TheRealTimWells
Posts: 24 +0
Hello
I'm have problems accessing any antivirus site and microsoft. I am trying to follow your 5 steps, here are my logs, if I've made a mistake or any other problems please let me know otherwise any help fixing the problem would be much appreciated.
Thanks
Tim
Malwarebytes Anti-Malware (Trial) 1.60.1.1000
www.malwarebytes.org
Database version: v2012.03.10.02
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Ali :: CHANGEME1 [administrator]
Protection: Enabled
3/11/2012 12:28:09 AM
mbam-log-2012-03-11 (00-28-09).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 161070
Time elapsed: 5 minute(s), 26 second(s)
Memory Processes Detected: 2
C:\WINDOWS\system32\A58227\E54A4C.EXE (Worm.AutoRun) -> 348 -> Delete on reboot.
C:\WINDOWS\system32\216C96\V9ED2F9F.EXE (Trojan.Agent) -> 3420 -> Delete on reboot.
Memory Modules Detected: 3
C:\WINDOWS\system32\216C96\krnln.fnr (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\216C96\eAPI.fne (Worm.Autorun) -> Delete on reboot.
C:\WINDOWS\system32\216C96\dp1.fne (Worm.Autorun) -> Delete on reboot.
Registry Keys Detected: 19
HKCR\CLSID\{7952f465-ac46-4a82-b383-870f3784d1cd} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{5D79F641-C168-40DF-A32F-BACEA7509E75} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{5D79F641-C168-40DF-A32F-BACEA7509E75} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{A0154E07-2B48-475C-A82A-80EFD84EA33E} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{A0154E07-2B48-475C-A82A-80EFD84EA33E} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{AB56DFDE-0C14-45B3-9DF6-7B0EBA617870} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{AB56DFDE-0C14-45B3-9DF6-7B0EBA617870} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{C98D5B61-B0EA-4D48-9839-1079D352D880} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C98D5B61-B0EA-4D48-9839-1079D352D880} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{CB41FC95-F1B3-4797-8BB6-1012FF62ABBA} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{CB41FC95-F1B3-4797-8BB6-1012FF62ABBA} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{DF22384F-CF68-4D19-969F-10423715528B} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF22384F-CF68-4D19-969F-10423715528B} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{04D2B915-19FF-41E9-994D-95DC898BEA43} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{0696F815-A3A9-490A-BB14-9EC3350B1276} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{8A7D2060-824D-4B17-B00A-759B1B5F30D9} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{F02C0832-C85C-4B93-8C6F-9DF20121A10D} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d09094b3-b426-4f16-a6d9-e211fe222127} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7895609d-c8b4-4cf5-a2c7-28223d0c3d92} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
Registry Values Detected: 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|E54A4C (Worm.AutoRun) -> Data: C:\WINDOWS\system32\A58227\E54A4C.EXE -> Quarantined and deleted successfully.
Registry Data Items Detected: 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL|CheckedValue (PUM.Hijack.System.Hidden) -> Bad: (0) Good: (1) -> Quarantined and repaired successfully.
Folders Detected: 1
C:\Documents and Settings\Ali\Local Settings\Temp\E_N4 (Worm.Autorun) -> Delete on reboot.
Files Detected: 22
C:\WINDOWS\system32\A58227\E54A4C.EXE (Worm.AutoRun) -> Delete on reboot.
C:\Documents and Settings\Ali\Local Settings\Temp\E_N4\krnln.fnr (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\Ali\Local Settings\Temp\E_N4\HtmlView.fne (HackTool.Patcher) -> Delete on reboot.
C:\Documents and Settings\Ali\Local Settings\Temp\E_N4\shell.fne (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\Ali\Local Settings\Temp\E_N4\dp1.fne (Worm.Autorun) -> Delete on reboot.
C:\Documents and Settings\Ali\Local Settings\Temp\E_N4\eAPI.fne (Worm.Autorun) -> Delete on reboot.
C:\Documents and Settings\Ali\Local Settings\Temp\E_N4\internet.fne (HackTool.Patcher) -> Delete on reboot.
C:\WINDOWS\system32\216C96\V9ED2F9F.EXE (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\216C96\krnln.fnr (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\216C96\eAPI.fne (Worm.Autorun) -> Delete on reboot.
C:\WINDOWS\system32\216C96\dp1.fne (Worm.Autorun) -> Delete on reboot.
