Jump to content


Photo

Gifted computer, checking if clean. Thanks!


  • This topic is locked This topic is locked
17 replies to this topic

#1 TimmU

TimmU

    Advanced Member

  • Full Member
  • PipPipPip
  • 158 posts

Posted 02 April 2012 - 03:15 PM

Hey guys. Thanks for the help in advance.

Running Windows XP.

Someone gave me this used computer and now im trying to make sure it's clean. I've run MBAM and spybot. Everything came out clean. Also installed avira and it did an initial scan and it was clean.

So now now im just double checking here to make sure it really is clean.

- The computer did have some porn on it. And lots of music. And lots of games. - I've deleted most as I can.

- The computer has this nagging windows update. I download and install these updates (4 of them), and windows update yellow shield still says to download them. what could be going on there?

Thank you very much for your help!




Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org

Database version: v2012.04.02.08

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Compaq_Owner :: DIANE [administrator]

4/2/2012 1:42:47 PM
mbam-log-2012-04-02 (13-42-47).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 181469
Time elapsed: 10 minute(s), 31 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)


///////////////////////////////////////////
///////////////////////////////////////////
///////////////////////////////////////////


.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by Compaq_Owner at 14:52:09 on 2012-04-02
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.574.326 [GMT -5:00]
.
AV: Avira Desktop *Enabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\IHU1.tmp.exe
svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\IHU1.tmp.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\WINDOWS\system32\wuauclt.exe
c:\windows\system\hpsysdrv.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://wapp.verizon.net/bookmarks/bmredir.asp?region=all&bw=fiber&cd=7.0unattached&bm=ho_central
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=63&bd=PRESARIO&pf=desktop
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=63&bd=PRESARIO&pf=desktop
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SearchHelper.dll
BHO: MSN Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.1125.0\msneshellx.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: MSN Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.1125.0\msneshellx.dll
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Recguard] c:\windows\sminst\RECGUARD.EXE
mRun: [HPBootOp] "c:\program files\hewlett-packard\hp boot optimizer\HPBootOp.exe" /run
mRun: [HP Software Update] c:\program files\hp\hp software update\HPwuSchd2.exe
mRun: [AdaptecDirectCD] "c:\program files\roxio\easy cd creator 5\directcd\DirectCD.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [Verizon_UninstallTracking] c:\docume~1\compaq~1\locals~1\temp\IHU1.tmp.exe /uninstalltrackingvendor=Verizon
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: {E2D4D26B-0180-43a4-B05F-462D6D54C789}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL
DPF: {01113300-3E00-11D2-8470-0060089874ED} - hxxps://activatemyfios.verizon.net/sdcCommon/download/FIOS/tgctlcm.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_05-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
TCP: DhcpNameServer = 192.168.1.254
TCP: Interfaces\{04902F5B-5BE5-46B8-AD76-A6AA9215A36F} : DhcpNameServer = 192.168.1.254
TCP: Interfaces\{80443072-5384-4D29-A197-604ECE8884D8} : DhcpNameServer = 16.92.3.242 16.92.3.243 16.81.3.243 16.118.3.243
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\compaq_owner\application data\mozilla\firefox\profiles\glrpwjt8.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
.
============= SERVICES / DRIVERS ===============
.
R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [2012-4-2 36000]
R2 AntiVirSchedulerService;Avira Scheduler;c:\program files\avira\antivir desktop\sched.exe [2012-4-2 86224]
R2 AntiVirService;Avira Realtime Protection;c:\program files\avira\antivir desktop\avguard.exe [2012-4-2 110032]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2012-4-2 74640]
S3 hamachi_oem;PlayLinc Adapter;c:\windows\system32\drivers\gan_adapter.sys [2006-10-19 10664]
S3 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2006-9-30 189792]
.
=============== Created Last 30 ================
.
2012-04-02 19:28:25 -------- d-----w- c:\documents and settings\compaq_owner\application data\Avira
2012-04-02 19:22:00 36000 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2012-04-02 19:21:59 74640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2012-04-02 19:21:57 -------- d-----w- c:\program files\Avira
2012-04-02 19:21:57 -------- d-----w- c:\documents and settings\all users\application data\Avira
2012-04-02 18:41:31 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-04-02 18:41:31 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-04-02 15:15:02 -------- d-----w- c:\windows\system32\scripting
2012-04-02 15:15:02 -------- d-----w- c:\windows\l2schemas
2012-04-02 15:15:01 -------- d-----w- c:\windows\system32\en
2012-04-02 15:15:01 -------- d-----w- c:\windows\system32\bits
2012-04-02 15:04:21 -------- d-----w- c:\windows\EHome
2012-04-02 13:41:12 744448 ------w- c:\windows\system32\dllcache\helpsvc.exe
2012-04-02 13:38:52 743424 ------w- c:\windows\system32\dllcache\iedvtool.dll
.
==================== Find3M ====================
.
2012-04-02 15:19:23 45056 ----a-w- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\uninstallui\eHelpSetup.exe
2012-04-02 15:19:21 61440 ----a-w- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\modemutil.dll
2012-04-02 15:19:21 44032 ----a-w- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\scripts\devcon.exe
2012-04-02 15:19:21 40960 ----a-w- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\ScDmi.dll
2012-04-02 15:19:21 341048 ----a-w- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\HPBasicDetection3.dll
2012-04-02 15:19:21 32768 ----a-w- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\uploadHSC.dll
2012-04-02 15:19:21 32768 ----a-w- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\Scom.dll
2012-04-02 15:19:21 217088 ----a-w- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\WebHelper.dll
2012-04-02 15:19:21 163840 ----a-w- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\modemcheck.dll
.
============= FINISH: 14:53:17.34 ===============

////////////////////////
//////////////////////////////
//////////////////////////////


Results of screen317's Security Check version 0.99.32
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Enabled!
Avira Free Antivirus
Avira successfully updated!
```````````````````````````````
Anti-malware/Other Utilities Check:

Spybot - Search & Destroy
Java™ 6 Update 15
Java™ 6 Update 3
Java™ 6 Update 7
Java version out of date!
Adobe Flash Player 9 Flash Player out of date!
Adobe Reader 9 Adobe Reader out of date!
Mozilla Firefox (11.0.)
````````````````````````````````
Process Check:
objlist.exe by Laurent

