BleepingComputer.com: Hardware parts slowly stop responding one by one until restart

Jump to content

Forum Guidelines

Posted Image Read the following topic before creating a new topic in this forum. It contains instructions on the what we would like you to post, which will enable us to help you more quickly.

Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help


Posted Image Unfortunately, with the amount of logs we receive per day, the average response time is 5 days. I want to assure you, though, that your topic will be looked at and responded to. So please be patient.


Posted Image DO NOT RUN ComboFix unless requested to.


Posted Image Only members of the Malware Response Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.


Posted Image When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.


Posted Image Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
Page 1 of 1
  • You cannot start a new topic
  • This topic is locked

Hardware parts slowly stop responding one by one until restart Never had a similar problem

#1 User is offline   pasza89 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 2
  • Joined: 24-January 12

Posted 24 January 2012 - 04:56 PM

Hi there!
Since 2 days I have a recurring problem with my PC, specs: AMD Phenom Quadcore, 2gb RAM, Geforce 8800 GT 512mb, HDD ~250gb /split into 60+190/, Windows XP Home SP3. Bought it around May 2008, never had serious problems with it, except 2 months ago had to change 1gb of ram for another unit, cuz it was damage and caused random PC restarts. Feel free to post advices on any level of advancement, I used to deal with all the problems myself. Thanks a lot for even reading this!

After several minutes since booting up (from 20min to 1 hour) I lose internet connection. Router (Livebox from TELECOM) works all right, it doesn't restart, my laptop has connection. Reseting router, reconnecting cable or turning off and on connection in Control Panel doesn't work. Few minutes later I lose next piece of hardware, usually sound. After that I lose mouse + keyboard and the only thing left is to manually restart PC. Sometimes when PC is booting up, after checking memory and drives, a POST message appears saying "CMOS checksum error". It hasn't appeared after I used fail-safe defaults in BIOS like 5 hours ago. I honestly have no idea what to do, I'm worried that it may be broken hardware and I hope it is just a virus that my antivir hasn't spotted. I'm using Avira Antivir Personal and Comodo Firewall.

The only thing I did that day was installing BlueSoleil's Blootooth drivers from CD I got with the device and thinking that was the cause of my problems I used a restore point from before installation.

Except for what I wrote, the computer runs perfectly fine, no slowdowns and so on.
Attached attach.txt and zipped ark.txt (it was over 1mb), here are DDS.TXT contents:


