Jump to content

Recommended Posts

  • Staff

What is WebWatcher?

The Malwarebytes research team has determined that WebWatcher is adware. These adware applications display advertisements not originating from the sites you are browsing.

This one is a LSP hijacker.

How do I know if my computer is affected by WebWatcher?

You may see this entry in your list of installed programs:

warning4.png

How did WebWatcher get on my computer?

Adware applications use different methods for distributing themselves. This particular one was bundled with other software.

How do I remove WebWatcher?

Our program Malwarebytes Anti-Malware can detect and remove this potentially unwanted program.

  • Please download Malwarebytes Anti-Malware to your desktop.
  • Double-click mbam-setup-version.exe and follow the prompts to install the program.
  • At the end, be sure a check-mark is placed next to the following:
    • Enable free trial of Malwarebytes Anti-Malware Premium
    • Launch Malwarebytes Anti-Malware
  • Then click Finish.
  • If an update is found, you will be prompted to download and install the latest version.
  • Once the program has loaded, select Scan now. Or select the Threat Scan from the Scan menu.
  • When the scan is complete , make sure that everything is set to "Quarantine", and click Apply Actions.
  • Reboot your computer if prompted.
Is there anything else I need to do to get rid of WebWatcher?
  • No, Malwarebytes' Anti-Malware removes WebWatcher completely.
How would the full version of Malwarebytes Anti-Malware help protect me?

We hope our application and this guide have helped you eradicate this hijacker.

As you can see below the full version of Malwarebytes Anti-Malware would have protected you against the WebWatcher adware. �It would have warned you before the rogue could install itself, giving you a chance to stop it before it became too late.

protection1.png

Technical details for experts

You will see these signs in a HijackThis log:

O10 - Unknown file in Winsock LSP: c:\windows\system32\webwatcherlsp.dllO10 - Unknown file in Winsock LSP: c:\windows\system32\webwatcherlsp.dllO10 - Unknown file in Winsock LSP: c:\windows\system32\webwatcherlsp.dllO10 - Unknown file in Winsock LSP: c:\windows\system32\webwatcherlsp.dllO10 - Unknown file in Winsock LSP: c:\windows\system32\webwatcherlsp.dllO23 - Service: WebWatcherProxy - WebWatcher - C:\Program Files\WebWatcher\WebWatcherProxy.exe
Possible signs in FRST logs:

 (WebWatcher) C:\Program Files\WebWatcher\WebWatcherProxy.exe Winsock: Catalog9 01 C:\Windows\system32\WebWatcherLSP.dll [325416] (WebWatcher) Winsock: Catalog9 02 C:\Windows\system32\WebWatcherLSP.dll [325416] (WebWatcher) Winsock: Catalog9 03 C:\Windows\system32\WebWatcherLSP.dll [325416] (WebWatcher) Winsock: Catalog9 04 C:\Windows\system32\WebWatcherLSP.dll [325416] (WebWatcher) Winsock: Catalog9 23 C:\Windows\system32\WebWatcherLSP.dll [325416] (WebWatcher) R2 WebWatcherProxy; C:\Program Files\WebWatcher\WebWatcherProxy.exe [1515608 2015-02-18] (WebWatcher) () C:\Windows\system32\WebWatcherProxy.ini () C:\Windows\system32\WebWatcherProxyOff.ini () C:\Program Files\WebWatcher (WebWatcher) C:\Windows\system32\WebWatcherLSP.dll C:\Users\{username}\AppData\Local\Temp\SpOrder.dllWebWatcher (HKLM\...\WebWatcher) (Version:  - )HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WebWatcherProxy => ""="service"
Alterations made by the installer:

