プラットフォーム:

Windows

 危険度:
 感染確認数:
 システムへの影響:
 情報漏えい:

  • マルウェアタイプ:
    アドウェア

  • 破壊活動の有無:
    なし

  • 暗号化:
     

  • 感染報告の有無 :
    はい

  概要

アドウェアは、他のマルウェアに作成されるか、悪意あるWebサイトからユーザが誤ってダウンロードすることによりコンピュータに侵入します。

  詳細

ファイルサイズ 8,020,416 bytes
タイプ EXE
メモリ常駐 はい
発見日 2020年1月13日

侵入方法

アドウェアは、他のマルウェアに作成されるか、悪意あるWebサイトからユーザが誤ってダウンロードすることによりコンピュータに侵入します。

インストール

アドウェアは、以下のプロセスを追加します。

  • "%User Temp%\nso8B30.tmp\Waeeujeil.exe"
  • %User Temp%\{GUID}.exe -s 300 -t 600 -r http://errors.{BLOCKED}statsservice.com/utility.gif?{random characters}
  • %User Temp%\comh.18754\GoogleUpdate.exe /silent /install "appguid={{GUID}}&appname={GUID}&needsadmin=True&lang=en"
  • %Program Files%\MPMP\{GUID}-3.exe /fIwyYjReh='MPMP' /MaVSES='%Program Files%\MPMP\54246.crx' /IIrLlIXDh=54246 /mbQigCM='001359' /nEATq='0' /mAMgNgLyD='0' /fCVstquGS=354A91DE7DC14C2A980B5427C0148BABIE /ROpwC=be6aa8aa1574234ad24e003e9b0dc90a /Urvihe=1_34_05_22 /fZulGR=1.34.5.22 /YDpNA=1562855042 /wJkGOed=http://stats.{BLOCKED}statsservice.com /Gffoh=http://errors.{BLOCKED}statsservice.com /yESOfh=300 /BGUJSPx=ie /LMFCR='{"asw":[0, 8197]}' /EurvNvZhi /RFOFJLcHn /sNvWRz /CZWhcFa=majjphhgppkndjjkmhhnbgafooenebhd /BMiSM=1.26.38 /TZtXhoTG=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDNoah7iM3oReLLaSfyvVCabRVMp55YZBmufkB4ZcTC1BqtOPtP9BvjxBgILPqIKglk4CyccXwgBK2C28bEQiWG7sG3fl1urw/KHfXOg1Xsybf8Oxx+jBOWKoVoKavSUsPnSXdvOvzgOkyihHQ7F30sBiy6suIv6nI4upG1zgLoDwIDAQAB /jwfdaYIy='http://update.{BLOCKED}statsservice.com/validator/{CAMP_ID}/update.json' /pebnyseX=1 /wDjpuFP={{GUID}} /jacVj='%Program Files%\MPMP\1293297481.mxaddon' /DflSga='1293297481.mxaddon' /sPzkmasYM='%Program Files%\MPMP\360-54246.crx' /ymswtHoM /gupYtn='installer' /uQPcK='%User Temp%\MPMPInstaller_1562855042.log'
  • %Program Files%\MPMP\MPMP-novainstaller.exe /rStPb /fIwyYjReh='MPMP' /IIrLlIXDh=54246 /mbQigCM='001359' /nEATq='0' /mAMgNgLyD='0' /fCVstquGS=354A91DE7DC14C2A980B5427C0148BABIE /ROpwC=be6aa8aa1574234ad24e003e9b0dc90a /Urvihe=1_34_05_22 /fZulGR=1.34.5.22 /YDpNA=1562855042 /wJkGOed=http://stats.{BLOCKED}statsservice.com /Gffoh=http://errors.{BLOCKED}statsservice.com /jHfBjGCsu=http://js.{BLOCKED}statsservice.com /BGUJSPx=ie /jPMHvFxp /friKgE='nova' /gupYtn=installer /uQPcK='%User Temp%\MPMPInstaller_1562855042.log' /aDjByNf='file://%User Temp%\nst9695.tmp\novaExtensionData'
  • %Program Files%\MPMP\MPMP-novainstaller.exe /BVUzW /YEpjJ /fIwyYjReh='MPMP' /IIrLlIXDh=54246 /mbQigCM='001359' /nEATq='0' /mAMgNgLyD='0' /fCVstquGS=354A91DE7DC14C2A980B5427C0148BABIE /ROpwC=be6aa8aa1574234ad24e003e9b0dc90a /Urvihe=1_34_05_22 /fZulGR=1.34.5.22 /YDpNA=1562855042 /wJkGOed=http://stats.{BLOCKED}statsservice.com /Gffoh=http://errors.{BLOCKED}statsservice.com /jHfBjGCsu=http://js.{BLOCKED}statsservice.com /BGUJSPx=ie /jPMHvFxp /friKgE='nova' /gupYtn=installer-update /uQPcK='%User Temp%\MPMPInstaller_1562855042.log'
  • %Program Files%\MPMP\{GUID}-4.exe /gVlfG /fIwyYjReh='MPMP' /MaVSES='%Program Files%\MPMP\54246.xpi' /IIrLlIXDh=54246 /mbQigCM='001359' /nEATq='0' /mAMgNgLyD='0' /fCVstquGS=354A91DE7DC14C2A980B5427C0148BABIE /ROpwC=be6aa8aa1574234ad24e003e9b0dc90a /Urvihe=1_34_05_22 /fZulGR=1.34.5.22 /YDpNA=1562855042 /wJkGOed=http://stats.{BLOCKED}statsservice.com /Gffoh=http://errors.{BLOCKED}statsservice.com /yESOfh=300 /CZWhcFa={GUID}@{GUID}.com /BMiSM=0.94 /MuXqEfQp=aa9719e64232b4695ae9ca89cd7f2aa84ca1279dfbc0d44a897ef19301c922b68com54246 /CzgwGkyDN= /wiehZWr='MPMP' /wMuQUM='MediaPlayerEnhance Extension' /ObgWby='Freeven' /BGUJSPx=ie /LMFCR='{"asw":[0, 8197]}' /RFOFJLcHn /sNvWRz /WcCzsYN /jwfdaYIy='http://update.{BLOCKED}statsservice.com/ff_agent_updates/{CAMP_ID}/update.json' /ymswtHoM /gupYtn='installer' /uQPcK='%User Temp%\MPMPInstaller_1562855042.log'
  • %Program Files%\MPMP\MPMP-codedownloader.exe /rStPb /fIwyYjReh='MPMP' /IIrLlIXDh=54246 /mbQigCM='001359' /nEATq='0' /mAMgNgLyD='0' /fCVstquGS=354A91DE7DC14C2A980B5427C0148BABIE /ROpwC=be6aa8aa1574234ad24e003e9b0dc90a /Urvihe=1_34_05_22 /fZulGR=1.34.5.22 /YDpNA=1562855042 /wJkGOed=http://stats.{BLOCKED}statsservice.com /Gffoh=http://errors.{BLOCKED}statsservice.com /jHfBjGCsu=http://js.{BLOCKED}statsservice.com /BGUJSPx=ie /RFOFJLcHn /gupYtn=installer /uQPcK='%User Temp%\MPMPInstaller_1562855042.log' /aDjByNf='file://%User Temp%\nst9695.tmp\extensionData'
  • %Program Files%\MPMP\MPMP-codedownloader.exe /BVUzW /YEpjJ /fIwyYjReh='MPMP' /IIrLlIXDh=54246 /mbQigCM='001359' /nEATq='0' /mAMgNgLyD='0' /fCVstquGS=354A91DE7DC14C2A980B5427C0148BABIE /ROpwC=be6aa8aa1574234ad24e003e9b0dc90a /Urvihe=1_34_05_22 /fZulGR=1.34.5.22 /YDpNA=1562855042 /wJkGOed=http://stats.{BLOCKED}statsservice.com /Gffoh=http://errors.{BLOCKED}statsservice.com /jHfBjGCsu=http://js.{BLOCKED}statsservice.com /BGUJSPx=ie /RFOFJLcHn /gupYtn=installer-update /uQPcK='%User Temp%\MPMPInstaller_1562855042.log'
  • regsvr32 /s "%Program Files%\MPMP\MPMP-bho.dll"
  • regsvr32 /s "%Program Files%\MPMP\MPMP-bho64.dll"
  • AF1.exe -d
  • "%Program Files%\globalUpdate\Update\GoogleUpdate.exe" /regsvc
  • "%Program Files%\globalUpdate\Update\GoogleUpdate.exe" /regserver
  • %Program Files%\globalUpdate\Update\GoogleUpdate.exe /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB2ZXJzaW9uPSIxLjMuMjUuMCIgaXNtYWNoaW5lPSIxIiBzZXNzaW9uaWQ9Ins2Q0U2QUNDMC0yNEY0LTQzNTctQjg2Qy0wQ0ZEMEM4NTFEQTh9IiBpbnN0YWxsc291cmNlPSJvdGhlcmluc3RhbGxjbWQiIHRlc3Rzb3VyY2U9ImF1dG8iIHJlcXVlc3RpZD0iezU4MENGNUQzLUI2RTQtNEI2QS1BOTk0LUYzMjhDNjUyQjE4MX0iPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSI2LjEiIHNwPSJTZXJ2aWNlIFBhY2sgMSIgYXJjaD0ieDY0Ii8-PGFwcCBhcHBpZD0iezQzMEZENEQwLUI3MjktNEY2MS1BQTM0LTkxNTI2NDgxNzk5RH0iIHZlcnNpb249IiIgbmV4dHZlcnNpb249IjEuMy4yNS4wIiBsYW5nPSJlbiIgYnJhbmQ9IiIgY2xpZW50PSIiPjxldmVudCBldmVudHR5cGU9IjIiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjAiLz48L2FwcD48L3JlcXVlc3Q-
  • %Program Files%\globalUpdate\Update\GoogleUpdate.exe /handoff "appguid={{GUID}}&appname={GUID}&needsadmin=True&lang=en" /installsource otherinstallcmd /sessionid "{6CE6ACC0-24F4-4357-B86C-0CFD0C851DA8}" /silent
  • taskeng.exe {963A14C8-F016-4C9C-8E12-5457B9EC281B} S-1-5-18:NT AUTHORITY\System:Service:
  • net
  • %System%\regsvr32.exe /s "%Program Files%\MPMP\MPMP-bho64.dll"
  • %System%\svchost.exe -k WerSvcGroup

アドウェアは、以下のフォルダを作成します。

  • %Program Files%\globalUpdate\Update
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins
  • %AppDataLocal%\globalUpdate
  • %AppDataLocal%\globalUpdate\CrashReports
  • %Program Files%\MPMP
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\locale\en-US
  • %User Temp%\comh.18754
  • %User Profile%\AppData
  • %Program Files%\globalUpdate\Update\Offline
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\userCode
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\defaults
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\locale
  • %Program Files%\globalUpdate
  • %Program Files%\globalUpdate\Update\1.3.25.0
  • %System Root%\Users
  • %Program Files%\globalUpdate\Update\Offline\{27F2D2DB-7D37-4E11-92F6-67B10F86EC61}
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\defaults\preferences
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome
  • %Program Files%\globalUpdate\CrashReports

自動実行方法

アドウェアは、自身をシステムサービスとして登録し、Windows起動時に自動実行されるよう以下のレジストリ値を追加します。

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\globalUpdate
ImagePath = "%Program Files%\globalUpdate\Update\GoogleUpdate.exe /svc"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\globalUpdatem
ImagePath = "%Program Files%\globalUpdate\Update\GoogleUpdate.exe /medsvc"

他のシステム変更

アドウェアは、以下のファイルを改変します。

  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions.json

(註:%Application Data%フォルダは、現在ログオンしているユーザのアプリケーションデータフォルダです。Windows 2000(32-bit)、XP、Server 2003(32-bit)の場合、通常 "C:\Documents and Settings\<ユーザ名>\Local Settings\Application Data" です。また、Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\Users\<ユーザ名>\AppData\Roaming" です。)

アドウェアは、以下のファイルを削除します。

  • %User Temp%\nst9695.tmp
  • %Windows%\Tasks\GoogleUpdateTask.job
  • %Windows%\Tasks\GoogleUpdateTaskMachine.job

(註:%User Temp%フォルダは、現在ログオンしているユーザの一時フォルダです。Windows 2000(32-bit)、XP、Server 2003(32-bit)の場合、通常 "C:\Documents and Settings\<ユーザー名>\Local Settings\Temp"です。また、Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\Users\<ユーザ名>\AppData\Local\Temp" です。. %Windows%フォルダは、Windowsが利用するフォルダで、いずれのオペレーティングシステム(OS)でも通常、"C:\Windows" です。.)

アドウェアは、以下のフォルダを削除します。

  • %User Temp%\nst9695.tmp
  • %User Temp%\nso8B30.tmp

(註:%User Temp%フォルダは、現在ログオンしているユーザの一時フォルダです。Windows 2000(32-bit)、XP、Server 2003(32-bit)の場合、通常 "C:\Documents and Settings\<ユーザー名>\Local Settings\Temp"です。また、Windows Vista、7、8、8.1、2008(64-bit)、2012(64-bit)、10(64-bit)の場合、通常 "C:\Users\<ユーザ名>\AppData\Local\Temp" です。)

アドウェアは、以下のレジストリキーを追加します。

HKEY_LOCAL_MACHINE\Software\Microsoft\
Windows\CurrentVersion\Uninstall\
MPMP

HKEY_LOCAL_MACHINE\Software\GlobalUpdate\
Update\Clients\{{GUID}}

HKEY_LOCAL_MACHINE\Software\GlobalUpdate\
UpdateDev

HKEY_LOCAL_MACHINE\Software\MPMP\
Installer

HKEY_LOCAL_MACHINE\Software\Microsoft\
Internet Explorer\Low Rights\ElevationPolicy\
{{GUID}}

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
Microsoft\Internet Explorer\Low Rights\
ElevationPolicy\{{GUID}}

HKEY_LOCAL_MACHINE\Software\globalUpdate\
Update\network

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
GlobalUpdate\Update\network\
secure

HKEY_LOCAL_MACHINE\Software\globalUpdate\
Update\ClientState

HKEY_LOCAL_MACHINE\Software\globalUpdate\
Update\Clients\{430FD4D0-B729-4F61-AA34-91526481799D}

HKEY_LOCAL_MACHINE\Software\globalUpdate\
Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}

HKEY_LOCAL_MACHINE\Software\globalUpdate\
Update\ClientStateMedium

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MozillaPlugins\@staging.google.com/globalUpdate Update;version=10

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MozillaPlugins\@staging.google.com/globalUpdate Update;version=10\MimeTypes

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MozillaPlugins\@staging.google.com/globalUpdate Update;version=10\MimeTypes\
application/x-vnd.google.oneclickctrl.10

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Ext\Stats\{5645E0E7-FC12-43BF-A6E4-F9751942B298}

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Ext\Stats\{5645E0E7-FC12-43BF-A6E4-F9751942B298}\
iexplore

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Ext\Stats\{5645E0E7-FC12-43BF-A6E4-F9751942B298}\
iexplore\AllowedDomains

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Ext\Stats\{5645E0E7-FC12-43BF-A6E4-F9751942B298}\
iexplore\AllowedDomains\*

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Internet Explorer\Low Rights\
ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdate.OneClickCtrl.10

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdate.OneClickCtrl.10\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}\
ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}\
InprocServer32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
MIME\Database\Content Type\
application/x-vnd.google.oneclickctrl.10

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MozillaPlugins\@staging.google.com/globalUpdate Update;version=4

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MozillaPlugins\@staging.google.com/globalUpdate Update;version=4\MimeTypes

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MozillaPlugins\@staging.google.com/globalUpdate Update;version=4\MimeTypes\
application/x-vnd.google.update3webcontrol.4

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Ext\Stats\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Ext\Stats\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}\
iexplore

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Ext\Stats\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}\
iexplore\AllowedDomains

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Ext\Stats\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}\
iexplore\AllowedDomains\*

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Internet Explorer\Low Rights\
ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdate.Update3WebControl.4

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdate.Update3WebControl.4\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}\
ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}\
InprocServer32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
MIME\Database\Content Type\
application/x-vnd.google.update3webcontrol.4

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\GoogleUpdate.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3COMClassService.1.0

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3COMClassService.1.0\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3COMClassService

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3COMClassService\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3COMClassService\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}\
ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}\
VersionIndependentProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassSvc.1.0

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassSvc.1.0\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassSvc

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassSvc\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassSvc\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}\
ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}\
VersionIndependentProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebSvc.1.0

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebSvc.1.0\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebSvc

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebSvc\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebSvc\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}\
ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}\
VersionIndependentProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoreClass.1

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoreClass.1\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoreClass

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoreClass\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoreClass\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}\
ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}\
VersionIndependentProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}\
InprocHandler32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}\
InprocServer32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}\
InProcServer32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{3CC60715-D6C5-429D-830E-43FA3F86C61D}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{3CC60715-D6C5-429D-830E-43FA3F86C61D}\
ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{3CC60715-D6C5-429D-830E-43FA3F86C61D}\
NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{3A807417-B46D-4D37-8C9A-19AC6DE204F9}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{3A807417-B46D-4D37-8C9A-19AC6DE204F9}\
ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{3A807417-B46D-4D37-8C9A-19AC6DE204F9}\
NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{07F41522-AF7D-4F26-B394-094F059FDB8A}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{07F41522-AF7D-4F26-B394-094F059FDB8A}\
ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{07F41522-AF7D-4F26-B394-094F059FDB8A}\
NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{DD1F043F-ABC8-4643-8B95-D2C5B22BB019}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{DD1F043F-ABC8-4643-8B95-D2C5B22BB019}\
ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{DD1F043F-ABC8-4643-8B95-D2C5B22BB019}\
NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{212E6D43-6062-492A-B8CC-144669FF11ED}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{212E6D43-6062-492A-B8CC-144669FF11ED}\
ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{212E6D43-6062-492A-B8CC-144669FF11ED}\
NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{555D7146-94A8-4C94-AE76-C39CDC7F7705}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{555D7146-94A8-4C94-AE76-C39CDC7F7705}\
ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{555D7146-94A8-4C94-AE76-C39CDC7F7705}\
NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{4517D94C-19BA-46FA-BE66-2A30CEAC4A85}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{4517D94C-19BA-46FA-BE66-2A30CEAC4A85}\
ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{4517D94C-19BA-46FA-BE66-2A30CEAC4A85}\
NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{224FE662-1E6D-4BC0-AEBB-9E2FB4057BE9}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{224FE662-1E6D-4BC0-AEBB-9E2FB4057BE9}\
ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{224FE662-1E6D-4BC0-AEBB-9E2FB4057BE9}\
NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{0C40F472-7407-4467-8914-1DEA7C326972}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{0C40F472-7407-4467-8914-1DEA7C326972}\
ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{0C40F472-7407-4467-8914-1DEA7C326972}\
NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{A6D54287-7939-466A-8579-92546D946C8C}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{A6D54287-7939-466A-8579-92546D946C8C}\
ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{A6D54287-7939-466A-8579-92546D946C8C}\
NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{0522D9A4-4D57-437D-978D-E5B3B6C9005D}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{0522D9A4-4D57-437D-978D-E5B3B6C9005D}\
ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{0522D9A4-4D57-437D-978D-E5B3B6C9005D}\
NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{A8F7D0A5-7074-40B8-9BDC-1174BDD0A132}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{A8F7D0A5-7074-40B8-9BDC-1174BDD0A132}\
ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{A8F7D0A5-7074-40B8-9BDC-1174BDD0A132}\
NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{D14D64BC-A0E4-42E3-BB72-FB41EA43C198}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{D14D64BC-A0E4-42E3-BB72-FB41EA43C198}\
ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{D14D64BC-A0E4-42E3-BB72-FB41EA43C198}\
NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{023E9EC8-B147-40EB-B0B3-DF90618FB371}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{023E9EC8-B147-40EB-B0B3-DF90618FB371}\
ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{023E9EC8-B147-40EB-B0B3-DF90618FB371}\
NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{ED0B64D4-BF27-4521-AD27-190F49BF5EA7}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{ED0B64D4-BF27-4521-AD27-190F49BF5EA7}\
ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{ED0B64D4-BF27-4521-AD27-190F49BF5EA7}\
NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{8120D9D6-785C-4413-9C0C-DF2028C56FAD}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{8120D9D6-785C-4413-9C0C-DF2028C56FAD}\
ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{8120D9D6-785C-4413-9C0C-DF2028C56FAD}\
NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{823AE2EB-E62C-4847-B192-C99B91B92416}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{823AE2EB-E62C-4847-B192-C99B91B92416}\
ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{823AE2EB-E62C-4847-B192-C99B91B92416}\
NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{9B9A45F4-18FC-484A-BACA-076D78273D8E}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{9B9A45F4-18FC-484A-BACA-076D78273D8E}\
ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{9B9A45F4-18FC-484A-BACA-076D78273D8E}\
NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{E3F3E8F9-F747-4DD6-BA6B-82A6CE1E0860}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{E3F3E8F9-F747-4DD6-BA6B-82A6CE1E0860}\
ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{E3F3E8F9-F747-4DD6-BA6B-82A6CE1E0860}\
NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{59D188FA-757A-424E-8C93-F58FFD896BD7}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{59D188FA-757A-424E-8C93-F58FFD896BD7}\
ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{59D188FA-757A-424E-8C93-F58FFD896BD7}\
NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{A78EDAFB-926F-4D93-AB13-8232D7378EB1}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{A78EDAFB-926F-4D93-AB13-8232D7378EB1}\
ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{A78EDAFB-926F-4D93-AB13-8232D7378EB1}\
NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{9B4F7CFE-987D-410E-A8E4-20182E0B3C24}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{9B4F7CFE-987D-410E-A8E4-20182E0B3C24}\
ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{9B4F7CFE-987D-410E-A8E4-20182E0B3C24}\
NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassMachine.1.0

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassMachine.1.0\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassMachine

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassMachine\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassMachine\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}\
ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}\
VersionIndependentProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}\
LocalServer32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}\
Elevation

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebMachine.1.0

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebMachine.1.0\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebMachine

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebMachine\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebMachine\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}\
ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}\
VersionIndependentProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}\
LocalServer32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}\
Elevation

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoCreateAsync.1.0

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoCreateAsync.1.0\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoCreateAsync

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoCreateAsync\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoCreateAsync\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}\
ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}\
VersionIndependentProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}\
LocalServer32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdate.OneClickProcessLauncherMachine.1.0

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdate.OneClickProcessLauncherMachine.1.0\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdate.OneClickProcessLauncherMachine

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdate.OneClickProcessLauncherMachine\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdate.OneClickProcessLauncherMachine\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}\
ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}\
VersionIndependentProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}\
LocalServer32

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Internet Explorer\Low Rights\
ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.ProcessLauncher.1.0

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.ProcessLauncher.1.0\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.ProcessLauncher

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.ProcessLauncher\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.ProcessLauncher\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}\
ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}\
VersionIndependentProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}\
LocalServer32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoreMachineClass.1

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoreMachineClass.1\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoreMachineClass

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoreMachineClass\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoreMachineClass\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}\
ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}\
VersionIndependentProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}\
LocalServer32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}\
Elevation

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
{random key}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassMachineFallback

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassMachineFallback\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassMachineFallback\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}\
ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}\
VersionIndependentProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}\
LocalServer32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}\
Elevation

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebMachineFallback.1.0

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebMachineFallback.1.0\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebMachineFallback

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebMachineFallback\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebMachineFallback\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}\
ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}\
VersionIndependentProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}\
LocalServer32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}\
Elevation

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CredentialDialogMachine.1.0

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CredentialDialogMachine.1.0\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CredentialDialogMachine

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CredentialDialogMachine\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CredentialDialogMachine\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}\
ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}\
VersionIndependentProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}\
LocalServer32

HKEY_LOCAL_MACHINE\Software\MPMP\
Chrome-Profiles

HKEY_LOCAL_MACHINE\Software\MPMP\
Chrome

HKEY_LOCAL_MACHINE\Software\MPMP\
ErrorLists-crchromeinstaller

HKEY_CURRENT_USER\Software\globalUpdate\
Update\proxy

HKEY_LOCAL_MACHINE\Software\Classes\
Local Settings

HKEY_LOCAL_MACHINE\Software\Classes\
Local Settings\Software

HKEY_LOCAL_MACHINE\Software\Classes\
Local Settings\Software\Microsoft

HKEY_LOCAL_MACHINE\Software\Classes\
Local Settings\Software\Microsoft\
Windows

HKEY_LOCAL_MACHINE\Software\Classes\
Local Settings\Software\Microsoft\
Windows\CurrentVersion

HKEY_LOCAL_MACHINE\Software\Classes\
Local Settings\Software\Microsoft\
Windows\CurrentVersion\AppContainer

HKEY_LOCAL_MACHINE\Software\Classes\
Local Settings\Software\Microsoft\
Windows\CurrentVersion\AppContainer\
Storage

HKEY_LOCAL_MACHINE\Software\Classes\
Local Settings\Software\Microsoft\
Windows\CurrentVersion\AppContainer\
Storage\windows_ie_ac_001

HKEY_LOCAL_MACHINE\Software\Classes\
Local Settings\Software\Microsoft\
Windows\CurrentVersion\AppContainer\
Storage\windows_ie_ac_001\Software

HKEY_LOCAL_MACHINE\Software\MPMP\
Update

HKEY_LOCAL_MACHINE\Software\MPMP\
Manifest

HKEY_LOCAL_MACHINE\Software\MPMP\
Code

HKEY_LOCAL_MACHINE\Software\MPMP\
Plugins

HKEY_LOCAL_MACHINE\Software\MPMP\
Plugins\251

HKEY_LOCAL_MACHINE\Software\MPMP\
Plugins\249

HKEY_LOCAL_MACHINE\Software\MPMP\
Plugins\250

HKEY_LOCAL_MACHINE\Software\MPMP\
Plugins\14

HKEY_LOCAL_MACHINE\Software\MPMP\
Plugins\78

HKEY_LOCAL_MACHINE\Software\MPMP\
Plugins\233

HKEY_LOCAL_MACHINE\Software\MPMP\
Plugins\253

HKEY_LOCAL_MACHINE\Software\MPMP\
Plugins\242

HKEY_LOCAL_MACHINE\Software\MPMP\
Plugins\211

HKEY_LOCAL_MACHINE\Software\MPMP\
Plugins\191

HKEY_LOCAL_MACHINE\Software\MPMP\
Plugins\184

HKEY_LOCAL_MACHINE\Software\MPMP\
Plugins\155

HKEY_LOCAL_MACHINE\Software\MPMP\
Plugins\102

HKEY_LOCAL_MACHINE\Software\MPMP\
Plugins\93

HKEY_LOCAL_MACHINE\Software\MPMP\
Plugins\91

HKEY_LOCAL_MACHINE\Software\MPMP\
Plugins\246

HKEY_LOCAL_MACHINE\Software\MPMP\
Plugins\4

HKEY_LOCAL_MACHINE\Software\MPMP\
Firefox\Profiles

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP

HKEY_CURRENT_USER\Software\Classes\
Local Settings\Software\Microsoft\
Windows\CurrentVersion\AppContainer

HKEY_CURRENT_USER\Software\Classes\
Local Settings\Software\Microsoft\
Windows\CurrentVersion\AppContainer\
Storage

HKEY_CURRENT_USER\Software\Classes\
Local Settings\Software\Microsoft\
Windows\CurrentVersion\AppContainer\
Storage\windows_ie_ac_001

HKEY_CURRENT_USER\Software\Classes\
Local Settings\Software\Microsoft\
Windows\CurrentVersion\AppContainer\
Storage\windows_ie_ac_001\Software

HKEY_CURRENT_USER\Software\Classes\
Local Settings\Software\Microsoft\
Windows\CurrentVersion\AppContainer\
Storage\windows_ie_ac_001\Software\
MPMP

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Update

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\Crossrider

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Installer

HKEY_LOCAL_MACHINE\Software\MPMP\
IE\Profiles

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Manifest

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Code

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\183

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\182

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\177

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\94

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\78

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\207

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\64

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\72

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\46

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\45

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\44

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\43

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\42

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\41

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\40

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\39

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\38

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\37

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\36

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\35

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\17

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\14

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\13

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\253

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\242

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\233

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\226

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\221

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\211

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\195

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\220

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\7

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\9

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\191

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\190

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\155

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\104

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\184

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\103

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\102

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\93

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\91

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\246

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\47

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\22

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\28

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\3

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\21

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\2

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\4

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\1

HKEY_CLASSES_ROOT\CrossriderApp0054246.Sandbox.1

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp0054246.Sandbox.1\CLSID

HKEY_CLASSES_ROOT\CrossriderApp0054246.BHO.1

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp0054246.BHO.1\CLSID

HKEY_CLASSES_ROOT\CrossriderApp0054246.Sandbox

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp0054246.Sandbox\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp0054246.Sandbox\CurVer

HKEY_CLASSES_ROOT\CrossriderApp0054246.BHO

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp0054246.BHO\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp0054246.BHO\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{{GUID}}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{{GUID}}\
ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{{GUID}}\
VersionIndependentProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{{GUID}}\
Programmable

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{{GUID}}\
InprocServer32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{{GUID}}\
TypeLib

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{{GUID}}\
Implemented Categories

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{{GUID}}\
Implemented Categories\{{GUID}}

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
explorer\Browser Helper Objects\{{GUID}}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{{GUID}}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{{GUID}}\
ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{{GUID}}\
TypeLib

