PUA_Besttoolbars
Windows
マルウェアタイプ:
トロイの木馬型
破壊活動の有無:
なし
暗号化:
感染報告の有無 :
はい
概要
マルウェアは、他のマルウェアに作成されるか、悪意あるWebサイトからユーザが誤ってダウンロードすることによりコンピュータに侵入します。
詳細
侵入方法
マルウェアは、他のマルウェアに作成されるか、悪意あるWebサイトからユーザが誤ってダウンロードすることによりコンピュータに侵入します。
インストール
マルウェアは、以下のフォルダを作成します。
- %System Root%\DOCUME~1
- %System Root%\DOCUME~1\Wilbert
- %User Profile%\LOCALS~1
- %User Temp%\nst3.tmp
- %Program Files%\IntelliConnect Search
- %Program Files%\IntelliConnect Search\img
- %Program Files%\IntelliConnect Search\popup
- %Program Files%\IntelliConnect Search\styles
(註:%System Root%フォルダは、オペレーティングシステム(OS)が存在する場所で、いずれのOSでも通常、 "C:" です。.. %User Profile% フォルダは、Windows 2000、XP および Server 2003 の場合、通常、"C:\Documents and Settings\<ユーザ名>"、Windows Vista 、 7 、8、8.1 、Server 2008 および Server 2012の場合、"C:\Users\<ユーザ名>" です。.. %User Temp%フォルダは、ユーザの一時フォルダで、Windows 2000、XP および Server 2003 の場合、通常、"C:\Documents and Settings\<ユーザー名>\Local Settings\Temp"、Windows Vista 、 7 、8、8.1 、Server 2008 および Server 2012の場合、"C:\Users\<ユーザ名>\AppData\Local\Temp" です。.. %Program Files%フォルダは、プログラムファイルのフォルダで、いずれのオペレーティングシステム(OS)でも通常、 "C:\Program Files"、64bitのOS上で32bitのアプリケーションを実行している場合、 "C:\Program Files (x86)" です。.)
自動実行方法
マルウェアは、以下のレジストリキーを追加し、自身をBrowser Helper Object(BHO)として登録します。これにより、Internet Explorer(IE)が起動するとマルウェアが自動実行されます。
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Explorer\
Browser Helper Objects\{D26D85EB-E331-40D9-A4C5-FE975A11EC59}
他のシステム変更
マルウェアは、以下のファイルを削除します。
- %User Temp%\nsy1.tmp
- %User Temp%\nst3.tmp
- %User Temp%\nst3.tmp\help_page.ini
(註:%User Temp%フォルダは、ユーザの一時フォルダで、Windows 2000、XP および Server 2003 の場合、通常、"C:\Documents and Settings\<ユーザー名>\Local Settings\Temp"、Windows Vista 、 7 、8、8.1 、Server 2008 および Server 2012の場合、"C:\Users\<ユーザ名>\AppData\Local\Temp" です。.)
マルウェアは、以下のレジストリキーを追加します。
HKEY_USERS\.DEFAULT\Software\
Microsoft\Internet Explorer\LowRegistry\
IntelliConnect
HKEY_USERS\S-1-5-19\Software\
Microsoft\Internet Explorer\LowRegistry\
IntelliConnect
HKEY_USERS\S-1-5-19_Classes\Software\
Microsoft\Internet Explorer\LowRegistry\
IntelliConnect
HKEY_USERS\S-1-5-20\Software\
Microsoft\Internet Explorer\LowRegistry\
IntelliConnect
HKEY_USERS\S-1-5-20_Classes\Software\
Microsoft\Internet Explorer\LowRegistry\
IntelliConnect
HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003\Software\
Microsoft\Internet Explorer\LowRegistry\
IntelliConnect
HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003_Classes\Software\
Microsoft\Internet Explorer\LowRegistry\
IntelliConnect
HKEY_USERS\.DEFAULT\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator
HKEY_USERS\.DEFAULT\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com
HKEY_USERS\.DEFAULT\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1
HKEY_USERS\.DEFAULT\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1\execute
HKEY_USERS\.DEFAULT\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1\execute\
Parameter1
HKEY_USERS\.DEFAULT\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1\execute\
Parameter2
HKEY_USERS\.DEFAULT\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1\execute\
Parameter3
HKEY_USERS\.DEFAULT\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1\execute\
Parameter4
HKEY_USERS\.DEFAULT\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1\execute\
Parameter5
HKEY_USERS\.DEFAULT\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2
HKEY_USERS\.DEFAULT\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2\execute
HKEY_USERS\.DEFAULT\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2\execute\
Parameter1
HKEY_USERS\.DEFAULT\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2\execute\
Parameter2
HKEY_USERS\.DEFAULT\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2\execute\
Parameter3
HKEY_USERS\.DEFAULT\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2\execute\
Parameter4
HKEY_USERS\.DEFAULT\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2\execute\
Parameter5
HKEY_USERS\S-1-5-19\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator
HKEY_USERS\S-1-5-19\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com
HKEY_USERS\S-1-5-19\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1
HKEY_USERS\S-1-5-19\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1\execute
HKEY_USERS\S-1-5-19\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1\execute\
Parameter1
HKEY_USERS\S-1-5-19\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1\execute\
Parameter2
HKEY_USERS\S-1-5-19\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1\execute\
Parameter3
HKEY_USERS\S-1-5-19\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1\execute\
Parameter4
HKEY_USERS\S-1-5-19\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1\execute\
Parameter5
HKEY_USERS\S-1-5-19\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2
HKEY_USERS\S-1-5-19\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2\execute
HKEY_USERS\S-1-5-19\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2\execute\
Parameter1
HKEY_USERS\S-1-5-19\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2\execute\
Parameter2
HKEY_USERS\S-1-5-19\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2\execute\
Parameter3
HKEY_USERS\S-1-5-19\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2\execute\
Parameter4
HKEY_USERS\S-1-5-19\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2\execute\
Parameter5
HKEY_USERS\S-1-5-19_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator
HKEY_USERS\S-1-5-19_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com
HKEY_USERS\S-1-5-19_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1
HKEY_USERS\S-1-5-19_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1\execute
HKEY_USERS\S-1-5-19_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1\execute\
Parameter1
HKEY_USERS\S-1-5-19_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1\execute\
Parameter2
HKEY_USERS\S-1-5-19_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1\execute\
Parameter3
HKEY_USERS\S-1-5-19_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1\execute\
Parameter4
HKEY_USERS\S-1-5-19_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1\execute\
Parameter5
HKEY_USERS\S-1-5-19_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2
HKEY_USERS\S-1-5-19_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2\execute
HKEY_USERS\S-1-5-19_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2\execute\
Parameter1
