-07-10 15:48:04 ----A---- C:\Windows\SWREG.exe
2012-07-10 15:48:04 ----A---- C:\Windows\sed.exe
2012-07-10 15:48:04 ----A---- C:\Windows\PEV.exe
2012-07-10 15:48:04 ----A---- C:\Windows\NIRCMD.exe
2012-07-10 15:48:04 ----A---- C:\Windows\MBR.exe
2012-07-10 15:48:04 ----A---- C:\Windows\grep.exe
2012-07-10 15:46:11 ----D---- C:\Qoobox
2012-07-10 15:45:43 ----D---- C:\Windows\erdnt
2012-07-09 10:44:37 ----A---- C:\Windows\SYSWOW64\npdeployJava1.dll
2012-07-09 10:43:40 ----D---- C:\ProgramData\McAfee
2012-07-07 22:59:07 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2012-07-07 22:59:07 ----A---- C:\Windows\system32\qdvd.dll
2012-06-23 09:59:08 ----A---- C:\Windows\system32\wups2.dll
2012-06-23 09:59:07 ----A---- C:\Windows\system32\wucltux.dll
2012-06-23 09:59:07 ----A---- C:\Windows\system32\wuaueng.dll
2012-06-23 09:59:07 ----A---- C:\Windows\system32\wuauclt.exe
2012-06-23 09:58:56 ----A---- C:\Windows\system32\wups.dll
2012-06-23 09:58:56 ----A---- C:\Windows\system32\wudriver.dll
2012-06-23 09:58:56 ----A---- C:\Windows\system32\wuapi.dll
2012-06-23 09:58:44 ----A---- C:\Windows\system32\wuwebv.dll
2012-06-23 09:58:44 ----A---- C:\Windows\system32\wuapp.exe
2012-06-20 22:57:56 ----D---- C:\Program Files\Common Files\STORMWARE
2012-06-20 22:57:56 ----A---- C:\Windows\SYSWOW64\bzFlRdr.dll
2012-06-20 22:57:56 ----A---- C:\Windows\SYSWOW64\bzDCT.dll
2012-06-13 07:06:34 ----A---- C:\Windows\system32\rdpwsx.dll
2012-06-13 07:06:34 ----A---- C:\Windows\system32\rdpcorekmts.dll
2012-06-13 07:06:33 ----A---- C:\Windows\system32\rdrmemptylst.exe
2012-06-13 07:06:28 ----A---- C:\Windows\system32\profsvc.dll
2012-06-13 07:06:26 ----A---- C:\Windows\system32\ntoskrnl.exe
2012-06-13 07:06:24 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2012-06-13 07:06:23 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2012-06-13 07:06:17 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2012-06-13 07:06:15 ----A---- C:\Windows\system32\msi.dll
2012-06-13 07:06:14 ----A---- C:\Windows\SYSWOW64\msi.dll
2012-06-13 07:06:09 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2012-06-13 07:06:09 ----A---- C:\Windows\system32\crypt32.dll
2012-06-13 07:06:08 ----A---- C:\Windows\system32\cryptsvc.dll
2012-06-13 07:06:08 ----A---- C:\Windows\system32\cryptnet.dll
2012-06-13 07:06:06 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2012-06-13 07:06:06 ----A---- C:\Windows\SYSWOW64\cryptnet.dll