アドウェアは、以下のレジストリ値を追加します。

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\MPMP
DisplayName = "MPMP"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\MPMP
DisplayIcon = "%Program Files%\MPMP\utils.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\MPMP
DisplayVersion = "1.34.5.22"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\MPMP
Publisher = "Freeven"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\MPMP
CrPublisherId = "21636"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\MPMP
CrAppId = "54246"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\MPMP
UninstallString = "%Program Files%\MPMP\Uninstall.exe /fcp=1"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
GlobalUpdate\Update\Clients\
{{GUID}}
pv = "1.3.25.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
GlobalUpdate\Update\Clients\
{{GUID}}
name = "Freeven"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
GlobalUpdate\Update\Clients\
{{GUID}}
bic = "354A91DE7DC14C2A980B5427C0148BABIE"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
GlobalUpdate\Update\Clients\
{{GUID}}
verifier = "be6aa8aa1574234ad24e003e9b0dc90a"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
GlobalUpdate\Update\Clients\
{{GUID}}
srcid_var = "001359"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
GlobalUpdate\UpdateDev
AuCheckPeriodMs = "21600000"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Installer
BundledChrome = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Installer
BundledNova = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Internet Explorer\MAIN\
FeatureControl\FEATURE_BROWSER_EMULATION\%Program Files%\
MPMP
MPMP-nova.exe = "8000"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Installer
BundledFirefox = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Installer
BundledIe = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Internet Explorer\Low Rights\
ElevationPolicy\{{GUID}}
AppName = "MPMP-codedownloader.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Internet Explorer\Low Rights\
ElevationPolicy\{{GUID}}
AppPath = "%Program Files%\MPMP"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Internet Explorer\Low Rights\
ElevationPolicy\{{GUID}}
Policy = "3"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Internet Explorer\Low Rights\ElevationPolicy\
{{GUID}}
AppName = "MPMP-codedownloader.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Internet Explorer\Low Rights\ElevationPolicy\
{{GUID}}
AppPath = "%Program Files%\MPMP"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Internet Explorer\Low Rights\ElevationPolicy\
{{GUID}}
Policy = "3"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
GlobalUpdate\Update
path = "%Program Files%\globalUpdate\Update\GoogleUpdate.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
GlobalUpdate\Update\Clients\
{430FD4D0-B729-4F61-AA34-91526481799D}
pv = "1.3.25.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
GlobalUpdate\Update\Clients\
{430FD4D0-B729-4F61-AA34-91526481799D}
name = "globalUpdate Update"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
GlobalUpdate\Update\ClientState\
{430FD4D0-B729-4F61-AA34-91526481799D}
pv = "1.3.25.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows NT\CurrentVersion\Image File Execution Options\
GoogleUpdate.exe
DisableExceptionChainValidation = "0"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
GlobalUpdate\Update
version = "1.3.25.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Path = "%Program Files%\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Description = "globalUpdate Update"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
ProductName = "globalUpdate Update"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Vendor = "globalUpdate"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Version = "10"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Internet Explorer\Low Rights\
ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
AppName = "GoogleUpdate.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Internet Explorer\Low Rights\
ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
AppPath = "%Program Files%\globalUpdate\Update"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Internet Explorer\Low Rights\
ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Policy = "3"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdate.OneClickCtrl.10
(Default) = "globalUpdate Update Plugin"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdate.OneClickCtrl.10\CLSID
(Default) = "{5645E0E7-FC12-43BF-A6E4-F9751942B298}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
(Default) = "globalUpdate Update Plugin"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}\
ProgID
(Default) = "globalUpdate.OneClickCtrl.10"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}\
InprocServer32
(Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}\
InprocServer32
ThreadingModel = "Apartment"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
MIME\Database\Content Type\
application/x-vnd.google.oneclickctrl.10
CLSID = "{5645E0E7-FC12-43BF-A6E4-F9751942B298}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Path = "%Program Files%\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Description = "globalUpdate Update"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
ProductName = "globalUpdate Update"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Vendor = "globalUpdate"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Version = "4"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Internet Explorer\Low Rights\
ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
AppName = "GoogleUpdateBroker.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Internet Explorer\Low Rights\
ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
AppPath = "%Program Files%\globalUpdate\Update\1.3.25.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Internet Explorer\Low Rights\
ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Policy = "3"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdate.Update3WebControl.4
(Default) = "globalUpdate Update Plugin"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdate.Update3WebControl.4\CLSID
(Default) = "{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
(Default) = "globalUpdate Update Plugin"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}\
ProgID
(Default) = "globalUpdate.Update3WebControl.4"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}\
InprocServer32
(Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}\
InprocServer32
ThreadingModel = "Apartment"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
MIME\Database\Content Type\
application/x-vnd.google.update3webcontrol.4
CLSID = "{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
GlobalUpdate\Update\ClientState\
{430FD4D0-B729-4F61-AA34-91526481799D}
brand = "GGLS"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
GlobalUpdate\Update\ClientState\
{430FD4D0-B729-4F61-AA34-91526481799D}
InstallTime = "1562855189"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
(Default) = "ServiceModule"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\GoogleUpdate.exe
AppID = "{577975B8-C40E-43E6-B0DE-4C6B44088B52}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
LocalService = "globalUpdate"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
ServiceParameters = "/comsvc"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3COMClassService.1.0
(Default) = "Update3COMClass"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3COMClassService.1.0\CLSID
(Default) = "{577975B8-C40E-43E6-B0DE-4C6B44088B52}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3COMClassService
(Default) = "Update3COMClass"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3COMClassService\CLSID
(Default) = "{577975B8-C40E-43E6-B0DE-4C6B44088B52}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3COMClassService\CurVer
(Default) = "globalUpdateUpdate.Update3COMClassService.1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
(Default) = "Update3COMClass"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}\
ProgID
(Default) = "globalUpdateUpdate.Update3COMClassService.1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}\
VersionIndependentProgID
(Default) = "globalUpdateUpdate.Update3COMClassService"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
AppID = "{577975B8-C40E-43E6-B0DE-4C6B44088B52}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
(Default) = "ServiceModule"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\GoogleUpdate.exe
AppID = "{3278F5CF-48F3-4253-A6BB-004CE84AF492}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
LocalService = "globalUpdatem"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
ServiceParameters = "/comsvc"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassSvc.1.0
(Default) = "Google Update Legacy On Demand"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassSvc.1.0\CLSID
(Default) = "{3278F5CF-48F3-4253-A6BB-004CE84AF492}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassSvc
(Default) = "Google Update Legacy On Demand"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassSvc\CLSID
(Default) = "{3278F5CF-48F3-4253-A6BB-004CE84AF492}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassSvc\CurVer
(Default) = "globalUpdateUpdate.OnDemandCOMClassSvc.1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
(Default) = "Google Update Legacy On Demand"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}\
ProgID
(Default) = "globalUpdateUpdate.OnDemandCOMClassSvc.1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}\
VersionIndependentProgID
(Default) = "globalUpdateUpdate.OnDemandCOMClassSvc"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
AppID = "{3278F5CF-48F3-4253-A6BB-004CE84AF492}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebSvc.1.0
(Default) = "GoogleUpdate Update3Web"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebSvc.1.0\CLSID
(Default) = "{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebSvc
(Default) = "GoogleUpdate Update3Web"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebSvc\CLSID
(Default) = "{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebSvc\CurVer
(Default) = "globalUpdateUpdate.Update3WebSvc.1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
(Default) = "GoogleUpdate Update3Web"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}\
ProgID
(Default) = "globalUpdateUpdate.Update3WebSvc.1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}\
VersionIndependentProgID
(Default) = "globalUpdateUpdate.Update3WebSvc"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
AppID = "{3278F5CF-48F3-4253-A6BB-004CE84AF492}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoreClass.1
(Default) = "Google Update Core Class"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoreClass.1\CLSID
(Default) = "{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoreClass
(Default) = "Google Update Core Class"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoreClass\CLSID
(Default) = "{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoreClass\CurVer
(Default) = "globalUpdateUpdate.CoreClass.1"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
(Default) = "Google Update Core Class"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}\
ProgID
(Default) = "globalUpdateUpdate.CoreClass.1"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}\
VersionIndependentProgID
(Default) = "globalUpdateUpdate.CoreClass"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
AppID = "{3278F5CF-48F3-4253-A6BB-004CE84AF492}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}\
InprocHandler32
(Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\psmachine.dll"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}\
InprocHandler32
ThreadingModel = "Both"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}\
InprocServer32
(Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\psmachine.dll"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}\
InprocServer32
ThreadingModel = "Both"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}\
InProcServer32
(Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\psmachine.dll"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}\
InProcServer32
ThreadingModel = "Both"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
(Default) = "PSFactoryBuffer"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{3CC60715-D6C5-429D-830E-43FA3F86C61D}\
ProxyStubClsid32
(Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{3CC60715-D6C5-429D-830E-43FA3F86C61D}
(Default) = "IProgressWndEvents"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{3CC60715-D6C5-429D-830E-43FA3F86C61D}\
NumMethods
(Default) = "9"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{3A807417-B46D-4D37-8C9A-19AC6DE204F9}\
ProxyStubClsid32
(Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{3A807417-B46D-4D37-8C9A-19AC6DE204F9}
(Default) = "IBrowserHttpRequest2"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{3A807417-B46D-4D37-8C9A-19AC6DE204F9}\
NumMethods
(Default) = "4"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{07F41522-AF7D-4F26-B394-094F059FDB8A}\
ProxyStubClsid32
(Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{07F41522-AF7D-4F26-B394-094F059FDB8A}
(Default) = "IAppBundleWeb"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{07F41522-AF7D-4F26-B394-094F059FDB8A}\
NumMethods
(Default) = "24"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{DD1F043F-ABC8-4643-8B95-D2C5B22BB019}\
ProxyStubClsid32
(Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{DD1F043F-ABC8-4643-8B95-D2C5B22BB019}
(Default) = "IProcessLauncher"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{DD1F043F-ABC8-4643-8B95-D2C5B22BB019}\
NumMethods
(Default) = "6"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{212E6D43-6062-492A-B8CC-144669FF11ED}\
ProxyStubClsid32
(Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{212E6D43-6062-492A-B8CC-144669FF11ED}
(Default) = "IAppVersion"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{212E6D43-6062-492A-B8CC-144669FF11ED}\
NumMethods
(Default) = "10"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{555D7146-94A8-4C94-AE76-C39CDC7F7705}\
ProxyStubClsid32
(Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{555D7146-94A8-4C94-AE76-C39CDC7F7705}
(Default) = "ICoCreateAsyncStatus"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{555D7146-94A8-4C94-AE76-C39CDC7F7705}\
NumMethods
(Default) = "10"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{4517D94C-19BA-46FA-BE66-2A30CEAC4A85}\
ProxyStubClsid32
(Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{4517D94C-19BA-46FA-BE66-2A30CEAC4A85}
(Default) = "IAppBundle"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{4517D94C-19BA-46FA-BE66-2A30CEAC4A85}\
NumMethods
(Default) = "39"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{224FE662-1E6D-4BC0-AEBB-9E2FB4057BE9}\
ProxyStubClsid32
(Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{224FE662-1E6D-4BC0-AEBB-9E2FB4057BE9}
(Default) = "ICoCreateAsync"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{224FE662-1E6D-4BC0-AEBB-9E2FB4057BE9}\
NumMethods
(Default) = "4"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{0C40F472-7407-4467-8914-1DEA7C326972}\
ProxyStubClsid32
(Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{0C40F472-7407-4467-8914-1DEA7C326972}
(Default) = "IAppWeb"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{0C40F472-7407-4467-8914-1DEA7C326972}\
NumMethods
(Default) = "14"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{A6D54287-7939-466A-8579-92546D946C8C}\
ProxyStubClsid32
(Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{A6D54287-7939-466A-8579-92546D946C8C}
(Default) = "IOneClickProcessLauncher"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{A6D54287-7939-466A-8579-92546D946C8C}\
NumMethods
(Default) = "4"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{0522D9A4-4D57-437D-978D-E5B3B6C9005D}\
ProxyStubClsid32
(Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{0522D9A4-4D57-437D-978D-E5B3B6C9005D}
(Default) = "IAppVersionWeb"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{0522D9A4-4D57-437D-978D-E5B3B6C9005D}\
NumMethods
(Default) = "10"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{A8F7D0A5-7074-40B8-9BDC-1174BDD0A132}\
ProxyStubClsid32
(Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{A8F7D0A5-7074-40B8-9BDC-1174BDD0A132}
(Default) = "IGoogleUpdate3WebSecurity"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{A8F7D0A5-7074-40B8-9BDC-1174BDD0A132}\
NumMethods
(Default) = "4"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{D14D64BC-A0E4-42E3-BB72-FB41EA43C198}\
ProxyStubClsid32
(Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{D14D64BC-A0E4-42E3-BB72-FB41EA43C198}
(Default) = "IPackage"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{D14D64BC-A0E4-42E3-BB72-FB41EA43C198}\
NumMethods
(Default) = "10"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{023E9EC8-B147-40EB-B0B3-DF90618FB371}\
ProxyStubClsid32
(Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{023E9EC8-B147-40EB-B0B3-DF90618FB371}
(Default) = "ICurrentState"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{023E9EC8-B147-40EB-B0B3-DF90618FB371}\
NumMethods
(Default) = "24"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{ED0B64D4-BF27-4521-AD27-190F49BF5EA7}\
ProxyStubClsid32
(Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{ED0B64D4-BF27-4521-AD27-190F49BF5EA7}
(Default) = "IJobObserver"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{ED0B64D4-BF27-4521-AD27-190F49BF5EA7}\
NumMethods
(Default) = "13"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{8120D9D6-785C-4413-9C0C-DF2028C56FAD}\
ProxyStubClsid32
(Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{8120D9D6-785C-4413-9C0C-DF2028C56FAD}
(Default) = "IGoogleUpdate"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{8120D9D6-785C-4413-9C0C-DF2028C56FAD}\
NumMethods
(Default) = "5"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{823AE2EB-E62C-4847-B192-C99B91B92416}\
ProxyStubClsid32
(Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{823AE2EB-E62C-4847-B192-C99B91B92416}
(Default) = "IApp"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{823AE2EB-E62C-4847-B192-C99B91B92416}\
NumMethods
(Default) = "40"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{9B9A45F4-18FC-484A-BACA-076D78273D8E}\
ProxyStubClsid32
(Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{9B9A45F4-18FC-484A-BACA-076D78273D8E}
(Default) = "IGoogleUpdateCore"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{9B9A45F4-18FC-484A-BACA-076D78273D8E}\
NumMethods
(Default) = "4"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{E3F3E8F9-F747-4DD6-BA6B-82A6CE1E0860}\
ProxyStubClsid32
(Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{E3F3E8F9-F747-4DD6-BA6B-82A6CE1E0860}
(Default) = "IRegistrationUpdateHook"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{E3F3E8F9-F747-4DD6-BA6B-82A6CE1E0860}\
NumMethods
(Default) = "8"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{59D188FA-757A-424E-8C93-F58FFD896BD7}\
ProxyStubClsid32
(Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{59D188FA-757A-424E-8C93-F58FFD896BD7}
(Default) = "ICredentialDialog"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{59D188FA-757A-424E-8C93-F58FFD896BD7}\
NumMethods
(Default) = "4"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{A78EDAFB-926F-4D93-AB13-8232D7378EB1}\
ProxyStubClsid32
(Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{A78EDAFB-926F-4D93-AB13-8232D7378EB1}
(Default) = "IGoogleUpdate3"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{A78EDAFB-926F-4D93-AB13-8232D7378EB1}\
NumMethods
(Default) = "10"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{9B4F7CFE-987D-410E-A8E4-20182E0B3C24}\
ProxyStubClsid32
(Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{9B4F7CFE-987D-410E-A8E4-20182E0B3C24}
(Default) = "IGoogleUpdate3Web"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{9B4F7CFE-987D-410E-A8E4-20182E0B3C24}\
NumMethods
(Default) = "8"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassMachine.1.0
(Default) = "Google Update Broker Class Factory"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassMachine.1.0\CLSID
(Default) = "{ADBC39BE-3D20-4333-8D99-E91EB1B62474}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassMachine
(Default) = "Google Update Broker Class Factory"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassMachine\CLSID
(Default) = "{ADBC39BE-3D20-4333-8D99-E91EB1B62474}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassMachine\CurVer
(Default) = "globalUpdateUpdate.OnDemandCOMClassMachine.1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
(Default) = "Google Update Broker Class Factory"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}\
ProgID
(Default) = "globalUpdateUpdate.OnDemandCOMClassMachine.1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}\
VersionIndependentProgID
(Default) = "globalUpdateUpdate.OnDemandCOMClassMachine"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}\
LocalServer32
(Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
LocalizedString = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-3000"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}\
Elevation
Enabled = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}\
Elevation
IconReference = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-1004"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebMachine.1.0
(Default) = "Google Update Broker Class Factory"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebMachine.1.0\CLSID
(Default) = "{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebMachine
(Default) = "Google Update Broker Class Factory"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebMachine\CLSID
(Default) = "{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebMachine\CurVer
(Default) = "globalUpdateUpdate.Update3WebMachine.1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
(Default) = "Google Update Broker Class Factory"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}\
ProgID
(Default) = "globalUpdateUpdate.Update3WebMachine.1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}\
VersionIndependentProgID
(Default) = "globalUpdateUpdate.Update3WebMachine"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}\
LocalServer32
(Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
LocalizedString = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-3000"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}\
Elevation
Enabled = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}\
Elevation
IconReference = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-1004"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoCreateAsync.1.0
(Default) = "CoCreateAsync"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoCreateAsync.1.0\CLSID
(Default) = "{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoCreateAsync
(Default) = "CoCreateAsync"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoCreateAsync\CLSID
(Default) = "{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoCreateAsync\CurVer
(Default) = "globalUpdateUpdate.CoCreateAsync.1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
(Default) = "CoCreateAsync"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}\
ProgID
(Default) = "globalUpdateUpdate.CoCreateAsync.1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}\
VersionIndependentProgID
(Default) = "globalUpdateUpdate.CoCreateAsync"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}\
LocalServer32
(Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdate.OneClickProcessLauncherMachine.1.0
(Default) = "globalUpdate.OneClickProcessLauncher"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdate.OneClickProcessLauncherMachine.1.0\CLSID
(Default) = "{5E89ACE9-E16B-499A-87B4-0DBF742404C1}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdate.OneClickProcessLauncherMachine
(Default) = "globalUpdate.OneClickProcessLauncher"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdate.OneClickProcessLauncherMachine\CLSID
(Default) = "{5E89ACE9-E16B-499A-87B4-0DBF742404C1}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdate.OneClickProcessLauncherMachine\CurVer
(Default) = "globalUpdate.OneClickProcessLauncherMachine.1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
(Default) = "globalUpdate.OneClickProcessLauncher"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}\
ProgID
(Default) = "globalUpdate.OneClickProcessLauncherMachine.1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}\
VersionIndependentProgID
(Default) = "globalUpdate.OneClickProcessLauncherMachine"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}\
LocalServer32
(Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Internet Explorer\Low Rights\
ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
CLSID = "{5E89ACE9-E16B-499A-87B4-0DBF742404C1}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Internet Explorer\Low Rights\
ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Policy = "3"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.ProcessLauncher.1.0
(Default) = "Google Update Process Launcher Class"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.ProcessLauncher.1.0\CLSID
(Default) = "{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.ProcessLauncher
(Default) = "Google Update Process Launcher Class"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.ProcessLauncher\CLSID
(Default) = "{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.ProcessLauncher\CurVer
(Default) = "globalUpdateUpdate.ProcessLauncher.1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
(Default) = "Google Update Process Launcher Class"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}\
ProgID
(Default) = "globalUpdateUpdate.ProcessLauncher.1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}\
VersionIndependentProgID
(Default) = "globalUpdateUpdate.ProcessLauncher"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}\
LocalServer32
(Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoreMachineClass.1
(Default) = "Google Update Core Class"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoreMachineClass.1\CLSID
(Default) = "{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoreMachineClass
(Default) = "Google Update Core Class"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoreMachineClass\CLSID
(Default) = "{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoreMachineClass\CurVer
(Default) = "globalUpdateUpdate.CoreMachineClass.1"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
(Default) = "Google Update Core Class"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}\
ProgID
(Default) = "globalUpdateUpdate.CoreMachineClass.1"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}\
VersionIndependentProgID
(Default) = "globalUpdateUpdate.CoreMachineClass"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}\
LocalServer32
(Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
LocalizedString = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-3000"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}\
Elevation
Enabled = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}\
Elevation
IconReference = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-1004"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
{random key}
(Default) = "Google Update Legacy On Demand"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0\CLSID
(Default) = "{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassMachineFallback
(Default) = "Google Update Legacy On Demand"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassMachineFallback\CLSID
(Default) = "{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassMachineFallback\CurVer
(Default) = "globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
(Default) = "Google Update Legacy On Demand"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}\
ProgID
(Default) = "globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}\
VersionIndependentProgID
(Default) = "globalUpdateUpdate.OnDemandCOMClassMachineFallback"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}\
LocalServer32
(Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
LocalizedString = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-3000"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}\
Elevation
Enabled = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}\
Elevation
IconReference = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-1004"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebMachineFallback.1.0
(Default) = "GoogleUpdate Update3Web"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebMachineFallback.1.0\CLSID
(Default) = "{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebMachineFallback
(Default) = "GoogleUpdate Update3Web"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebMachineFallback\CLSID
(Default) = "{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebMachineFallback\CurVer
(Default) = "globalUpdateUpdate.Update3WebMachineFallback.1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
(Default) = "GoogleUpdate Update3Web"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}\
ProgID
(Default) = "globalUpdateUpdate.Update3WebMachineFallback.1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}\
VersionIndependentProgID
(Default) = "globalUpdateUpdate.Update3WebMachineFallback"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}\
LocalServer32
(Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
LocalizedString = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-3000"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}\
Elevation
Enabled = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}\
Elevation
IconReference = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-1004"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CredentialDialogMachine.1.0
(Default) = "GoogleUpdate CredentialDialog"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CredentialDialogMachine.1.0\CLSID
(Default) = "{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CredentialDialogMachine
(Default) = "GoogleUpdate CredentialDialog"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CredentialDialogMachine\CLSID
(Default) = "{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CredentialDialogMachine\CurVer
(Default) = "globalUpdateUpdate.CredentialDialogMachine.1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
(Default) = "GoogleUpdate CredentialDialog"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}\
ProgID
(Default) = "globalUpdateUpdate.CredentialDialogMachine.1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}\
VersionIndependentProgID
(Default) = "globalUpdateUpdate.CredentialDialogMachine"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}\
LocalServer32
(Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Chrome-Profiles\%AppDataLocal%\
Google\Chrome\User Data
Default = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Chrome
TotalProfiles = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\ErrorLists-crchromeinstaller
post_for_sign_Invalid HTTP(S) status code = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\ErrorLists-crchromeinstaller
insert_cook_db_1_table cookies has no column named secure = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\ErrorLists-crchromeinstaller
insert_cook_db_1_table cookies has no column named secure = "2"