C:\Program Files\14res.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\14Uninstall TotalRecipeSearch.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\2bres.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\2bUninstall BetterCareerSearch.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\64res.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\64Uninstall TelevisionFanatic.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\Ali\Local Settings\Temp\E_N4\cnvpe.fne (Worm.Autorun) -> Quarantined and deleted successfully.
C:\Program Files\14res.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Program Files\2bres.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Program Files\64res.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Documents and Settings\Ali\Local Settings\Temp\E_N4\spec.fne (Worm.Autorun) -> Delete on reboot.
(end)
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit quick scan 2012-03-11 01:07:10
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 WDC_WD1600BEVT-24A23T0 rev.01.01A02
Running: wnn3s7c3.exe; Driver: C:\DOCUME~1\Ali\LOCALS~1\Temp\fwdcapog.sys
---- Services - GMER 1.0.15 ----
Service C:\WINDOWS\system32\svchost.exe (*** hidden *** ) [AUTO] apxqn <-- ROOTKIT !!!
Service C:\WINDOWS\system32\svchost.exe (*** hidden *** ) [AUTO] blzjtmx <-- ROOTKIT !!!
Service C:\WINDOWS\system32\svchost.exe (*** hidden *** ) [AUTO] wofflzn <-- ROOTKIT !!!
---- EOF - GMER 1.0.15 ----
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by Ali at 1:17:09 on 2012-03-11
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.516 [GMT 13:00]
.
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\PROGRA~1\Lenovo\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Lenovo\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Ali\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Ali\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.7227.1100\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [Google Update] "c:\documents and settings\ali\local settings\application data\google\update\GoogleUpdate.exe" /c
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
dRunOnce: [IE8] rundll32 advpack.dll,LaunchINFSection IE8.INF,FirstUserStart
dRunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32
StartupFolder: c:\docume~1\ali\startm~1\programs\startup\e54a4c.lnk - c:\windows\system32\a58227\E54A4C.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\lenovo\bluetooth software\BTTray.exe
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
IE: Send to &Bluetooth Device... - c:\program files\lenovo\bluetooth software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\lenovo\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\lenovo\bluetooth software\btsendto_ie.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} - hxxp://www.caminova.net/en/downloads/getmodule.aspx?lang=en
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\wpdshserviceobj.dll
.
============= SERVICES / DRIVERS ===============
.
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2012-3-11 652360]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-3-11 20464]
S2 apxqn;Time Shell;c:\windows\system32\svchost.exe -k netsvcs [2008-4-15 14336]
S2 blzjtmx;Config System;c:\windows\system32\svchost.exe -k netsvcs [2008-4-15 14336]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-4-26 136176]
S2 wofflzn;Task Universal;c:\windows\system32\svchost.exe -k netsvcs [2008-4-15 14336]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2011-3-20 1691480]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-4-26 136176]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\drivers\rtsustor.sys --> c:\windows\system32\drivers\RtsUStor.sys [?]
S3 RtsUIR;Realtek IR Driver;c:\windows\system32\drivers\rts516xir.sys --> c:\windows\system32\drivers\Rts516xIR.sys [?]
.
=============== Created Last 30 ================
.
2012-03-10 11:25:35 -------- d-----w- c:\documents and settings\ali\application data\Malwarebytes
2012-03-10 11:25:29 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2012-03-10 11:25:28 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-03-10 11:25:27 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-02-26 20:52:46 -------- d--h--w- c:\windows\system32\CF6B60
2012-02-26 20:52:46 -------- d--h--w- c:\windows\system32\A58227
2012-02-26 20:52:46 -------- d--h--w- c:\windows\system32\216C96
2012-02-26 20:52:46 -------- d--h--w- c:\windows\system32\18CB3B
2012-02-25 02:39:25 -------- d-----w- c:\program files\CCleaner
2012-02-25 02:25:46 -------- d-----w- c:\documents and settings\ali\local settings\application data\WMTools Downloaded Files
2012-02-19 20:53:03 -------- d-----w- c:\documents and settings\ali\application data\Foxit Software
2012-02-09 21:21:13 -------- d-----w- c:\program files\Foxit Software
2012-02-09 21:13:46 -------- d-----w- c:\program files\Installs
.
==================== Find3M ====================
.
.
============= FINISH: 1:23:30.93 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 3/21/2011 8:11:58 AM
System Uptime: 3/11/2012 12:53:40 AM (1 hours ago)
.