Avira Antivir avgnt.exe
Avira Antivir avguard.exe
``````````End of Log````````````

//////////////////////////////////////////////////////////
////////////////////////////////////////////////////////
//////////////////////////////////////////////////////////







Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 2:59:05 PM, on 4/2/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\IHU1.tmp.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\IHU1.tmp.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\WINDOWS\system32\wuauclt.exe
c:\windows\system\hpsysdrv.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\Documents and Settings\Compaq_Owner\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.h...ARIO&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://wapp.verizon....d&bm=ho_central
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.h...ARIO&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Verizon_UninstallTracking] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\IHU1.tmp.exe /uninstalltrackingvendor=Verizon
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemyfi...IOS/tgctlcm.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Realtime Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 6853 bytes

#2 nasdaq

nasdaq

    Forum Deity

  • Global Moderator
  • PipPipPipPipPip
  • 47,832 posts

Posted 03 April 2012 - 07:34 AM

Is this process running from a Temporary folder necessary?

C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\IHU1.tmp.exe

If you ever use a Cleaning tool it will most likely be deleted because of this location.
I suggest your move it or reinstall it in it's own folder.
===

Secure your system by updating 3rd party programs.

Your version of Java is outdated and needs to be updated to take advantage of fixes that have eliminated security vulnerabilities.

Check your present version and update as recommended.
https://www.java.com...d/installed.jsp

If present remove the old version(s) of Java using the Add/Remove Programs applet.


Java™ 6 Update 15
Java™ 6 Update 3
Java™ 6 Update 7


===

Critical vulnerabilities have been identified in Adobe Flash Player 10.3.183.10 and earlier versions... being exploited in the wild in active targeted attacks...

Get the latest Flash Player

On the top of the page you will be given an opportunity to download the version for your operating system.
Make sure you select appropriate version.

You will also have an option to install the Free! McAfee Security Scan Plus Un-check the box if you are NOT using McAfee's virus protection software.

For the users of Internet Explorer download version 11.
Flash Player 11 (64 bit)
Flash Player 11 (32 bit)
===

Get the latest version of the Adobe Reader.
http://get.adobe.com/reader/
Before your download I suggest you unckeck the box on the top right "Include in your download" this is not required. While the installation is in progress you can also deny the installation of any other programs that may be suggested.

When installed remove your old version of the Reader using the Add/Remove Programs applet if present.

Secunia Personal Software Inspector (PSI)
http://secunia.com/v...nning/personal/
Secunia PSI is a security scanner which identifies programs that are insecure and need updates.
If interested in security I would download the tool and run it.
<<<>>>

Please let me know if you have any other issues with this computer.
nasdaq

Favorite tools: [ SpywareBlaster ] [ Spybot ] [ AdAware ] [ HijackThis ]
[ Housecall online virus scan ] [ Bitdefender online virus scan ]
[ AVG antivirus ] [ Sunbelt Personal Firewall ] [ ZoneAlarm firewall ]

My help is free, but if we have helped you in anyway,please considerDonating ,
see this topic for details.
We need members like you.

========
Shouldn't water be worth more than diamonds?
Adam Smith Glasgow, 1760

#3 TimmU

TimmU

    Advanced Member

  • Full Member
  • PipPipPip
  • 158 posts

Posted 04 April 2012 - 09:42 AM

hi nasdaq. thanks so much for your help.

about this...

C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\IHU1.tmp.exe

.. I don't know what that is, or if it's necessary. I can't even find it. I think I'd delete it if I knew how. What should I do with about this, in your opinion?


I've updated 3rd party programs as you suggested.


Other issues:

- Windows Messenger shows up on the systems tray. But when I go to Add Remove Programs, it doesn't show. I would like to delete it. Any suggestions?

- Secunia shows F-Secure Backweb 6.x (End of Life). This sounds like a security tool. I can't find this on Add Remove Programs either. I would like to delete it. Any suggestions?

- Windows tells me there are updates ready to install on your computer. I install them, then turn off the computer to finish installation. Then I turn the computer back on and it still shows the same update to install again. I tried installing from the windows update website- and still the same thing. These updates keep asking to be installed, even after i already installed them. They always deal with Microsift .Net Framework. Any suggestions on what to do?

Thanks nasdaq. I appreciate your help!

Edited by TimmU, 04 April 2012 - 09:48 AM.


#4 nasdaq

nasdaq

    Forum Deity

  • Global Moderator
  • PipPipPipPipPip
  • 47,832 posts

Posted 05 April 2012 - 06:44 AM

Run this tool.
We will see what it finds and what we can delete.

Please download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your Anti-Virus and Anti-Spyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
  • Some Rookit infection may damage your boot sector. The Windows Recovery Console may be needed to restore it. Do not bypass this installation. You may regret it.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Posted Image


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Posted Image

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Note: If you have difficulty properly disabling your protection programs, refer to this link --> http://www.bleepingc...opic114351.html

Do not mouse click ComboFix's window while it's running. That may cause it to stall
===
nasdaq

Favorite tools: [ SpywareBlaster ] [ Spybot ] [ AdAware ] [ HijackThis ]
[ Housecall online virus scan ] [ Bitdefender online virus scan ]
[ AVG antivirus ] [ Sunbelt Personal Firewall ] [ ZoneAlarm firewall ]

My help is free, but if we have helped you in anyway,please considerDonating ,
see this topic for details.
We need members like you.

========
Shouldn't water be worth more than diamonds?
Adam Smith Glasgow, 1760

#5 TimmU

TimmU

    Advanced Member

  • Full Member
  • PipPipPip
  • 158 posts

Posted 05 April 2012 - 08:42 AM

OK, thanks. Here is your requested log:



ComboFix 12-04-05.06 - Compaq_Owner 04/05/2012 8:22.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.574.312 [GMT -5:00]
Running from: c:\documents and settings\Compaq_Owner\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\DirectCDUserNameE.txt
c:\documents and settings\Compaq_Owner\WINDOWS
c:\documents and settings\Default User\WINDOWS
c:\windows\system32\config\systemprofile\WINDOWS
c:\windows\system32\PowerToyReadme.htm
.
.
((((((((((((((((((((((((( Files Created from 2012-03-05 to 2012-04-05 )))))))))))))))))))))))))))))))
.
.
2012-04-04 12:00 . 2012-04-04 12:00 -------- d-----w- c:\documents and settings\Compaq_Owner\Local Settings\Application Data\Secunia PSI
2012-04-04 11:59 . 2012-04-04 11:59 -------- d-----w- c:\program files\Secunia
2012-04-04 11:50 . 2012-04-04 11:51 -------- d-----w- c:\program files\Common Files\Adobe
2012-04-04 11:41 . 2012-04-04 11:41 73728 ----a-w- c:\windows\system32\javacpl.cpl
2012-04-04 11:41 . 2012-04-04 11:41 472808 ----a-w- c:\windows\system32\deployJava1.dll
2012-04-04 01:00 . 2012-04-04 01:00 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-04-04 01:00 . 2012-04-04 01:00 418464 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-04-03 21:57 . 2011-02-08 13:33 978944 ------w- c:\windows\system32\dllcache\mfc42.dll
2012-04-03 21:57 . 2010-09-18 06:53 953856 ------w- c:\windows\system32\dllcache\mfc40u.dll
2012-04-03 21:56 . 2010-08-23 16:12 617472 ------w- c:\windows\system32\dllcache\comctl32.dll
2012-04-03 21:55 . 2010-11-02 15:17 40960 ------w- c:\windows\system32\dllcache\ndproxy.sys
2012-04-03 21:54 . 2011-04-21 13:37 105472 ------w- c:\windows\system32\dllcache\mup.sys
2012-04-03 21:44 . 2012-01-09 16:20 139784 ------w- c:\windows\system32\dllcache\rdpwd.sys
2012-04-03 21:44 . 2011-07-08 14:02 10496 ------w- c:\windows\system32\dllcache\ndistapi.sys
2012-04-03 21:44 . 2012-01-11 19:06 3072 ------w- c:\windows\system32\iacenc.dll
2012-04-03 21:44 . 2012-01-11 19:06 3072 ------w- c:\windows\system32\dllcache\iacenc.dll
2012-04-03 21:35 . 2010-10-11 14:59 45568 ------w- c:\windows\system32\dllcache\wab.exe
2012-04-02 19:28 . 2012-04-02 19:28 -------- d-----w- c:\documents and settings\Compaq_Owner\Application Data\Avira
2012-04-02 19:22 . 2011-09-16 21:09 36000 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2012-04-02 19:21 . 2012-01-31 13:57 74640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2012-04-02 19:21 . 2012-01-31 13:57 137416 ----a-w- c:\windows\system32\drivers\avipbb.sys
2012-04-02 19:21 . 2012-04-02 19:21 -------- d-----w- c:\program files\Avira
2012-04-02 19:21 . 2012-04-02 19:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2012-04-02 19:00 . 2012-04-02 19:00 -------- d-----w- c:\documents and settings\Compaq_Owner\Local Settings\Application Data\Mozilla
2012-04-02 18:41 . 2012-04-02 18:41 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-04-02 18:41 . 2011-12-10 20:24 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-04-02 15:15 . 2012-04-02 15:15 -------- d-----w- c:\windows\system32\scripting
2012-04-02 15:15 . 2012-04-02 15:15 -------- d-----w- c:\windows\l2schemas
2012-04-02 15:15 . 2012-04-02 15:15 -------- d-----w- c:\windows\system32\en
2012-04-02 15:15 . 2012-04-02 15:15 -------- d-----w- c:\windows\system32\bits
2012-04-02 15:04 . 2012-04-02 15:04 -------- d-----w- c:\windows\EHome
2012-04-02 13:51 . 2012-04-02 13:52 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Temp
2012-04-02 13:41 . 2010-06-14 14:31 744448 ------w- c:\windows\system32\dllcache\helpsvc.exe
2012-04-02 13:38 . 2011-12-17 19:46 743424 ------w- c:\windows\system32\dllcache\iedvtool.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-02 15:19 . 2012-04-02 15:19 45056 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\uninstallUI\eHelpSetup.exe
2012-04-02 15:19 . 2012-04-02 15:19 61440 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\modemutil.dll
2012-04-02 15:19 . 2012-04-02 15:19 44032 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Scripts\devcon.exe
2012-04-02 15:19 . 2012-04-02 15:19 40960 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\ScDmi.dll
2012-04-02 15:19 . 2012-04-02 15:19 341048 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\HPBasicDetection3.dll
2012-04-02 15:19 . 2012-04-02 15:19 32768 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\uploadHSC.dll
2012-04-02 15:19 . 2012-04-02 15:19 32768 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\Scom.dll
2012-04-02 15:19 . 2012-04-02 15:19 217088 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll
2012-04-02 15:19 . 2012-04-02 15:19 163840 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\modemcheck.dll
2012-02-03 09:22 . 2004-08-04 11:00 1860096 ----a-w- c:\windows\system32\win32k.sys