File system details [View: All details] (Selection)---------------------------------------------------    Adds the folder C:\Program Files\WebWatcher       Adds the file freebl3.dll"="8/30/2013 8:11 PM, 303104 bytes, A       Adds the file HealthcareHelp.exe"="2/19/2015 3:04 AM, 111536 bytes, A       Adds the file libnspr4.dll"="8/30/2013 8:11 PM, 295424 bytes, A       Adds the file libplc4.dll"="8/30/2013 8:11 PM, 48640 bytes, A       Adds the file libplds4.dll"="8/30/2013 8:11 PM, 46080 bytes, A       Adds the file nss3.dll"="8/30/2013 8:11 PM, 854528 bytes, A       Adds the file nssckbi.dll"="8/30/2013 8:11 PM, 417280 bytes, A       Adds the file nssdbm3.dll"="8/30/2013 8:11 PM, 164352 bytes, A       Adds the file nssutil3.dll"="8/30/2013 8:11 PM, 135680 bytes, A       Adds the file Run.exe"="1/13/2015 12:17 PM, 53248 bytes, A       Adds the file smime3.dll"="8/30/2013 8:11 PM, 132608 bytes, A       Adds the file softokn3.dll"="8/30/2013 8:11 PM, 230400 bytes, A       Adds the file sqlite3.dll"="8/30/2013 8:11 PM, 455168 bytes, A       Adds the file ssl3.dll"="8/30/2013 8:11 PM, 228352 bytes, A       Adds the file WebWatcherCert.dll"="2/18/2015 10:23 PM, 189248 bytes, A       Adds the file WebWatcherLSP.dll"="2/18/2015 10:22 PM, 325416 bytes, A       Adds the file WebWatcherLSP.exe"="2/18/2015 10:21 PM, 285976 bytes, A       Adds the file WebWatcherLSP64.dll"="2/18/2015 10:22 PM, 370760 bytes, A       Adds the file WebWatcherLSP64.exe"="2/18/2015 10:21 PM, 329680 bytes, A       Adds the file WebWatcherProxy.exe"="2/18/2015 10:20 PM, 1515608 bytes, A       Adds the file WebWatcherProxy.tlb"="2/17/2015 8:16 AM, 52332 bytes, A    In the existing folder C:\Windows\System32       Adds the file WebWatcherLSP.dll"="2/18/2015 10:22 PM, 325416 bytes, A       Adds the file WebWatcherProxy.ini"="4/2/2015 8:20 AM, 4720 bytes, A       Adds the file WebWatcherProxyOff.ini"="4/2/2015 8:20 AM, 2488 bytes, ARegistry details [View: All details] (Selection)------------------------------------------------    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{0BB0FD04-3D80-40B7-9EDA-7FD850F9B0C6}]       "(Default)"="REG_SZ", "WebWatcherProxy"       "InstallingUser"="REG_SZ", "bQBiAGEAbQBwAGMAXABtAGEAbAB3AGEAcgBlAGIAeQB0AGUAcwAAAA=="       "KomodiaParameters1"="REG_DWORD", 0       "LaunchPermission"="REG_BINARY, ..L.\...0................................. ....... ...       "LocalService"="REG_SZ", "WebWatcherProxy"       "ServiceParameters"="REG_SZ", "-Service"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\WebWatcherProxy.EXE]       "AppID"="REG_SZ", "{0BB0FD04-3D80-40B7-9EDA-7FD850F9B0C6}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2936C9CD-1297-403E-8C6D-15A5C7B8982E}]       "(Default)"="REG_SZ", "LSPLogic Class"       "AppID"="REG_SZ", "{0BB0FD04-3D80-40B7-9EDA-7FD850F9B0C6}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2936C9CD-1297-403E-8C6D-15A5C7B8982E}\LocalServer32]       "(Default)"="REG_SZ", ""C:\Program Files\WebWatcher\WebWatcherProxy.exe""    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2936C9CD-1297-403E-8C6D-15A5C7B8982E}\ProgID]       "(Default)"="REG_SZ", "WebWatcherProxyLib.LSPLogic.1"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2936C9CD-1297-403E-8C6D-15A5C7B8982E}\Programmable]    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2936C9CD-1297-403E-8C6D-15A5C7B8982E}\TypeLib]       "(Default)"="REG_SZ", "{260EF2BF-62C5-4313-975E-591A7BFAFB2B}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2936C9CD-1297-403E-8C6D-15A5C7B8982E}\VersionIndependentProgID]       "(Default)"="REG_SZ", "WebWatcherProxyLib.LSPLogic"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{476650C2-69C2-4E54-819E-366614ACC273}]       "(Default)"="REG_SZ", "DataContainer Class"       "AppID"="REG_SZ", "{0BB0FD04-3D80-40B7-9EDA-7FD850F9B0C6}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{476650C2-69C2-4E54-819E-366614ACC273}\LocalServer32]       "(Default)"="REG_SZ", ""C:\Program Files\WebWatcher\WebWatcherProxy.exe""    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{476650C2-69C2-4E54-819E-366614ACC273}\ProgID]       "(Default)"="REG_SZ", "WebWatcherProxyLib.DataContainer.1"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{476650C2-69C2-4E54-819E-366614ACC273}\Programmable]    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{476650C2-69C2-4E54-819E-366614ACC273}\TypeLib]       "(Default)"="REG_SZ", "{260EF2BF-62C5-4313-975E-591A7BFAFB2B}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{476650C2-69C2-4E54-819E-366614ACC273}\VersionIndependentProgID]       "(Default)"="REG_SZ", "WebWatcherProxyLib.DataContainer"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{533403E2-6E21-4615-9E28-43F4E97E977B}]       "(Default)"="REG_SZ", "DataTableFields Class"       "AppID"="REG_SZ", "{0BB0FD04-3D80-40B7-9EDA-7FD850F9B0C6}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{533403E2-6E21-4615-9E28-43F4E97E977B}\LocalServer32]       "(Default)"="REG_SZ", ""C:\Program Files\WebWatcher\WebWatcherProxy.exe""    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{533403E2-6E21-4615-9E28-43F4E97E977B}\ProgID]       "(Default)"="REG_SZ", "WebWatcherProxyLib.DataTableFields.1"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{533403E2-6E21-4615-9E28-43F4E97E977B}\Programmable]    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{533403E2-6E21-4615-9E28-43F4E97E977B}\TypeLib]       "(Default)"="REG_SZ", "{260EF2BF-62C5-4313-975E-591A7BFAFB2B}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{533403E2-6E21-4615-9E28-43F4E97E977B}\VersionIndependentProgID]       "(Default)"="REG_SZ", "WebWatcherProxyLib.DataTableFields"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{546022DB-DCCB-4A4B-90BE-7943160A6279}]       "(Default)"="REG_SZ", "DataTableHolder Class"       "AppID"="REG_SZ", "{0BB0FD04-3D80-40B7-9EDA-7FD850F9B0C6}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{546022DB-DCCB-4A4B-90BE-7943160A6279}\LocalServer32]       "(Default)"="REG_SZ", ""C:\Program Files\WebWatcher\WebWatcherProxy.exe""    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{546022DB-DCCB-4A4B-90BE-7943160A6279}\ProgID]       "(Default)"="REG_SZ", "WebWatcherProxyLib.DataTableHolder.1"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{546022DB-DCCB-4A4B-90BE-7943160A6279}\Programmable]    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{546022DB-DCCB-4A4B-90BE-7943160A6279}\TypeLib]       "(Default)"="REG_SZ", "{260EF2BF-62C5-4313-975E-591A7BFAFB2B}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{546022DB-DCCB-4A4B-90BE-7943160A6279}\VersionIndependentProgID]       "(Default)"="REG_SZ", "WebWatcherProxyLib.DataTableHolder"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{91596794-049C-4624-BE02-C2C8A60AFC36}]       "(Default)"="REG_SZ", "DataController Class"       "AppID"="REG_SZ", "{0BB0FD04-3D80-40B7-9EDA-7FD850F9B0C6}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{91596794-049C-4624-BE02-C2C8A60AFC36}\LocalServer32]       "(Default)"="REG_SZ", ""C:\Program Files\WebWatcher\WebWatcherProxy.exe""    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{91596794-049C-4624-BE02-C2C8A60AFC36}\ProgID]       "(Default)"="REG_SZ", "WebWatcherProxyLib.DataController.1"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{91596794-049C-4624-BE02-C2C8A60AFC36}\Programmable]    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{91596794-049C-4624-BE02-C2C8A60AFC36}\TypeLib]       "(Default)"="REG_SZ", "{260EF2BF-62C5-4313-975E-591A7BFAFB2B}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{91596794-049C-4624-BE02-C2C8A60AFC36}\VersionIndependentProgID]       "(Default)"="REG_SZ", "WebWatcherProxyLib.DataController"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9C812FE5-C99B-4EB8-83B5-12B33B34A887}]       "(Default)"="REG_SZ", "DataTable Class"       "AppID"="REG_SZ", "{0BB0FD04-3D80-40B7-9EDA-7FD850F9B0C6}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9C812FE5-C99B-4EB8-83B5-12B33B34A887}\LocalServer32]       "(Default)"="REG_SZ", ""C:\Program Files\WebWatcher\WebWatcherProxy.exe""    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9C812FE5-C99B-4EB8-83B5-12B33B34A887}\ProgID]       "(Default)"="REG_SZ", "WebWatcherProxyLib.DataTable.1"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9C812FE5-C99B-4EB8-83B5-12B33B34A887}\Programmable]    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9C812FE5-C99B-4EB8-83B5-12B33B34A887}\TypeLib]       "(Default)"="REG_SZ", "{260EF2BF-62C5-4313-975E-591A7BFAFB2B}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9C812FE5-C99B-4EB8-83B5-12B33B34A887}\VersionIndependentProgID]       "(Default)"="REG_SZ", "WebWatcherProxyLib.DataTable"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A062EFDC-C209-4561-BFF8-B9E8FF4DC03A}]       "(Default)"="REG_SZ", "ReadOnlyManager Class"       "AppID"="REG_SZ", "{0BB0FD04-3D80-40B7-9EDA-7FD850F9B0C6}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A062EFDC-C209-4561-BFF8-B9E8FF4DC03A}\LocalServer32]       "(Default)"="REG_SZ", ""C:\Program Files\WebWatcher\WebWatcherProxy.exe""    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A062EFDC-C209-4561-BFF8-B9E8FF4DC03A}\ProgID]       "(Default)"="REG_SZ", "WebWatcherProxyLib.ReadOnlyManager.1"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A062EFDC-C209-4561-BFF8-B9E8FF4DC03A}\Programmable]    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A062EFDC-C209-4561-BFF8-B9E8FF4DC03A}\TypeLib       "(Default)"="REG_SZ", "{260EF2BF-62C5-4313-975E-591A7BFAFB2B}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A062EFDC-C209-4561-BFF8-B9E8FF4DC03A}\VersionIndependentProgID]       "(Default)"="REG_SZ", "WebWatcherProxyLib.ReadOnlyManager"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DDE6A9EC-8BA0-4BA9-97AB-BB9057D7F40B}]       "(Default)"="REG_SZ", "WatchDog Class"       "AppID"="REG_SZ", "{0BB0FD04-3D80-40B7-9EDA-7FD850F9B0C6}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DDE6A9EC-8BA0-4BA9-97AB-BB9057D7F40B}\LocalServer32]       "(Default)"="REG_SZ", ""C:\Program Files\WebWatcher\WebWatcherProxy.exe""    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DDE6A9EC-8BA0-4BA9-97AB-BB9057D7F40B}\ProgID]       "(Default)"="REG_SZ", "WebWatcherProxyLib.WatchDog.1"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DDE6A9EC-8BA0-4BA9-97AB-BB9057D7F40B}\Programmable]    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DDE6A9EC-8BA0-4BA9-97AB-BB9057D7F40B}\TypeLib]       "(Default)"="REG_SZ", "{260EF2BF-62C5-4313-975E-591A7BFAFB2B}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DDE6A9EC-8BA0-4BA9-97AB-BB9057D7F40B}\VersionIndependentProgID]       "(Default)"="REG_SZ", "WebWatcherProxyLib.WatchDog"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}]       "(Default)"="REG_SZ", "ISSHController"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}\ProxyStubClsid]       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}\ProxyStubClsid32]       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}\TypeLib]       "(Default)"="REG_SZ", "{260EF2BF-62C5-4313-975E-591A7BFAFB2B}"       "Version"="REG_SZ", "1.0"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}]       "(Default)"="REG_SZ", "IDataTableFields"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}\ProxyStubClsid]       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}\ProxyStubClsid32]       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}\TypeLib]       "(Default)"="REG_SZ", "{260EF2BF-62C5-4313-975E-591A7BFAFB2B}"       "Version"="REG_SZ", "1.0"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{28E46C93-A83E-4D7D-BB00-E5C371E65C8B}]       "(Default)"="REG_SZ", "IDataStatistics"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{28E46C93-A83E-4D7D-BB00-E5C371E65C8B}\ProxyStubClsid]       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{28E46C93-A83E-4D7D-BB00-E5C371E65C8B}\ProxyStubClsid32]       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{28E46C93-A83E-4D7D-BB00-E5C371E65C8B}\TypeLib]       "(Default)"="REG_SZ", "{260EF2BF-62C5-4313-975E-591A7BFAFB2B}"       "Version"="REG_SZ", "1.0"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{29554878-0746-47A9-9217-B9F57831CE32}]       "(Default)"="REG_SZ", "IDataContainer"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{29554878-0746-47A9-9217-B9F57831CE32}\ProxyStubClsid]       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{29554878-0746-47A9-9217-B9F57831CE32}\ProxyStubClsid32]       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{29554878-0746-47A9-9217-B9F57831CE32}\TypeLib]       "(Default)"="REG_SZ", "{260EF2BF-62C5-4313-975E-591A7BFAFB2B}"       "Version"="REG_SZ", "1.0"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}]       "(Default)"="REG_SZ", "INATDriver"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}\ProxyStubClsid]       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}\ProxyStubClsid32]       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}\TypeLib]       "(Default)"="REG_SZ", "{260EF2BF-62C5-4313-975E-591A7BFAFB2B}"       "Version"="REG_SZ", "1.0"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{455B1D78-1FC1-4131-889D-35454FD7BFFC}]       "(Default)"="REG_SZ", "ILSPLogic"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{455B1D78-1FC1-4131-889D-35454FD7BFFC}\ProxyStubClsid]       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{455B1D78-1FC1-4131-889D-35454FD7BFFC}\ProxyStubClsid32]       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{455B1D78-1FC1-4131-889D-35454FD7BFFC}\TypeLib]       "(Default)"="REG_SZ", "{260EF2BF-62C5-4313-975E-591A7BFAFB2B}"       "Version"="REG_SZ", "1.0"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4A690BA7-0428-4C60-8B64-BD448D90D16D}]       "(Default)"="REG_SZ", "IDataController"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4A690BA7-0428-4C60-8B64-BD448D90D16D}\ProxyStubClsid]       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4A690BA7-0428-4C60-8B64-BD448D90D16D}\ProxyStubClsid32]       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4A690BA7-0428-4C60-8B64-BD448D90D16D}\TypeLib]       "(Default)"="REG_SZ", "{260EF2BF-62C5-4313-975E-591A7BFAFB2B}"       "Version"="REG_SZ", "1.0"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}]       "(Default)"="REG_SZ", "IWFPController"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}\ProxyStubClsid]       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}\ProxyStubClsid32]       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}\TypeLib]       "(Default)"="REG_SZ", "{260EF2BF-62C5-4313-975E-591A7BFAFB2B}"       "Version"="REG_SZ", "1.0"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}]       "(Default)"="REG_SZ", "IChatControl"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}\ProxyStubClsid]       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}\ProxyStubClsid32]       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}\TypeLib]       "(Default)"="REG_SZ", "{260EF2BF-62C5-4313-975E-591A7BFAFB2B}"       "Version"="REG_SZ", "1.0"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8C7D53D5-33A8-4C92-8C90-D021A7B1217F}]       "(Default)"="REG_SZ", "IDataTable"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8C7D53D5-33A8-4C92-8C90-D021A7B1217F}\ProxyStubClsid]       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8C7D53D5-33A8-4C92-8C90-D021A7B1217F}\ProxyStubClsid32]       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8C7D53D5-33A8-4C92-8C90-D021A7B1217F}\TypeLib]       "(Default)"="REG_SZ", "{260EF2BF-62C5-4313-975E-591A7BFAFB2B}"       "Version"="REG_SZ", "1.0"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}]       "(Default)"="REG_SZ", "IInjector"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}\ProxyStubClsid]       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}\ProxyStubClsid32]       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}\TypeLib]       "(Default)"="REG_SZ", "{260EF2BF-62C5-4313-975E-591A7BFAFB2B}"       "Version"="REG_SZ", "1.0"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{93BE68AB-DE96-4933-92F9-344694EDAD65}]       "(Default)"="REG_SZ", "IWatchDog"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{93BE68AB-DE96-4933-92F9-344694EDAD65}\ProxyStubClsid]       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{93BE68AB-DE96-4933-92F9-344694EDAD65}\ProxyStubClsid32]       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{93BE68AB-DE96-4933-92F9-344694EDAD65}\TypeLib]       "(Default)"="REG_SZ", "{260EF2BF-62C5-4313-975E-591A7BFAFB2B}"       "Version"="REG_SZ", "1.0"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AFE33A6D-3087-418F-88C8-082B72D803CD}]       "(Default)"="REG_SZ", "IParentalControl"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AFE33A6D-3087-418F-88C8-082B72D803CD}\ProxyStubClsid]       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AFE33A6D-3087-418F-88C8-082B72D803CD}\ProxyStubClsid32]       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AFE33A6D-3087-418F-88C8-082B72D803CD}\TypeLib]       "(Default)"="REG_SZ", "{260EF2BF-62C5-4313-975E-591A7BFAFB2B}"       "Version"="REG_SZ", "1.0"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B8E4BFDB-6446-4582-9FCD-745A9CB170AB}]       "(Default)"="REG_SZ", "IProxyChecks"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B8E4BFDB-6446-4582-9FCD-745A9CB170AB}\ProxyStubClsid]       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B8E4BFDB-6446-4582-9FCD-745A9CB170AB}\ProxyStubClsid32]       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B8E4BFDB-6446-4582-9FCD-745A9CB170AB}\TypeLib]       "(Default)"="REG_SZ", "{260EF2BF-62C5-4313-975E-591A7BFAFB2B}"       "Version"="REG_SZ", "1.0"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C1F5E799-B218-4C32-B189-3C389BA140BB}]       "(Default)"="REG_SZ", "IReadOnlyManager"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C1F5E799-B218-4C32-B189-3C389BA140BB}\ProxyStubClsid]       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C1F5E799-B218-4C32-B189-3C389BA140BB}\ProxyStubClsid32]       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C1F5E799-B218-4C32-B189-3C389BA140BB}\TypeLib]       "(Default)"="REG_SZ", "{260EF2BF-62C5-4313-975E-591A7BFAFB2B}"       "Version"="REG_SZ", "1.0"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CC513FE0-7232-471B-B300-16780D81CE06}]       "(Default)"="REG_SZ", "IDataTableHolder"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CC513FE0-7232-471B-B300-16780D81CE06}\ProxyStubClsid]       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CC513FE0-7232-471B-B300-16780D81CE06}\ProxyStubClsid32]       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CC513FE0-7232-471B-B300-16780D81CE06}\TypeLib]       "(Default)"="REG_SZ", "{260EF2BF-62C5-4313-975E-591A7BFAFB2B}"       "Version"="REG_SZ", "1.0"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F60C9408-3110-4C98-A139-ABE1EE1111DD}]       "(Default)"="REG_SZ", "IParentalControlController"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F60C9408-3110-4C98-A139-ABE1EE1111DD}\ProxyStubClsid]       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F60C9408-3110-4C98-A139-ABE1EE1111DD}\ProxyStubClsid32]       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F60C9408-3110-4C98-A139-ABE1EE1111DD}\TypeLib]       "(Default)"="REG_SZ", "{260EF2BF-62C5-4313-975E-591A7BFAFB2B}"       "Version"="REG_SZ", "1.0"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{260EF2BF-62C5-4313-975E-591A7BFAFB2B}\1.0]       "(Default)"="REG_SZ", "WebWatcherProxy 1.0 Type Library"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{260EF2BF-62C5-4313-975E-591A7BFAFB2B}\1.0\0\win32]       "(Default)"="REG_SZ", "C:\Program Files\WebWatcher\WebWatcherProxy.tlb"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{260EF2BF-62C5-4313-975E-591A7BFAFB2B}\1.0\FLAGS]       "(Default)"="REG_SZ", "0"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{260EF2BF-62C5-4313-975E-591A7BFAFB2B}\1.0\HELPDIR]       "(Default)"="REG_SZ", "C:\Program Files\WebWatcher"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebWatcherProxyLib.DataContainer]       "(Default)"="REG_SZ", "DataContainer Class"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebWatcherProxyLib.DataContainer\CLSID]       "(Default)"="REG_SZ", "{476650C2-69C2-4E54-819E-366614ACC273}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebWatcherProxyLib.DataContainer\CurVer]       "(Default)"="REG_SZ", "WebWatcherProxyLib.DataContainer.1"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebWatcherProxyLib.DataContainer.1]       "(Default)"="REG_SZ", "DataContainer Class"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebWatcherProxyLib.DataContainer.1\CLSID]       "(Default)"="REG_SZ", "{476650C2-69C2-4E54-819E-366614ACC273}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebWatcherProxyLib.DataController]       "(Default)"="REG_SZ", "DataController Class"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebWatcherProxyLib.DataController\CLSID]       "(Default)"="REG_SZ", "{91596794-049C-4624-BE02-C2C8A60AFC36}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebWatcherProxyLib.DataController\CurVer]       "(Default)"="REG_SZ", "WebWatcherProxyLib.DataController.1"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebWatcherProxyLib.DataController.1]       "(Default)"="REG_SZ", "DataController Class"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebWatcherProxyLib.DataController.1\CLSID]       "(Default)"="REG_SZ", "{91596794-049C-4624-BE02-C2C8A60AFC36}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebWatcherProxyLib.DataTable]       "(Default)"="REG_SZ", "DataTable Class"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebWatcherProxyLib.DataTable\CLSID]       "(Default)"="REG_SZ", "{9C812FE5-C99B-4EB8-83B5-12B33B34A887}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebWatcherProxyLib.DataTable\CurVer]       "(Default)"="REG_SZ", "WebWatcherProxyLib.DataTable.1"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebWatcherProxyLib.DataTable.1]       "(Default)"="REG_SZ", "DataTable Class"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebWatcherProxyLib.DataTable.1\CLSID]       "(Default)"="REG_SZ", "{9C812FE5-C99B-4EB8-83B5-12B33B34A887}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebWatcherProxyLib.DataTableFields]       "(Default)"="REG_SZ", "DataTableFields Class"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebWatcherProxyLib.DataTableFields\CLSID]       "(Default)"="REG_SZ", "{533403E2-6E21-4615-9E28-43F4E97E977B}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebWatcherProxyLib.DataTableFields\CurVer]       "(Default)"="REG_SZ", "WebWatcherProxyLib.DataTableFields.1"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebWatcherProxyLib.DataTableFields.1]       "(Default)"="REG_SZ", "DataTableFields Class"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebWatcherProxyLib.DataTableFields.1\CLSID]       "(Default)"="REG_SZ", "{533403E2-6E21-4615-9E28-43F4E97E977B}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebWatcherProxyLib.DataTableHolder]       "(Default)"="REG_SZ", "DataTableHolder Class"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebWatcherProxyLib.DataTableHolder\CLSID]       "(Default)"="REG_SZ", "{546022DB-DCCB-4A4B-90BE-7943160A6279}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebWatcherProxyLib.DataTableHolder\CurVer]       "(Default)"="REG_SZ", "WebWatcherProxyLib.DataTableHolder.1"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebWatcherProxyLib.DataTableHolder.1]       "(Default)"="REG_SZ", "DataTableHolder Class"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebWatcherProxyLib.DataTableHolder.1\CLSID]       "(Default)"="REG_SZ", "{546022DB-DCCB-4A4B-90BE-7943160A6279}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebWatcherProxyLib.LSPLogic]       "(Default)"="REG_SZ", "LSPLogic Class"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebWatcherProxyLib.LSPLogic\CLSID]       "(Default)"="REG_SZ", "{2936C9CD-1297-403E-8C6D-15A5C7B8982E}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebWatcherProxyLib.LSPLogic\CurVer]       "(Default)"="REG_SZ", "WebWatcherProxyLib.LSPLogic.1"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebWatcherProxyLib.LSPLogic.1]       "(Default)"="REG_SZ", "LSPLogic Class"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebWatcherProxyLib.LSPLogic.1\CLSID]       "(Default)"="REG_SZ", "{2936C9CD-1297-403E-8C6D-15A5C7B8982E}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebWatcherProxyLib.ReadOnlyManager]       "(Default)"="REG_SZ", "ReadOnlyManager Class"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebWatcherProxyLib.ReadOnlyManager\CLSID]       "(Default)"="REG_SZ", "{A062EFDC-C209-4561-BFF8-B9E8FF4DC03A}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebWatcherProxyLib.ReadOnlyManager\CurVer]       "(Default)"="REG_SZ", "WebWatcherProxyLib.ReadOnlyManager.1"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebWatcherProxyLib.ReadOnlyManager.1]       "(Default)"="REG_SZ", "ReadOnlyManager Class"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebWatcherProxyLib.ReadOnlyManager.1\CLSID]       "(Default)"="REG_SZ", "{A062EFDC-C209-4561-BFF8-B9E8FF4DC03A}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebWatcherProxyLib.WatchDog]       "(Default)"="REG_SZ", "WatchDog Class"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebWatcherProxyLib.WatchDog\CLSID]       "(Default)"="REG_SZ", "{DDE6A9EC-8BA0-4BA9-97AB-BB9057D7F40B}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebWatcherProxyLib.WatchDog\CurVer]       "(Default)"="REG_SZ", "WebWatcherProxyLib.WatchDog.1"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebWatcherProxyLib.WatchDog.1]       "(Default)"="REG_SZ", "WatchDog Class"    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebWatcherProxyLib.WatchDog.1\CLSID]       "(Default)"="REG_SZ", "{DDE6A9EC-8BA0-4BA9-97AB-BB9057D7F40B}"    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WebWatcher]       "DisplayIcon"="REG_SZ", "C:\Program Files\WebWatcher\uninstall.exe"       "DisplayName"="REG_SZ", "WebWatcher"       "NoModify"="REG_DWORD", 1       "NoRepair"="REG_DWORD", 1       "UninstallString"="REG_SZ", "C:\Program Files\WebWatcher\uninstall.exe"    [HKEY_LOCAL_MACHINE\SOFTWARE\WebWatcher]       "Path"="REG_SZ", "C:\Program Files\WebWatcher"    [HKEY_LOCAL_MACHINE\SOFTWARE\WebWatcher\Components]       "Main"="REG_SZ", "1"    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WebWatcherProxy]       "(Default)"="REG_SZ", "service"    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\WebWatcherProxy]       "DependOnService"="REG_MULTI_SZ, "RPCSS "       "DisplayName"="REG_SZ", "WebWatcherProxy"       "ErrorControl"="REG_DWORD", 1       "FailureActions"="REG_BINARY, ......................       "ImagePath"="REG_EXPAND_SZ, "C:\Program Files\WebWatcher\WebWatcherProxy.exe"       "ObjectName"="REG_SZ", "LocalSystem"       "Start"="REG_DWORD", 2       "Type"="REG_DWORD", 16    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\WinSock2\Parameters\AppId_Catalog\0C94089E]       "AppFullPath"="REG_SZ", "C:\Program Files\WebWatcher\WebWatcherProxy.exe"       "PermittedLspCategories"="REG_DWORD", 3840    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\WinSock2\Parameters\AppId_Catalog\0D8BECC7]       "AppFullPath"="REG_SZ", "c:\program files\microsoft visual studio 12.0\common7\ide\devenv.exe"       "PermittedLspCategories"="REG_DWORD", 3840    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\WinSock2\Parameters\AppId_Catalog\134790A4]       "AppFullPath"="REG_SZ", "c:\program Files\microsoft office\office15\lync.exe"       "PermittedLspCategories"="REG_DWORD", 3840    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\WinSock2\Parameters\AppId_Catalog\2159C6D8]       "AppFullPath"="REG_SZ", "c:\program Files\Microsoft Office 15\root\office15\lync.exe"       "PermittedLspCategories"="REG_DWORD", 3840    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\WinSock2\Parameters\AppId_Catalog\2EB3D11A]       "AppFullPath"="REG_SZ", "c:\program files\microsoft sql server\110\tools\binn\managementstudio\ssms.exe"       "PermittedLspCategories"="REG_DWORD", 3840    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\WinSock2\Parameters\AppId_Catalog\31B4C347]       "AppFullPath"="REG_SZ", "C:\Program Files\Microsoft SQL Server\MSSQL11.SQLEXPRESS\MSSQL\Binn\sqlservr.exe"       "PermittedLspCategories"="REG_DWORD", 3840    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9]
Malwarebytes Anti-Malware log:

Malwarebytes Anti-Malwarewww.malwarebytes.orgScan Date: 4/2/2015Scan Time: 8:29:13 AMLogfile: mbamWebWatcher.txtAdministrator: YesVersion: 2.01.0.1004Malware Database: v2015.04.02.02Rootkit Database: v2015.03.31.01License: FreeMalware Protection: DisabledMalicious Website Protection: DisabledSelf-protection: DisabledOS: Windows 7 Service Pack 1CPU: x86File System: NTFSUser: MalwarebytesScan Type: Threat ScanResult: CompletedObjects Scanned: 294264Time Elapsed: 4 min, 18 secMemory: EnabledStartup: EnabledFilesystem: EnabledArchives: EnabledRootkits: DisabledHeuristics: EnabledPUP: EnabledPUM: EnabledProcesses: 1PUP.Optional.Winsock.Hijack, C:\Program Files\WebWatcher\WebWatcherProxy.exe, 576, Delete-on-Reboot, [8149f96e7c0e66d08f34eb533ec4f010]Modules: 14PUP.Optional.Winsock.Hijack, C:\Windows\System32\WebWatcherLSP.dll, Delete-on-Reboot, [b1194a1d24661c1ab70c63dbc33f8e72], PUP.Optional.Winsock.Hijack, C:\Windows\System32\WebWatcherLSP.dll, Delete-on-Reboot, [b1194a1d24661c1ab70c63dbc33f8e72], PUP.Optional.Winsock.Hijack, C:\Windows\System32\WebWatcherLSP.dll, Delete-on-Reboot, [b1194a1d24661c1ab70c63dbc33f8e72], PUP.Optional.Winsock.Hijack, C:\Windows\System32\WebWatcherLSP.dll, Delete-on-Reboot, [b1194a1d24661c1ab70c63dbc33f8e72], PUP.Optional.Winsock.Hijack, C:\Windows\System32\WebWatcherLSP.dll, Delete-on-Reboot, [b1194a1d24661c1ab70c63dbc33f8e72], PUP.Optional.Winsock.Hijack, C:\Windows\System32\WebWatcherLSP.dll, Delete-on-Reboot, [b1194a1d24661c1ab70c63dbc33f8e72], PUP.Optional.Winsock.Hijack, C:\Program Files\WebWatcher\WebWatcherCert.dll, Delete-on-Reboot, [6e5c4f183357142282414ef0cf33669a], PUP.Optional.WebWatcher.A, C:\Program Files\WebWatcher\freebl3.dll, Delete-on-Reboot, [9f2bfa6d800a0234f1a95c592dd6d52b], PUP.Optional.WebWatcher.A, C:\Program Files\WebWatcher\libnspr4.dll, Delete-on-Reboot, [9f2bfa6d800a0234f1a95c592dd6d52b], PUP.Optional.WebWatcher.A, C:\Program Files\WebWatcher\libplc4.dll, Delete-on-Reboot, [9f2bfa6d800a0234f1a95c592dd6d52b], PUP.Optional.WebWatcher.A, C:\Program Files\WebWatcher\libplds4.dll, Delete-on-Reboot, [9f2bfa6d800a0234f1a95c592dd6d52b], PUP.Optional.WebWatcher.A, C:\Program Files\WebWatcher\nss3.dll, Delete-on-Reboot, [9f2bfa6d800a0234f1a95c592dd6d52b], PUP.Optional.WebWatcher.A, C:\Program Files\WebWatcher\nssutil3.dll, Delete-on-Reboot, [9f2bfa6d800a0234f1a95c592dd6d52b], PUP.Optional.WebWatcher.A, C:\Program Files\WebWatcher\smime3.dll, Delete-on-Reboot, [9f2bfa6d800a0234f1a95c592dd6d52b], Registry Keys: 37PUP.Optional.Winsock.Hijack, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WebWatcherProxy, Quarantined, [8149f96e7c0e66d08f34eb533ec4f010], PUP.Optional.WebWatcher.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{260EF2BF-62C5-4313-975E-591A7BFAFB2B}, Quarantined, [9f2bfa6d800a0234f1a95c592dd6d52b], PUP.Optional.WebWatcher.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}, Quarantined, [9f2bfa6d800a0234f1a95c592dd6d52b], PUP.Optional.WebWatcher.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}, Quarantined, [9f2bfa6d800a0234f1a95c592dd6d52b], PUP.Optional.WebWatcher.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{28E46C93-A83E-4D7D-BB00-E5C371E65C8B}, Quarantined, [9f2bfa6d800a0234f1a95c592dd6d52b], PUP.Optional.WebWatcher.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{29554878-0746-47A9-9217-B9F57831CE32}, Quarantined, [9f2bfa6d800a0234f1a95c592dd6d52b], PUP.Optional.WebWatcher.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}, Quarantined, [9f2bfa6d800a0234f1a95c592dd6d52b], PUP.Optional.WebWatcher.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{455B1D78-1FC1-4131-889D-35454FD7BFFC}, Quarantined, [9f2bfa6d800a0234f1a95c592dd6d52b], PUP.Optional.WebWatcher.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{4A690BA7-0428-4C60-8B64-BD448D90D16D}, Quarantined, [9f2bfa6d800a0234f1a95c592dd6d52b], PUP.Optional.WebWatcher.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}, Quarantined, [9f2bfa6d800a0234f1a95c592dd6d52b], PUP.Optional.WebWatcher.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}, Quarantined, [9f2bfa6d800a0234f1a95c592dd6d52b], PUP.Optional.WebWatcher.