[infectionpnkbstra]

Solved
swazolie Posted messages 66 Status Membre -  
 billou631 -
Hello,

While looking in Kério, I spotted this program: pnkbstra. It seems to be an infection and this might explain the slowness of my PC.

Out of curiosity, I performed a HijackThis scan where it appears along with pnkbstrb.exe.

Thank you for your help
I am pasting the report

Logfile of HijackThis v1.99.1
Scan saved at 14:15:16, on 03/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ctfmon.exe
c:\program files\Common Files\Logitech\lvmvfm\LVPrcSrv.exe
C:\Program Files\SAGEM\SAGEM F@st 800-908\dslmon.exe
C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.free.fr/freebox/index.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Links
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-908\dslmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=https://www.free.fr/freebox/index.html
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\Common Files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
Configuration: Windows XP Firefox 2.0.0.4

7 réponses

billou631
 
These are the services used by PunkBuster, the anti-cheat software for Call of Duty 4. ^^
1
sassou2009 Posted messages 60 Registration date   Status Membre 2
 
Try it with this and paste the report there
to Download: http://www.suspectfile.com/systemscan/43697/sys43697.exe
0
B@rtito Posted messages 24 Status Membre
 
I don't know if it can help you, but on this site they say it comes from a game
http://www.bf2live.com/forum/index.php?showtopic=17092
0
swazolie Posted messages 66 Status Membre 12
 
I think I've solved my problem by looking a little:
virus freeze

the lines no longer appear on the hijackthis report.

thank you both for your help.

* I did the scan with suspectfile: do we really need all this info.....it can be intrusive especially on a forum!
0
Eiwelne
 
Hello everyone!
Thanks to those who will respond to help me

So I’m playing CoD4 and this afternoon, I take a break and when I try to reconnect it shows me

eiwelne .... eiwelne
Restriction: Service Communication Failure: Pnkbstra.exe

It's an anti-cheat software that's bugging a bit, to be honest.
So I'm wandering around the internet, installing Punkbuster, starting it up, putting CoD4 in the list, pressing "Check for updates" and then it tells me, "All available updates have been applied."
I start Call of Duty 4 and bam, the same message.
I’ve looked at a lot of forums on the internet but it's tough.
For your info, I have Windows XP.

If anyone can help me and tell me what I need to do.
0
Tauren_Corrida Posted messages 288 Status Membre 28
 
Hi everyone!
For me, it's nothing like an infection; BnkBstrA and B are updates to check for cheating logs. If you're used to connecting to servers, there's a chance they got installed.

However, you can block their startup or simply delete them in Windows!

Thanks to a certain iFuturelist ^^
0
dono
 
Indeed, normally PnkBstra is software designed to "protect" online game servers against attacks and the use of third-party software.

However, there was a version of Punk Buster that was faulty for about a month. To check if you have this bad version, when you start your computer (before doing anything), go to the Task Manager (Ctrl+Alt+Del). In the "Processes" tab, check if "PnkBstrA" is in that list.

If it is, then you have the erroneous version of Punk Buster. The problem is that with this version, PB attempted to make its software "more autonomous" by allowing it to start with the computer rather than when a game is launched. (Since they received many reports that having a second software starting at the same time as the game slowed down game performance.)
However, they messed up, and the version was changed back to one like the previous ones: Starting only when you open a game.
However, the update for Punk Buster did not erase the "background" part of the faulty version. So now, you have a "PnkBstrA" that starts with your computer, which cannot be removed by standard means and which takes about 800-900K of memory.

There are two solutions:

1. Simply stop the process directly in the Task Manager after each startup. This will not prevent you from playing your games in any way. If you want, it's a "trace" of Punk Buster that is totally useless. When you start your games, the real Punk Buster will open as before under a different process.

2. Try to find the source of PnkBstrA and delete it. I haven't been able to find it yet because it is located in the system folders, in a place that allows it to start at the same time as your computer, but which keeps it invisible in all "process removal" software.
(Do not confuse it with the real PnkBstrA from Punk Buster that is also in the system folders. I managed to find that one, delete it, but the process still did not disappear. I therefore had to reinstall Punk Buster to fix the error.)
0
Svan > dono
 
Hi everyone, I regularly play Battlefield 2142 but for about a month now, I haven’t been able to due to Punkbuster. Here’s the message:

IMPORTANT PB: RESTRICTION: Communication Service Failure: PnkBstrB.exe heartbeats stopped

In summary, I've updated Punkbuster, the pbsvc is okay, I have Avast as my antivirus but it never changed anything. I've been playing on this for about 3 years and never had this issue before. I also did a complete reinstall of my PC (in case of a virus), I completely uninstalled Punkbuster and reinstalled it again. I replaced Punkbuster A and B in system32 and Punkbuster K in the drivers with those from two friends who manage to play perfectly, but nothing works, still the same problem and the same message. My internet provider is Free, hard reboot is okay, I removed the router and it’s still the same, I put it back and it’s still the same. I'm really desperate and I can’t find any help anywhere. I’ve tried all the solutions on almost all the forums but nothing works. When I start my PC, PnkBstrA.exe and B are already active, but even removing them before starting to play or even after launching the game doesn’t work.

So, if anyone can help me out of this mess, thanks in advance.
0
sky22
 
Use Avast antivirus to protect yourself from malware.
-2