2012-01-09 16:20 . 2004-08-04 11:00 139784 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-03-13 04:39 . 2012-04-02 19:00 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2006-03-08 16010240]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-23 237568]
"HP Software Update"="c:\program files\HP\HP Software Update\HPwuSchd2.exe" [2005-02-17 49152]
"AdaptecDirectCD"="c:\program files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-10-15 684032]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-01-25 7311360]
"nwiz"="nwiz.exe" [2006-01-25 1519616]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-01-25 86016]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2012-01-31 258512]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_05\bin\jusched.exe" [2005-08-27 36975]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
.
c:\documents and settings\Default User\Start Menu\Programs\Startup\
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2006-6-19 27136]
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Compaq Connections\\5577497\\Program\\Compaq Connections.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
.
R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [4/2/2012 2:22 PM 36000]
R2 AntiVirSchedulerService;Avira Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [4/2/2012 2:22 PM 86224]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [4/3/2012 8:00 PM 253600]
S3 hamachi_oem;PlayLinc Adapter;c:\windows\system32\drivers\gan_adapter.sys [10/19/2006 11:11 AM 10664]
.
Contents of the 'Scheduled Tasks' folder
.
2012-04-05 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-04 01:00]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://wapp.verizon.net/bookmarks/bmredir.asp?region=all&bw=fiber&cd=7.0unattached&bm=ho_central
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=63&bd=PRESARIO&pf=desktop
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=63&bd=PRESARIO&pf=desktop
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.254
FF - ProfilePath - c:\documents and settings\Compaq_Owner\Application Data\Mozilla\Firefox\Profiles\glrpwjt8.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-04-05 08:31
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Completion time: 2012-04-05 08:35:21
ComboFix-quarantined-files.txt 2012-04-05 13:35
ComboFix2.txt 2009-04-16 20:17
.
Pre-Run: 96,404,774,912 bytes free
Post-Run: 97,006,129,152 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - 932C108056510FB22BFEDA15A2FD1CA7

#6 nasdaq

nasdaq

    Forum Deity

  • Global Moderator
  • PipPipPipPipPip
  • 47,832 posts

Posted 06 April 2012 - 07:17 AM

- Windows Messenger shows up on the systems tray. But when I go to Add Remove Programs, it doesn't show. I would like to delete it. Any suggestions?

- Secunia shows F-Secure Backweb 6.x (End of Life). This sounds like a security tool. I can't find this on Add Remove Programs either. I would like to delete it. Any suggestions?

- Windows tells me there are updates ready to install on your computer. I install them, then turn off the computer to finish installation. Then I turn the computer back on and it still shows the same update to install again. I tried installing from the windows update website- and still the same thing. These updates keep asking to be installed, even after i already installed them. They always deal with Microsift .Net Framework. Any suggestions on what to do?


- Windows Messenger shows up on the systems tray. But when I go to Add Remove Programs, it doesn't show. I would like to delete it. Any suggestions?

- Secunia shows F-Secure Backweb 6.x (End of Life). This sounds like a security tool. I can't find this on Add Remove Programs either. I would like to delete it. Any suggestions?


-Windows Messenger. Can you not right click on the icon and delete it.?
If not look at the properties of the icon and let me know what file it is referencing.

F-Secure

I do not see the programs in your ComboFix log.

Possibly there are entries in the Registry that triggers this.

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2


If your operating system is 64 bit download this tool:
SystemLook_x64.exe
  • Double-click SystemLook.exe to run it.
  • Copy and paste the content of the following bold text into the main textfield:


    :regfind
    F-Secure
    Windows Messenger

  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
===

Do you still have a problem with the Microsoft Updates?
nasdaq

Favorite tools: [ SpywareBlaster ] [ Spybot ] [ AdAware ] [ HijackThis ]
[ Housecall online virus scan ] [ Bitdefender online virus scan ]
[ AVG antivirus ] [ Sunbelt Personal Firewall ] [ ZoneAlarm firewall ]

My help is free, but if we have helped you in anyway,please considerDonating ,
see this topic for details.
We need members like you.

========
Shouldn't water be worth more than diamonds?
Adam Smith Glasgow, 1760

#7 TimmU

TimmU

    Advanced Member

  • Full Member
  • PipPipPip
  • 158 posts

Posted 06 April 2012 - 07:15 PM

Thanks nasdaq.

I could not delete Windows Messenger by right click.

Here is the reference forlder:

"C:\Program Files\Messenger\msmsgs.exe"

Yes. Still the same problem with the Windows update.


SystemLook 30.07.11 by jpshortstuff
Log created at 14:41 on 06/04/2012 by Compaq_Owner
Administrator - Elevation successful

========== regfind ==========

Searching for "F-Secure"
No data found.

Searching for "Windows Messenger"
[HKEY_CURRENT_USER\AppEvents\Schemes\Apps\MSMSGS]
@="Windows Messenger"
[HKEY_CURRENT_USER\Software\Microsoft\MessengerService]
@="Windows Messenger"
[HKEY_LOCAL_MACHINE\SOFTWARE\Clients\IM\Windows Messenger]
[HKEY_LOCAL_MACHINE\SOFTWARE\Clients\IM\Windows Messenger]
@="Windows Messenger"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
@="Windows Messenger 4.7"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683}]
"MenuText"="Windows Messenger"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683}]
"ToolTip"="Windows Messenger"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MessengerService]
@="Windows Messenger"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Messenger]
"Description"="Transmits net send and Alerter service messages between clients and servers. This service is not related to Windows Messenger. If this service is stopped, Alerter messages will not be transmitted. If this service is disabled, any services that explicitly depend on it will fail to start."
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Messenger]
"Description"="Transmits net send and Alerter service messages between clients and servers. This service is not related to Windows Messenger. If this service is stopped, Alerter messages will not be transmitted. If this service is disabled, any services that explicitly depend on it will fail to start."
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Messenger]
"Description"="Transmits net send and Alerter service messages between clients and servers. This service is not related to Windows Messenger. If this service is stopped, Alerter messages will not be transmitted. If this service is disabled, any services that explicitly depend on it will fail to start."
[HKEY_USERS\S-1-5-21-731258140-3504450384-2171803040-1009\AppEvents\Schemes\Apps\MSMSGS]
@="Windows Messenger"
[HKEY_USERS\S-1-5-21-731258140-3504450384-2171803040-1009\Software\Microsoft\MessengerService]
@="Windows Messenger"

-= EOF =-

#8 nasdaq

nasdaq

    Forum Deity

  • Global Moderator
  • PipPipPipPipPip
  • 47,832 posts

Posted 07 April 2012 - 06:54 AM

; Purpose: Remove traces in the registry.
;
; Instructions: Copy and paste this text IN BOLD into a text editor such as Notepad.
;
; Save this text as Fix.reg. Make sure the "Save as type:" is "All Files (*.*)" and save it to your desktop.

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683}]
"MenuText"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683}]
"ToolTip"=-



; Double-click on Fix.reg. When it asks you to merge the information to the registry click Yes.

On a Vista or Windows 7 operating system, right click the Fix.reg and run as Administrator.

Delete the Fix.reg file when done.

===

Run the SystemTool and paste this in the search box.

:regfind
Backweb


Post the result.
nasdaq

Favorite tools: [ SpywareBlaster ] [ Spybot ] [ AdAware ] [ HijackThis ]
[ Housecall online virus scan ] [ Bitdefender online virus scan ]
[ AVG antivirus ] [ Sunbelt Personal Firewall ] [ ZoneAlarm firewall ]

My help is free, but if we have helped you in anyway,please considerDonating ,
see this topic for details.
We need members like you.

========
Shouldn't water be worth more than diamonds?
Adam Smith Glasgow, 1760

#9 TimmU

TimmU

    Advanced Member

  • Full Member
  • PipPipPip
  • 158 posts

Posted 08 April 2012 - 12:46 PM

Hi nasdaq. Thanks for your help. The requested log is the following:


SystemLook 30.07.11 by jpshortstuff
Log created at 12:43 on 08/04/2012 by Compaq_Owner
Administrator - Elevation successful

========== regfind ==========

Searching for "Backweb"
[HKEY_LOCAL_MACHINE\SOFTWARE\BackWeb]
[HKEY_LOCAL_MACHINE\SOFTWARE\BackWeb\BackWeb-Client]
[HKEY_LOCAL_MACHINE\SOFTWARE\BackWeb\BackWeb-Client\Applications\5577497\Classes\BackWeb.ChannelDirectoryCtrl]
[HKEY_LOCAL_MACHINE\SOFTWARE\BackWeb\BackWeb-Client\Applications\5577497\Classes\BackWeb.Channels]
[HKEY_LOCAL_MACHINE\SOFTWARE\BackWeb\BackWeb-Client\Applications\5577497\Classes\BackWeb.Client]
[HKEY_LOCAL_MACHINE\SOFTWARE\BackWeb\BackWeb-Client\Applications\5577497\Classes\BackWeb.Client.ScriptHelper]
[HKEY_LOCAL_MACHINE\SOFTWARE\BackWeb\BackWeb-Client\Applications\5577497\Classes\BackWeb.ClientCommander]
[HKEY_LOCAL_MACHINE\SOFTWARE\BackWeb\BackWeb-Client\Applications\5577497\Classes\BackWeb.ClientDialogs]
[HKEY_LOCAL_MACHINE\SOFTWARE\BackWeb\BackWeb-Client\Applications\5577497\Classes\BackWeb.DataSetNotifier]
[HKEY_LOCAL_MACHINE\SOFTWARE\BackWeb\BackWeb-Client\Applications\5577497\Classes\BackWeb.DataSets]
[HKEY_LOCAL_MACHINE\SOFTWARE\BackWeb\BackWeb-Client\Applications\5577497\Classes\BackWeb.DocMap]
[HKEY_LOCAL_MACHINE\SOFTWARE\BackWeb\BackWeb-Client\Applications\5577497\Classes\BackWeb.FileAccess]
[HKEY_LOCAL_MACHINE\SOFTWARE\BackWeb\BackWeb-Client\Applications\5577497\Classes\BackWeb.FileAccessViaDir]
[HKEY_LOCAL_MACHINE\SOFTWARE\BackWeb\BackWeb-Client\Applications\5577497\Classes\BackWeb.FileReplication]
[HKEY_LOCAL_MACHINE\SOFTWARE\BackWeb\BackWeb-Client\Applications\5577497\Classes\BackWeb.FileReplicationCleanup]
[HKEY_LOCAL_MACHINE\SOFTWARE\BackWeb\BackWeb-Client\Applications\5577497\Classes\BackWeb.FileReplicationExtension]
[HKEY_LOCAL_MACHINE\SOFTWARE\BackWeb\BackWeb-Client\Applications\5577497\Classes\BackWeb.InteractiveUserClientCommander]
[HKEY_LOCAL_MACHINE\SOFTWARE\BackWeb\BackWeb-Client\Applications\5577497\Classes\BackWeb.PlugProtocol]
[HKEY_LOCAL_MACHINE\SOFTWARE\BackWeb\BackWeb-Client\Applications\5577497\Classes\BackWeb.PortalPlugin]
[HKEY_LOCAL_MACHINE\SOFTWARE\BackWeb\BackWeb-Client\Applications\5577497\Classes\BackWeb.ScriptExt]
[HKEY_LOCAL_MACHINE\SOFTWARE\BackWeb\BackWeb-Client\Applications\5577497\Classes\BackWeb.SMMgr]
[HKEY_LOCAL_MACHINE\SOFTWARE\BackWeb\BackWeb-Client\Applications\5577497\Classes\BackWeb.VBFileReplicationExtension]
[HKEY_LOCAL_MACHINE\SOFTWARE\BackWeb\BackWeb-Client\Applications\5577497\ClientExtensions\BackWeb.FileReplicationExtension-5577497]
[HKEY_LOCAL_MACHINE\SOFTWARE\BackWeb\BackWeb-Client\Applications\5577497\ClientExtensions\BackWeb.FileReplicationExtension-5577497]
@="BackWeb.FileReplicationExtension-5577497"