======List of files/folders modified in the last 1 month======

2012-07-11 22:30:00 ----D---- C:\Users\Pepino\AppData\Roaming\Spamihilator
2012-07-11 19:02:12 ----D---- C:\Windows\system32\config
2012-07-11 18:58:32 ----D---- C:\Windows\Prefetch
2012-07-11 18:49:23 ----D---- C:\Windows\Minidump
2012-07-11 18:49:20 ----D---- C:\Windows
2012-07-11 17:37:57 ----SHD---- C:\System Volume Information
2012-07-11 17:37:37 ----D---- C:\Windows\system32\drivers
2012-07-11 17:37:15 ----D---- C:\Windows\inf
2012-07-11 16:03:42 ----D---- C:\ProgramData\NVIDIA
2012-07-11 16:02:03 ----D---- C:\ProgramData
2012-07-11 16:02:00 ----D---- C:\Program Files\MAXON
2012-07-11 16:00:54 ----D---- C:\Windows\System32
2012-07-11 16:00:50 ----D---- C:\Program Files\NVIDIA Corporation
2012-07-11 16:00:48 ----D---- C:\Users\Pepino\AppData\Roaming\MAXON
2012-07-11 16:00:17 ----D---- C:\Windows\SysWOW64
2012-07-11 15:57:40 ----D---- C:\Windows\system32\DriverStore
2012-07-11 15:57:40 ----D---- C:\Windows\system32\catroot
2012-07-11 15:57:36 ----RD---- C:\Users
2012-07-11 15:57:36 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2012-07-11 15:28:46 ----D---- C:\Windows\system32\catroot2
2012-07-11 15:21:23 ----RD---- C:\Program Files (x86)
2012-07-11 15:17:27 ----D---- C:\Windows\system32\Tasks
2012-07-11 08:46:29 ----SHD---- C:\Windows\Installer
2012-07-11 08:11:33 ----D---- C:\Windows\system32\LogFiles
2012-07-11 07:36:08 ----D---- C:\Windows\SoftwareDistribution
2012-07-11 07:35:47 ----D---- C:\Windows\debug
2012-07-11 00:37:35 ----D---- C:\Windows\winsxs
2012-07-11 00:35:27 ----D---- C:\Windows\SYSWOW64\migration
2012-07-11 00:35:27 ----D---- C:\Windows\system32\migration
2012-07-11 00:35:27 ----D---- C:\Program Files\Internet Explorer
2012-07-11 00:35:27 ----D---- C:\Program Files (x86)\Internet Explorer
2012-07-11 00:33:17 ----D---- C:\ProgramData\Microsoft Help
2012-07-11 00:30:43 ----A---- C:\Windows\system32\MRT.exe
2012-07-11 00:19:21 ----D---- C:\Users\Pepino\AppData\Roaming\TuneUp Software
2012-07-11 00:00:22 ----A---- C:\Windows\system.ini
2012-07-11 00:00:14 ----D---- C:\Windows\system32\drivers\etc
2012-07-10 23:56:11 ----D---- C:\Windows\SYSWOW64\drivers
2012-07-10 23:56:11 ----D---- C:\Windows\AppPatch
2012-07-10 23:56:08 ----D---- C:\Program Files\Common Files
2012-07-10 23:56:08 ----D---- C:\Program Files (x86)\Common Files
2012-07-10 21:45:19 ----RD---- C:\Program Files
2012-07-10 21:17:40 ----D---- C:\Windows\system32\NDF
2012-07-10 20:02:04 ----D---- C:\ProgramData\Apple Computer
2012-07-10 20:00:48 ----D---- C:\Program Files\Java
2012-07-10 18:22:10 ----D---- C:\Program Files (x86)\Total CMA Pack
2012-07-10 17:27:26 ----D---- C:\ProgramData\ACD Systems
2012-07-09 10:44:32 ----A---- C:\Windows\SYSWOW64\deployJava1.dll
2012-07-08 14:40:26 ----D---- C:\Windows\registration
2012-07-03 18:21:28 ----A---- C:\Windows\SYSWOW64\aswBoot.exe
2012-07-03 18:21:18 ----A---- C:\Windows\system32\aswBoot.exe
2012-06-28 08:52:55 ----D---- C:\Program Files (x86)\CCleaner
2012-06-24 10:41:41 ----D---- C:\Windows\rescache
2012-06-24 10:18:19 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2012-06-23 23:41:21 ----D---- C:\Windows\system32\cs-CZ
2012-06-20 22:57:57 ----RSD---- C:\Windows\assembly
2012-06-20 22:57:35 ----D---- C:\Program Files (x86)\STORMWARE
2012-06-20 22:56:52 ----D---- C:\ProgramData\STORMWARE
2012-06-17 20:17:55 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2012-06-17 10:16:29 ----D---- C:\Program Files (x86)\Mozilla Firefox
2012-06-13 14:48:56 ----D---- C:\Windows\Microsoft.NET
2012-06-13 14:04:13 ----D---- C:\Windows\SYSWOW64\cs-CZ
2012-06-13 11:06:36 ----A---- C:\Windows\system32\PerfStringBackup.INI