HKEY_CURRENT_USER\Software\globalUpdate\
Update\proxy
source = "IE"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP
ActiveAppId = "54246"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Update
LastCheck = "1562855063"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Installer
Bic = "354A91DE7DC14C2A980B5427C0148BABIE"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Installer
Verifier = "be6aa8aa1574234ad24e003e9b0dc90a"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Installer
Time = "1562855042"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Installer
StatsDomain = "http://stats.{BLOCKED}statsservice.com"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Installer
ErrorsDomain = "http://errors.{BLOCKED}statsservice.com"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Installer
CodeDownloadDomain = "http://js.{BLOCKED}statsservice.com"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Installer
FullVersion = "1.34.5.22"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Installer
FullVersionForUrl = "1_34_05_22"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Installer
SrcId = "001359"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Installer
SubId = "0"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Installer
ZData = "0"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Installer
DefaultBrowser = "ie"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Installer
OsName = "7"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Installer
Params = "{ source_id : 001359, sub_id : 0, uzid : 0}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Manifest
Name = "MPMP"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Manifest
Manifest = "NA"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Manifest
Description = "MediaPlayerEnhance Extension"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Manifest
PublisherName = "Freeven"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Manifest
HomePageUrl = "NA"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Manifest
RunInFrame = "false"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Manifest
ThanksUrl = "NA"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Manifest
DisableIe = "true"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Manifest
EnableSearchIE = "false"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Manifest
Version = "38"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Manifest
UpdateInterval = "360"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Manifest
BgVersion = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Manifest
AddressbarURL = "NA"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Manifest
ChangePrevious = "false"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Manifest
SetNewTab = "false"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Manifest
PublisherId = "21636"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Manifest
ModeType = "production"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Manifest
PluginsManifestVersion = "30"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Manifest
IsButtonEnabled = "false"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Manifest
UninstallerOfferUrl = "NA"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Manifest
UninstallerOfferAction = "NA"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Code
AppJavaScript = "{random characters}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Code
BgJavaScript = "{random characters}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Code
NewTabJavaScript = ""

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\251
Version = "8"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\251
Name = "versionBinaryString"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\251
JavaScript = "{random characters}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\251
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/Nova/versionBinaryString.js"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\249
Version = "6"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\249
Name = "native"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\249
JavaScript = "{random characters}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\249
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/Nova/native.js"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\250
Version = "5"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\250
Name = "api"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\250
JavaScript = "{random characters}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\250
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/Nova/api.js"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\14
Version = "11"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\14
Name = "CrossriderUtils"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\14
JavaScript = "{random characters}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\14
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/CrossriderUtils.js"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\78
Version = "5"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\78
Name = "CrossriderInfo"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\78
JavaScript = "{random characters}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\78
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/CrossriderInfo.js"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\233
Version = "5"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\233
Name = "revizer_p_dynamic_b2b_2_m"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\233
JavaScript = "{random characters}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\233
Url = "{random characters}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\253
Version = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\253
Name = "pixel_inject"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\253
JavaScript = "{random characters}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\253
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/pixel_inject.js"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\242
Version = "3"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\242
Name = "price_gong_m"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\242
JavaScript = "{random characters}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\242
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/price_gong_m.js"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\211
Version = "5"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\211
Name = "revizer_ws_dynamic_b2b_light_m"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\211
JavaScript = "{random characters}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\211
Url = "{random characters}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\191
Version = "5"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\191
Name = "ciuvo_m"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\191
JavaScript = "{random characters}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\191
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/ciuvo_m.js"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\184
Version = "9"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\184
Name = "noproblemppc_m"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\184
JavaScript = "{random characters}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\184
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/noproblemppc_m.js"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\155
Version = "3"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\155
Name = "ibario_pops_m"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\155
JavaScript = "{random characters}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\155
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/ibario_pops_m.js"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\102
Version = "7"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\102
Name = "dealply_m"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\102
JavaScript = "{random characters}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\102
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/dealply_m.js"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\93
Version = "10"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\93
Name = "superfish_no_coupons_m"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\93
JavaScript = "{random characters}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\93
Url = "{random characters}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\91
Version = "49"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\91
Name = "monetizationLoader.js"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\91
JavaScript = "{random characters}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\91
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/monetizationLoader.js"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\246
Version = "10"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\246
Name = "setup"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\246
JavaScript = "{random characters}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\246
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/setup.js"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\4
Version = "4"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\4
Name = "jquery_1_7_1"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\4
JavaScript = "{random characters}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\4
Url = "http://js.{BLOCKED}statsservice.com/plugins/javascripts/jquery-1_7_1_min.js"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins
AppPluginList = "246,14,78,4,93,102,155,184,191,211,233,242,253,91"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins
BgPluginList = "246,4,14,78,251,249,250,93,102,155,184,191,211,233,242,253,91"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins
NewTabPluginList = "14,78,4"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins
OnRequestPluginList = "14"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins
BrowserEventPluginList = "14"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins
PopupPluginList = "4,14,78"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Update
LastCheck = "1562855064"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Firefox\Profiles\
%Application Data%\Mozilla\Firefox\
Profiles
lj5mikyj.default = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Firefox
TotalProfiles = "1"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP
ActiveAppId = "54246"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Update
LastCheck = "1562855079"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\Crossrider
Bic = "354A91DE7DC14C2A980B5427C0148BABIE"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\Crossrider
Verifier = "be6aa8aa1574234ad24e003e9b0dc90a"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Installer
Time = "1562855042"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Installer
StatsDomain = "http://stats.{BLOCKED}statsservice.com"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Installer
ErrorsDomain = "http://errors.{BLOCKED}statsservice.com"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Installer
CodeDownloadDomain = "http://js.{BLOCKED}statsservice.com"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Installer
FullVersion = "1.34.5.22"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Installer
FullVersionForUrl = "1_34_05_22"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Installer
SrcId = "001359"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Installer
SubId = "0"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Installer
ZData = "0"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Installer
DefaultBrowser = "ie"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Installer
OsName = "7"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Installer
Params = "{ source_id : 001359, sub_id : 0, uzid : 0}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\IE\Profiles
S-1-5-21-2407829820-1079796033-203259571-500 = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\IE
TotalProfiles = "1"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Manifest
Name = "MPMP"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Manifest
Manifest = "NA"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Manifest
Description = "MediaPlayerEnhance Extension"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Manifest
PublisherName = "Freeven"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Manifest
HomePageUrl = "NA"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Manifest
RunInFrame = "false"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Manifest
ThanksUrl = "NA"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Manifest
DisableIe = "true"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Manifest
EnableSearchIE = "false"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Manifest
Version = "38"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Manifest
UpdateInterval = "360"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Manifest
BgVersion = "1"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Manifest
AddressbarURL = "NA"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Manifest
ChangePrevious = "false"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Manifest
SetNewTab = "false"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Manifest
PublisherId = "21636"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Manifest
ModeType = "production"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Manifest
PluginsManifestVersion = "30"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Manifest
IsButtonEnabled = "false"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Manifest
UninstallerOfferUrl = "NA"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Manifest
UninstallerOfferAction = "NA"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Code
AppJavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Code
BgJavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Code
NewTabJavaScript = ""

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
183
Version = "4"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
183
Name = "tabsWrapper"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
183
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
183
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/tabsWrapper.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
182
Version = "3"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
182
Name = "openUrl"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
182
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
182
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/openUrl.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
177
Version = "2"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
177
Name = "crossriderDashboard"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
177
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
177
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/crossriderDashboard.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
94
Version = "2"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
94
Name = "IEPopup"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
94
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
94
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IEPopup.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
78
Version = "5"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
78
Name = "CrossriderInfo"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
78
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
78
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/CrossriderInfo.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
207
Version = "2"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
207
Name = "dbWrapper"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
207
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
207
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/dbWrapper.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
64
Version = "3"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
64
Name = "appApiMessage"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
64
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
64
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/appApiMessage.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
72
Version = "5"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
72
Name = "appApiValidation"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
72
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
72
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/appApiValidation.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
46
Version = "5"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
46
Name = "IETimers"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
46
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
46
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IETimers.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
45
Version = "4"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
45
Name = "IEOnRequest"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
45
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
45
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IEOnRequest.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
44
Version = "6"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
44
Name = "IEMisc"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
44
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
44
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IEMisc.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
43
Version = "5"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
43
Name = "IEMessaging"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
43
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
43
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IEMessaging.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
42
Version = "9"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
42
Name = "IEInternal"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
42
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
42
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IEInternal.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
41
Version = "7"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
41
Name = "IEInfo"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
41
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
41
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IEInfo.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
40
Version = "4"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
40
Name = "IEExtension"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
40
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
40
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IEExtension.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
39
Version = "5"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
39
Name = "IEDatabase"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
39
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
39
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IEDatabase.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
38
Version = "4"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
38
Name = "IECallbacks"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
38
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
38
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IECallbacks.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
37
Version = "6"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
37
Name = "IEBrowserEvents"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
37
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
37
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IEBrowserEvents.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
36
Version = "8"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
36
Name = "IEBackground"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
36
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
36
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IEBackground.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
35
Version = "4"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
35
Name = "IEAjax"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
35
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
35
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IEAjax.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
17
Version = "4"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
17
Name = "jQuery"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
17
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
17
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/jQuery.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
14
Version = "11"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
14
Name = "CrossriderUtils"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
14
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
14
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/CrossriderUtils.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
13
Version = "7"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
13
Name = "CrossriderAppUtils"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
13
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
13
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/CrossriderAppUtils.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
253
Version = "1"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
253
Name = "pixel_inject"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
253
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
253
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/pixel_inject.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
242
Version = "3"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
242
Name = "price_gong_m"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
242
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
242
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/price_gong_m.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
233
Version = "5"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
233
Name = "revizer_p_dynamic_b2b_2_m"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
233
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
233
Url = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
226
Version = "4"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
226
Name = "set_campaign_id_m"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
226
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
226
Url = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
221
Version = "2"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
221
Name = "icm_downloads_m"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
221
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
221
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/icm_downloads_m.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
211
Version = "5"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
211
Name = "revizer_ws_dynamic_b2b_light_m"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
211
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
211
Url = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
195
Version = "25"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
195
Name = "icm_convertmedia_m"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
195
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
195
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/icm_convertmedia_m.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
220
Version = "8"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
220
Name = "icm_base_m"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
220
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
220
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/icm_base_m.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
7
Version = "2"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
7
Name = "hooks"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
7
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
7
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/hooks.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
9
Version = "3"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
9
Name = "search_engine_hook"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
9
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
9
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/searchengines_hook.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
191
Version = "5"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
191
Name = "ciuvo_m"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
191
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
191
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/ciuvo_m.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
190
Version = "3"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
190
Name = "pops_5_m"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
190
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
190
Url = "http://js.{BLOCKED}statsservice.com/plugins/javascripts/monetization/geo/pops_5_m.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
155
Version = "3"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
155
Name = "ibario_pops_m"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
155
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
155
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/ibario_pops_m.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
104
Version = "9"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
104
Name = "jollywallet_m"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
104
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
104
Url = "http://js.{BLOCKED}statsservice.com/plugins/javascripts/monetization/geo/jollywallet_m.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
184
Version = "9"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
184
Name = "noproblemppc_m"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
184
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
184
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/noproblemppc_m.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
103
Version = "8"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
103
Name = "intext_5_m"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
103
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
103
Url = "http://js.{BLOCKED}statsservice.com/plugins/javascripts/monetization/geo/intext_5_m.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
102
Version = "7"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
102
Name = "dealply_m"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
102
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
102
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/dealply_m.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
93
Version = "10"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
93
Name = "superfish_no_coupons_m"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
93
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
93
Url = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
91
Version = "49"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
91
Name = "monetizationLoader.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
91
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
91
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/monetizationLoader.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
246
Version = "10"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
246
Name = "setup"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
246
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
246
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/setup.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
47
Version = "3"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
47
Name = "resources_background"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
47
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
47
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/resources_background.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
22
Version = "5"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
22
Name = "resources"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
22
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
22
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/resources.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
28
Version = "4"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
28
Name = "initializer"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
28
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
28
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/initializer.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
3
Version = "2"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
3
Name = "ie8_fix_2"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
3
JavaScript = "(function(){var b=dummy so this plugin won't be empty;})();"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
3
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie8_fix_2.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
21
Version = "5"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
21
Name = "debug"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
21
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
21
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/debug.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
2
Version = "2"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
2
Name = "ie8_fix_1"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
2
JavaScript = "(function(){var b=dummy so this plugin won't be empty;})();"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
2
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie8_fix_1.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
4
Version = "4"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
4
Name = "jquery_1_7_1"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
4
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
4
Url = "http://js.{BLOCKED}statsservice.com/plugins/javascripts/jquery-1_7_1_min.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
1
Version = "10"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
1
Name = "base"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
1
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
1
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/base.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins
AppPluginList = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins
BgPluginList = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins
NewTabPluginList = "42,38,46,17,14,78,13,41,44,39,35,43,40,64,2,4,3,1,21,22,72,28"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins
OnRequestPluginList = "14,42,41,39,38,43,45,64,72"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins
BrowserEventPluginList = "14,42,41,44,39,38,43,37,64,72"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins
PopupPluginList = "42,38,46,41,44,39,35,43,36,4,14,78,13,64,207,47,182,72,94"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp0054246.Sandbox.1
(Default) = "CrossriderApp0054246.Sandbox"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp0054246.Sandbox.1\CLSID
(Default) = "{{GUID}}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp0054246.BHO.1
(Default) = "CrossriderApp0054246"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp0054246.BHO.1\CLSID
(Default) = "{{GUID}}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp0054246.Sandbox
(Default) = "CrossriderApp0054246.Sandbox"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp0054246.Sandbox\CLSID
(Default) = "{{GUID}}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp0054246.Sandbox\CurVer
(Default) = "CrossriderApp0054246.Sandbox"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp0054246.BHO
(Default) = "CrossriderApp0054246"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp0054246.BHO\CLSID
(Default) = "{{GUID}}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp0054246.BHO\CurVer
(Default) = "CrossriderApp0054246"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{{GUID}}
(Default) = "MPMP"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{{GUID}}\
ProgID
(Default) = "CrossriderApp0054246.BHO.1"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{{GUID}}\
VersionIndependentProgID
(Default) = "CrossriderApp0054246"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{{GUID}}\
InprocServer32
(Default) = "%Program Files%\MPMP\MPMP-bho.dll"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{{GUID}}\
InprocServer32
ThreadingModel = "Apartment"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{{GUID}}\
TypeLib
(Default) = "{{GUID}}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{{GUID}}\
Implemented Categories
(Default) = ""

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{{GUID}}\
Implemented Categories\{{GUID}}
(Default) = ""

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{{GUID}}
(Default) = "CrossriderApp0054246.Sandbox"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{{GUID}}\
ProgID
(Default) = "CrossriderApp0054246.Sandbox.1"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{{GUID}}\
VersionIndependentProgID
(Default) = "CrossriderApp0054246.Sandbox"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
explorer\Browser Helper Objects\{{GUID}}
(Default) = "CrossriderApp0054246"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
explorer\Browser Helper Objects\{{GUID}}
NoExplorer = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{{GUID}}
(Default) = "ICrossriderBHO"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{{GUID}}\
ProxyStubClsid32
(Default) = "{00020424-0000-0000-C000-000000000046}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{{GUID}}\
TypeLib
(Default) = "{{GUID}}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{{GUID}}\
TypeLib
Version = "1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{{GUID}}
(Default) = "ISandBox"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\globalUpdate
DisplayName = "globalUpdate Update Service (globalUpdate)"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\globalUpdate
Start = "SERVICE_AUTO_START"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\globalUpdatem
DisplayName = "globalUpdate Update Service (globalUpdatem)"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\globalUpdatem
Start = "SERVICE_DEMAND_START"

アドウェアは、以下のレジストリキーを削除します。

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
GlobalUpdate\Update\eulaaccepted

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
GlobalUpdate\Update\mi

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
GlobalUpdate\Update\ui

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
GlobalUpdate\Update\LastChecked

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
GlobalUpdate\Update\ClientState\
{430FD4D0-B729-4F61-AA34-91526481799D}\UpdateAvailableCount

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
GlobalUpdate\Update\ClientState\
{430FD4D0-B729-4F61-AA34-91526481799D}\UpdateAvailableSince

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
GlobalUpdate\Update\uid

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
GlobalUpdate\Update\network\
secure\sk

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
GlobalUpdate\Update\network\
secure\c