[HKEY_LOCAL_MACHINE\SOFTWARE\BackWeb\BackWeb-Client\Applications\5577497\ClientExtensions\{9A837B42-7675-4593-BFD0-5052ABD21EF2}]
"BackWeb.ClientExt"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\BackWeb\BackWeb-Client\Applications\5577497\Components\BackWeb]
[HKEY_LOCAL_MACHINE\SOFTWARE\BackWeb\BackWeb-Client\Applications\5577497\Components\backwebEn]
[HKEY_LOCAL_MACHINE\SOFTWARE\BackWeb\BackWeb-Client\Applications\5577497\Components\Infoc\UI]
"WindowClassName"="BackWebInfocenterClass - %appid%"
[HKEY_LOCAL_MACHINE\SOFTWARE\BackWeb\BackWeb-Client\Applications\5577497\RunnersMapping\BackWeb-5577497.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\BackWeb\BackWeb-Client\Applications\5577497\RunnersMapping\Compaq Connections.exe]
"MappedTo"="BackWeb-5577497.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\BackWeb\BackWeb-Client\Applications\5577497\Shortcuts\0\FileReplication]
"locating_path"="$BackwebVersion\program\repBead.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\BackWeb\BackWeb-Client\TypeLibs\{53FCF357-5323-11D0-A864-0000B43699FC}_2.11_0_win32]
"V6.3.2.116-5577497"="C:\Program Files\Compaq Connections\5577497\6.3.2.116-5577497\Program\BackWeb.tlb"
[HKEY_LOCAL_MACHINE\SOFTWARE\BackWeb\BackWeb-Client\Versions\6.3.2.116-5577497\Private Components\BackWeb]
[HKEY_LOCAL_MACHINE\SOFTWARE\BackWeb\BackWeb-Client\Versions\6.3.2.116-5577497\Private Components\BackWeb]
"Runners"="BackWeb.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\BackWeb\BackWeb-Client\Versions\6.3.2.116-5577497\Private Components\backwebEn]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{217243C3-D350-4AA4-9D24-54C16B02C147}]
@="BackWeb Client Commander"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{23CADE87-078D-402F-AF83-D4FAE9E6A540}]
@="BackWeb Interactive User Client Commander"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{98E1DCF2-832A-4251-BFD0-21460F9C1CDD}]
@="BackWeb Client Files Access"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{be3ae019-cfaf-4814-a658-666dc6da499c}]
@="BackWeb Plug-in"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{C1F5BF1A-695A-4037-8285-D818851714A5}]
@="BackWeb Client Files Access Via Directory"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BackWeb.Client-5577497]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BackWeb.Client-5577497]
@="BackWeb Client"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BackWeb.Client.ScriptHelper-5577497]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BackWeb.ClientCommander-5577497]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BackWeb.ClientCommander-5577497]
@="BackWeb Client Commander"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BackWeb.ClientDialogs-5577497]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BackWeb.ClientDialogs-5577497]
@="BackWeb Client Dialogs"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BackWeb.ClientExt]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BackWeb.ClientExt]
@="BackWeb ClientExt Class"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BackWeb.ClientExt\CurVer]
@="BackWeb.ClientExt.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BackWeb.ClientExt.1]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BackWeb.ClientExt.1]
@="BackWeb ClientExt Class"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BackWeb.FileAccess-5577497]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BackWeb.FileAccess-5577497]
@="BackWeb Client Files Access"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BackWeb.FileAccessViaDir-5577497]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BackWeb.FileAccessViaDir-5577497]
@="BackWeb Client Files Access Via Directory"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BackWeb.FileReplication-5577497]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BackWeb.FileReplication-5577497]
@="BackWeb File Replicator"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BackWeb.FileReplicationCleanup-5577497]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BackWeb.FileReplicationCleanup-5577497]
@="BackWeb File Replication Cleanup"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BackWeb.FileReplicationExtension-5577497]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BackWeb.FileReplicationExtension-5577497]
@="BackWeb File Replication Extension"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BackWeb.InteractiveUserClientCommander-5577497]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BackWeb.InteractiveUserClientCommander-5577497]
@="BackWeb Interactive User Client Commander"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BackWeb.VBFileReplicationExtension-5577497]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BackWeb.VBFileReplicationExtension-5577497]
@="BackWeb File Replication Extension Creator for Visual Basic"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\bwpfile]
@="BackWeb InfoPak Preview File"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D24706B-7383-4869-B167-81DD7496F66B}]
@="BackWeb File Replication Extension Creator for Visual Basic"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D24706B-7383-4869-B167-81DD7496F66B}\ProgID]
@="BackWeb.VBFileReplicationExtension-5577497"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{217243C3-D350-4AA4-9D24-54C16B02C147}]
@="BackWeb Client Commander"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{217243C3-D350-4AA4-9D24-54C16B02C147}\ProgID]
@="BackWeb.ClientCommander-5577497"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{23CADE87-078D-402F-AF83-D4FAE9E6A540}]
@="BackWeb Interactive User Client Commander"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{23CADE87-078D-402F-AF83-D4FAE9E6A540}\ProgID]
@="BackWeb.InteractiveUserClientCommander-5577497"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{423F8629-BB66-40AA-9FF4-58934A3BDD99}]
@="BackWeb File Replication Cleanup"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{423F8629-BB66-40AA-9FF4-58934A3BDD99}\ProgID]
@="BackWeb.FileReplicationCleanup-5577497"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A6E63AB-3865-4F1C-92F7-04CC5D92C7DD}]
@="BackWeb File Replicator"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A6E63AB-3865-4F1C-92F7-04CC5D92C7DD}\ProgID]
@="BackWeb.FileReplication-5577497"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7BE5AE8C-5890-4CD4-A6E1-DFDB6E48EDC6}]
@="BackWeb Client Dialogs"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7BE5AE8C-5890-4CD4-A6E1-DFDB6E48EDC6}\ProgID]
@="BackWeb.ClientDialogs-5577497"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8A634AF3-9802-458A-A14C-C12B185F0633}\ProgID]
@="BackWeb.Client.ScriptHelper-5577497"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{98E1DCF2-832A-4251-BFD0-21460F9C1CDD}]
@="BackWeb Client Files Access"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{98E1DCF2-832A-4251-BFD0-21460F9C1CDD}\ProgID]
@="BackWeb.FileAccess-5577497"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9A837B42-7675-4593-BFD0-5052ABD21EF2}]
@="BackWeb ClientExt Class"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9A837B42-7675-4593-BFD0-5052ABD21EF2}\ProgID]
@="BackWeb ClientExt.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9A837B42-7675-4593-BFD0-5052ABD21EF2}\VersionIndependentProgID]
@="BackWeb.ClientExt"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BE3AE019-CFAF-4814-A658-666DC6DA499C}]
@="BackWeb Client"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BE3AE019-CFAF-4814-A658-666DC6DA499C}\ProgID]
@="BackWeb.Client-5577497"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C1F5BF1A-695A-4037-8285-D818851714A5}]
@="BackWeb Client Files Access Via Directory"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C1F5BF1A-695A-4037-8285-D818851714A5}\ProgID]
@="BackWeb.FileAccessViaDir-5577497"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F56CB5F5-5032-468C-85B0-E5C680164C66}]
@="BackWeb File Replication Extension"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F56CB5F5-5032-468C-85B0-E5C680164C66}\ProgID]
@="BackWeb.FileReplicationExtension-5577497"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\iadfile]
@="BackWeb Channel Registration File"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0007BE40-C496-11D2-BFBF-00A0C93A4D75}]
@="IBackWebUpstreamMessage5_5"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{001B3F20-D866-11D1-8B4C-00609761C47A}]
@="IBackWebDisplaySettings4_2"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{025632A0-BCEC-11D1-8B35-00609761C47A}]
@="IBackWebChannel4_2"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{037B1EF0-C61A-11D5-BA26-000000000000}]
@="IBackWebGeneralSettings6_1_4"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{05846520-04FF-11D2-B044-00A0C94CD67E}]
@="IBackWebFileStoreSettings"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0668A670-2D8C-11D3-B9CD-00C04F9CD5A7}]
@="IBackWebInfoPakExternalUpdate5_5"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0BBD4090-AF55-11D4-B94C-0010A4FBBFC9}]
@="IBackWebTimingServices"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0C6E0440-0B50-11D1-9951-444553540000}]
@="IBackWebDirectoryEntry"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0CF56A20-AF64-11D4-B94C-0010A4FBBFC9}]
@="IBackWebTimer"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0D1F7C83-8123-11D0-B5CA-0000B43698D6}]
@="IBackWebDownloadTimeConstraint"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0D1F7C84-8123-11D0-B5CA-0000B43698D6}]
@="IBackWebDownloadTimeConstraintCollection"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0EC3CFD0-1EFB-11D6-BA63-0010A4FBBFC9}]
@="IBackWeb6_2"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0F4FE440-983F-11D0-9B9C-444553540000}]
@="IBackWebExtension"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{10B2F8C7-B017-4EDF-B7C8-2A1ABF07E263}]
@="IBackWeb6_3"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{12473FC3-61A7-11D0-A866-0000B43699FC}]
@="IBackWebGeneralSettings"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{12473FC4-61A7-11D0-A866-0000B43699FC}]
@="IBackWebDialerSettings"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{12473FC5-61A7-11D0-A866-0000B43699FC}]
@="IBackWebCommSettings"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{12473FC6-61A7-11D0-A866-0000B43699FC}]
@="IBackWebDisplaySettings"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{12473FC7-61A7-11D0-A866-0000B43699FC}]
@="IBackWebSetup"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{12966061-E035-11D2-8C23-00105AA63533}]
@="IBackWebCommSettings6"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{12966062-E035-11D2-8C23-00105AA63533}]
@="IBackWebDisplaySettings6"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{12F4DD61-A432-477C-8664-C1B0E6368DF3}]
@="IBackWebCommSettings6_1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{13837DA8-EF54-4675-AFB8-8E28A01CC26D}]
@="IBackWebUpstreamMessageCollection6_3"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{15030BC0-0B52-11D1-9951-444553540000}]
@="IBackWebDirectory"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1816DBE3-70AA-4B40-8925-369F4DFE93FF}]
@="IBackWebGeneralSettings6_3_1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{18DD4341-D87E-11D2-8C20-00105AA63533}]
@="IBackWebChannelVariableCollection6"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1D91D9E0-004B-11D1-9951-444553540000}]
@="IBackWebStoryFieldCollection"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1E8B2080-AF64-11D4-B94C-0010A4FBBFC9}]