Motherboard: LENOVO | | Mariana2
Processor: Intel(R) Atom(TM) CPU N270 @ 1.60GHz | CPU | 798/533mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 149 GiB total, 127.989 GiB free.
.
==== Disabled Device Manager Items =============
.
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Intel(R) WiFi Link 5100 AGN
Device ID: PCI\VEN_8086&DEV_4237&SUBSYS_12118086&REV_00\4&20975680&0&00E1
Manufacturer: Intel Corporation
Name: Intel(R) WiFi Link 5100 AGN
PNP Device ID: PCI\VEN_8086&DEV_4237&SUBSYS_12118086&REV_00\4&20975680&0&00E1
Service: NETw5x32
.
Class GUID:
Description:
Device ID: ACPI\VPC2004\0
Manufacturer:
Name:
PNP Device ID: ACPI\VPC2004\0
Service:
.
==== System Restore Points ===================
.
RP53: 12/13/2011 3:28:58 PM - System Checkpoint
RP54: 12/15/2011 12:23:05 PM - System Checkpoint
RP55: 12/22/2011 11:50:35 AM - System Checkpoint
RP56: 2/1/2012 2:52:21 PM - System Checkpoint
RP57: 2/3/2012 11:08:40 AM - System Checkpoint
RP58: 2/7/2012 9:49:14 AM - System Checkpoint
RP59: 2/9/2012 10:55:54 AM - System Checkpoint
RP60: 2/10/2012 2:40:54 PM - System Checkpoint
RP61: 2/14/2012 11:01:03 AM - System Checkpoint
RP62: 2/16/2012 9:26:04 AM - System Checkpoint
RP63: 2/20/2012 11:27:07 AM - System Checkpoint
RP64: 2/20/2012 3:09:20 PM - Unsigned driver install
RP65: 2/20/2012 3:11:50 PM - Unsigned driver install
RP66: 2/20/2012 3:35:17 PM - Unsigned driver install
RP67: 2/22/2012 2:52:25 PM - System Checkpoint
RP68: 2/24/2012 11:18:38 AM - System Checkpoint
RP69: 2/26/2012 6:03:04 PM - System Checkpoint
RP70: 3/2/2012 6:46:15 PM - System Checkpoint
RP71: 3/6/2012 10:31:34 AM - System Checkpoint
RP72: 3/9/2012 9:57:28 AM - System Checkpoint
.
==== Installed Programs ======================
.
Adobe Flash Player 11 ActiveX
CCleaner
Document Express DjVu Plug-in (autoinstall)
Foxit Reader 5.1
GIMP 2.6.11
Google Chrome
Google Toolbar for Internet Explorer
Google Update Helper
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Intel(R) Graphics Media Accelerator Driver
Java Auto Updater
Java(TM) 6 Update 24
Lenovo Bluetooth with Enhanced Data Rate Software
Malwarebytes Anti-Malware version 1.60.1.1000
MSN
REALTEK GbE & FE Ethernet PCI-E NIC Driver
Realtek High Definition Audio Driver
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB941569)
Sereby's Updatepack - IE8 Addon Version 1.0.7
USB2.0 Card Reader Software
VLC media player 1.1.9
WebFldrs XP
Windows Driver Package - Intel (NETw5x32) net (11/17/2008 12.2.0.11)
Windows Driver Package - Intel (w29n51) net (12/19/2007 9.0.4.39)
.
==== Event Viewer Messages From Past Week ========
.
3/8/2012 9:05:12 AM, error: Tcpip [4199] - The system detected an address conflict for IP address 192.168.1.7 with the system having network hardware address 78:A3:E4:C1:B6:57. Network operations on this system may be disrupted as a result.
3/6/2012 2:16:23 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the stisvc service.
3/5/2012 9:32:51 AM, error: Service Control Manager [7023] - The Time Shell service terminated with the following error: A dynamic link library (DLL) initialization routine failed.
3/5/2012 9:32:51 AM, error: Service Control Manager [7023] - The Task Universal service terminated with the following error: A dynamic link library (DLL) initialization routine failed.
3/5/2012 9:32:51 AM, error: Service Control Manager [7023] - The Config System service terminated with the following error: A dynamic link library (DLL) initialization routine failed.
3/5/2012 9:32:51 AM, error: Service Control Manager [7000] - The Parallel port driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
3/11/2012 12:51:16 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Fips intelppm
3/11/2012 12:50:07 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
3/11/2012 12:36:57 AM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.
3/10/2012 11:55:19 PM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service BITS with arguments "" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}
.