作成活動

アドウェアは、以下のファイルを作成します。

  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\21.js
  • %Program Files%\MPMP\54246.crx
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\3e24ea90dedf010dd73864ad8afb9842.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\4f1f2311b6dfe8dc9398b9e63abadc95.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\680792568ec55a86a7e80045e550e236.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe.old
  • %Windows%\Tasks\{GUID}-1.job
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\28.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\popup.html
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\4.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\userCode\extension.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\psuser.dll.old
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\7.js
  • %User Temp%\comh.18754\GoogleUpdateBroker.exe
  • %Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\18be4636f65b5a79a226b006ca76a4e2.js
  • %User Temp%\comh.18754\GoogleUpdateHelper.msi
  • %Program Files%\MPMP\MPMP.ico
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\91.js
  • %User Temp%\AF2.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\221.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateHelper.msi.old
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\45d83464f48807f918f66018f5438b9e.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\183.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\64.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\9.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\search_dialog.xul
  • %Program Files%\MPMP\MPMP-bho.dll
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\installer.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\98.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\5028e2cbf92f3b87b57c694503c57e72.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\37993b8abf06e383d7ef53385525f010.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\787e77f8d7ecc7156be99bd0b0fde217.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\47.js
  • %All Users Profile%\Microsoft\Network\Downloader\qmgr0.dat
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\253.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\190.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\panelarrow-up.png
  • %User Temp%\comh.18754\goopdateres_en.dll
  • %Windows%\Tasks\{GUID}-3.job
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\dialog.js
  • %Windows%\Tasks\{GUID}-6.job
  • %Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe.old
  • %User Temp%\AF1.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\3cdbe045a4a0d3f50bd7b4f8b905fc1d.js
  • %User Temp%\comh.18754\npGoogleUpdate4.dll
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\d011f9d6a8671d3a2bc2b558decdb410.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\button3.png
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\2778ebbf69e285e413df59bb58a8fca9.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\background.html
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\102.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\93.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\userCode\background.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\13.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\4b4b6daaa6ac343ffc1b119ddb0b246c.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\2d5d68b375151fbed320fd2c0181c191.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions.json
  • %User Temp%\comh.18754\goopdate.dll
  • %User Temp%\comh.18754\GoogleUpdate.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\icon48.png
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\bd82ad0f96fb35e02c077edbf2b9f8c6.js
  • %Windows%\Tasks\globalUpdateUpdateTaskMachineUA.job
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\246.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\49566522acce9f80ebb86c35dfb155d3.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\78.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\update.css
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\icon24.png
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\191.js
  • %Program Files%\globalUpdate\Update\GoogleUpdate.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\16.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\5ef7cf534cdbca51efd63b695e3d0f62.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe
  • %Program Files%\MPMP\54246.xpi
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\1370ab8db88b6403223ec11e7a236c84.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\50d601b837ee9834f42c82ddcb1d0c65.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\177.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\icon16.png
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\options.js
  • %All Users Profile%\Microsoft\Network\Downloader\qmgr1.dat
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\d35d0bca3d387bec73e98493bae4bebe.js
  • %User Temp%\comh.18754\GoogleCrashHandler.exe
  • %Program Files%\MPMP\MPMP-nova.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\226.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\defaults\preferences\prefs.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\182.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\9caf939c72d899c9467323bea849b4a3.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\goopdateres_en.dll
  • %Program Files%\MPMP\utils.exe
  • %Program Files%\MPMP\Uninstall.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\6f5764ff79aeb23978e9db22d7981041.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins.json
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\207.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\icon128.png
  • %Program Files%\globalUpdate\Update\1.3.25.0\GoogleCrashHandler.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\button4.png
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\72.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\crossrider_statusbar.png
  • %Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll.old
  • %Program Files%\MPMP\MPMP-codedownloader.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\ceec657593dea2fb9978c177d58f364c.js
  • %User Temp%\comh.18754\psuser.dll
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\104.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\bdbd33145ab7dbb7b5175dc29e13a54f.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\211.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\3438e9cee6f289fe93d7d8abe705ba24.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdate.exe
  • %User Temp%\comh.18754\GoogleUpdateOnDemand.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\ffCoreFilesIndex.txt
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\install.rdf
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\browser.xul
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\8cf406521b5bdabeda6c9b01aad99f51.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\6589406f5c43cdd372d3b9893fe94669.js
  • %Program Files%\MPMP\{GUID}-3.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\184.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\1.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\f04545df6da39e41ae904087d7b3a91c.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\goopdateres_en.dll.old
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\manifest.xml
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\9dba55b4f2557e03aca1fe863b4a9f9e.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\c1ab6a0d65c6bdb80c05eb57261a3d55.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateHelper.msi
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\24e5241137ac099bd0069f5361058525.js
  • %Program Files%\MPMP\MPMP-nova.dll
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\242.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\155.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\22.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\17.js
  • %Program Files%\MPMP\1293297481.mxaddon
  • %Windows%\Tasks\{GUID}-7.job
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\skin.css
  • %Program Files%\globalUpdate\Update\1.3.25.0\psmachine.dll
  • %Program Files%\globalUpdate\Update\1.3.25.0\GoogleCrashHandler.exe.old
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\195.js
  • %User Temp%\{GUID}.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\3dad8746f8926aafde94171b87503811.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\14.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\options.xul
  • %Program Files%\MPMP\360-54246.crx
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\a3e7c3935aee4f766e6a9b9f5e92c869.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\button1.png
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\c5379747c774cf9228f58cd8633a488f.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll.old
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome.manifest
  • %Windows%\Tasks\temp_{GUID}-7.job
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\f44fe937f6668d4047fb81235269a0e1.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\d827b91b474a06b7771997ad452f2201.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\b51ab7bc967684e1c1f0c290f11ebd30.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\53251c7e83b57e1fb7e90172c5dda028.js
  • %Windows%\Tasks\{GUID}-4.job
  • %Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdate.exe.old
  • %User Temp%\comh.18754\psmachine.dll
  • %Program Files%\MPMP\MPMP-novainstaller.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\3030fc4f3b901802369e95d81dda52be.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\bdeaae1663cfe8266d0bfbc7678dc967.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\babbc84c37010a7be8cf9c5b17340fab.js
  • %AppDataLocal%\Google\Chrome\User Data\Local State
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\103.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\button2.png
  • %Program Files%\globalUpdate\Update\1.3.25.0\psmachine.dll.old
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\af0d6e867c53d6d02549f5c2a1a1c625.js
  • %Windows%\Tasks\globalUpdateUpdateTaskMachineCore.job
  • %Program Files%\MPMP\bgNova.html
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\button5.png
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\220.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\psuser.dll
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\locale\en-US\translations.dtd
  • %Program Files%\MPMP\{GUID}-4.exe
  • %Program Files%\MPMP\MPMP-bho64.dll
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\233.js

その他

アドウェアは、以下の不正なWebサイトにアクセスします。

  • http://update.{BLOCKED}statsservice.com/installer_updates/001359/update.json
  • http://errors.{BLOCKED}statsservice.com/installer-error.gif?{random characters}
  • http://stats.{BLOCKED}statsservice.com/installer.gif?{random characters}
  • http://logs.{BLOCKED}statsservice.com/monetization.gif?{random characters}
  • http://update.{BLOCKED}statsservice.com/omaha/430FD4D0-B729-4F61-AA34-91526481799D/1/ping.xml?rand=11039
  • http://errors.{BLOCKED}statsservice.com/ch-agent-error.gif?{random characters}
  • http://update.{BLOCKED}statsservice.com/omaha/B13CB685-2858-4509-BB2E-34E3545B73F9/1/update.xml?{random characters}
  • http://update.{BLOCKED}statsservice.com/omaha/B13CB685-2858-4509-BB2E-34E3545B73F9/1/update.xml?rand=11378
  • http://stats.{BLOCKED}statsservice.com/stats.gif?{random characters}
  • http://js.{BLOCKED}statsservice.com/plugin/apps/54246/manifest/1_34_05_22/nova/manifest.xml?ver=38&rnd=1990
  • http://update.{BLOCKED}statsservice.com/omaha/B13CB685-2858-4509-BB2E-34E3545B73F9/1/ping.xml?rand=11405
  • http://update.{BLOCKED}statsservice.com/omaha/B13CB685-2858-4509-BB2E-34E3545B73F9/1/ping.xml?rand=19984
  • http://js.{BLOCKED}statsservice.com/plugin/apps/54246/manifest/1_34_05_22/ie11/manifest.xml?ver=38&rnd=125
  • http://www.{BLOCKED}apis.com

このウイルス情報は、自動解析システムにより作成されました。

  対応方法

対応検索エンジン: 9.850

手順 1

Windows XP、Windows Vista および Windows 7 のユーザは、コンピュータからマルウェアもしくはアドウェア等を完全に削除するために、ウイルス検索の実行前には必ず「システムの復元」を無効にしてください。

手順 2

「Adware.Win32.Crossrider.A」で検出したファイル名を確認し、そのファイルを終了します。

[ 詳細 ]

  • すべての実行中プロセスが、Windows のタスクマネージャに表示されない場合があります。この場合、"Process Explorer" などのツールを使用しマルウェアのファイルを終了してください。"Process Explorer" については、こちらをご参照下さい。
  • 検出ファイルが、Windows のタスクマネージャまたは "Process Explorer" に表示されるものの、削除できない場合があります。この場合、コンピュータをセーフモードで再起動してください。
    セーフモードについては、こちらをご参照下さい。
  • 検出ファイルがタスクマネージャ上で表示されない場合、次の手順にお進みください。

手順 3

不明なレジストリキーを削除します。

[ 詳細 ]

警告:レジストリはWindowsの構成情報が格納されているデータベースであり、レジストリの編集内容に問題があると、システムが正常に動作しなくなる場合があります。
レジストリの編集はお客様の責任で行っていただくようお願いいたします。弊社ではレジストリの編集による如何なる問題に対しても補償いたしかねます。
レジストリの編集前にこちらをご参照ください。

  • In HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall
    • MPMP
  • In HKEY_LOCAL_MACHINE\Software\GlobalUpdate\Update\Clients
    • {{GUID}}
  • In HKEY_LOCAL_MACHINE\Software\GlobalUpdate
    • UpdateDev
  • In HKEY_LOCAL_MACHINE\Software\MPMP
    • Installer
  • In HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy
    • {{GUID}}
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy
    • {{GUID}}
  • In HKEY_LOCAL_MACHINE\Software\globalUpdate\Update
    • network
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GlobalUpdate\Update\network
    • secure
  • In HKEY_LOCAL_MACHINE\Software\globalUpdate\Update
    • ClientState
  • In HKEY_LOCAL_MACHINE\Software\globalUpdate\Update\Clients
    • {430FD4D0-B729-4F61-AA34-91526481799D}
  • In HKEY_LOCAL_MACHINE\Software\globalUpdate\Update\ClientState
    • {430FD4D0-B729-4F61-AA34-91526481799D}
  • In HKEY_LOCAL_MACHINE\Software\globalUpdate\Update
    • ClientStateMedium
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins
    • @staging.google.com/globalUpdate Update;version=10
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
    • MimeTypes
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10\MimeTypes
    • application/x-vnd.google.oneclickctrl.10
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved
    • {5645E0E7-FC12-43BF-A6E4-F9751942B298}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\Stats
    • {5645E0E7-FC12-43BF-A6E4-F9751942B298}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\Stats\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
    • iexplore
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\Stats\{5645E0E7-FC12-43BF-A6E4-F9751942B298}\iexplore
    • AllowedDomains
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\Stats\{5645E0E7-FC12-43BF-A6E4-F9751942B298}\iexplore\AllowedDomains
    • *
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy
    • {5645E0E7-FC12-43BF-A6E4-F9751942B298}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdate.OneClickCtrl.10
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID
    • {5645E0E7-FC12-43BF-A6E4-F9751942B298}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
    • InprocServer32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type
    • application/x-vnd.google.oneclickctrl.10
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins
    • @staging.google.com/globalUpdate Update;version=4
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
    • MimeTypes
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4\MimeTypes
    • application/x-vnd.google.update3webcontrol.4
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved
    • {C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\Stats
    • {C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\Stats\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
    • iexplore
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\Stats\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}\iexplore
    • AllowedDomains
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\Stats\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}\iexplore\AllowedDomains
    • *
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy
    • {C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdate.Update3WebControl.4
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID
    • {C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
    • InprocServer32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type
    • application/x-vnd.google.update3webcontrol.4
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID
    • {577975B8-C40E-43E6-B0DE-4C6B44088B52}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID
    • GoogleUpdate.exe
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdateUpdate.Update3COMClassService.1.0
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdateUpdate.Update3COMClassService
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID
    • {577975B8-C40E-43E6-B0DE-4C6B44088B52}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID
    • {3278F5CF-48F3-4253-A6BB-004CE84AF492}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdateUpdate.OnDemandCOMClassSvc.1.0
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdateUpdate.OnDemandCOMClassSvc
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID
    • {3278F5CF-48F3-4253-A6BB-004CE84AF492}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdateUpdate.Update3WebSvc.1.0
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdateUpdate.Update3WebSvc
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID
    • {7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdateUpdate.CoreClass.1
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdateUpdate.CoreClass
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID
    • {3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID
    • {02A96331-0CA6-40E2-A87D-C224601985EB}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
    • InprocHandler32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID
    • {E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
    • InprocServer32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID
    • {CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
    • InProcServer32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface
    • {3CC60715-D6C5-429D-830E-43FA3F86C61D}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{3CC60715-D6C5-429D-830E-43FA3F86C61D}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{3CC60715-D6C5-429D-830E-43FA3F86C61D}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface
    • {3A807417-B46D-4D37-8C9A-19AC6DE204F9}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{3A807417-B46D-4D37-8C9A-19AC6DE204F9}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{3A807417-B46D-4D37-8C9A-19AC6DE204F9}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface
    • {07F41522-AF7D-4F26-B394-094F059FDB8A}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{07F41522-AF7D-4F26-B394-094F059FDB8A}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{07F41522-AF7D-4F26-B394-094F059FDB8A}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface
    • {DD1F043F-ABC8-4643-8B95-D2C5B22BB019}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DD1F043F-ABC8-4643-8B95-D2C5B22BB019}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DD1F043F-ABC8-4643-8B95-D2C5B22BB019}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface
    • {212E6D43-6062-492A-B8CC-144669FF11ED}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{212E6D43-6062-492A-B8CC-144669FF11ED}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{212E6D43-6062-492A-B8CC-144669FF11ED}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface
    • {555D7146-94A8-4C94-AE76-C39CDC7F7705}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{555D7146-94A8-4C94-AE76-C39CDC7F7705}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{555D7146-94A8-4C94-AE76-C39CDC7F7705}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface
    • {4517D94C-19BA-46FA-BE66-2A30CEAC4A85}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{4517D94C-19BA-46FA-BE66-2A30CEAC4A85}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{4517D94C-19BA-46FA-BE66-2A30CEAC4A85}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface
    • {224FE662-1E6D-4BC0-AEBB-9E2FB4057BE9}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{224FE662-1E6D-4BC0-AEBB-9E2FB4057BE9}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{224FE662-1E6D-4BC0-AEBB-9E2FB4057BE9}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface
    • {0C40F472-7407-4467-8914-1DEA7C326972}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{0C40F472-7407-4467-8914-1DEA7C326972}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{0C40F472-7407-4467-8914-1DEA7C326972}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface
    • {A6D54287-7939-466A-8579-92546D946C8C}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{A6D54287-7939-466A-8579-92546D946C8C}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{A6D54287-7939-466A-8579-92546D946C8C}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface
    • {0522D9A4-4D57-437D-978D-E5B3B6C9005D}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{0522D9A4-4D57-437D-978D-E5B3B6C9005D}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{0522D9A4-4D57-437D-978D-E5B3B6C9005D}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface
    • {A8F7D0A5-7074-40B8-9BDC-1174BDD0A132}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{A8F7D0A5-7074-40B8-9BDC-1174BDD0A132}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{A8F7D0A5-7074-40B8-9BDC-1174BDD0A132}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface
    • {D14D64BC-A0E4-42E3-BB72-FB41EA43C198}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D14D64BC-A0E4-42E3-BB72-FB41EA43C198}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D14D64BC-A0E4-42E3-BB72-FB41EA43C198}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface
    • {023E9EC8-B147-40EB-B0B3-DF90618FB371}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{023E9EC8-B147-40EB-B0B3-DF90618FB371}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{023E9EC8-B147-40EB-B0B3-DF90618FB371}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface
    • {ED0B64D4-BF27-4521-AD27-190F49BF5EA7}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{ED0B64D4-BF27-4521-AD27-190F49BF5EA7}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{ED0B64D4-BF27-4521-AD27-190F49BF5EA7}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface
    • {8120D9D6-785C-4413-9C0C-DF2028C56FAD}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{8120D9D6-785C-4413-9C0C-DF2028C56FAD}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{8120D9D6-785C-4413-9C0C-DF2028C56FAD}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface
    • {823AE2EB-E62C-4847-B192-C99B91B92416}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{823AE2EB-E62C-4847-B192-C99B91B92416}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{823AE2EB-E62C-4847-B192-C99B91B92416}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface
    • {9B9A45F4-18FC-484A-BACA-076D78273D8E}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9B9A45F4-18FC-484A-BACA-076D78273D8E}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9B9A45F4-18FC-484A-BACA-076D78273D8E}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface
    • {E3F3E8F9-F747-4DD6-BA6B-82A6CE1E0860}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F3E8F9-F747-4DD6-BA6B-82A6CE1E0860}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F3E8F9-F747-4DD6-BA6B-82A6CE1E0860}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface
    • {59D188FA-757A-424E-8C93-F58FFD896BD7}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{59D188FA-757A-424E-8C93-F58FFD896BD7}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{59D188FA-757A-424E-8C93-F58FFD896BD7}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface
    • {A78EDAFB-926F-4D93-AB13-8232D7378EB1}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{A78EDAFB-926F-4D93-AB13-8232D7378EB1}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{A78EDAFB-926F-4D93-AB13-8232D7378EB1}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface
    • {9B4F7CFE-987D-410E-A8E4-20182E0B3C24}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9B4F7CFE-987D-410E-A8E4-20182E0B3C24}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9B4F7CFE-987D-410E-A8E4-20182E0B3C24}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdateUpdate.OnDemandCOMClassMachine.1.0
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdateUpdate.OnDemandCOMClassMachine
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID
    • {ADBC39BE-3D20-4333-8D99-E91EB1B62474}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
    • LocalServer32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
    • Elevation
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdateUpdate.Update3WebMachine.1.0
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdateUpdate.Update3WebMachine
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID
    • {FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
    • LocalServer32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
    • Elevation
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdateUpdate.CoCreateAsync.1.0
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdateUpdate.CoCreateAsync
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID
    • {E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
    • LocalServer32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdate.OneClickProcessLauncherMachine.1.0
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdate.OneClickProcessLauncherMachine
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID
    • {5E89ACE9-E16B-499A-87B4-0DBF742404C1}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
    • LocalServer32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy
    • {5E89ACE9-E16B-499A-87B4-0DBF742404C1}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdateUpdate.ProcessLauncher.1.0
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdateUpdate.ProcessLauncher
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID
    • {8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
    • LocalServer32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdateUpdate.CoreMachineClass.1
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdateUpdate.CoreMachineClass
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID
    • {6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
    • LocalServer32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
    • Elevation
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • {random key}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdateUpdate.OnDemandCOMClassMachineFallback
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID
    • {69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
    • LocalServer32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
    • Elevation
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdateUpdate.Update3WebMachineFallback.1.0
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdateUpdate.Update3WebMachineFallback
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID
    • {F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
    • LocalServer32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
    • Elevation
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdateUpdate.CredentialDialogMachine.1.0
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdateUpdate.CredentialDialogMachine
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID
    • {834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
    • LocalServer32
  • In HKEY_LOCAL_MACHINE\Software\MPMP
    • Chrome-Profiles
  • In HKEY_LOCAL_MACHINE\Software\MPMP
    • Chrome
  • In HKEY_LOCAL_MACHINE\Software\MPMP
    • ErrorLists-crchromeinstaller
  • In HKEY_CURRENT_USER\Software\globalUpdate\Update
    • proxy
  • In HKEY_LOCAL_MACHINE\Software\Classes
    • Local Settings
  • In HKEY_LOCAL_MACHINE\Classes\Local Settings
    • Software
  • In HKEY_LOCAL_MACHINE\Software\Classes\Local Settings\Software
    • Microsoft
  • In HKEY_LOCAL_MACHINE\Software\Classes\Local Settings\Software\Microsoft
    • Windows
  • In HKEY_LOCAL_MACHINE\Software\Classes\Local Settings\Software\Microsoft\Windows
    • CurrentVersion
  • In HKEY_LOCAL_MACHINE\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion
    • AppContainer
  • In HKEY_LOCAL_MACHINE\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer
    • Storage
  • In HKEY_LOCAL_MACHINE\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage
    • windows_ie_ac_001
  • In HKEY_LOCAL_MACHINE\Classes\Local Settings\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001
    • Software
  • In HKEY_LOCAL_MACHINE\Software\MPMP
    • Update
  • In HKEY_LOCAL_MACHINE\Software\MPMP
    • Manifest
  • In HKEY_LOCAL_MACHINE\Software\MPMP
    • Code
  • In HKEY_LOCAL_MACHINE\Software\MPMP
    • Plugins
  • In HKEY_LOCAL_MACHINE\Software\MPMP\Plugins
    • 251
  • In HKEY_LOCAL_MACHINE\Software\MPMP\Plugins
    • 249
  • In HKEY_LOCAL_MACHINE\Software\MPMP\Plugins
    • 250
  • In HKEY_LOCAL_MACHINE\Software\MPMP\Plugins
    • 14
  • In HKEY_LOCAL_MACHINE\Software\MPMP\Plugins
    • 78
  • In HKEY_LOCAL_MACHINE\Software\MPMP\Plugins
    • 233
  • In HKEY_LOCAL_MACHINE\Software\MPMP\Plugins
    • 253
  • In HKEY_LOCAL_MACHINE\Software\MPMP\Plugins
    • 242
  • In HKEY_LOCAL_MACHINE\Software\MPMP\Plugins
    • 211
  • In HKEY_LOCAL_MACHINE\Software\MPMP\Plugins
    • 191
  • In HKEY_LOCAL_MACHINE\Software\MPMP\Plugins
    • 184
  • In HKEY_LOCAL_MACHINE\Software\MPMP\Plugins
    • 155
  • In HKEY_LOCAL_MACHINE\Software\MPMP\Plugins
    • 102
  • In HKEY_LOCAL_MACHINE\Software\MPMP\Plugins
    • 93
  • In HKEY_LOCAL_MACHINE\Software\MPMP\Plugins
    • 91
  • In HKEY_LOCAL_MACHINE\Software\MPMP\Plugins
    • 246
  • In HKEY_LOCAL_MACHINE\Software\MPMP\Plugins
    • 4
  • In HKEY_LOCAL_MACHINE\Software\MPMP\Firefox
    • Profiles
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software
    • MPMP
  • In HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion
    • AppContainer
  • In HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer
    • Storage
  • In HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage
    • windows_ie_ac_001
  • In HKEY_CURRENT_USER\Classes\Local Settings\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001
    • Software
  • In HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software
    • MPMP
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP
    • Update
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software
    • Crossrider
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP
    • Installer
  • In HKEY_LOCAL_MACHINE\Software\MPMP\IE
    • Profiles
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP
    • Manifest
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP
    • Code
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP
    • Plugins
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 183
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 182
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 177
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 94
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 78
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 207
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 64
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 72
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 46
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 45
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 44
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 43
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 42
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 41
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 40
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 39
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 38
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 37
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 36
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 35
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 17
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 14
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 13
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 253
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 242
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 233
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 226
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 221
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 211
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 195
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 220
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 7
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 9
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 191
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 190
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 155
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 104
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 184
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 103
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 102
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 93
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 91
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 246
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 47
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 22
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 28
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 3
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 21
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 2
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 4
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 1
  • In HKEY_CLASSES_ROOT
    • CrossriderApp0054246.Sandbox.1
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0054246.Sandbox.1
    • CLSID
  • In HKEY_CLASSES_ROOT
    • CrossriderApp0054246.BHO.1
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0054246.BHO.1
    • CLSID
  • In HKEY_CLASSES_ROOT
    • CrossriderApp0054246.Sandbox
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0054246.Sandbox
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0054246.Sandbox
    • CurVer
  • In HKEY_CLASSES_ROOT
    • CrossriderApp0054246.BHO
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0054246.BHO
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0054246.BHO
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID
    • {{GUID}}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{{GUID}}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{{GUID}}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{{GUID}}
    • Programmable
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{{GUID}}
    • InprocServer32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{{GUID}}
    • TypeLib
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{{GUID}}
    • Implemented Categories
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\Implemented Categories
    • {{GUID}}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects
    • {{GUID}}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface
    • {{GUID}}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{{GUID}}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{{GUID}}
    • TypeLib