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2011-07-15 503352]
R1 aswRdr;aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [2012-07-03 54072]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2012-07-03 958400]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2012-07-03 355856]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2012-07-03 59728]
R1 ISODrive;ISO DVD/CD-ROM Device Driver; \??\C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys [2010-01-29 115600]
R2 adfs;adfs; C:\Windows\system32\drivers\adfs.sys [2008-06-27 88632]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2012-07-03 25232]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2012-07-03 71064]
R3 DKRtWrt;DKRtWrt; C:\Windows\system32\DRIVERS\DKRtWrt.sys [2011-02-14 44624]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 34152]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2009-06-25 1778592]
R3 KMWDFILTERV1;HIDUASServiceDesc; C:\Windows\system32\DRIVERS\RPGMOUSEV1.sys [2009-06-10 24576]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-07-30 236544]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys [2011-09-22 11856]
R3 wacmoumonitor;Wacom Mode Helper; C:\Windows\system32\DRIVERS\wacmoumonitor.sys [2011-09-08 13312]
R3 wacommousefilter;Wacom Mouse Filter Driver; C:\Windows\system32\DRIVERS\wacommousefilter.sys [2007-02-16 12848]
R3 wacomvhid;Wacom Virtual Hid Driver; C:\Windows\system32\DRIVERS\wacomvhid.sys [2009-09-22 16168]
S3 az2uh25t;az2uh25t; C:\Windows\system32\drivers\az2uh25t.sys []
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 cpuz135;cpuz135; \??\C:\Windows\TEMP\cpuz135\cpuz135_x64.sys []
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2011-12-04 25640]
S3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2010-02-08 82816]
S3 PTSimBus;PenTablet Bus Enumerator; C:\Windows\system32\DRIVERS\PTSimBus.sys []
S3 PTSimHid;PenTablet Simulated HID MiniDriver; C:\Windows\system32\DRIVERS\PTSimHid.sys []
S3 SANDRA;SANDRA; \??\C:\Program Files\SiSoftware\SiSoftware Sandra Professional Home 2011\WNt500x64\Sandra.sys []
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-07-03 44808]
R2 BCUService;Browser Configuration Utility Service; C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe [2009-08-04 219360]
R2 Bonjour Service;Bonjour Service; C:\Program Files (x86)\Bonjour\mDNSResponder.exe [2011-07-12 387944]
R2 Diskeeper;Diskeeper; C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe [2012-01-04 2646864]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2012-02-10 889664]
R2 PSI_SVC_2;Protexis Licensing V2; c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [2010-03-10 189728]
R2 PSI_SVC_2_x64;Protexis Licensing V2 x64; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [2010-11-30 336824]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2007-05-28 275968]
R2 TabletServicePen;TabletServicePen; C:\Program Files\Tablet\Pen\Pen_Tablet.exe [2011-09-08 6583160]
R2 TouchServicePen;Wacom Consumer Touch Service; C:\Program Files\Tablet\Pen\Pen_TouchService.exe [2011-09-08 528760]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe [2011-12-14 2123584]
R2 UxTuneUp;@%SystemRoot%\System32\uxtuneup.dll,-4096; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 wampapache;wampapache; c:\wamp\bin\apache\apache2.2.21\bin\httpd.exe [2011-09-26 21504]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 KmGameMouseServiceV1;Game Mouse Communication And Update Service V1; C:\Program Files (x86)\Trust\GXT14 Mouse\GameMouseServiceApp.exe [2009-05-18 354816]
S2 KMService;KMService; C:\Windows\syswow64\srvany.exe [2003-04-18 8192]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-24 250056]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-01-23 655624]
S3 gusvc;Google Updater Service; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-11-20 136120]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 51740536]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-06-17 113120]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 wampmysqld;wampmysqld; c:\wamp\bin\mysql\mysql5.5.20\bin\mysqld.exe [2012-01-25 9690112]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-05-19 1255736]

-----------------EOF-----------------

Re: prosím o pomoc - častý BSOD

Napsal: 11 črc 2012 21:57
od Rudy
Log vypadá OK. Nemáte v PC něco přetaktováno?

Re: prosím o pomoc - častý BSOD

Napsal: 12 črc 2012 11:38
od pepino
ne, přetaktováno nemám, do takových věcí se nepouštím. Zkusil jsem udělat memtest RAM a přitom přehodil paměti. Test jsem měl spuštěný tak 4hod. a vše bylo OK. Kupodivu od té doby PC nespadl (22hod). Tak uvidíme. Zatím děkuji.

Re: prosím o pomoc - častý BSOD

Napsal: 12 črc 2012 20:26
od Rudy
Zatím nemáte zač!