==== End Of File ===========================
I'm have problems accessing any antivirus site and microsoft. I am trying to follow your 5 steps, here are my logs, if I've made a mistake or any other problems please let me know otherwise any help fixing the problem would be much appreciated.
Thanks
Tim
Malwarebytes Anti-Malware (Trial) 1.60.1.1000
www.malwarebytes.org
Database version: v2012.03.10.02
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Ali :: CHANGEME1 [administrator]
Protection: Enabled
3/11/2012 12:28:09 AM
mbam-log-2012-03-11 (00-28-09).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 161070
Time elapsed: 5 minute(s), 26 second(s)
Memory Processes Detected: 2
C:\WINDOWS\system32\A58227\E54A4C.EXE (Worm.AutoRun) -> 348 -> Delete on reboot.
C:\WINDOWS\system32\216C96\V9ED2F9F.EXE (Trojan.Agent) -> 3420 -> Delete on reboot.
Memory Modules Detected: 3
C:\WINDOWS\system32\216C96\krnln.fnr (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\216C96\eAPI.fne (Worm.Autorun) -> Delete on reboot.
C:\WINDOWS\system32\216C96\dp1.fne (Worm.Autorun) -> Delete on reboot.
Registry Keys Detected: 19
HKCR\CLSID\{7952f465-ac46-4a82-b383-870f3784d1cd} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{5D79F641-C168-40DF-A32F-BACEA7509E75} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{5D79F641-C168-40DF-A32F-BACEA7509E75} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{A0154E07-2B48-475C-A82A-80EFD84EA33E} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{A0154E07-2B48-475C-A82A-80EFD84EA33E} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{AB56DFDE-0C14-45B3-9DF6-7B0EBA617870} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{AB56DFDE-0C14-45B3-9DF6-7B0EBA617870} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{C98D5B61-B0EA-4D48-9839-1079D352D880} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C98D5B61-B0EA-4D48-9839-1079D352D880} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{CB41FC95-F1B3-4797-8BB6-1012FF62ABBA} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{CB41FC95-F1B3-4797-8BB6-1012FF62ABBA} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{DF22384F-CF68-4D19-969F-10423715528B} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF22384F-CF68-4D19-969F-10423715528B} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{04D2B915-19FF-41E9-994D-95DC898BEA43} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{0696F815-A3A9-490A-BB14-9EC3350B1276} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{8A7D2060-824D-4B17-B00A-759B1B5F30D9} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{F02C0832-C85C-4B93-8C6F-9DF20121A10D} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d09094b3-b426-4f16-a6d9-e211fe222127} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7895609d-c8b4-4cf5-a2c7-28223d0c3d92} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
Registry Values Detected: 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|E54A4C (Worm.AutoRun) -> Data: C:\WINDOWS\system32\A58227\E54A4C.EXE -> Quarantined and deleted successfully.
Registry Data Items Detected: 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL|CheckedValue (PUM.Hijack.System.Hidden) -> Bad: (0) Good: (1) -> Quarantined and repaired successfully.
Folders Detected: 1
C:\Documents and Settings\Ali\Local Settings\Temp\E_N4 (Worm.Autorun) -> Delete on reboot.
Files Detected: 22
C:\WINDOWS\system32\A58227\E54A4C.EXE (Worm.AutoRun) -> Delete on reboot.
C:\Documents and Settings\Ali\Local Settings\Temp\E_N4\krnln.fnr (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\Ali\Local Settings\Temp\E_N4\HtmlView.fne (HackTool.Patcher) -> Delete on reboot.
C:\Documents and Settings\Ali\Local Settings\Temp\E_N4\shell.fne (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\Ali\Local Settings\Temp\E_N4\dp1.fne (Worm.Autorun) -> Delete on reboot.
C:\Documents and Settings\Ali\Local Settings\Temp\E_N4\eAPI.fne (Worm.Autorun) -> Delete on reboot.
C:\Documents and Settings\Ali\Local Settings\Temp\E_N4\internet.fne (HackTool.Patcher) -> Delete on reboot.
C:\WINDOWS\system32\216C96\V9ED2F9F.EXE (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\216C96\krnln.fnr (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\216C96\eAPI.fne (Worm.Autorun) -> Delete on reboot.
C:\WINDOWS\system32\216C96\dp1.fne (Worm.Autorun) -> Delete on reboot.
