flyers16
April 27th, 2008, 03:33 PM
It started when I realized I was infected with Malware/Spyware. The machine has since been cleaned & all traces of the infection have been removed.
Now I’m not able to view this PC on my network, I have 3 machines on the Network that used to talk to each other, the infected one will not see the other 2 anymore….it know they’re there but can’t connect. I’m having a DNS/NIC card/netbt issue or a combination of several things.
I tried the registerdns but it doesn’t work, spits this error msg out (#4)
FLYESR16 (Vista Ult.) is the machine with the problem. 16FLYERS (XP) is machine #2……..and machine #3 (XP) is off now. Network card is an Intel PRO/1000 PL. I’ve bounced between assigning an IP & obtaining one automatically…..no change.
Here are the errors I receive that I’m certain are the problem, any chance anyone can make heads or tails of these? Any advice or help would be greatly appreciated.
thanks………:disgust:
1.)
Log Name: System
Source: BROWSER
Date: 4/20/2008 5:41:51 PM
Event ID: 8032
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: FLYERS16
Description:
The browser service has failed to retrieve the backup list too many times on transport \Device\NetBT_Tcpip_{2BE3D013-4252-4CB3-A3A7-CCCA0A521E07}. The backup browser is stopping.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="BROWSER" />
<EventID Qualifiers="49152">8032</EventID>
<Level>2</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2008-04-20T21:41:51.000Z" />
<EventRecordID>59345</EventRecordID>
<Channel>System</Channel>
<Computer>FLYERS16</Computer>
<Security />
</System>
<EventData>
<Data>\Device\NetBT_Tcpip_{2BE3D013-4252-4CB3-A3A7-CCCA0A521E07}</Data>
<Binary>35000000</Binary>
</EventData>
</Event>
2.)
Log Name: System
Source: BROWSER
Date: 4/20/2008 5:40:09 PM
Event ID: 8021
Task Category: None
Level: Warning
Keywords: Classic
User: N/A
Computer: FLYERS16
Description:
The browser service was unable to retrieve a list of servers from the browser master \\16FLYERS on the network \Device\NetBT_Tcpip_{2BE3D013-4252-4CB3-A3A7-CCCA0A521E07}.
Browser master: \\16FLYERS
Network: \Device\NetBT_Tcpip_{2BE3D013-4252-4CB3-A3A7-CCCA0A521E07}
This event may be caused by a temporary loss of network connectivity. If this message appears again, verify that the server is still connected to the network. The return code is in the Data text box.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="BROWSER" />
<EventID Qualifiers="32768">8021</EventID>
<Level>3</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2008-04-20T21:40:09.000Z" />
<EventRecordID>59341</EventRecordID>
<Channel>System</Channel>
<Computer>FLYERS16</Computer>
<Security />
</System>
<EventData>
<Data>\\16FLYERS</Data>
<Data>\Device\NetBT_Tcpip_{2BE3D013-4252-4CB3-A3A7-CCCA0A521E07}</Data>
<Binary>35000000</Binary>
</EventData>
</Event>
3.)
Log Name: System
Source: netbt
Date: 4/19/2008 8:40:42 AM
Event ID: 4311
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: FLYERS16
Description:
Initialization failed because the driver device could not be created. Use the string "101111111111" to identify the interface for which initialization failed. It represents the MAC address of the failed interface or the Globally Unique Interface Identifier (GUID) if NetBT was unable to map from GUID to MAC address. If neither the MAC address nor the GUID were available, the string represents a cluster device name.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="netbt" />
<EventID Qualifiers="49152">4311</EventID>
<Level>2</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2008-04-19T12:40:42.656Z" />
<EventRecordID>49748</EventRecordID>
<Channel>System</Channel>
<Computer>FLYERS16</Computer>
<Security />
</System>
<EventData>
<Data>
</Data>
<Data>101111111111</Data>
<Binary>000000000200320000000000D71000C0130100003B0000C000 000000000000000000000000000000</Binary>
</EventData>
</Event>
4.)
Log Name: System
Source: DnsApi
Date: 4/26/2008 8:11:44 AM
Event ID: 11150
Task Category: None
Level: Warning
Keywords: Classic
User: N/A
Computer: FLYERS16
Description:
The system failed to register network adapter with settings:
Adapter Name : {2BE3D013-4252-4CB3-A3A7-CCCA0A521E07}
Host Name : FLYERS16
Adapter-specific Domain Suffix : hsda.pa.comcast.net
DNS Server list :
192.168.1.1
Sent update to server : <?>
IP Address(es) :
192.168.1.103
The cause of this DNS registration failure was because the DNS update request timed out after being sent to the specified DNS Server. This is probably because the authoritative DNS server for the name being updated is not running.
You can manually retry registration of the network adapter and its settings by typing "ipconfig /registerdns" at the command prompt. If problems still persist, contact your network systems administrator to verify network conditions.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="DnsApi" />
<EventID Qualifiers="32768">11150</EventID>
<Level>3</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2008-04-26T12:11:44.000Z" />
<EventRecordID>59977</EventRecordID>
<Channel>System</Channel>
<Computer>FLYERS16</Computer>
<Security />
</System>
<EventData>
<Data>{2BE3D013-4252-4CB3-A3A7-CCCA0A521E07}</Data>
<Data>FLYERS16</Data>
<Data>hsda.pa.comcast.net</Data>
<Data> 192.168.1.1</Data>
<Data><?></Data>
<Data>192.168.1.103</Data>
<Data>
</Data>
<Binary>B4050000</Binary>
</EventData>
</Event>
Now I’m not able to view this PC on my network, I have 3 machines on the Network that used to talk to each other, the infected one will not see the other 2 anymore….it know they’re there but can’t connect. I’m having a DNS/NIC card/netbt issue or a combination of several things.