手順 4

このレジストリ値を削除します。

[ 詳細 ]

警告:レジストリはWindowsの構成情報が格納されているデータベースであり、レジストリの編集内容に問題があると、システムが正常に動作しなくなる場合があります。
レジストリの編集はお客様の責任で行っていただくようお願いいたします。弊社ではレジストリの編集による如何なる問題に対しても補償いたしかねます。
レジストリの編集前にこちらをご参照ください。

  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\MPMP
    • DisplayName = "MPMP"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\MPMP
    • DisplayIcon = "%Program Files%\MPMP\utils.exe"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\MPMP
    • DisplayVersion = "1.34.5.22"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\MPMP
    • Publisher = "Freeven"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\MPMP
    • CrPublisherId = "21636"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\MPMP
    • CrAppId = "54246"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\MPMP
    • UninstallString = "%Program Files%\MPMP\Uninstall.exe /fcp=1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GlobalUpdate\Update\Clients\{{GUID}}
    • pv = "1.3.25.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GlobalUpdate\Update\Clients\{{GUID}}
    • name = "Freeven"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GlobalUpdate\Update\Clients\{{GUID}}
    • bic = "354A91DE7DC14C2A980B5427C0148BABIE"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GlobalUpdate\Update\Clients\{{GUID}}
    • verifier = "be6aa8aa1574234ad24e003e9b0dc90a"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GlobalUpdate\Update\Clients\{{GUID}}
    • srcid_var = "001359"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GlobalUpdate\UpdateDev
    • AuCheckPeriodMs = "21600000"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Installer
    • BundledChrome = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Installer
    • BundledNova = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\%Program Files%\MPMP
    • MPMP-nova.exe = "8000"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Installer
    • BundledFirefox = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Installer
    • BundledIe = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{{GUID}}
    • AppName = "MPMP-codedownloader.exe"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{{GUID}}
    • AppPath = "%Program Files%\MPMP"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{{GUID}}
    • Policy = "3"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{{GUID}}
    • AppName = "MPMP-codedownloader.exe"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{{GUID}}
    • AppPath = "%Program Files%\MPMP"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{{GUID}}
    • Policy = "3"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GlobalUpdate\Update
    • path = "%Program Files%\globalUpdate\Update\GoogleUpdate.exe"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GlobalUpdate\Update\Clients\{430FD4D0-B729-4F61-AA34-91526481799D}
    • pv = "1.3.25.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GlobalUpdate\Update\Clients\{430FD4D0-B729-4F61-AA34-91526481799D}
    • name = "globalUpdate Update"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GlobalUpdate\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}
    • pv = "1.3.25.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GoogleUpdate.exe
    • DisableExceptionChainValidation = "0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GlobalUpdate\Update
    • version = "1.3.25.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
    • Path = "%Program Files%\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
    • Description = "globalUpdate Update"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
    • ProductName = "globalUpdate Update"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
    • Vendor = "globalUpdate"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
    • Version = "10"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
    • AppName = "GoogleUpdate.exe"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
    • AppPath = "%Program Files%\globalUpdate\Update"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
    • Policy = "3"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
    • (Default) = "globalUpdate Update Plugin"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10\CLSID
    • (Default) = "{5645E0E7-FC12-43BF-A6E4-F9751942B298}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
    • (Default) = "globalUpdate Update Plugin"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}\ProgID
    • (Default) = "globalUpdate.OneClickCtrl.10"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}\InprocServer32
    • (Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}\InprocServer32
    • ThreadingModel = "Apartment"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-vnd.google.oneclickctrl.10
    • CLSID = "{5645E0E7-FC12-43BF-A6E4-F9751942B298}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
    • Path = "%Program Files%\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
    • Description = "globalUpdate Update"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
    • ProductName = "globalUpdate Update"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
    • Vendor = "globalUpdate"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
    • Version = "4"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
    • AppName = "GoogleUpdateBroker.exe"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
    • AppPath = "%Program Files%\globalUpdate\Update\1.3.25.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
    • Policy = "3"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
    • (Default) = "globalUpdate Update Plugin"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdate.Update3WebControl.4\CLSID
    • (Default) = "{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
    • (Default) = "globalUpdate Update Plugin"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}\ProgID
    • (Default) = "globalUpdate.Update3WebControl.4"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}\InprocServer32
    • (Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}\InprocServer32
    • ThreadingModel = "Apartment"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-vnd.google.update3webcontrol.4
    • CLSID = "{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GlobalUpdate\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}
    • brand = "GGLS"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GlobalUpdate\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}
    • InstallTime = "1562855189"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
    • (Default) = "ServiceModule"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\GoogleUpdate.exe
    • AppID = "{577975B8-C40E-43E6-B0DE-4C6B44088B52}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
    • LocalService = "globalUpdate"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
    • ServiceParameters = "/comsvc"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
    • (Default) = "Update3COMClass"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0\CLSID
    • (Default) = "{577975B8-C40E-43E6-B0DE-4C6B44088B52}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
    • (Default) = "Update3COMClass"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService\CLSID
    • (Default) = "{577975B8-C40E-43E6-B0DE-4C6B44088B52}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService\CurVer
    • (Default) = "globalUpdateUpdate.Update3COMClassService.1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
    • (Default) = "Update3COMClass"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}\ProgID
    • (Default) = "globalUpdateUpdate.Update3COMClassService.1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}\VersionIndependentProgID
    • (Default) = "globalUpdateUpdate.Update3COMClassService"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
    • AppID = "{577975B8-C40E-43E6-B0DE-4C6B44088B52}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
    • (Default) = "ServiceModule"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\GoogleUpdate.exe
    • AppID = "{3278F5CF-48F3-4253-A6BB-004CE84AF492}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
    • LocalService = "globalUpdatem"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
    • ServiceParameters = "/comsvc"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
    • (Default) = "Google Update Legacy On Demand"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0\CLSID
    • (Default) = "{3278F5CF-48F3-4253-A6BB-004CE84AF492}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
    • (Default) = "Google Update Legacy On Demand"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc\CLSID
    • (Default) = "{3278F5CF-48F3-4253-A6BB-004CE84AF492}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc\CurVer
    • (Default) = "globalUpdateUpdate.OnDemandCOMClassSvc.1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
    • (Default) = "Google Update Legacy On Demand"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}\ProgID
    • (Default) = "globalUpdateUpdate.OnDemandCOMClassSvc.1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}\VersionIndependentProgID
    • (Default) = "globalUpdateUpdate.OnDemandCOMClassSvc"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
    • AppID = "{3278F5CF-48F3-4253-A6BB-004CE84AF492}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
    • (Default) = "GoogleUpdate Update3Web"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0\CLSID
    • (Default) = "{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
    • (Default) = "GoogleUpdate Update3Web"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc\CLSID
    • (Default) = "{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc\CurVer
    • (Default) = "globalUpdateUpdate.Update3WebSvc.1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
    • (Default) = "GoogleUpdate Update3Web"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}\ProgID
    • (Default) = "globalUpdateUpdate.Update3WebSvc.1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}\VersionIndependentProgID
    • (Default) = "globalUpdateUpdate.Update3WebSvc"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
    • AppID = "{3278F5CF-48F3-4253-A6BB-004CE84AF492}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
    • (Default) = "Google Update Core Class"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1\CLSID
    • (Default) = "{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
    • (Default) = "Google Update Core Class"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoreClass\CLSID
    • (Default) = "{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoreClass\CurVer
    • (Default) = "globalUpdateUpdate.CoreClass.1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
    • (Default) = "Google Update Core Class"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}\ProgID
    • (Default) = "globalUpdateUpdate.CoreClass.1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}\VersionIndependentProgID
    • (Default) = "globalUpdateUpdate.CoreClass"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
    • AppID = "{3278F5CF-48F3-4253-A6BB-004CE84AF492}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}\InprocHandler32
    • (Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\psmachine.dll"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}\InprocHandler32
    • ThreadingModel = "Both"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}\InprocServer32
    • (Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\psmachine.dll"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}\InprocServer32
    • ThreadingModel = "Both"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}\InProcServer32
    • (Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\psmachine.dll"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}\InProcServer32
    • ThreadingModel = "Both"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
    • (Default) = "PSFactoryBuffer"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{3CC60715-D6C5-429D-830E-43FA3F86C61D}\ProxyStubClsid32
    • (Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{3CC60715-D6C5-429D-830E-43FA3F86C61D}
    • (Default) = "IProgressWndEvents"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{3CC60715-D6C5-429D-830E-43FA3F86C61D}\NumMethods
    • (Default) = "9"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{3A807417-B46D-4D37-8C9A-19AC6DE204F9}\ProxyStubClsid32
    • (Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{3A807417-B46D-4D37-8C9A-19AC6DE204F9}
    • (Default) = "IBrowserHttpRequest2"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{3A807417-B46D-4D37-8C9A-19AC6DE204F9}\NumMethods
    • (Default) = "4"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{07F41522-AF7D-4F26-B394-094F059FDB8A}\ProxyStubClsid32
    • (Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{07F41522-AF7D-4F26-B394-094F059FDB8A}
    • (Default) = "IAppBundleWeb"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{07F41522-AF7D-4F26-B394-094F059FDB8A}\NumMethods
    • (Default) = "24"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DD1F043F-ABC8-4643-8B95-D2C5B22BB019}\ProxyStubClsid32
    • (Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DD1F043F-ABC8-4643-8B95-D2C5B22BB019}
    • (Default) = "IProcessLauncher"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DD1F043F-ABC8-4643-8B95-D2C5B22BB019}\NumMethods
    • (Default) = "6"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{212E6D43-6062-492A-B8CC-144669FF11ED}\ProxyStubClsid32
    • (Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{212E6D43-6062-492A-B8CC-144669FF11ED}
    • (Default) = "IAppVersion"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{212E6D43-6062-492A-B8CC-144669FF11ED}\NumMethods
    • (Default) = "10"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{555D7146-94A8-4C94-AE76-C39CDC7F7705}\ProxyStubClsid32
    • (Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{555D7146-94A8-4C94-AE76-C39CDC7F7705}
    • (Default) = "ICoCreateAsyncStatus"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{555D7146-94A8-4C94-AE76-C39CDC7F7705}\NumMethods
    • (Default) = "10"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{4517D94C-19BA-46FA-BE66-2A30CEAC4A85}\ProxyStubClsid32
    • (Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{4517D94C-19BA-46FA-BE66-2A30CEAC4A85}
    • (Default) = "IAppBundle"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{4517D94C-19BA-46FA-BE66-2A30CEAC4A85}\NumMethods
    • (Default) = "39"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{224FE662-1E6D-4BC0-AEBB-9E2FB4057BE9}\ProxyStubClsid32
    • (Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{224FE662-1E6D-4BC0-AEBB-9E2FB4057BE9}
    • (Default) = "ICoCreateAsync"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{224FE662-1E6D-4BC0-AEBB-9E2FB4057BE9}\NumMethods
    • (Default) = "4"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{0C40F472-7407-4467-8914-1DEA7C326972}\ProxyStubClsid32
    • (Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{0C40F472-7407-4467-8914-1DEA7C326972}
    • (Default) = "IAppWeb"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{0C40F472-7407-4467-8914-1DEA7C326972}\NumMethods
    • (Default) = "14"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{A6D54287-7939-466A-8579-92546D946C8C}\ProxyStubClsid32
    • (Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{A6D54287-7939-466A-8579-92546D946C8C}
    • (Default) = "IOneClickProcessLauncher"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{A6D54287-7939-466A-8579-92546D946C8C}\NumMethods
    • (Default) = "4"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{0522D9A4-4D57-437D-978D-E5B3B6C9005D}\ProxyStubClsid32
    • (Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{0522D9A4-4D57-437D-978D-E5B3B6C9005D}
    • (Default) = "IAppVersionWeb"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{0522D9A4-4D57-437D-978D-E5B3B6C9005D}\NumMethods
    • (Default) = "10"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{A8F7D0A5-7074-40B8-9BDC-1174BDD0A132}\ProxyStubClsid32
    • (Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{A8F7D0A5-7074-40B8-9BDC-1174BDD0A132}
    • (Default) = "IGoogleUpdate3WebSecurity"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{A8F7D0A5-7074-40B8-9BDC-1174BDD0A132}\NumMethods
    • (Default) = "4"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D14D64BC-A0E4-42E3-BB72-FB41EA43C198}\ProxyStubClsid32
    • (Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D14D64BC-A0E4-42E3-BB72-FB41EA43C198}
    • (Default) = "IPackage"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D14D64BC-A0E4-42E3-BB72-FB41EA43C198}\NumMethods
    • (Default) = "10"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{023E9EC8-B147-40EB-B0B3-DF90618FB371}\ProxyStubClsid32
    • (Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{023E9EC8-B147-40EB-B0B3-DF90618FB371}
    • (Default) = "ICurrentState"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{023E9EC8-B147-40EB-B0B3-DF90618FB371}\NumMethods
    • (Default) = "24"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{ED0B64D4-BF27-4521-AD27-190F49BF5EA7}\ProxyStubClsid32
    • (Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{ED0B64D4-BF27-4521-AD27-190F49BF5EA7}
    • (Default) = "IJobObserver"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{ED0B64D4-BF27-4521-AD27-190F49BF5EA7}\NumMethods
    • (Default) = "13"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{8120D9D6-785C-4413-9C0C-DF2028C56FAD}\ProxyStubClsid32
    • (Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{8120D9D6-785C-4413-9C0C-DF2028C56FAD}
    • (Default) = "IGoogleUpdate"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{8120D9D6-785C-4413-9C0C-DF2028C56FAD}\NumMethods
    • (Default) = "5"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{823AE2EB-E62C-4847-B192-C99B91B92416}\ProxyStubClsid32
    • (Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{823AE2EB-E62C-4847-B192-C99B91B92416}
    • (Default) = "IApp"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{823AE2EB-E62C-4847-B192-C99B91B92416}\NumMethods
    • (Default) = "40"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9B9A45F4-18FC-484A-BACA-076D78273D8E}\ProxyStubClsid32
    • (Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9B9A45F4-18FC-484A-BACA-076D78273D8E}
    • (Default) = "IGoogleUpdateCore"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9B9A45F4-18FC-484A-BACA-076D78273D8E}\NumMethods
    • (Default) = "4"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F3E8F9-F747-4DD6-BA6B-82A6CE1E0860}\ProxyStubClsid32
    • (Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F3E8F9-F747-4DD6-BA6B-82A6CE1E0860}
    • (Default) = "IRegistrationUpdateHook"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F3E8F9-F747-4DD6-BA6B-82A6CE1E0860}\NumMethods
    • (Default) = "8"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{59D188FA-757A-424E-8C93-F58FFD896BD7}\ProxyStubClsid32
    • (Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{59D188FA-757A-424E-8C93-F58FFD896BD7}
    • (Default) = "ICredentialDialog"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{59D188FA-757A-424E-8C93-F58FFD896BD7}\NumMethods
    • (Default) = "4"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{A78EDAFB-926F-4D93-AB13-8232D7378EB1}\ProxyStubClsid32
    • (Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{A78EDAFB-926F-4D93-AB13-8232D7378EB1}
    • (Default) = "IGoogleUpdate3"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{A78EDAFB-926F-4D93-AB13-8232D7378EB1}\NumMethods
    • (Default) = "10"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9B4F7CFE-987D-410E-A8E4-20182E0B3C24}\ProxyStubClsid32
    • (Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9B4F7CFE-987D-410E-A8E4-20182E0B3C24}
    • (Default) = "IGoogleUpdate3Web"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9B4F7CFE-987D-410E-A8E4-20182E0B3C24}\NumMethods
    • (Default) = "8"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
    • (Default) = "Google Update Broker Class Factory"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0\CLSID
    • (Default) = "{ADBC39BE-3D20-4333-8D99-E91EB1B62474}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
    • (Default) = "Google Update Broker Class Factory"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine\CLSID
    • (Default) = "{ADBC39BE-3D20-4333-8D99-E91EB1B62474}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine\CurVer
    • (Default) = "globalUpdateUpdate.OnDemandCOMClassMachine.1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
    • (Default) = "Google Update Broker Class Factory"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}\ProgID
    • (Default) = "globalUpdateUpdate.OnDemandCOMClassMachine.1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}\VersionIndependentProgID
    • (Default) = "globalUpdateUpdate.OnDemandCOMClassMachine"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}\LocalServer32
    • (Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
    • LocalizedString = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-3000"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}\Elevation
    • Enabled = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}\Elevation
    • IconReference = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-1004"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
    • (Default) = "Google Update Broker Class Factory"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0\CLSID
    • (Default) = "{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
    • (Default) = "Google Update Broker Class Factory"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine\CLSID
    • (Default) = "{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine\CurVer
    • (Default) = "globalUpdateUpdate.Update3WebMachine.1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
    • (Default) = "Google Update Broker Class Factory"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}\ProgID
    • (Default) = "globalUpdateUpdate.Update3WebMachine.1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}\VersionIndependentProgID
    • (Default) = "globalUpdateUpdate.Update3WebMachine"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}\LocalServer32
    • (Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
    • LocalizedString = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-3000"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}\Elevation
    • Enabled = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}\Elevation
    • IconReference = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-1004"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
    • (Default) = "CoCreateAsync"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0\CLSID
    • (Default) = "{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
    • (Default) = "CoCreateAsync"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync\CLSID
    • (Default) = "{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync\CurVer
    • (Default) = "globalUpdateUpdate.CoCreateAsync.1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
    • (Default) = "CoCreateAsync"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}\ProgID
    • (Default) = "globalUpdateUpdate.CoCreateAsync.1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}\VersionIndependentProgID
    • (Default) = "globalUpdateUpdate.CoCreateAsync"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}\LocalServer32
    • (Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
    • (Default) = "globalUpdate.OneClickProcessLauncher"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0\CLSID
    • (Default) = "{5E89ACE9-E16B-499A-87B4-0DBF742404C1}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
    • (Default) = "globalUpdate.OneClickProcessLauncher"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine\CLSID
    • (Default) = "{5E89ACE9-E16B-499A-87B4-0DBF742404C1}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine\CurVer
    • (Default) = "globalUpdate.OneClickProcessLauncherMachine.1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
    • (Default) = "globalUpdate.OneClickProcessLauncher"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}\ProgID
    • (Default) = "globalUpdate.OneClickProcessLauncherMachine.1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}\VersionIndependentProgID
    • (Default) = "globalUpdate.OneClickProcessLauncherMachine"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}\LocalServer32
    • (Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
    • CLSID = "{5E89ACE9-E16B-499A-87B4-0DBF742404C1}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
    • Policy = "3"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
    • (Default) = "Google Update Process Launcher Class"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0\CLSID
    • (Default) = "{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
    • (Default) = "Google Update Process Launcher Class"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher\CLSID
    • (Default) = "{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher\CurVer
    • (Default) = "globalUpdateUpdate.ProcessLauncher.1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
    • (Default) = "Google Update Process Launcher Class"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}\ProgID
    • (Default) = "globalUpdateUpdate.ProcessLauncher.1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}\VersionIndependentProgID
    • (Default) = "globalUpdateUpdate.ProcessLauncher"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}\LocalServer32
    • (Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
    • (Default) = "Google Update Core Class"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1\CLSID
    • (Default) = "{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
    • (Default) = "Google Update Core Class"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass\CLSID
    • (Default) = "{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass\CurVer
    • (Default) = "globalUpdateUpdate.CoreMachineClass.1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
    • (Default) = "Google Update Core Class"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}\ProgID
    • (Default) = "globalUpdateUpdate.CoreMachineClass.1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}\VersionIndependentProgID
    • (Default) = "globalUpdateUpdate.CoreMachineClass"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}\LocalServer32
    • (Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
    • LocalizedString = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-3000"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}\Elevation
    • Enabled = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}\Elevation
    • IconReference = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-1004"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\{random key}
    • (Default) = "Google Update Legacy On Demand"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0\CLSID
    • (Default) = "{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
    • (Default) = "Google Update Legacy On Demand"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback\CLSID
    • (Default) = "{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback\CurVer
    • (Default) = "globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
    • (Default) = "Google Update Legacy On Demand"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}\ProgID
    • (Default) = "globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}\VersionIndependentProgID
    • (Default) = "globalUpdateUpdate.OnDemandCOMClassMachineFallback"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}\LocalServer32
    • (Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
    • LocalizedString = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-3000"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}\Elevation
    • Enabled = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}\Elevation
    • IconReference = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-1004"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
    • (Default) = "GoogleUpdate Update3Web"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0\CLSID
    • (Default) = "{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
    • (Default) = "GoogleUpdate Update3Web"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback\CLSID
    • (Default) = "{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback\CurVer
    • (Default) = "globalUpdateUpdate.Update3WebMachineFallback.1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
    • (Default) = "GoogleUpdate Update3Web"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}\ProgID
    • (Default) = "globalUpdateUpdate.Update3WebMachineFallback.1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}\VersionIndependentProgID
    • (Default) = "globalUpdateUpdate.Update3WebMachineFallback"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}\LocalServer32
    • (Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
    • LocalizedString = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-3000"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}\Elevation
    • Enabled = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}\Elevation
    • IconReference = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-1004"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
    • (Default) = "GoogleUpdate CredentialDialog"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0\CLSID
    • (Default) = "{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
    • (Default) = "GoogleUpdate CredentialDialog"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine\CLSID
    • (Default) = "{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine\CurVer
    • (Default) = "globalUpdateUpdate.CredentialDialogMachine.1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
    • (Default) = "GoogleUpdate CredentialDialog"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}\ProgID
    • (Default) = "globalUpdateUpdate.CredentialDialogMachine.1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}\VersionIndependentProgID
    • (Default) = "globalUpdateUpdate.CredentialDialogMachine"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}\LocalServer32
    • (Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Chrome-Profiles\%AppDataLocal%\Google\Chrome\User Data
    • Default = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Chrome
    • TotalProfiles = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\ErrorLists-crchromeinstaller
    • post_for_sign_Invalid HTTP(S) status code = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\ErrorLists-crchromeinstaller
    • insert_cook_db_1_table cookies has no column named secure = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\ErrorLists-crchromeinstaller
    • insert_cook_db_1_table cookies has no column named secure = "2"
  • In HKEY_CURRENT_USER\Software\globalUpdate\Update\proxy
    • source = "IE"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP
    • ActiveAppId = "54246"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Update
    • LastCheck = "1562855063"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Installer
    • Bic = "354A91DE7DC14C2A980B5427C0148BABIE"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Installer
    • Verifier = "be6aa8aa1574234ad24e003e9b0dc90a"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Installer
    • Time = "1562855042"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Installer
    • StatsDomain = "http://stats.{BLOCKED}statsservice.com"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Installer
    • ErrorsDomain = "http://errors.{BLOCKED}statsservice.com"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Installer
    • CodeDownloadDomain = "http://js.{BLOCKED}statsservice.com"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Installer
    • FullVersion = "1.34.5.22"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Installer
    • FullVersionForUrl = "1_34_05_22"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Installer
    • SrcId = "001359"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Installer
    • SubId = "0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Installer
    • ZData = "0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Installer
    • DefaultBrowser = "ie"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Installer
    • OsName = "7"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Installer
    • Params = "{ source_id : 001359, sub_id : 0, uzid : 0}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Manifest
    • Name = "MPMP"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Manifest
    • Manifest = "NA"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Manifest
    • Description = "MediaPlayerEnhance Extension"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Manifest
    • PublisherName = "Freeven"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Manifest
    • HomePageUrl = "NA"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Manifest
    • RunInFrame = "false"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Manifest
    • ThanksUrl = "NA"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Manifest
    • DisableIe = "true"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Manifest
    • EnableSearchIE = "false"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Manifest
    • Version = "38"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Manifest