C:\Program Files\14res.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\14Uninstall TotalRecipeSearch.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\2bres.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\2bUninstall BetterCareerSearch.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\64res.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\64Uninstall TelevisionFanatic.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\Ali\Local Settings\Temp\E_N4\cnvpe.fne (Worm.Autorun) -> Quarantined and deleted successfully.
C:\Program Files\14res.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Program Files\2bres.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Program Files\64res.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Documents and Settings\Ali\Local Settings\Temp\E_N4\spec.fne (Worm.Autorun) -> Delete on reboot.
(end)
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit quick scan 2012-03-11 01:07:10
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 WDC_WD1600BEVT-24A23T0 rev.01.01A02
Running: wnn3s7c3.exe; Driver: C:\DOCUME~1\Ali\LOCALS~1\Temp\fwdcapog.sys
---- Services - GMER 1.0.15 ----
Service C:\WINDOWS\system32\svchost.exe (*** hidden *** ) [AUTO] apxqn <-- ROOTKIT !!!
Service C:\WINDOWS\system32\svchost.exe (*** hidden *** ) [AUTO] blzjtmx <-- ROOTKIT !!!
Service C:\WINDOWS\system32\svchost.exe (*** hidden *** ) [AUTO] wofflzn <-- ROOTKIT !!!
---- EOF - GMER 1.0.15 ----
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by Ali at 1:17:09 on 2012-03-11
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.516 [GMT 13:00]
.
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\PROGRA~1\Lenovo\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Lenovo\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Ali\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Ali\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.7227.1100\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [Google Update] "c:\documents and settings\ali\local settings\application data\google\update\GoogleUpdate.exe" /c
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
dRunOnce: [IE8] rundll32 advpack.dll,LaunchINFSection IE8.INF,FirstUserStart
dRunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32
StartupFolder: c:\docume~1\ali\startm~1\programs\startup\e54a4c.lnk - c:\windows\system32\a58227\E54A4C.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\lenovo\bluetooth software\BTTray.exe
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
IE: Send to &Bluetooth Device... - c:\program files\lenovo\bluetooth software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\lenovo\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\lenovo\bluetooth software\btsendto_ie.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} - hxxp://www.caminova.net/en/downloads/getmodule.aspx?lang=en
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\wpdshserviceobj.dll
.
============= SERVICES / DRIVERS ===============
.
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2012-3-11 652360]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-3-11 20464]
S2 apxqn;Time Shell;c:\windows\system32\svchost.exe -k netsvcs [2008-4-15 14336]
S2 blzjtmx;Config System;c:\windows\system32\svchost.exe -k netsvcs [2008-4-15 14336]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-4-26 136176]
S2 wofflzn;Task Universal;c:\windows\system32\svchost.exe -k netsvcs [2008-4-15 14336]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2011-3-20 1691480]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-4-26 136176]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\drivers\rtsustor.sys --> c:\windows\system32\drivers\RtsUStor.sys [?]
S3 RtsUIR;Realtek IR Driver;c:\windows\system32\drivers\rts516xir.sys --> c:\windows\system32\drivers\Rts516xIR.sys [?]
.
=============== Created Last 30 ================
.
2012-03-10 11:25:35 -------- d-----w- c:\documents and settings\ali\application data\Malwarebytes
2012-03-10 11:25:29 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2012-03-10 11:25:28 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-03-10 11:25:27 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-02-26 20:52:46 -------- d--h--w- c:\windows\system32\CF6B60
2012-02-26 20:52:46 -------- d--h--w- c:\windows\system32\A58227
2012-02-26 20:52:46 -------- d--h--w- c:\windows\system32\216C96
2012-02-26 20:52:46 -------- d--h--w- c:\windows\system32\18CB3B
2012-02-25 02:39:25 -------- d-----w- c:\program files\CCleaner
2012-02-25 02:25:46 -------- d-----w- c:\documents and settings\ali\local settings\application data\WMTools Downloaded Files
2012-02-19 20:53:03 -------- d-----w- c:\documents and settings\ali\application data\Foxit Software
2012-02-09 21:21:13 -------- d-----w- c:\program files\Foxit Software
2012-02-09 21:13:46 -------- d-----w- c:\program files\Installs
.
==================== Find3M ====================
.
.
============= FINISH: 1:23:30.93 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 3/21/2011 8:11:58 AM
System Uptime: 3/11/2012 12:53:40 AM (1 hours ago)
.
Motherboard: LENOVO | | Mariana2
Processor: Intel(R) Atom(TM) CPU N270 @ 1.60GHz | CPU | 798/533mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 149 GiB total, 127.989 GiB free.