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{8C7D53D5-33A8-4C92-8C90-D021A7B1217F}, Quarantined, [9f2bfa6d800a0234f1a95c592dd6d52b], PUP.Optional.WebWatcher.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}, Quarantined, [9f2bfa6d800a0234f1a95c592dd6d52b], PUP.Optional.WebWatcher.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{93BE68AB-DE96-4933-92F9-344694EDAD65}, Quarantined, [9f2bfa6d800a0234f1a95c592dd6d52b], PUP.Optional.WebWatcher.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{AFE33A6D-3087-418F-88C8-082B72D803CD}, Quarantined, [9f2bfa6d800a0234f1a95c592dd6d52b], PUP.Optional.WebWatcher.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B8E4BFDB-6446-4582-9FCD-745A9CB170AB}, Quarantined, [9f2bfa6d800a0234f1a95c592dd6d52b], PUP.Optional.WebWatcher.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{C1F5E799-B218-4C32-B189-3C389BA140BB}, Quarantined, [9f2bfa6d800a0234f1a95c592dd6d52b], PUP.Optional.WebWatcher.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{CC513FE0-7232-471B-B300-16780D81CE06}, Quarantined, [9f2bfa6d800a0234f1a95c592dd6d52b], PUP.Optional.WebWatcher.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{F60C9408-3110-4C98-A139-ABE1EE1111DD}, Quarantined, [9f2bfa6d800a0234f1a95c592dd6d52b], PUP.Optional.WebWatcher.A, HKLM\SOFTWARE\CLASSES\WebWatcherProxyLib.DataContainer, Quarantined, [a52580e7a6e42b0bb6e9783da360f60a], PUP.Optional.WebWatcher.A, HKLM\SOFTWARE\CLASSES\WebWatcherProxyLib.DataContainer.1, Quarantined, [7159d5926822999d8f103b7a0cf727d9], PUP.Optional.WebWatcher.A, HKLM\SOFTWARE\CLASSES\WebWatcherProxyLib.DataController, Quarantined, [ab1f1f484644b87eb6e9caeb857ea15f], PUP.Optional.WebWatcher.A, HKLM\SOFTWARE\CLASSES\WebWatcherProxyLib.DataController.1, Quarantined, [ac1e7cebb6d448eea8f7aa0b4bb8926e], PUP.Optional.WebWatcher.A, HKLM\SOFTWARE\CLASSES\WebWatcherProxyLib.DataTable, Quarantined, [5a70ed7acbbf60d6356a30855da6d828], PUP.Optional.WebWatcher.A, HKLM\SOFTWARE\CLASSES\WebWatcherProxyLib.DataTable.1, Quarantined, [36942e3990faf343f9a64075956e32ce], PUP.Optional.WebWatcher.A, HKLM\SOFTWARE\CLASSES\WebWatcherProxyLib.DataTableFields, Quarantined, [7b4f82e58406f541bae55d58d82b3ac6], PUP.Optional.WebWatcher.A, HKLM\SOFTWARE\CLASSES\WebWatcherProxyLib.DataTableFields.1, Quarantined, [eae020474d3d0531049b704536cd1ae6], PUP.Optional.WebWatcher.A, HKLM\SOFTWARE\CLASSES\WebWatcherProxyLib.DataTableHolder, Quarantined, [56748fd8acde1a1c148b3f76857ed729], PUP.Optional.WebWatcher.A, HKLM\SOFTWARE\CLASSES\WebWatcherProxyLib.DataTableHolder.1, Quarantined, [4e7ca7c0d2b84ceaeab5892cfd066d93], PUP.Optional.WebWatcher.A, HKLM\SOFTWARE\CLASSES\WebWatcherProxyLib.LSPLogic, Quarantined, [a32776f1b3d70d29029ddadb0300f907], PUP.Optional.WebWatcher.A, HKLM\SOFTWARE\CLASSES\WebWatcherProxyLib.LSPLogic.1, Quarantined, [f8d283e47a104bebaef12e87c241758b], PUP.Optional.WebWatcher.A, HKLM\SOFTWARE\CLASSES\WebWatcherProxyLib.ReadOnlyManager, Quarantined, [7b4fdb8c5c2e072ff8a7d2e39f649f61], PUP.Optional.WebWatcher.A, HKLM\SOFTWARE\CLASSES\WebWatcherProxyLib.ReadOnlyManager.1, Quarantined, [4882b7b0781265d1544b14a118eb0bf5], PUP.Optional.WebWatcher.A, HKLM\SOFTWARE\CLASSES\WebWatcherProxyLib.WatchDog, Quarantined, [4b7fea7d3555a88eb1ee6a4b1ee53ec2], PUP.Optional.WebWatcher.A, HKLM\SOFTWARE\CLASSES\WebWatcherProxyLib.WatchDog.1, Quarantined, [646682e5fd8ddf57c1def7be3ac945bb], PUP.Optional.WebWatcher.A, HKLM\SOFTWARE\CLASSES\APPID\WebWatcherProxy.EXE, Quarantined, [5c6ed1963e4c72c4b4ea892c14ef2cd4], PUP.Optional.GlobalUpdate.C, HKCU\SOFTWARE\GLOBALUPDATE\UPDATE\PROXY, Quarantined, [71594b1cb4d638fe1a4733834ab9cb35], Registry Values: 3PUP.Optional.GlobalUpdate.C, HKLM\SOFTWARE\GLOBALUPDATE\UPDATEDEV|AuCheckPeriodMs, 21600000, Quarantined, [e6e44b1c8307989ed0f8d3e2ac5704fc]PUP.Optional.WebWatcher.