@="IBackWebTimerNotifications"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{23F43240-F78D-11D0-9A50-00AA004812C2}]
@="IBackWeb2"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{28BC6260-DA2F-11D3-B87B-0010A404098C}]
@="IBackWebShutdownProtector"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{29DE5E9B-1C04-40FE-9472-2082C6BB1DE3}]
@="IBackWebChannel7_1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{29E5AF70-B615-11D4-B953-0010A4FBBFC9}]
@="IBackWeb6_0_1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2A58F590-D30B-11D2-8C1E-00105AA63533}]
@="IBackWebGeneralSettings6"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2ACD753B-7EF9-4909-9231-AD6F79E59190}]
@="IBackWebCommSettings7_2_1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2D8ACF70-B161-11D3-BE20-000086397BAD}]
@="IBackWebAttentionManagement"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2DE07D90-DC04-11D0-A875-0000B43699FC}]
@="IBackWebInfoPakDownloadServices"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2E4C4083-3280-4680-9932-0C05B375D71F}]
@="IBackWeb6_3_1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2F068020-F87D-11D0-9A50-00AA004812C2}]
@="IBackWebCustomUserInterface"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2F099AF0-6329-11D0-A866-0000B43699FC}]
@="IBackWebSetupNotifications"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2F0A7430-D34B-11D5-BA2F-0010A4FBBFC9}]
@="IBackWebInfoPak6_2"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2F523082-5A0B-11D0-9B9C-444553540000}]
@="IBackWebChannelTableNotifications"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{34349540-5B8E-11D1-AF44-00AA00480CBE}]
@="IBackWebUpstreamMessageCollection"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{34349541-5B8E-11D1-AF44-00AA00480CBE}]
@="IBackWebUpstreamMessage"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3667E7B0-4F28-11D1-8ADB-00609761C47A}]
@="IBackWebSetup4"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{393920B3-6415-4045-BFF7-69D3CD024261}]
@="IBackWebChannel6_3"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3A43BD61-F0F5-11D2-8C29-00105AA63533}]
@="IBackWeb6"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3AF78A6E-6F14-11D1-A884-0000B43699FC}]
@="IBackWebFileAccess"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3AF78A71-6F14-11D1-A884-0000B43699FC}]
@="IBackWebInfoPakFilesCollection"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3AF78A74-6F14-11D1-A884-0000B43699FC}]
@="IBackWebInfoPakFile"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3AF78A77-6F14-11D1-A884-0000B43699FC}]
@="IBackWebOpenInfoPakFile"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3C027500-C2C7-11D3-B864-0010A404098C}]
@="IBackWeb5_5_1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{419DBB00-B161-11D3-BE20-000086397BAD}]
@="IBackWebAttentionManagementLogic"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{41CEBDC0-32C1-11D1-9951-444553540000}]
@="IBackWebDirectoryNotifications"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{44230BC0-3105-11D1-9951-444553540000}]
@="IBackWebStoryTableNotifications"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4A3666F3-5F2D-11D0-A866-0000B43699FC}]
@="IBackWebInfoPakNotifications"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4AD8B831-E3B3-11D3-AEAE-00105A680865}]
@="IBackWebAttentionManagementContext"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4EC60050-6E5B-11D2-893B-00104BCA9324}]
@="IBackWebFileReplicationManager"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{53C327E0-6576-11D1-BB4B-0000B4369751}]
@="IBackWebChannelDownloadServices2"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{53FCF355-5323-11D0-A864-0000B43699FC}]
@="IBackWeb"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{53FCF35A-5323-11D0-A864-0000B43699FC}]
@="IBackWebChannelCollection"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{53FCF35B-5323-11D0-A864-0000B43699FC}]
@="IBackWebChannel"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{577B3560-C6F3-11D1-AA87-0000B43695BE}]
@="IBackWebFileReplicationResultNotifications"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{581E26D0-DC70-11D2-A64B-00104B9B511A}]
@="IBackWebSetup5_5"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5B1E13A0-004B-11D1-9951-444553540000}]
@="IBackWebStoryField"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5B267241-C2A4-11D3-BE42-000086397BAD}]
@="IBackWebCertificate5_5_1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5DF6CE40-0B50-11D1-9951-444553540000}]
@="IBackWebDirectoryEntryCollection"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5F7A39B8-267B-4EAF-96C1-D727CA053672}]
@="IBackWebFileReplication6_3_2"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{608FE360-6FB2-11D1-A885-0000B43699FC}]
@="IBackWebFileAccessViaDir"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{60BFF8B0-A3CC-11D2-BF9C-00A0C93A4D75}]
@="IBackWebChannel5_5"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{610141C2-7701-11D1-B042-004095903824}]
@="IBackWebInfoPak4_2"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{63CE5B70-AF54-11D4-B94C-0010A4FBBFC9}]
@="IBackWeb6_1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6A21FEE0-5A23-11D3-82F5-00600874D315}]
@="IBackWebStory6"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6EFC6591-E13D-11D2-8C23-00105AA63533}]
@="IBackWebDownloadTimeConstraintCollection6"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6F791E27-0741-4A28-B234-6D813E31AEA7}]
@="IBackWebCertificate7_1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{70C8EF70-2EE2-11D3-B9CD-00C04F9CD5A7}]
@="IBackWebFileAccessViaDir5_5"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{72B62B40-17D1-11D1-96A7-F8E906C10000}]
@="IBackWebAlertSettings"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{73C3FCC0-C4AF-11D1-AA87-0000B43695BE}]
@="IBackWebChannel5"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{740904E0-0BFB-11D1-9951-444553540000}]
@="IBackWeb4"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{74946131-D63B-11D2-8C1F-00105AA63533}]
@="IBackWebChannelCollection6"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{76F0D380-B617-11D4-B953-0010A4FBBFC9}]
@="IBackWebExtensionVariables"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{79D25F04-04FE-11D2-B044-00A0C94CD67E}]
@="IBackWebSetup5"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8028B940-4932-11D1-9951-444553540000}]
@="IBackWebPlayer"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8131F530-649E-11D0-A866-0000B43699FC}]
@="IBackWebAllInfoPakCollection"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{848D6E81-1699-11D3-A793-00105A68088F}]
@="IBackWebGeneralSettings5_5"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8847C5C0-E2C5-11D3-B882-0010A404098C}]
@="IBackWebCommander"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8EA7FB0A-C26A-48A6-9EEE-3501855C4DF8}]
@="IBackWebUpstreamNotifications"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8EB0E1A0-C4B0-11D1-AA87-0000B43695BE}]
@="IBackWebGeneralSettings5"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9132E380-DC21-11D0-A875-0000B43699FC}]
@="IBackWebChannelDownloadServices"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9175A9C0-C6DB-11D1-AA87-0000B43695BE}]
@="IBackWebFileReplicationNotifications"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{93BF8F00-DBE8-11D0-A875-0000B43699FC}]
@="IBackWebItemDownloadServices"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{946AE641-E1E0-11D2-8C23-00105AA63533}]
@="IBackWebDialerSettings6"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9647FB70-DC0F-11D0-A875-0000B43699FC}]
@="IBackWebChannel2"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{98A90D6A-7E63-45BE-88E4-AFB44FAB5C62}]
@="IBackWebGeneralSettings6_3_2"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9A9FCE90-B619-11D3-B857-0010A404098C}]
@="IBackWebExtension6"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9A9FCE91-B619-11D3-B857-0010A404098C}]
@="IBackWebCustomUserInterface6"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9DB46422-FF61-11D0-9951-444553540000}]
@="IBackWebStoryCollection"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9DB46423-FF61-11D0-9951-444553540000}]
@="IBackWebAllStoryCollection"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9DB46424-FF61-11D0-9951-444553540000}]
@="IBackWebStory"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A17240E1-DD5C-11D3-AEA6-00105A680865}]
@="IBackWebSetup6"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A4BC67F0-6C90-11D0-A866-0000B43699FC}]
@="IBackWebChannelVariableCollection"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A7AC2542-1B0C-11D2-83B1-00C0F01859AC}]
@="IBackWebCertificate"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A7AC2543-1B0C-11D2-83B1-00C0F01859AC}]
@="IBackWebCertificateCollection"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A84355A1-D242-11D2-8C1D-00105AA63533}]
@="IBackWebChannel6"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A88B5B90-FB6E-11D5-BA47-0010A4FBBFC9}]
@="IBackWebCommSettings6_2"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AA3B2B15-5F3F-4AE2-9273-D3E07A4A2775}]
@="IBackWebExtensionRequestHandler"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AD705AC0-AF5D-11D4-B94C-0010A4FBBFC9}]
@="IBackWebUserNotIdleDetector"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AE345B98-B6EE-4296-930F-80BFC562B844}]
@="IBackWebDisplaySettings6_2"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AEE96320-2131-11D1-9951-444553540000}]
@="IBackWebChannel4"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AF6BD5B0-D3F3-11D4-B966-0010A4FBBFC9}]
@="IBackWebChannel6_1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B033A622-FE92-4F1F-B48F-FEE197DA69E2}]
@="IBackWeb7_1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B60D9F50-F32E-11D5-BA43-0010A4FBBFC9}]
@="IBackWebStory6_2"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B738B058-B74F-11D1-AA87-0000B43695BE}]
@="IBackWebFileReplication"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B738B05A-B74F-11D1-AA87-0000B43695BE}]
@="IBackWebFileReplicationCleanup"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B941E960-5A21-11D3-82F5-00600874D315}]
@="IBackWebInfoPak6"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B952C110-AF5D-11D4-B94C-0010A4FBBFC9}]
@="IBackWebUserNotIdleDetectorNotifications"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B9E582A3-E440-452F-BD59-F7E723B7CCFF}]
@="IBackWebInfoPak6_3"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BAD37BC0-2231-11D1-9951-444553540000}]
@="IBackWebCommunications"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BCD0C200-69C1-11D1-8AF8-00609761C47A}]
@="IBackWebChannelCollection4"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BD2F5D0C-9C5C-4279-9909-F07973E1BE57}]
@="IBackWebFileReplicationCleanup6_3_2"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BF24C8F0-FB6F-11D5-BA47-0010A4FBBFC9}]
@="IBackWebTempSetting"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C8CEEEE0-17D6-11D1-96A7-F8E906C10000}]
@="IBackWebFilterSettings"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CADD3D20-F328-11D5-BA43-0010A4FBBFC9}]
@="IBackWebChannel6_2"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CD2DE130-C60C-11D5-BA25-0010A4FBBFC9}]
@="IBackWebCommander6_1_4"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CE2F2BC0-C116-11D3-B861-0010A404098C}]
@="IBackWebChannel5_5_1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CE6C0A50-BE92-11D2-B9B0-00C04F9CD5A7}]