.
==== Disabled Device Manager Items =============
.
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Intel(R) WiFi Link 5100 AGN
Device ID: PCI\VEN_8086&DEV_4237&SUBSYS_12118086&REV_00\4&20975680&0&00E1
Manufacturer: Intel Corporation
Name: Intel(R) WiFi Link 5100 AGN
PNP Device ID: PCI\VEN_8086&DEV_4237&SUBSYS_12118086&REV_00\4&20975680&0&00E1
Service: NETw5x32
.
Class GUID:
Description:
Device ID: ACPI\VPC2004\0
Manufacturer:
Name:
PNP Device ID: ACPI\VPC2004\0
Service:
.
==== System Restore Points ===================
.
RP53: 12/13/2011 3:28:58 PM - System Checkpoint
RP54: 12/15/2011 12:23:05 PM - System Checkpoint
RP55: 12/22/2011 11:50:35 AM - System Checkpoint
RP56: 2/1/2012 2:52:21 PM - System Checkpoint
RP57: 2/3/2012 11:08:40 AM - System Checkpoint
RP58: 2/7/2012 9:49:14 AM - System Checkpoint
RP59: 2/9/2012 10:55:54 AM - System Checkpoint
RP60: 2/10/2012 2:40:54 PM - System Checkpoint
RP61: 2/14/2012 11:01:03 AM - System Checkpoint
RP62: 2/16/2012 9:26:04 AM - System Checkpoint
RP63: 2/20/2012 11:27:07 AM - System Checkpoint
RP64: 2/20/2012 3:09:20 PM - Unsigned driver install
RP65: 2/20/2012 3:11:50 PM - Unsigned driver install
RP66: 2/20/2012 3:35:17 PM - Unsigned driver install
RP67: 2/22/2012 2:52:25 PM - System Checkpoint
RP68: 2/24/2012 11:18:38 AM - System Checkpoint
RP69: 2/26/2012 6:03:04 PM - System Checkpoint
RP70: 3/2/2012 6:46:15 PM - System Checkpoint
RP71: 3/6/2012 10:31:34 AM - System Checkpoint
RP72: 3/9/2012 9:57:28 AM - System Checkpoint
.
==== Installed Programs ======================
.
Adobe Flash Player 11 ActiveX
CCleaner
Document Express DjVu Plug-in (autoinstall)
Foxit Reader 5.1
GIMP 2.6.11
Google Chrome
Google Toolbar for Internet Explorer
Google Update Helper
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Intel(R) Graphics Media Accelerator Driver
Java Auto Updater
Java(TM) 6 Update 24
Lenovo Bluetooth with Enhanced Data Rate Software
Malwarebytes Anti-Malware version 1.60.1.1000
MSN
REALTEK GbE & FE Ethernet PCI-E NIC Driver
Realtek High Definition Audio Driver
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB941569)
Sereby's Updatepack - IE8 Addon Version 1.0.7
USB2.0 Card Reader Software
VLC media player 1.1.9
WebFldrs XP
Windows Driver Package - Intel (NETw5x32) net (11/17/2008 12.2.0.11)
Windows Driver Package - Intel (w29n51) net (12/19/2007 9.0.4.39)
.
==== Event Viewer Messages From Past Week ========
.
3/8/2012 9:05:12 AM, error: Tcpip [4199] - The system detected an address conflict for IP address 192.168.1.7 with the system having network hardware address 78:A3:E4:C1:B6:57. Network operations on this system may be disrupted as a result.
3/6/2012 2:16:23 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the stisvc service.
3/5/2012 9:32:51 AM, error: Service Control Manager [7023] - The Time Shell service terminated with the following error: A dynamic link library (DLL) initialization routine failed.
3/5/2012 9:32:51 AM, error: Service Control Manager [7023] - The Task Universal service terminated with the following error: A dynamic link library (DLL) initialization routine failed.
3/5/2012 9:32:51 AM, error: Service Control Manager [7023] - The Config System service terminated with the following error: A dynamic link library (DLL) initialization routine failed.
3/5/2012 9:32:51 AM, error: Service Control Manager [7000] - The Parallel port driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
3/11/2012 12:51:16 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Fips intelppm
3/11/2012 12:50:07 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
3/11/2012 12:36:57 AM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.
3/10/2012 11:55:19 PM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service BITS with arguments "" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}
.
==== End Of File ===========================