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WEBWATCHERPROXY|ImagePath, C:\Program Files\WebWatcher\WebWatcherProxy.exe, Quarantined, [4e7c4c1ba8e2ea4caaf3219409fa07f9]PUP.Optional.GlobalUpdate.C, HKCU\SOFTWARE\GLOBALUPDATE\UPDATE\PROXY|source, IE, Quarantined, [71594b1cb4d638fe1a4733834ab9cb35]Registry Data: 0(No malicious items detected)Folders: 1PUP.Optional.WebWatcher.A, C:\Program Files\WebWatcher, Delete-on-Reboot, [9f2bfa6d800a0234f1a95c592dd6d52b], Files: 29PUP.Optional.Winsock.Hijack, C:\Windows\System32\WebWatcherLSP.dll, Delete-on-Reboot, [b1194a1d24661c1ab70c63dbc33f8e72], PUP.Optional.Winsock.Hijack, C:\Program Files\WebWatcher\WebWatcherProxy.exe, Delete-on-Reboot, [8149f96e7c0e66d08f34eb533ec4f010], PUP.Optional.Winsock.Hijack, C:\Program Files\WebWatcher\WebWatcherCert.dll, Delete-on-Reboot, [6e5c4f183357142282414ef0cf33669a], PUP.Optional.WebWatcher.A, C:\Users\{username}\Desktop\WebWatcherProxy.exe, Quarantined, [06c492d5e9a15cda57af2cc211f4b24e], PUP.Optional.Winsock.Hijack, C:\Program Files\WebWatcher\WebWatcherLSP.dll, Quarantined, [13b768ff85057cba566dad91e61ce020], PUP.Optional.Winsock.Hijack, C:\Program Files\WebWatcher\WebWatcherLSP.exe, Quarantined, [c604adbaf09a5fd79033fd4144bef808], PUP.Optional.Winsock.Hijack, C:\Program Files\WebWatcher\WebWatcherLSP64.dll, Quarantined, [6a60184f4f3b082eead9f34bb64cec14], PUP.Optional.Winsock.Hijack, C:\Program Files\WebWatcher\WebWatcherLSP64.exe, Quarantined, [fbcf94d3b5d5ca6c5c67033b837fb64a], PUP.Optional.WebWatcher.A, C:\Users\{username}\AppData\Local\Temp\WebWatcherLSP.ini.log, Quarantined, [319972f57119de582a696550da292ad6], PUP.Optional.WebWatcher.A, C:\Users\{username}\AppData\Local\Temp\WebWatcherProxyr.log, Quarantined, [f5d506619bef74c2841011a4659eab55], PUP.Optional.WebWatcher.A, C:\Windows\Temp\WebWatcherProxyr.log, Quarantined, [ffcbee79b7d3e94d5044cbea0300fe02], PUP.Optional.WebWatcher.A, C:\Windows\Temp\WebWatcherProxy.log, Delete-on-Reboot, [3e8c96d12b5fd660563f8431788b847c], PUP.Optional.WebWatcher.A, C:\Windows\System32\WebWatcherProxy.ini, Quarantined, [408aef78038784b20890565f62a1ea16], PUP.Optional.WebWatcher.A, C:\Windows\System32\WebWatcherProxyOff.ini, Quarantined, [8842adba9af0c2749306c4f1768d867a], PUP.Optional.WebWatcher.A, C:\Program Files\WebWatcher\WebWatcherProxy.tlb, Quarantined, [9f2bfa6d800a0234f1a95c592dd6d52b], PUP.Optional.WebWatcher.A, C:\Program Files\WebWatcher\freebl3.dll, Delete-on-Reboot, [9f2bfa6d800a0234f1a95c592dd6d52b], PUP.Optional.WebWatcher.A, C:\Program Files\WebWatcher\HealthcareHelp.exe, Quarantined, [9f2bfa6d800a0234f1a95c592dd6d52b], PUP.Optional.WebWatcher.A, C:\Program Files\WebWatcher\libnspr4.dll, Delete-on-Reboot, [9f2bfa6d800a0234f1a95c592dd6d52b], PUP.Optional.WebWatcher.A, C:\Program Files\WebWatcher\libplc4.dll, Delete-on-Reboot, [9f2bfa6d800a0234f1a95c592dd6d52b], PUP.Optional.WebWatcher.A, C:\Program Files\WebWatcher\libplds4.dll, Delete-on-Reboot, [9f2bfa6d800a0234f1a95c592dd6d52b], PUP.Optional.WebWatcher.A, C:\Program Files\WebWatcher\nss3.dll, Delete-on-Reboot, [9f2bfa6d800a0234f1a95c592dd6d52b], PUP.Optional.WebWatcher.A, C:\Program Files\WebWatcher\nssckbi.dll, Quarantined, [9f2bfa6d800a0234f1a95c592dd6d52b], PUP.Optional.WebWatcher.A, C:\Program Files\WebWatcher\nssdbm3.dll, Quarantined, [9f2bfa6d800a0234f1a95c592dd6d52b], PUP.Optional.WebWatcher.A, C:\Program Files\WebWatcher\nssutil3.dll, Delete-on-Reboot, [9f2bfa6d800a0234f1a95c592dd6d52b], PUP.Optional.WebWatcher.A, C:\Program Files\WebWatcher\Run.exe, Quarantined, [9f2bfa6d800a0234f1a95c592dd6d52b], PUP.Optional.WebWatcher.A, C:\Program Files\WebWatcher\smime3.dll, Delete-on-Reboot, [9f2bfa6d800a0234f1a95c592dd6d52b], PUP.Optional.WebWatcher.A, C:\Program Files\WebWatcher\softokn3.dll, Quarantined, [9f2bfa6d800a0234f1a95c592dd6d52b], PUP.Optional.WebWatcher.A, C:\Program Files\WebWatcher\sqlite3.dll, Quarantined, [9f2bfa6d800a0234f1a95c592dd6d52b], PUP.Optional.WebWatcher.A, C:\Program Files\WebWatcher\ssl3.dll, Quarantined, [9f2bfa6d800a0234f1a95c592dd6d52b], Physical Sectors: 0(No malicious items detected)(end)
As mentioned before the full version of Malwarebytes Anti-Malware could have protected your computer against this threat.

We use different ways of protecting your computer(s):

  • Dynamically Blocks Malware Sites & Servers
  • Malware Execution Prevention
Save yourself the hassle and get protected.
Link to post
Share on other sites

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.