@="IBackWebChannel5_0_1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CF513E20-10EC-11D2-B044-00A0C94CD67E}]
@="IBackWebInfoPak5"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CF513E21-10EC-11D2-B044-00A0C94CD67E}]
@="IBackWebInfoPakExternalUpdateCollection"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CF513E22-10EC-11D2-B044-00A0C94CD67E}]
@="IBackWebInfoPakExternalUpdate"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CF513E23-10EC-11D2-B044-00A0C94CD67E}]
@="IBackWebInfoPakFilesCollection5"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CF513E24-10EC-11D2-B044-00A0C94CD67E}]
@="IBackWebInfoPakFile5"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CF7CE690-2C7A-11D2-AFF7-00104B6FDB95}]
@="IBackWebChannelVariableCollection5"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D055A4B0-1A34-11D2-B980-00C04F9CD5A7}]
@="IBackWebInfoPakSubdirsCollection"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D055A4B1-1A34-11D2-B980-00C04F9CD5A7}]
@="IBackWebInfoPakSubdir"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D0894D60-6C6C-11D0-A866-0000B43699FC}]
@="IBackWebApplicationNotifications"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D382C311-FDB7-11D3-9099-00104B9B511A}]
@="IBackWebCapabilities"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D6BD8C50-5A3E-4CE8-8A6E-343D1C0B74DC}]
@="IBackWebUpstreamMessage6_3"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D6F7929C-DDBC-4FCF-9F66-6CB56DE43390}]
@="IBackWebExtension6_3_1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D8B14791-E5DB-11D2-8C24-00105AA63533}]
@="IBackWebCommunications6"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D8CB83C0-AF57-11D4-B94C-0010A4FBBFC9}]
@="IBackWebUserIdleTimer"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DA4CE69D-B9BE-4FF8-A2FA-7A27CDA1107E}]
@="IBackWebCommSettings7_1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DD7499A4-3BF4-4FFA-8253-FEDAF7492441}]
@="IBackWebStoryTableNotifications6_3"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E01AD640-F87D-11D0-9A50-00AA004812C2}]
@="IBackWebGeneralSettings2"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E2FF0110-C29D-11D3-B864-0010A404098C}]
@="IBackWebGeneralSettings5_5_1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E50876A0-AF5A-11D4-B94C-0010A4FBBFC9}]
@="IBackWebUserIdleTimerNotifications"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB1FFFC1-5688-11D0-A865-0000B43699FC}]
@="IBackWebInfoPakCollection"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB1FFFC2-5688-11D0-A865-0000B43699FC}]
@="IBackWebInfoPak"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB2FA8C0-37C5-11D4-B8DE-0010A4FBBFC9}]
@="IBackWebInfoPakAccess"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EDA02220-C4AF-11D2-B9B3-00C04F9CD5A7}]
@="IBackWebInfoPak5_5"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F4B0C3F1-BC3E-11D3-906F-00104B9B511A}]
@="IBackWebComponent"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F4B0C3F2-BC3E-11D3-906F-00104B9B511A}]
@="IBackWebComponentCollection"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F82F55E8-7698-4593-B963-920539528CC2}]
@="IBackWebFileNotifications"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FBAB6C00-5924-11D2-B991-00C04F9CD5A7}]
@="IBackWebStory5"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FD395090-29CF-11D4-B8D0-0010A4FBBFC9}]
@="IBackWebChannelVariable6"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEFCA7F0-6C8E-11D0-A866-0000B43699FC}]
@="IBackWebChannelVariable"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FF41662F-0248-4FE2-90A6-10086BFD424E}]
@="IBackWebCommSettings6_3"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{3AF78A60-6F14-11D1-A884-0000B43699FC}\2.0]
@="BackWebFiles Type Library (v2.0)"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{53FCF357-5323-11D0-A864-0000B43699FC}\2.b]
@="BackWeb Type Library (v2.11)"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{53FCF357-5323-11D0-A864-0000B43699FC}\2.b\0\win32]
@="C:\Program Files\Compaq Connections\5577497\6.3.2.116-5577497\Program\BackWeb.tlb"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{8847C5C1-E2C5-11D3-B882-0010A404098C}\1.1]
@="BackWebCommander Type Library (v1.1)"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{97972D22-C259-11D1-AA87-0000B43695BE}\2.0]
@="BackWebFileReplicationExtension Type Library (v2.0)"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{ADEB3C02-C90B-4907-B23C-C051F5DB99A3}\1.0]
@="BackWeb ClientExt Class 1.0 Type Library"

-= EOF =-

#10 nasdaq

nasdaq

    Forum Deity

  • Global Moderator
  • PipPipPipPipPip
  • 47,832 posts

Posted 09 April 2012 - 07:28 AM

; Purpose: Remove traces in the registry.
;
; Instructions: Copy and paste this text IN BOLD into a text editor such as Notepad.
;
; Save this text as Fix.reg. Make sure the "Save as type:" is "All Files (*.*)" and save it to your desktop.

REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\BackWeb\BackWeb-Client]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{217243C3-D350-4AA4-9D24-54C16B02C147}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{23CADE87-078D-402F-AF83-D4FAE9E6A540}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{98E1DCF2-832A-4251-BFD0-21460F9C1CDD}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{be3ae019-cfaf-4814-a658-666dc6da499c}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{C1F5BF1A-695A-4037-8285-D818851714A5}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BackWeb.Client-5577497]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BackWeb.ClientExt]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BackWeb.FileAccess-5577497]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BackWeb.FileAccessViaDir-5577497]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BackWeb.FileReplication-5577497]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BackWeb.InteractiveUserClientCommander-5577497]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BackWeb.VBFileReplicationExtension-5577497]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\bwpfile]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D24706B-7383-4869-B167-81DD7496F66B}\ProgID]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{217243C3-D350-4AA4-9D24-54C16B02C147}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{23CADE87-078D-402F-AF83-D4FAE9E6A540}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{423F8629-BB66-40AA-9FF4-58934A3BDD99}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A6E63AB-3865-4F1C-92F7-04CC5D92C7DD}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7BE5AE8C-5890-4CD4-A6E1-DFDB6E48EDC6}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8A634AF3-9802-458A-A14C-C12B185F0633}\ProgID]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{98E1DCF2-832A-4251-BFD0-21460F9C1CDD}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9A837B42-7675-4593-BFD0-5052ABD21EF2}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BE3AE019-CFAF-4814-A658-666DC6DA499C}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C1F5BF1A-695A-4037-8285-D818851714A5}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F56CB5F5-5032-468C-85B0-E5C680164C66}]



; Double-click on Fix.reg. When it asks you to merge the information to the registry click Yes.

On a Vista or Windows 7 operating system, right click the Fix.reg and run as Administrator.

Delete the Fix.reg file when done.

If you are still advised that some backweb are still present run the SystemLook again for backweb.
I will remove the rest of the registry keys.
nasdaq

Favorite tools: [ SpywareBlaster ] [ Spybot ] [ AdAware ] [ HijackThis ]
[ Housecall online virus scan ] [ Bitdefender online virus scan ]
[ AVG antivirus ] [ Sunbelt Personal Firewall ] [ ZoneAlarm firewall ]

My help is free, but if we have helped you in anyway,please considerDonating ,
see this topic for details.
We need members like you.

========
Shouldn't water be worth more than diamonds?
Adam Smith Glasgow, 1760

#11 TimmU

TimmU

    Advanced Member

  • Full Member
  • PipPipPip
  • 158 posts

Posted 09 April 2012 - 10:54 AM

Hi nasdaq. Thanks. Secunia still shows it. Here is a fresh scan. Thanks a lot,

SystemLook 30.07.11 by jpshortstuff
Log created at 10:52 on 09/04/2012 by Compaq_Owner
Administrator - Elevation successful

========== regfind ==========

Searching for "Backweb"
[HKEY_LOCAL_MACHINE\SOFTWARE\BackWeb]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BackWeb.Client.ScriptHelper-5577497]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BackWeb.ClientCommander-5577497]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BackWeb.ClientCommander-5577497]
@="BackWeb Client Commander"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BackWeb.ClientDialogs-5577497]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BackWeb.ClientDialogs-5577497]
@="BackWeb Client Dialogs"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BackWeb.ClientExt.1]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BackWeb.ClientExt.1]
@="BackWeb ClientExt Class"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BackWeb.FileReplicationCleanup-5577497]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BackWeb.FileReplicationCleanup-5577497]
@="BackWeb File Replication Cleanup"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BackWeb.FileReplicationExtension-5577497]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BackWeb.FileReplicationExtension-5577497]
@="BackWeb File Replication Extension"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D24706B-7383-4869-B167-81DD7496F66B}]
@="BackWeb File Replication Extension Creator for Visual Basic"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\iadfile]
@="BackWeb Channel Registration File"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0007BE40-C496-11D2-BFBF-00A0C93A4D75}]
@="IBackWebUpstreamMessage5_5"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{001B3F20-D866-11D1-8B4C-00609761C47A}]
@="IBackWebDisplaySettings4_2"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{025632A0-BCEC-11D1-8B35-00609761C47A}]
@="IBackWebChannel4_2"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{037B1EF0-C61A-11D5-BA26-000000000000}]
@="IBackWebGeneralSettings6_1_4"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{05846520-04FF-11D2-B044-00A0C94CD67E}]
@="IBackWebFileStoreSettings"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0668A670-2D8C-11D3-B9CD-00C04F9CD5A7}]
@="IBackWebInfoPakExternalUpdate5_5"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0BBD4090-AF55-11D4-B94C-0010A4FBBFC9}]
@="IBackWebTimingServices"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0C6E0440-0B50-11D1-9951-444553540000}]
@="IBackWebDirectoryEntry"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0CF56A20-AF64-11D4-B94C-0010A4FBBFC9}]
@="IBackWebTimer"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0D1F7C83-8123-11D0-B5CA-0000B43698D6}]
@="IBackWebDownloadTimeConstraint"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0D1F7C84-8123-11D0-B5CA-0000B43698D6}]
@="IBackWebDownloadTimeConstraintCollection"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0EC3CFD0-1EFB-11D6-BA63-0010A4FBBFC9}]
@="IBackWeb6_2"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0F4FE440-983F-11D0-9B9C-444553540000}]
@="IBackWebExtension"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{10B2F8C7-B017-4EDF-B7C8-2A1ABF07E263}]
@="IBackWeb6_3"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{12473FC3-61A7-11D0-A866-0000B43699FC}]