.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_29
Run by Pawel at 21:20:13 on 2012-01-24
Microsoft Windows XP Home Edition 5.1.2600.3.1250.48.1045.18.2046.1282 [GMT 1:00]
.
AV: AntiVir Desktop *Disabled/Outdated* {AD166499-45F9-482A-A743-FDD3350758C7}
FW: COMODO Firewall *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\Program Files\Sandboxie\SbieSvc.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Xfire\Xfire.exe
C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
D:\Tribes Ascend\HiPatchService.exe
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Tunngle\TnglCtrl.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
c:\program files\avira\antivir desktop\avcenter.exe
.
============== Pseudo HJT Report ===============
.
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
mRun: [ORAHSSSessionManager] "c:\program files\livebox\sessionmanager\SessionManager.exe"
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [JMB36X IDE Setup] c:\windows\raidtool\xInsIDE.exe
mRun: [36X Raid Configurer] c:\windows\system32\xRaidSetup.exe boot
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [COMODO Internet Security] "c:\program files\comodo\comodo internet security\cfp.exe" -h
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
mRun: [nwiz] c:\program files\nvidia corporation\nview\nwiz.exe /installquiet
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\pawel\menust~1\programy\autost~1\xfire.lnk - c:\program files\xfire\Xfire.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office12\REFIEBAR.DLL
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://windowsupdate.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1314622730015
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1318609977140
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
TCP: Interfaces\{4194B6A1-8B7B-43BE-8EE9-09D52FB2FE76} : DhcpNameServer = 192.168.1.1
AppInit_DLLs: c:\windows\system32\guard32.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\pawel\dane aplikacji\mozilla\firefox\profiles\7b02oy8x.default\
FF - prefs.js: browser.search.selectedEngine - The Pirate Bay
FF - prefs.js: browser.startup.homepage - hxxp://www.google.pl/ig
FF - prefs.js: network.proxy.ftp - 212.118.224.154
FF - prefs.js: network.proxy.ftp_port - 80
FF - prefs.js: network.proxy.http - 212.118.224.154
FF - prefs.js: network.proxy.http_port - 80
FF - prefs.js: network.proxy.socks - 212.118.224.154
FF - prefs.js: network.proxy.socks_port - 80
FF - prefs.js: network.proxy.ssl - 212.118.224.154
FF - prefs.js: network.proxy.ssl_port - 80
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\documents and settings\pawel\ustawienia lokalne\dane aplikacji\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: c:\program files\microsoft\web platform installer\NPWPIDetector.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll
.
============= SERVICES / DRIVERS ===============
.
P2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;d:\tribes ascend\HiPatchService.exe [2012-1-12 8704]
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2011-9-24 11608]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [2011-10-7 492768]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2011-10-7 31704]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [2011-8-29 232512]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2011-9-24 136360]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2011-9-24 66616]
R2 cmdAgent;COMODO Internet Security Helper Service;c:\program files\comodo\comodo internet security\cmdagent.exe [2011-10-7 1883328]
R2 MsDepSvc;Usługa agenta wdrażania w sieci Web;c:\program files\iis\microsoft web deploy\MsDepSvc.exe [2011-4-1 67400]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\nvidia corporation\nvidia updatus\daemonu.exe [2012-1-12 2253120]
R2 TunngleService;TunngleService;c:\program files\tunngle\TnglCtrl.exe [2011-9-28 741224]
R3 SbieDrv;SbieDrv;c:\program files\sandboxie\SbieDrv.sys [2011-11-23 131856]
R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\drivers\tap0901t.sys [2011-9-28 27136]
S2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2011-9-24 269480]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 GGSAFERDriver;GGSAFER Driver;\??\d:\inne\garena\safedrv.sys --> d:\inne\garena\safedrv.sys [?]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [2011-12-19 104752]
S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\drivers\vboxnetflt.sys --> c:\windows\system32\drivers\VBoxNetFlt.sys [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 MSSQL$SQL;SQL Server (SQL);c:\program files\microsoft sql server\mssql10.sql\mssql\binn\sqlservr.exe [2008-7-10 40999448]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\microsoft sql server\100\shared\sqladhlp.exe [2010-4-3 44896]
S4 RsFx0102;RsFx0102 Driver;c:\windows\system32\drivers\RsFx0102.sys [2008-7-10 242712]
S4 RsFx0150;RsFx0150 Driver;c:\windows\system32\drivers\RsFx0150.sys [2010-4-3 240608]
S4 SQLAgent$SQL;SQL Server Agent (SQL);c:\program files\microsoft sql server\mssql10.sql\mssql\binn\SQLAGENT.EXE [2008-7-10 369688]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\microsoft sql server\mssql10_50.sqlexpress\mssql\binn\SQLAGENT.EXE [2010-4-3 367456]
.
=============== Created Last 30 ================
.
2012-01-24 19:50:03 -------- d-----w- C:\Darksiders
2012-01-24 18:07:25 -------- d-----w- c:\windows\system32\wbem\repository\FS
2012-01-24 18:07:25 -------- d-----w- c:\windows\system32\wbem\Repository
2012-01-23 18:23:46 8192 ----a-w- c:\windows\system32\wshirda.dll
2012-01-23 18:23:46 28672 ----a-w- c:\windows\system32\irmon.dll
2012-01-23 18:23:46 152064 ----a-w- c:\windows\system32\irftp.exe
2012-01-23 18:20:32 82148 ----a-w- c:\windows\system32\drivers\VcommMgr.sys
2012-01-22 12:30:37 -------- d-----w- c:\documents and settings\pawel\ustawienia lokalne\dane aplikacji\DassaultSystemes
2012-01-22 12:30:37 -------- d-----w- c:\documents and settings\pawel\dane aplikacji\DassaultSystemes
2012-01-22 12:30:37 -------- d-----w- c:\documents and settings\all users\dane aplikacji\DassaultSystemes
2012-01-22 12:16:38 -------- d-----w- c:\documents and settings\pawel\.comsol
2012-01-21 15:28:42 -------- d-----w- C:\6b66960dd4f8070559a4216d
2012-01-21 12:39:27 -------- d-----w- c:\windows\C5C1C0F0D62F4DBF81D4D7EF397C228B.TMP
2012-01-21 12:21:39 -------- d-----w- c:\program files\common files\BioWare
2012-01-16 17:06:07 -------- d-----w- c:\documents and settings\pawel\ustawienia lokalne\dane aplikacji\PMB Files
2012-01-16 17:06:04 -------- d-----w- c:\documents and settings\all users\dane aplikacji\PMB Files
2012-01-12 22:26:18 -------- d-----w- c:\documents and settings\all users\dane aplikacji\NVIDIA Corporation
2012-01-12 21:15:03 -------- d-----w- C:\cod
2012-01-12 18:53:23 -------- d-----w- c:\documents and settings\all users\dane aplikacji\Hi-Rez Studios
2012-01-04 08:34:44 626688 ----a-w- c:\program files\mozilla firefox\msvcr80.dll
2012-01-04 08:34:44 548864 ----a-w- c:\program files\mozilla firefox\msvcp80.dll
2012-01-04 08:34:44 479232 ----a-w- c:\program files\mozilla firefox\msvcm80.dll
2012-01-04 08:34:44 43992 ----a-w- c:\program files\mozilla firefox\mozutils.dll
2012-01-03 07:22:02 103864 ----a-w- c:\program files\mozilla firefox\plugins\nppdf32.dll
2011-12-28 23:23:04 40960 ----a-r- c:\documents and settings\pawel\dane aplikacji\microsoft\installer\{9559f7ca-5e34-4237-a2d9-d856464ad727}\ARPPRODUCTICON.exe
.
==================== Find3M ====================
.
2012-01-22 20:08:35 444952 ----a-w- c:\windows\system32\wrap_oal.dll
2012-01-22 20:08:35 109080 ----a-w- c:\windows\system32\OpenAL32.dll
2012-01-12 22:56:01 285176 ----a-w- c:\windows\system32\nvdrsdb0.bin
2012-01-12 22:56:01 1 ----a-w- c:\windows\system32\nvdrssel.bin
2012-01-12 22:55:36 285176 ----a-w- c:\windows\system32\nvdrsdb1.bin
2012-01-09 22:28:37 138160 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2012-01-09 22:28:24 271200 ----a-w- c:\windows\system32\PnkBstrB.xtr
2012-01-09 22:28:24 271200 ----a-w- c:\windows\system32\PnkBstrB.exe
2012-01-03 19:32:46 271200 ----a-w- c:\windows\system32\PnkBstrB.ex0
2011-12-19 13:12:00 104752 ----a-w- c:\windows\system32\drivers\VBoxNetAdp.sys
2011-12-19 13:11:58 91440 ----a-w- c:\windows\system32\drivers\VBoxUSBMon.sys
2011-12-19 13:11:58 158512 ----a-w- c:\windows\system32\drivers\VBoxDrv.sys
2011-12-15 04:39:42 42392 ----a-w- c:\windows\system32\xfcodec.dll
2011-11-27 15:52:02 75136 ----a-w- c:\windows\system32\PnkBstrA.exe
2011-11-15 13:21:28 97792 ----a-w- c:\windows\system32\drivers\ACEDRV05.sys
2011-11-11 13:48:23 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
.
============= FINISH: 21:21:09,73 ===============