    • UpdateInterval = "360"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Manifest
    • BgVersion = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Manifest
    • AddressbarURL = "NA"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Manifest
    • ChangePrevious = "false"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Manifest
    • SetNewTab = "false"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Manifest
    • PublisherId = "21636"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Manifest
    • ModeType = "production"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Manifest
    • PluginsManifestVersion = "30"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Manifest
    • IsButtonEnabled = "false"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Manifest
    • UninstallerOfferUrl = "NA"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Manifest
    • UninstallerOfferAction = "NA"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Code
    • AppJavaScript = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Code
    • BgJavaScript = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Code
    • NewTabJavaScript = ""
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\251
    • Version = "8"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\251
    • Name = "versionBinaryString"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\251
    • JavaScript = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\251
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/Nova/versionBinaryString.js"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\249
    • Version = "6"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\249
    • Name = "native"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\249
    • JavaScript = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\249
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/Nova/native.js"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\250
    • Version = "5"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\250
    • Name = "api"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\250
    • JavaScript = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\250
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/Nova/api.js"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\14
    • Version = "11"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\14
    • Name = "CrossriderUtils"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\14
    • JavaScript = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\14
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/CrossriderUtils.js"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\78
    • Version = "5"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\78
    • Name = "CrossriderInfo"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\78
    • JavaScript = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\78
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/CrossriderInfo.js"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\233
    • Version = "5"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\233
    • Name = "revizer_p_dynamic_b2b_2_m"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\233
    • JavaScript = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\233
    • Url = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\253
    • Version = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\253
    • Name = "pixel_inject"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\253
    • JavaScript = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\253
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/pixel_inject.js"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\242
    • Version = "3"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\242
    • Name = "price_gong_m"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\242
    • JavaScript = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\242
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/price_gong_m.js"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\211
    • Version = "5"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\211
    • Name = "revizer_ws_dynamic_b2b_light_m"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\211
    • JavaScript = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\211
    • Url = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\191
    • Version = "5"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\191
    • Name = "ciuvo_m"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\191
    • JavaScript = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\191
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/ciuvo_m.js"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\184
    • Version = "9"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\184
    • Name = "noproblemppc_m"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\184
    • JavaScript = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\184
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/noproblemppc_m.js"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\155
    • Version = "3"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\155
    • Name = "ibario_pops_m"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\155
    • JavaScript = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\155
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/ibario_pops_m.js"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\102
    • Version = "7"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\102
    • Name = "dealply_m"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\102
    • JavaScript = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\102
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/dealply_m.js"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\93
    • Version = "10"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\93
    • Name = "superfish_no_coupons_m"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\93
    • JavaScript = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\93
    • Url = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\91
    • Version = "49"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\91
    • Name = "monetizationLoader.js"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\91
    • JavaScript = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\91
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/monetizationLoader.js"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\246
    • Version = "10"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\246
    • Name = "setup"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\246
    • JavaScript = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\246
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/setup.js"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\4
    • Version = "4"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\4
    • Name = "jquery_1_7_1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\4
    • JavaScript = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\4
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/javascripts/jquery-1_7_1_min.js"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins
    • AppPluginList = "246,14,78,4,93,102,155,184,191,211,233,242,253,91"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins
    • BgPluginList = "246,4,14,78,251,249,250,93,102,155,184,191,211,233,242,253,91"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins
    • NewTabPluginList = "14,78,4"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins
    • OnRequestPluginList = "14"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins
    • BrowserEventPluginList = "14"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins
    • PopupPluginList = "4,14,78"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Update
    • LastCheck = "1562855064"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Firefox\Profiles\%Application Data%\Mozilla\Firefox\Profiles
    • lj5mikyj.default = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Firefox
    • TotalProfiles = "1"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP
    • ActiveAppId = "54246"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Update
    • LastCheck = "1562855079"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\Crossrider
    • Bic = "354A91DE7DC14C2A980B5427C0148BABIE"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\Crossrider
    • Verifier = "be6aa8aa1574234ad24e003e9b0dc90a"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Installer
    • Time = "1562855042"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Installer
    • StatsDomain = "http://stats.{BLOCKED}statsservice.com"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Installer
    • ErrorsDomain = "http://errors.{BLOCKED}statsservice.com"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Installer
    • CodeDownloadDomain = "http://js.{BLOCKED}statsservice.com"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Installer
    • FullVersion = "1.34.5.22"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Installer
    • FullVersionForUrl = "1_34_05_22"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Installer
    • SrcId = "001359"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Installer
    • SubId = "0"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Installer
    • ZData = "0"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Installer
    • DefaultBrowser = "ie"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Installer
    • OsName = "7"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Installer
    • Params = "{ source_id : 001359, sub_id : 0, uzid : 0}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\IE\Profiles
    • S-1-5-21-2407829820-1079796033-203259571-500 = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\IE
    • TotalProfiles = "1"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Manifest
    • Name = "MPMP"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Manifest
    • Manifest = "NA"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Manifest
    • Description = "MediaPlayerEnhance Extension"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Manifest
    • PublisherName = "Freeven"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Manifest
    • HomePageUrl = "NA"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Manifest
    • RunInFrame = "false"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Manifest
    • ThanksUrl = "NA"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Manifest
    • DisableIe = "true"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Manifest
    • EnableSearchIE = "false"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Manifest
    • Version = "38"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Manifest
    • UpdateInterval = "360"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Manifest
    • BgVersion = "1"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Manifest
    • AddressbarURL = "NA"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Manifest
    • ChangePrevious = "false"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Manifest
    • SetNewTab = "false"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Manifest
    • PublisherId = "21636"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Manifest
    • ModeType = "production"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Manifest
    • PluginsManifestVersion = "30"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Manifest
    • IsButtonEnabled = "false"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Manifest
    • UninstallerOfferUrl = "NA"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Manifest
    • UninstallerOfferAction = "NA"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Code
    • AppJavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Code
    • BgJavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Code
    • NewTabJavaScript = ""
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\183
    • Version = "4"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\183
    • Name = "tabsWrapper"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\183
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\183
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/tabsWrapper.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\182
    • Version = "3"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\182
    • Name = "openUrl"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\182
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\182
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/openUrl.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\177
    • Version = "2"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\177
    • Name = "crossriderDashboard"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\177
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\177
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/crossriderDashboard.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\94
    • Version = "2"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\94
    • Name = "IEPopup"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\94
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\94
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IEPopup.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\78
    • Version = "5"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\78
    • Name = "CrossriderInfo"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\78
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\78
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/CrossriderInfo.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\207
    • Version = "2"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\207
    • Name = "dbWrapper"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\207
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\207
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/dbWrapper.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\64
    • Version = "3"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\64
    • Name = "appApiMessage"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\64
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\64
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/appApiMessage.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\72
    • Version = "5"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\72
    • Name = "appApiValidation"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\72
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\72
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/appApiValidation.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\46
    • Version = "5"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\46
    • Name = "IETimers"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\46
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\46
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IETimers.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\45
    • Version = "4"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\45
    • Name = "IEOnRequest"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\45
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\45
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IEOnRequest.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\44
    • Version = "6"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\44
    • Name = "IEMisc"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\44
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\44
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IEMisc.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\43
    • Version = "5"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\43
    • Name = "IEMessaging"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\43
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\43
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IEMessaging.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\42
    • Version = "9"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\42
    • Name = "IEInternal"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\42
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\42
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IEInternal.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\41
    • Version = "7"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\41
    • Name = "IEInfo"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\41
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\41
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IEInfo.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\40
    • Version = "4"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\40
    • Name = "IEExtension"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\40
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\40
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IEExtension.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\39
    • Version = "5"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\39
    • Name = "IEDatabase"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\39
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\39
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IEDatabase.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\38
    • Version = "4"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\38
    • Name = "IECallbacks"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\38
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\38
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IECallbacks.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\37
    • Version = "6"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\37
    • Name = "IEBrowserEvents"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\37
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\37
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IEBrowserEvents.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\36
    • Version = "8"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\36
    • Name = "IEBackground"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\36
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\36
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IEBackground.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\35
    • Version = "4"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\35
    • Name = "IEAjax"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\35
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\35
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IEAjax.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\17
    • Version = "4"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\17
    • Name = "jQuery"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\17
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\17
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/jQuery.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\14
    • Version = "11"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\14
    • Name = "CrossriderUtils"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\14
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\14
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/CrossriderUtils.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\13
    • Version = "7"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\13
    • Name = "CrossriderAppUtils"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\13
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\13
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/CrossriderAppUtils.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\253
    • Version = "1"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\253
    • Name = "pixel_inject"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\253
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\253
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/pixel_inject.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\242
    • Version = "3"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\242
    • Name = "price_gong_m"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\242
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\242
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/price_gong_m.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\233
    • Version = "5"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\233
    • Name = "revizer_p_dynamic_b2b_2_m"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\233
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\233
    • Url = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\226
    • Version = "4"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\226
    • Name = "set_campaign_id_m"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\226
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\226
    • Url = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\221
    • Version = "2"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\221
    • Name = "icm_downloads_m"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\221
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\221
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/icm_downloads_m.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\211
    • Version = "5"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\211
    • Name = "revizer_ws_dynamic_b2b_light_m"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\211
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\211
    • Url = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\195
    • Version = "25"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\195
    • Name = "icm_convertmedia_m"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\195
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\195
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/icm_convertmedia_m.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\220
    • Version = "8"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\220
    • Name = "icm_base_m"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\220
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\220
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/icm_base_m.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\7
    • Version = "2"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\7
    • Name = "hooks"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\7
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\7
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/hooks.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\9
    • Version = "3"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\9
    • Name = "search_engine_hook"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\9
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\9
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/searchengines_hook.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\191
    • Version = "5"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\191
    • Name = "ciuvo_m"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\191
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\191
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/ciuvo_m.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\190
    • Version = "3"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\190
    • Name = "pops_5_m"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\190
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\190
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/javascripts/monetization/geo/pops_5_m.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\155
    • Version = "3"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\155
    • Name = "ibario_pops_m"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\155
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\155
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/ibario_pops_m.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\104
    • Version = "9"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\104
    • Name = "jollywallet_m"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\104
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\104
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/javascripts/monetization/geo/jollywallet_m.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\184
    • Version = "9"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\184
    • Name = "noproblemppc_m"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\184
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\184
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/noproblemppc_m.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\103
    • Version = "8"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\103
    • Name = "intext_5_m"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\103
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\103
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/javascripts/monetization/geo/intext_5_m.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\102
    • Version = "7"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\102
    • Name = "dealply_m"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\102
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\102
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/dealply_m.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\93
    • Version = "10"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\93
    • Name = "superfish_no_coupons_m"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\93
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\93
    • Url = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\91
    • Version = "49"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\91
    • Name = "monetizationLoader.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\91
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\91
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/monetizationLoader.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\246
    • Version = "10"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\246
    • Name = "setup"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\246
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\246
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/setup.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\47
    • Version = "3"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\47
    • Name = "resources_background"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\47
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\47
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/resources_background.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\22
    • Version = "5"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\22
    • Name = "resources"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\22
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\22
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/resources.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\28
    • Version = "4"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\28
    • Name = "initializer"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\28
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\28
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/initializer.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\3
    • Version = "2"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\3
    • Name = "ie8_fix_2"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\3
    • JavaScript = "(function(){var b=dummy so this plugin won't be empty;})();"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\3
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie8_fix_2.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\21
    • Version = "5"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\21
    • Name = "debug"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\21
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\21
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/debug.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\2
    • Version = "2"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\2
    • Name = "ie8_fix_1"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\2
    • JavaScript = "(function(){var b=dummy so this plugin won't be empty;})();"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\2
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie8_fix_1.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\4
    • Version = "4"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\4
    • Name = "jquery_1_7_1"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\4
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\4
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/javascripts/jquery-1_7_1_min.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\1
    • Version = "10"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\1
    • Name = "base"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\1
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\1
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/base.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins
    • AppPluginList = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins
    • BgPluginList = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins
    • NewTabPluginList = "42,38,46,17,14,78,13,41,44,39,35,43,40,64,2,4,3,1,21,22,72,28"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins
    • OnRequestPluginList = "14,42,41,39,38,43,45,64,72"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins
    • BrowserEventPluginList = "14,42,41,44,39,38,43,37,64,72"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins
    • PopupPluginList = "42,38,46,41,44,39,35,43,36,4,14,78,13,64,207,47,182,72,94"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0054246.Sandbox.1
    • (Default) = "CrossriderApp0054246.Sandbox"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0054246.Sandbox.1\CLSID
    • (Default) = "{{GUID}}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0054246.BHO.1
    • (Default) = "CrossriderApp0054246"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0054246.BHO.1\CLSID
    • (Default) = "{{GUID}}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0054246.Sandbox
    • (Default) = "CrossriderApp0054246.Sandbox"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0054246.Sandbox\CLSID
    • (Default) = "{{GUID}}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0054246.Sandbox\CurVer
    • (Default) = "CrossriderApp0054246.Sandbox"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0054246.BHO
    • (Default) = "CrossriderApp0054246"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0054246.BHO\CLSID
    • (Default) = "{{GUID}}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0054246.BHO\CurVer
    • (Default) = "CrossriderApp0054246"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{{GUID}}
    • (Default) = "MPMP"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{{GUID}}\ProgID
    • (Default) = "CrossriderApp0054246.BHO.1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{{GUID}}\VersionIndependentProgID
    • (Default) = "CrossriderApp0054246"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{{GUID}}\InprocServer32
    • (Default) = "%Program Files%\MPMP\MPMP-bho.dll"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{{GUID}}\InprocServer32
    • ThreadingModel = "Apartment"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{{GUID}}\TypeLib
    • (Default) = "{{GUID}}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{{GUID}}\Implemented Categories
    • (Default) = ""
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{{GUID}}\Implemented Categories\{{GUID}}
    • (Default) = ""
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{{GUID}}
    • (Default) = "CrossriderApp0054246.Sandbox"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{{GUID}}\ProgID
    • (Default) = "CrossriderApp0054246.Sandbox.1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{{GUID}}\VersionIndependentProgID
    • (Default) = "CrossriderApp0054246.Sandbox"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{{GUID}}
    • (Default) = "CrossriderApp0054246"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{{GUID}}
    • NoExplorer = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{{GUID}}
    • (Default) = "ICrossriderBHO"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{{GUID}}\ProxyStubClsid32
    • (Default) = "{00020424-0000-0000-C000-000000000046}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{{GUID}}\TypeLib
    • (Default) = "{{GUID}}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{{GUID}}\TypeLib
    • Version = "1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{{GUID}}
    • (Default) = "ISandBox"
  • In HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\globalUpdate
    • DisplayName = "globalUpdate Update Service (globalUpdate)"
  • In HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\globalUpdate
    • Start = "SERVICE_AUTO_START"
  • In HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\globalUpdatem
    • DisplayName = "globalUpdate Update Service (globalUpdatem)"
  • In HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\globalUpdatem
    • Start = "SERVICE_DEMAND_START"