I tried the registerdns but it doesn’t work, spits this error msg out (#4)
FLYESR16 (Vista Ult.) is the machine with the problem. 16FLYERS (XP) is machine #2……..and machine #3 (XP) is off now. Network card is an Intel PRO/1000 PL. I’ve bounced between assigning an IP & obtaining one automatically…..no change.
Here are the errors I receive that I’m certain are the problem, any chance anyone can make heads or tails of these? Any advice or help would be greatly appreciated.
thanks………:disgust:
1.)
Log Name: System
Source: BROWSER
Date: 4/20/2008 5:41:51 PM
Event ID: 8032
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: FLYERS16
Description:
The browser service has failed to retrieve the backup list too many times on transport \Device\NetBT_Tcpip_{2BE3D013-4252-4CB3-A3A7-CCCA0A521E07}. The backup browser is stopping.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="BROWSER" />
<EventID Qualifiers="49152">8032</EventID>
<Level>2</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2008-04-20T21:41:51.000Z" />
<EventRecordID>59345</EventRecordID>
<Channel>System</Channel>
<Computer>FLYERS16</Computer>
<Security />
</System>
<EventData>
<Data>\Device\NetBT_Tcpip_{2BE3D013-4252-4CB3-A3A7-CCCA0A521E07}</Data>
<Binary>35000000</Binary>
</EventData>
</Event>
2.)
Log Name: System
Source: BROWSER
Date: 4/20/2008 5:40:09 PM
Event ID: 8021
Task Category: None
Level: Warning
Keywords: Classic
User: N/A
Computer: FLYERS16
Description:
The browser service was unable to retrieve a list of servers from the browser master \\16FLYERS on the network \Device\NetBT_Tcpip_{2BE3D013-4252-4CB3-A3A7-CCCA0A521E07}.
Browser master: \\16FLYERS
Network: \Device\NetBT_Tcpip_{2BE3D013-4252-4CB3-A3A7-CCCA0A521E07}
This event may be caused by a temporary loss of network connectivity. If this message appears again, verify that the server is still connected to the network. The return code is in the Data text box.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="BROWSER" />
<EventID Qualifiers="32768">8021</EventID>
<Level>3</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2008-04-20T21:40:09.000Z" />
<EventRecordID>59341</EventRecordID>
<Channel>System</Channel>
<Computer>FLYERS16</Computer>
<Security />
</System>
<EventData>
<Data>\\16FLYERS</Data>
<Data>\Device\NetBT_Tcpip_{2BE3D013-4252-4CB3-A3A7-CCCA0A521E07}</Data>
<Binary>35000000</Binary>
</EventData>
</Event>
3.)
Log Name: System
Source: netbt
Date: 4/19/2008 8:40:42 AM
Event ID: 4311
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: FLYERS16
Description:
Initialization failed because the driver device could not be created. Use the string "101111111111" to identify the interface for which initialization failed. It represents the MAC address of the failed interface or the Globally Unique Interface Identifier (GUID) if NetBT was unable to map from GUID to MAC address. If neither the MAC address nor the GUID were available, the string represents a cluster device name.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="netbt" />
<EventID Qualifiers="49152">4311</EventID>
<Level>2</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2008-04-19T12:40:42.656Z" />
<EventRecordID>49748</EventRecordID>
<Channel>System</Channel>
<Computer>FLYERS16</Computer>
<Security />
</System>
<EventData>
<Data>
</Data>
<Data>101111111111</Data>
<Binary>000000000200320000000000D71000C0130100003B0000C000 000000000000000000000000000000</Binary>
</EventData>
</Event>
4.)
Log Name: System
Source: DnsApi
Date: 4/26/2008 8:11:44 AM
Event ID: 11150
Task Category: None
Level: Warning
Keywords: Classic
User: N/A
Computer: FLYERS16
Description:
The system failed to register network adapter with settings:
Adapter Name : {2BE3D013-4252-4CB3-A3A7-CCCA0A521E07}
Host Name : FLYERS16
Adapter-specific Domain Suffix : hsda.pa.comcast.net
DNS Server list :
192.168.1.1
Sent update to server : <?>
IP Address(es) :
192.168.1.103
The cause of this DNS registration failure was because the DNS update request timed out after being sent to the specified DNS Server. This is probably because the authoritative DNS server for the name being updated is not running.
You can manually retry registration of the network adapter and its settings by typing "ipconfig /registerdns" at the command prompt. If problems still persist, contact your network systems administrator to verify network conditions.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="DnsApi" />
<EventID Qualifiers="32768">11150</EventID>
<Level>3</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2008-04-26T12:11:44.000Z" />
<EventRecordID>59977</EventRecordID>
<Channel>System</Channel>
<Computer>FLYERS16</Computer>
<Security />
</System>
<EventData>
<Data>{2BE3D013-4252-4CB3-A3A7-CCCA0A521E07}</Data>
<Data>FLYERS16</Data>
<Data>hsda.pa.comcast.net</Data>
<Data> 192.168.1.1</Data>
<Data><?></Data>
<Data>192.168.1.103</Data>
<Data>
</Data>
<Binary>B4050000</Binary>
</EventData>
</Event>