Reset nastepuje neiregularnie. Wywala niebieski ekran. W rożnych momentach: podczas grania, podczas pracy w aplikacjami typu word, photoshop, arz podczas uruchamiania sie systemu. Juz raz formatowalem dysk i instalowalem system przez ten problem. Wtedy nei pomogla instalacja SP2, nowych sterownikow do graficznej…
Zalaczam log:
Logfile of HijackThis v1.99.1
Scan saved at 18:28:15, on 2006-10-29
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
D:\programy\firewall\smc.exe
C:\WINDOWS\system32\spoolsv.exe
D:\programy\antywirus\aswUpdSv.exe
D:\programy\antywirus\ashServ.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
D:\programy\antywirus\ashWebSv.exe
C:\WINDOWS\System32\RUNDLL32.EXE
D:\programy\antywirus\ashMaiSv.exe
D:\programy\ANTYWI~1\ashDisp.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
D:\programy\quicktime\qttask.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
D:\programy\tlen\Tlen.pl\tlen.exe
C:\WINDOWS\System32\wuauclt.exe
D:\programy\opera\Opera.exe
D:\programy\debugging\windbg.exe
D:\programy\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 10.4.0.50:80
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\programy\reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM…\Run: [soundMan] SOUNDMAN.EXE
O4 - HKLM…\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM…\Run: [nwiz] nwiz.exe /install
O4 - HKLM…\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM…\Run: [smcService] D:\programy\firewall\smc.exe -startgui
O4 - HKLM…\Run: [avast!] D:\programy\ANTYWI~1\ashDisp.exe
O4 - HKLM…\Run: [sunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM…\Run: [QuickTime Task] “D:\programy\quicktime\qttask.exe” -atboottime
O4 - HKLM…\Run: [iSUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM…\Run: [iSUSScheduler] “C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe” -start
O4 - HKLM…\Run: [CorelDRAW Graphics Suite 11b] D:\programy\coreldraw12\Languages\PL\Programs\Registration.exe /title=“CorelDRAW Graphics Suite 12” /date=110706 serial=dr12wux-1148251-qrt lang=PL
O4 - HKCU…\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU…\Run: [MSMSGS] “C:\Program Files\Messenger\msmsgs.exe” /background
O4 - HKCU…\Run: [Komunikator] D:\programy\tlen\Tlen.pl\tlen.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\programy\reader\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = D:\programy\office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra ‘Tools’ menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra ‘Tools’ menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O17 - HKLM\System\CCS\Services\Tcpip…{227BC5BF-7FD6-41EE-9127-FCEB1B23BFAC}: NameServer = 217.8.168.244,157.25.5.18
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - D:\programy\antywirus\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - D:\programy\antywirus\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - D:\programy\antywirus\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - D:\programy\antywirus\ashWebSv.exe" /service (file missing)
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - D:\programy\firewall\smc.exe
A takze tekst z debuggera:
Loading Dump File [C]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: *** Invalid ***
****************************************************************************
* Symbol loading may be unreliable without a symbol search path. *
* Use .symfix to have the debugger choose a symbol path. *
* After setting your symbol path, use .reload to refresh symbol locations. *
****************************************************************************
Executable search path is:
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
Unable to load image ntoskrnl.exe, Win32 error 2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
*** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe
Windows XP Kernel Version 2600 MP (2 procs) Free x86 compatible
Product: WinNt
Kernel base = 0x804d0000 PsLoadedModuleList = 0x8054ae28
Debug session time: Sun Oct 29 17:26:39.842 2006 (GMT+1)
System Uptime: 0 days 2:44:55.437
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
Unable to load image ntoskrnl.exe, Win32 error 2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
*** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe
Loading Kernel Symbols
…
Loading User Symbols
Loading unloaded module list
…
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 50, {a7994ba4, 0, bf8637f6, 0}
***** Kernel symbols are WRONG. Please fix symbols to do analysis.
***** Kernel symbols are WRONG. Please fix symbols to do analysis.
Unable to load image win32k.sys, Win32 error 2
*** WARNING: Unable to verify timestamp for win32k.sys
*** ERROR: Module load completed but symbols could not be loaded for win32k.sys
Probably caused by : win32k.sys ( win32k+637f6 )
Followup: MachineOwner
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: a7994ba4, memory referenced.
Arg2: 00000000, value 0 = read operation, 1 = write operation.
Arg3: bf8637f6, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 00000000, (reserved)
Debugging Details:
***** Kernel symbols are WRONG. Please fix symbols to do analysis.
***** Kernel symbols are WRONG. Please fix symbols to do analysis.
MODULE_NAME: win32k
FAULTING_MODULE: 804d0000 nt
DEBUG_FLR_IMAGE_TIMESTAMP: 3b7de698
READ_ADDRESS: unable to get nt!MmSpecialPoolStart
unable to get nt!MmSpecialPoolEnd
unable to get nt!MmPoolCodeStart
unable to get nt!MmPoolCodeEnd
a7994ba4
FAULTING_IP:
win32k+637f6
bf8637f6 ?? ???
MM_INTERNAL_CODE: 0
CUSTOMER_CRASH_COUNT: 5
DEFAULT_BUCKET_ID: WRONG_SYMBOLS
BUGCHECK_STR: 0x50
LAST_CONTROL_TRANSFER: from 00000000 to 80517ee6
STACK_TEXT:
f798ea70 00000000 a7994ba4 00000000 bf8637f6 nt+0x47ee6
STACK_COMMAND: .bugcheck ; kb
FOLLOWUP_IP:
win32k+637f6
bf8637f6 ?? ???
FOLLOWUP_NAME: MachineOwner
IMAGE_NAME: win32k.sys
SYMBOL_NAME: win32k+637f6
BUCKET_ID: WRONG_SYMBOLS
Followup: MachineOwner
pomocy, ja sie nie znam…