@="IBackWebGeneralSettings"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{12473FC4-61A7-11D0-A866-0000B43699FC}]
@="IBackWebDialerSettings"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{12473FC5-61A7-11D0-A866-0000B43699FC}]
@="IBackWebCommSettings"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{12473FC6-61A7-11D0-A866-0000B43699FC}]
@="IBackWebDisplaySettings"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{12473FC7-61A7-11D0-A866-0000B43699FC}]
@="IBackWebSetup"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{12966061-E035-11D2-8C23-00105AA63533}]
@="IBackWebCommSettings6"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{12966062-E035-11D2-8C23-00105AA63533}]
@="IBackWebDisplaySettings6"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{12F4DD61-A432-477C-8664-C1B0E6368DF3}]
@="IBackWebCommSettings6_1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{13837DA8-EF54-4675-AFB8-8E28A01CC26D}]
@="IBackWebUpstreamMessageCollection6_3"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{15030BC0-0B52-11D1-9951-444553540000}]
@="IBackWebDirectory"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1816DBE3-70AA-4B40-8925-369F4DFE93FF}]
@="IBackWebGeneralSettings6_3_1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{18DD4341-D87E-11D2-8C20-00105AA63533}]
@="IBackWebChannelVariableCollection6"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1D91D9E0-004B-11D1-9951-444553540000}]
@="IBackWebStoryFieldCollection"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1E8B2080-AF64-11D4-B94C-0010A4FBBFC9}]
@="IBackWebTimerNotifications"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{23F43240-F78D-11D0-9A50-00AA004812C2}]
@="IBackWeb2"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{28BC6260-DA2F-11D3-B87B-0010A404098C}]
@="IBackWebShutdownProtector"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{29DE5E9B-1C04-40FE-9472-2082C6BB1DE3}]
@="IBackWebChannel7_1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{29E5AF70-B615-11D4-B953-0010A4FBBFC9}]
@="IBackWeb6_0_1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2A58F590-D30B-11D2-8C1E-00105AA63533}]
@="IBackWebGeneralSettings6"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2ACD753B-7EF9-4909-9231-AD6F79E59190}]
@="IBackWebCommSettings7_2_1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2D8ACF70-B161-11D3-BE20-000086397BAD}]
@="IBackWebAttentionManagement"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2DE07D90-DC04-11D0-A875-0000B43699FC}]
@="IBackWebInfoPakDownloadServices"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2E4C4083-3280-4680-9932-0C05B375D71F}]
@="IBackWeb6_3_1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2F068020-F87D-11D0-9A50-00AA004812C2}]
@="IBackWebCustomUserInterface"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2F099AF0-6329-11D0-A866-0000B43699FC}]
@="IBackWebSetupNotifications"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2F0A7430-D34B-11D5-BA2F-0010A4FBBFC9}]
@="IBackWebInfoPak6_2"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2F523082-5A0B-11D0-9B9C-444553540000}]
@="IBackWebChannelTableNotifications"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{34349540-5B8E-11D1-AF44-00AA00480CBE}]
@="IBackWebUpstreamMessageCollection"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{34349541-5B8E-11D1-AF44-00AA00480CBE}]
@="IBackWebUpstreamMessage"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3667E7B0-4F28-11D1-8ADB-00609761C47A}]
@="IBackWebSetup4"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{393920B3-6415-4045-BFF7-69D3CD024261}]
@="IBackWebChannel6_3"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3A43BD61-F0F5-11D2-8C29-00105AA63533}]
@="IBackWeb6"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3AF78A6E-6F14-11D1-A884-0000B43699FC}]
@="IBackWebFileAccess"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3AF78A71-6F14-11D1-A884-0000B43699FC}]
@="IBackWebInfoPakFilesCollection"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3AF78A74-6F14-11D1-A884-0000B43699FC}]
@="IBackWebInfoPakFile"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3AF78A77-6F14-11D1-A884-0000B43699FC}]
@="IBackWebOpenInfoPakFile"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3C027500-C2C7-11D3-B864-0010A404098C}]
@="IBackWeb5_5_1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{419DBB00-B161-11D3-BE20-000086397BAD}]
@="IBackWebAttentionManagementLogic"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{41CEBDC0-32C1-11D1-9951-444553540000}]
@="IBackWebDirectoryNotifications"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{44230BC0-3105-11D1-9951-444553540000}]
@="IBackWebStoryTableNotifications"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4A3666F3-5F2D-11D0-A866-0000B43699FC}]
@="IBackWebInfoPakNotifications"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4AD8B831-E3B3-11D3-AEAE-00105A680865}]
@="IBackWebAttentionManagementContext"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4EC60050-6E5B-11D2-893B-00104BCA9324}]
@="IBackWebFileReplicationManager"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{53C327E0-6576-11D1-BB4B-0000B4369751}]
@="IBackWebChannelDownloadServices2"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{53FCF355-5323-11D0-A864-0000B43699FC}]
@="IBackWeb"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{53FCF35A-5323-11D0-A864-0000B43699FC}]
@="IBackWebChannelCollection"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{53FCF35B-5323-11D0-A864-0000B43699FC}]
@="IBackWebChannel"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{577B3560-C6F3-11D1-AA87-0000B43695BE}]
@="IBackWebFileReplicationResultNotifications"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{581E26D0-DC70-11D2-A64B-00104B9B511A}]
@="IBackWebSetup5_5"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5B1E13A0-004B-11D1-9951-444553540000}]
@="IBackWebStoryField"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5B267241-C2A4-11D3-BE42-000086397BAD}]
@="IBackWebCertificate5_5_1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5DF6CE40-0B50-11D1-9951-444553540000}]
@="IBackWebDirectoryEntryCollection"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5F7A39B8-267B-4EAF-96C1-D727CA053672}]
@="IBackWebFileReplication6_3_2"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{608FE360-6FB2-11D1-A885-0000B43699FC}]
@="IBackWebFileAccessViaDir"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{60BFF8B0-A3CC-11D2-BF9C-00A0C93A4D75}]
@="IBackWebChannel5_5"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{610141C2-7701-11D1-B042-004095903824}]
@="IBackWebInfoPak4_2"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{63CE5B70-AF54-11D4-B94C-0010A4FBBFC9}]
@="IBackWeb6_1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6A21FEE0-5A23-11D3-82F5-00600874D315}]
@="IBackWebStory6"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6EFC6591-E13D-11D2-8C23-00105AA63533}]
@="IBackWebDownloadTimeConstraintCollection6"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6F791E27-0741-4A28-B234-6D813E31AEA7}]
@="IBackWebCertificate7_1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{70C8EF70-2EE2-11D3-B9CD-00C04F9CD5A7}]
@="IBackWebFileAccessViaDir5_5"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{72B62B40-17D1-11D1-96A7-F8E906C10000}]
@="IBackWebAlertSettings"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{73C3FCC0-C4AF-11D1-AA87-0000B43695BE}]
@="IBackWebChannel5"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{740904E0-0BFB-11D1-9951-444553540000}]
@="IBackWeb4"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{74946131-D63B-11D2-8C1F-00105AA63533}]
@="IBackWebChannelCollection6"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{76F0D380-B617-11D4-B953-0010A4FBBFC9}]
@="IBackWebExtensionVariables"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{79D25F04-04FE-11D2-B044-00A0C94CD67E}]
@="IBackWebSetup5"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8028B940-4932-11D1-9951-444553540000}]
@="IBackWebPlayer"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8131F530-649E-11D0-A866-0000B43699FC}]
@="IBackWebAllInfoPakCollection"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{848D6E81-1699-11D3-A793-00105A68088F}]
@="IBackWebGeneralSettings5_5"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8847C5C0-E2C5-11D3-B882-0010A404098C}]
@="IBackWebCommander"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8EA7FB0A-C26A-48A6-9EEE-3501855C4DF8}]
@="IBackWebUpstreamNotifications"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8EB0E1A0-C4B0-11D1-AA87-0000B43695BE}]
@="IBackWebGeneralSettings5"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9132E380-DC21-11D0-A875-0000B43699FC}]
@="IBackWebChannelDownloadServices"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9175A9C0-C6DB-11D1-AA87-0000B43695BE}]
@="IBackWebFileReplicationNotifications"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{93BF8F00-DBE8-11D0-A875-0000B43699FC}]
@="IBackWebItemDownloadServices"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{946AE641-E1E0-11D2-8C23-00105AA63533}]
@="IBackWebDialerSettings6"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9647FB70-DC0F-11D0-A875-0000B43699FC}]
@="IBackWebChannel2"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{98A90D6A-7E63-45BE-88E4-AFB44FAB5C62}]
@="IBackWebGeneralSettings6_3_2"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9A9FCE90-B619-11D3-B857-0010A404098C}]
@="IBackWebExtension6"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9A9FCE91-B619-11D3-B857-0010A404098C}]
@="IBackWebCustomUserInterface6"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9DB46422-FF61-11D0-9951-444553540000}]
@="IBackWebStoryCollection"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9DB46423-FF61-11D0-9951-444553540000}]
@="IBackWebAllStoryCollection"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9DB46424-FF61-11D0-9951-444553540000}]
@="IBackWebStory"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A17240E1-DD5C-11D3-AEA6-00105A680865}]
@="IBackWebSetup6"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A4BC67F0-6C90-11D0-A866-0000B43699FC}]
@="IBackWebChannelVariableCollection"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A7AC2542-1B0C-11D2-83B1-00C0F01859AC}]
@="IBackWebCertificate"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A7AC2543-1B0C-11D2-83B1-00C0F01859AC}]
@="IBackWebCertificateCollection"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A84355A1-D242-11D2-8C1D-00105AA63533}]
@="IBackWebChannel6"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A88B5B90-FB6E-11D5-BA47-0010A4FBBFC9}]
@="IBackWebCommSettings6_2"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AA3B2B15-5F3F-4AE2-9273-D3E07A4A2775}]
@="IBackWebExtensionRequestHandler"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AD705AC0-AF5D-11D4-B94C-0010A4FBBFC9}]
@="IBackWebUserNotIdleDetector"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AE345B98-B6EE-4296-930F-80BFC562B844}]
@="IBackWebDisplaySettings6_2"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AEE96320-2131-11D1-9951-444553540000}]
@="IBackWebChannel4"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AF6BD5B0-D3F3-11D4-B966-0010A4FBBFC9}]
@="IBackWebChannel6_1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B033A622-FE92-4F1F-B48F-FEE197DA69E2}]
@="IBackWeb7_1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B60D9F50-F32E-11D5-BA43-0010A4FBBFC9}]