Attached File(s)

  • Attached File  attach.txt (15.96K)
    Number of downloads: 0
  • Attached File  ark.zip (61.15K)
    Number of downloads: 0


#2 User is offline   pasza89 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 2
  • Joined: 24-January 12

Posted 27 January 2012 - 05:15 PM

I solved the issue. It was broken power supply, had to replace it.

The thread can be closed, but I'll leave it, because someone may have similar problem and may stumble upon my thread containing the solution!

Thanks anyways

This post has been edited by pasza89: 27 January 2012 - 05:15 PM


#3 User is offline   myrti 

  • bleepin' _temp_
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Instructor
  • Posts: 27,527
  • Joined: 25-January 08
  • Gender:Female
  • Location:At home

Posted 29 January 2012 - 09:30 AM

Thanks for lettings us know! :)

I'll go ahead and close the topic then.

regards myrti
If I have been helping you and haven't replied in 2 days, feel free to shoot me a PM!

Posted Image
Please don't send help request via PM, unless I am already helping you. Use the forums!

I know not with what weapons World War III will be fought, but World War IV will be fought with sticks and stones. ~ Albert Einstein
Heroism on command, senseless violence, and all the loathsome nonsense that goes by the name of patriotism -- how passionately I hate them! ~ Albert Einstein

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • This topic is locked

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users