手順 5

以下のファイルを検索し削除します。

[ 詳細 ]
コンポーネントファイルが隠しファイル属性の場合があります。[詳細設定オプション]をクリックし、[隠しファイルとフォルダの検索]のチェックボックスをオンにし、検索結果に隠しファイルとフォルダが含まれるようにしてください。
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\21.js
  • %Program Files%\MPMP\54246.crx
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\3e24ea90dedf010dd73864ad8afb9842.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\4f1f2311b6dfe8dc9398b9e63abadc95.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\680792568ec55a86a7e80045e550e236.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe.old
  • %Windows%\Tasks\{GUID}-1.job
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\28.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\popup.html
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\4.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\userCode\extension.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\psuser.dll.old
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\7.js
  • %User Temp%\comh.18754\GoogleUpdateBroker.exe
  • %Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\18be4636f65b5a79a226b006ca76a4e2.js
  • %User Temp%\comh.18754\GoogleUpdateHelper.msi
  • %Program Files%\MPMP\MPMP.ico
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\91.js
  • %User Temp%\AF2.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\221.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateHelper.msi.old
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\45d83464f48807f918f66018f5438b9e.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\183.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\64.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\9.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\search_dialog.xul
  • %Program Files%\MPMP\MPMP-bho.dll
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\installer.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\98.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\5028e2cbf92f3b87b57c694503c57e72.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\37993b8abf06e383d7ef53385525f010.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\787e77f8d7ecc7156be99bd0b0fde217.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\47.js
  • %All Users Profile%\Microsoft\Network\Downloader\qmgr0.dat
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\253.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\190.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\panelarrow-up.png
  • %User Temp%\comh.18754\goopdateres_en.dll
  • %Windows%\Tasks\{GUID}-3.job
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\dialog.js
  • %Windows%\Tasks\{GUID}-6.job
  • %Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe.old
  • %User Temp%\AF1.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\3cdbe045a4a0d3f50bd7b4f8b905fc1d.js
  • %User Temp%\comh.18754\npGoogleUpdate4.dll
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\d011f9d6a8671d3a2bc2b558decdb410.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\button3.png
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\2778ebbf69e285e413df59bb58a8fca9.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\background.html
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\102.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\93.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\userCode\background.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\13.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\4b4b6daaa6ac343ffc1b119ddb0b246c.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\2d5d68b375151fbed320fd2c0181c191.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions.json
  • %User Temp%\comh.18754\goopdate.dll
  • %User Temp%\comh.18754\GoogleUpdate.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\icon48.png
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\bd82ad0f96fb35e02c077edbf2b9f8c6.js
  • %Windows%\Tasks\globalUpdateUpdateTaskMachineUA.job
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\246.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\49566522acce9f80ebb86c35dfb155d3.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\78.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\update.css
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\icon24.png
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\191.js
  • %Program Files%\globalUpdate\Update\GoogleUpdate.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\16.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\5ef7cf534cdbca51efd63b695e3d0f62.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe
  • %Program Files%\MPMP\54246.xpi
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\1370ab8db88b6403223ec11e7a236c84.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\50d601b837ee9834f42c82ddcb1d0c65.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\177.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\icon16.png
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\options.js
  • %All Users Profile%\Microsoft\Network\Downloader\qmgr1.dat
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\d35d0bca3d387bec73e98493bae4bebe.js
  • %User Temp%\comh.18754\GoogleCrashHandler.exe
  • %Program Files%\MPMP\MPMP-nova.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\226.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\defaults\preferences\prefs.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\182.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\9caf939c72d899c9467323bea849b4a3.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\goopdateres_en.dll
  • %Program Files%\MPMP\utils.exe
  • %Program Files%\MPMP\Uninstall.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\6f5764ff79aeb23978e9db22d7981041.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins.json
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\207.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\icon128.png
  • %Program Files%\globalUpdate\Update\1.3.25.0\GoogleCrashHandler.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\button4.png
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\72.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\crossrider_statusbar.png
  • %Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll.old
  • %Program Files%\MPMP\MPMP-codedownloader.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\ceec657593dea2fb9978c177d58f364c.js
  • %User Temp%\comh.18754\psuser.dll
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\104.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\bdbd33145ab7dbb7b5175dc29e13a54f.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\211.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\3438e9cee6f289fe93d7d8abe705ba24.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdate.exe
  • %User Temp%\comh.18754\GoogleUpdateOnDemand.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\ffCoreFilesIndex.txt
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\install.rdf
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\browser.xul
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\8cf406521b5bdabeda6c9b01aad99f51.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\6589406f5c43cdd372d3b9893fe94669.js
  • %Program Files%\MPMP\{GUID}-3.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\184.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\1.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\f04545df6da39e41ae904087d7b3a91c.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\goopdateres_en.dll.old
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\manifest.xml
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\9dba55b4f2557e03aca1fe863b4a9f9e.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\c1ab6a0d65c6bdb80c05eb57261a3d55.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateHelper.msi
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\24e5241137ac099bd0069f5361058525.js
  • %Program Files%\MPMP\MPMP-nova.dll
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\242.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\155.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\22.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\17.js
  • %Program Files%\MPMP\1293297481.mxaddon
  • %Windows%\Tasks\{GUID}-7.job
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\skin.css
  • %Program Files%\globalUpdate\Update\1.3.25.0\psmachine.dll
  • %Program Files%\globalUpdate\Update\1.3.25.0\GoogleCrashHandler.exe.old
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\195.js
  • %User Temp%\{GUID}.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\3dad8746f8926aafde94171b87503811.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\14.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\options.xul
  • %Program Files%\MPMP\360-54246.crx
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\a3e7c3935aee4f766e6a9b9f5e92c869.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\button1.png
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\c5379747c774cf9228f58cd8633a488f.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll.old
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome.manifest
  • %Windows%\Tasks\temp_{GUID}-7.job
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\f44fe937f6668d4047fb81235269a0e1.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\d827b91b474a06b7771997ad452f2201.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\b51ab7bc967684e1c1f0c290f11ebd30.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\53251c7e83b57e1fb7e90172c5dda028.js
  • %Windows%\Tasks\{GUID}-4.job
  • %Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdate.exe.old
  • %User Temp%\comh.18754\psmachine.dll
  • %Program Files%\MPMP\MPMP-novainstaller.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\3030fc4f3b901802369e95d81dda52be.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\bdeaae1663cfe8266d0bfbc7678dc967.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\babbc84c37010a7be8cf9c5b17340fab.js
  • %AppDataLocal%\Google\Chrome\User Data\Local State
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\103.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\button2.png
  • %Program Files%\globalUpdate\Update\1.3.25.0\psmachine.dll.old
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\af0d6e867c53d6d02549f5c2a1a1c625.js
  • %Windows%\Tasks\globalUpdateUpdateTaskMachineCore.job
  • %Program Files%\MPMP\bgNova.html
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\button5.png
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\220.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\psuser.dll
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\locale\en-US\translations.dtd
  • %Program Files%\MPMP\{GUID}-4.exe
  • %Program Files%\MPMP\MPMP-bho64.dll
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\233.js

手順 6

以下のフォルダを検索し削除します。

[ 詳細 ]
フォルダが隠しフォルダ属性に設定されている場合があります。[詳細設定オプション]をクリックし、[隠しファイルとフォルダの検索]のチェックボックスをオンにし、検索結果に隠しファイルとフォルダが含まれるようにしてください。
  • %Program Files%\globalUpdate\Update
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins
  • %AppDataLocal%\globalUpdate
  • %AppDataLocal%\globalUpdate\CrashReports
  • %Program Files%\MPMP
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\locale\en-US
  • %User Temp%\comh.18754
  • %User Profile%\AppData
  • %Program Files%\globalUpdate\Update\Offline
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\userCode
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\defaults
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\locale
  • %Program Files%\globalUpdate
  • %Program Files%\globalUpdate\Update\1.3.25.0
  • %System Root%\Users
  • %Program Files%\globalUpdate\Update\Offline\{27F2D2DB-7D37-4E11-92F6-67B10F86EC61}
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\defaults\preferences
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome
  • %Program Files%\globalUpdate\CrashReports

手順 7

最新のバージョン(エンジン、パターンファイル)を導入したウイルス対策製品を用い、ウイルス検索を実行してください。「Adware.Win32.Crossrider.A」と検出したファイルはすべて削除してください。 検出されたファイルが、弊社ウイルス対策製品により既に駆除、隔離またはファイル削除の処理が実行された場合、ウイルスの処理は完了しており、他の削除手順は特にありません。

手順 8

以下のファイルをバックアップを用いて修復します。マイクロソフト製品に関連したファイルのみに修復されます。このマルウェアが同社製品以外のプログラムをも削除した場合には、該当プログラムを再度インストールする必要があります。

  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions.json

手順 9

以下のファイルをバックアップを用いて修復します。なお、マイクロソフト製品に関連したファイルのみ修復されます。このマルウェア/グレイウェア/スパイウェアが同社製品以外のプログラムをも削除した場合には、該当プログラムを再度インストールする必要があります。

  • %User Temp%\nst9695.tmp
  • %Windows%\Tasks\GoogleUpdateTask.job
  • %Windows%\Tasks\GoogleUpdateTaskMachine.job

手順 10

以下の削除されたレジストリキーまたはレジストリ値をバックアップを用いて修復します。

※註:マイクロソフト製品に関連したレジストリキーおよびレジストリ値のみが修復されます。このマルウェアもしくはアドウェア等が同社製品以外のプログラムも削除した場合には、該当プログラムを再度インストールする必要があります。

  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GlobalUpdate\Update
    • eulaaccepted
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GlobalUpdate\Update
    • mi
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GlobalUpdate\Update
    • ui
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GlobalUpdate\Update
    • LastChecked
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GlobalUpdate\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}
    • UpdateAvailableCount
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GlobalUpdate\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}
    • UpdateAvailableSince
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GlobalUpdate\Update
    • uid
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GlobalUpdate\Update\network\secure
    • sk
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GlobalUpdate\Update\network\secure
    • c


ご利用はいかがでしたか? アンケートにご協力ください