@="IBackWebStory6_2"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B738B058-B74F-11D1-AA87-0000B43695BE}]
@="IBackWebFileReplication"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B738B05A-B74F-11D1-AA87-0000B43695BE}]
@="IBackWebFileReplicationCleanup"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B941E960-5A21-11D3-82F5-00600874D315}]
@="IBackWebInfoPak6"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B952C110-AF5D-11D4-B94C-0010A4FBBFC9}]
@="IBackWebUserNotIdleDetectorNotifications"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B9E582A3-E440-452F-BD59-F7E723B7CCFF}]
@="IBackWebInfoPak6_3"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BAD37BC0-2231-11D1-9951-444553540000}]
@="IBackWebCommunications"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BCD0C200-69C1-11D1-8AF8-00609761C47A}]
@="IBackWebChannelCollection4"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BD2F5D0C-9C5C-4279-9909-F07973E1BE57}]
@="IBackWebFileReplicationCleanup6_3_2"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BF24C8F0-FB6F-11D5-BA47-0010A4FBBFC9}]
@="IBackWebTempSetting"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C8CEEEE0-17D6-11D1-96A7-F8E906C10000}]
@="IBackWebFilterSettings"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CADD3D20-F328-11D5-BA43-0010A4FBBFC9}]
@="IBackWebChannel6_2"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CD2DE130-C60C-11D5-BA25-0010A4FBBFC9}]
@="IBackWebCommander6_1_4"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CE2F2BC0-C116-11D3-B861-0010A404098C}]
@="IBackWebChannel5_5_1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CE6C0A50-BE92-11D2-B9B0-00C04F9CD5A7}]
@="IBackWebChannel5_0_1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CF513E20-10EC-11D2-B044-00A0C94CD67E}]
@="IBackWebInfoPak5"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CF513E21-10EC-11D2-B044-00A0C94CD67E}]
@="IBackWebInfoPakExternalUpdateCollection"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CF513E22-10EC-11D2-B044-00A0C94CD67E}]
@="IBackWebInfoPakExternalUpdate"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CF513E23-10EC-11D2-B044-00A0C94CD67E}]
@="IBackWebInfoPakFilesCollection5"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CF513E24-10EC-11D2-B044-00A0C94CD67E}]
@="IBackWebInfoPakFile5"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CF7CE690-2C7A-11D2-AFF7-00104B6FDB95}]
@="IBackWebChannelVariableCollection5"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D055A4B0-1A34-11D2-B980-00C04F9CD5A7}]
@="IBackWebInfoPakSubdirsCollection"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D055A4B1-1A34-11D2-B980-00C04F9CD5A7}]
@="IBackWebInfoPakSubdir"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D0894D60-6C6C-11D0-A866-0000B43699FC}]
@="IBackWebApplicationNotifications"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D382C311-FDB7-11D3-9099-00104B9B511A}]
@="IBackWebCapabilities"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D6BD8C50-5A3E-4CE8-8A6E-343D1C0B74DC}]
@="IBackWebUpstreamMessage6_3"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D6F7929C-DDBC-4FCF-9F66-6CB56DE43390}]
@="IBackWebExtension6_3_1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D8B14791-E5DB-11D2-8C24-00105AA63533}]
@="IBackWebCommunications6"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D8CB83C0-AF57-11D4-B94C-0010A4FBBFC9}]
@="IBackWebUserIdleTimer"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DA4CE69D-B9BE-4FF8-A2FA-7A27CDA1107E}]
@="IBackWebCommSettings7_1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DD7499A4-3BF4-4FFA-8253-FEDAF7492441}]
@="IBackWebStoryTableNotifications6_3"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E01AD640-F87D-11D0-9A50-00AA004812C2}]
@="IBackWebGeneralSettings2"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E2FF0110-C29D-11D3-B864-0010A404098C}]
@="IBackWebGeneralSettings5_5_1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E50876A0-AF5A-11D4-B94C-0010A4FBBFC9}]
@="IBackWebUserIdleTimerNotifications"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB1FFFC1-5688-11D0-A865-0000B43699FC}]
@="IBackWebInfoPakCollection"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB1FFFC2-5688-11D0-A865-0000B43699FC}]
@="IBackWebInfoPak"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB2FA8C0-37C5-11D4-B8DE-0010A4FBBFC9}]
@="IBackWebInfoPakAccess"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EDA02220-C4AF-11D2-B9B3-00C04F9CD5A7}]
@="IBackWebInfoPak5_5"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F4B0C3F1-BC3E-11D3-906F-00104B9B511A}]
@="IBackWebComponent"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F4B0C3F2-BC3E-11D3-906F-00104B9B511A}]
@="IBackWebComponentCollection"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F82F55E8-7698-4593-B963-920539528CC2}]
@="IBackWebFileNotifications"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FBAB6C00-5924-11D2-B991-00C04F9CD5A7}]
@="IBackWebStory5"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FD395090-29CF-11D4-B8D0-0010A4FBBFC9}]
@="IBackWebChannelVariable6"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEFCA7F0-6C8E-11D0-A866-0000B43699FC}]
@="IBackWebChannelVariable"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FF41662F-0248-4FE2-90A6-10086BFD424E}]
@="IBackWebCommSettings6_3"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{3AF78A60-6F14-11D1-A884-0000B43699FC}\2.0]
@="BackWebFiles Type Library (v2.0)"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{53FCF357-5323-11D0-A864-0000B43699FC}\2.b]
@="BackWeb Type Library (v2.11)"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{53FCF357-5323-11D0-A864-0000B43699FC}\2.b\0\win32]
@="C:\Program Files\Compaq Connections\5577497\6.3.2.116-5577497\Program\BackWeb.tlb"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{8847C5C1-E2C5-11D3-B882-0010A404098C}\1.1]
@="BackWebCommander Type Library (v1.1)"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{97972D22-C259-11D1-AA87-0000B43695BE}\2.0]
@="BackWebFileReplicationExtension Type Library (v2.0)"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{ADEB3C02-C90B-4907-B23C-C051F5DB99A3}\1.0]
@="BackWeb ClientExt Class 1.0 Type Library"

-= EOF =-

#12 nasdaq

nasdaq

    Forum Deity

  • Global Moderator
  • PipPipPipPipPip
  • 47,832 posts

Posted 10 April 2012 - 06:43 AM

I'm not worry about the rest of the registry entries.
They are all remnant items. None of them is referencing a .exe file that could be used as a process.
Nothing can happen here. Just leave them alone.

A good registry cleaner may help you. I do not subscribe to any of them.
nasdaq

Favorite tools: [ SpywareBlaster ] [ Spybot ] [ AdAware ] [ HijackThis ]
[ Housecall online virus scan ] [ Bitdefender online virus scan ]
[ AVG antivirus ] [ Sunbelt Personal Firewall ] [ ZoneAlarm firewall ]

My help is free, but if we have helped you in anyway,please considerDonating ,
see this topic for details.
We need members like you.

========
Shouldn't water be worth more than diamonds?
Adam Smith Glasgow, 1760

#13 TimmU

TimmU

    Advanced Member

  • Full Member
  • PipPipPip
  • 158 posts

Posted 10 April 2012 - 07:45 AM

Hey nasdaq. Thanks a lot. That sounds good to me. I'll leave it like that.

The only thing left here is the Windows Update dealing with Microsoft .Net Framework. Like I said before, I keep installing them, but they always come back telling me to install these updates again. I don't know what is going on with that. If you have any suggestions, I would appreciate it. If not, no problem, and thanks anyway.

Thanks nasdaq

Edited by TimmU, 10 April 2012 - 07:49 AM.


#14 nasdaq

nasdaq

    Forum Deity

  • Global Moderator
  • PipPipPipPipPip
  • 47,832 posts

Posted 11 April 2012 - 06:56 AM

Do you know which version is not installing correctly?

Have a look at this page.

http://blogs.msdn.co...l-failures.aspx
nasdaq

Favorite tools: [ SpywareBlaster ] [ Spybot ] [ AdAware ] [ HijackThis ]
[ Housecall online virus scan ] [ Bitdefender online virus scan ]
[ AVG antivirus ] [ Sunbelt Personal Firewall ] [ ZoneAlarm firewall ]

My help is free, but if we have helped you in anyway,please considerDonating ,
see this topic for details.
We need members like you.

========
Shouldn't water be worth more than diamonds?
Adam Smith Glasgow, 1760

#15 TimmU

TimmU

    Advanced Member

  • Full Member
  • PipPipPip
  • 158 posts

Posted 11 April 2012 - 11:30 AM

Hey nasdaq. Guess what?

As i was looking at the link you provided (thanks by the way), I was going through the steps to figure out the version, and then I looked at my systems tray and... nothing. The yellow windows update shield was gone! - so the problem is fixed!

I have no idea how that happened. And i swear just yesterday it was still there telling me about the .Net Framework install. But now it's gone!

I even restarted to make sure it wasn't some kind of glitch. But sure enough, it was gone.

How cool is that?

No idea how that got fixed, but I'll take it. :)

Thanks nasdaq. If you think from what you've seen that the computer should be secure, then i guess we're done.

Thank you so much nasdaq. I do appreciate your help!!

#16 nasdaq

nasdaq

    Forum Deity

  • Global Moderator
  • PipPipPipPipPip
  • 47,832 posts

Posted 12 April 2012 - 07:07 AM

Glad we could help.

Sometime after an update just one or two restarts will do it.


Time for some housekeeping

The following will implement some cleanup procedures as well as reset System Restore points:

Click Start > Run and copy/paste the following bold text into the Run box and click OK:

ComboFix /Uninstall
===

Delete the other tools we used.

Surf Safely, and Think Prevention!
===
nasdaq

Favorite tools: [ SpywareBlaster ] [ Spybot ] [ AdAware ] [ HijackThis ]
[ Housecall online virus scan ] [ Bitdefender online virus scan ]
[ AVG antivirus ] [ Sunbelt Personal Firewall ] [ ZoneAlarm firewall ]

My help is free, but if we have helped you in anyway,please considerDonating ,
see this topic for details.
We need members like you.

========
Shouldn't water be worth more than diamonds?
Adam Smith Glasgow, 1760

#17 TimmU

TimmU

    Advanced Member

  • Full Member
  • PipPipPip
  • 158 posts

Posted 12 April 2012 - 07:20 AM

Clean up executed. Thanks.

You know, I just noticed that when I turn off the computer (as opposed to restart) there are updates being installed. So now, the windows update shield is not notifying me about the .Net Framework, but is still trying to install them at shut-down.

It's cool though, I will get help directly at the microsoft forums.

Thanks a lot nasdaq. I appreciate your help. Have a good one!

#18 nasdaq

nasdaq

    Forum Deity

  • Global Moderator
  • PipPipPipPipPip
  • 47,832 posts

Posted 18 April 2012 - 06:39 AM

Since the issue appears to be resolved this Topic is closed.

If you need this topic reopened, please tell the moderating team by replying here with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic.
nasdaq

Favorite tools: [ SpywareBlaster ] [ Spybot ] [ AdAware ] [ HijackThis ]
[ Housecall online virus scan ] [ Bitdefender online virus scan ]
[ AVG antivirus ] [ Sunbelt Personal Firewall ] [ ZoneAlarm firewall ]

My help is free, but if we have helped you in anyway,please considerDonating ,
see this topic for details.
We need members like you.

========
Shouldn't water be worth more than diamonds?
Adam Smith Glasgow, 1760




1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Member of ASAP and UNITE
Support SpywareInfo Forum - click the button