HKEY_USERS\S-1-5-19_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2\execute\
Parameter2
HKEY_USERS\S-1-5-19_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2\execute\
Parameter3
HKEY_USERS\S-1-5-19_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2\execute\
Parameter4
HKEY_USERS\S-1-5-19_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2\execute\
Parameter5
HKEY_USERS\S-1-5-20\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator
HKEY_USERS\S-1-5-20\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com
HKEY_USERS\S-1-5-20\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1
HKEY_USERS\S-1-5-20\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1\execute
HKEY_USERS\S-1-5-20\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1\execute\
Parameter1
HKEY_USERS\S-1-5-20\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1\execute\
Parameter2
HKEY_USERS\S-1-5-20\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1\execute\
Parameter3
HKEY_USERS\S-1-5-20\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1\execute\
Parameter4
HKEY_USERS\S-1-5-20\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1\execute\
Parameter5
HKEY_USERS\S-1-5-20\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2
HKEY_USERS\S-1-5-20\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2\execute
HKEY_USERS\S-1-5-20\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2\execute\
Parameter1
HKEY_USERS\S-1-5-20\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2\execute\
Parameter2
HKEY_USERS\S-1-5-20\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2\execute\
Parameter3
HKEY_USERS\S-1-5-20\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2\execute\
Parameter4
HKEY_USERS\S-1-5-20\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2\execute\
Parameter5
HKEY_USERS\S-1-5-20_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator
HKEY_USERS\S-1-5-20_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com
HKEY_USERS\S-1-5-20_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1
HKEY_USERS\S-1-5-20_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1\execute
HKEY_USERS\S-1-5-20_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1\execute\
Parameter1
HKEY_USERS\S-1-5-20_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1\execute\
Parameter2
HKEY_USERS\S-1-5-20_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1\execute\
Parameter3
HKEY_USERS\S-1-5-20_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1\execute\
Parameter4
HKEY_USERS\S-1-5-20_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1\execute\
Parameter5
HKEY_USERS\S-1-5-20_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2
HKEY_USERS\S-1-5-20_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2\execute
HKEY_USERS\S-1-5-20_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2\execute\
Parameter1
HKEY_USERS\S-1-5-20_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2\execute\
Parameter2
HKEY_USERS\S-1-5-20_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2\execute\
Parameter3
HKEY_USERS\S-1-5-20_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2\execute\
Parameter4
HKEY_USERS\S-1-5-20_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2\execute\
Parameter5
HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator
HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com
HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1
HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1\execute
HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1\execute\
Parameter1
HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1\execute\
Parameter2
HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1\execute\
Parameter3
HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1\execute\
Parameter4
HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1\execute\
Parameter5
HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2
HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2\execute
HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2\execute\
Parameter1
HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2\execute\
Parameter2
HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2\execute\
Parameter3
HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2\execute\
Parameter4
HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2\execute\
Parameter5
HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator
HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com
HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1
HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1\execute
HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1\execute\
Parameter1
HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1\execute\
Parameter2
HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1\execute\
Parameter3
HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1\execute\
Parameter4
HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action1\execute\
Parameter5
HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2
HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2\execute
HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2\execute\
Parameter1
HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2\execute\
Parameter2
HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2\execute\
Parameter3
HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2\execute\
Parameter4
HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003_Classes\Software\
Microsoft\Windows\CurrentVersion\
Internet Settings\Activities\Search Accelerator\
cch.com\Action2\execute\
Parameter5
HKEY_LOCAL_MACHINE\Software\Google\
Chrome\NativeMessagingHosts\intelliconnect.sendmessages
HKEY_LOCAL_MACHINE\Software\Microsoft\
Windows\CurrentVersion\Uninstall\
IntelliConnect Search
HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\MINIE
HKEY_CURRENT_USER\Software\IntelliConnect Search
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Internet Explorer\Low Rights\ElevationPolicy\
{83BC8A3A-5770-4b45-87A3-02D65C3076C3}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Internet Explorer\Main\FeatureControl\
FEATURE_BROWSER_EMULATION
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Internet Explorer\Main\FeatureControl\
FEATURE_WEBOC_MOVESIZECHILD
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{18B9B16E-716F-43DF-A6AD-512C7D2EB983}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\BackgroundHost.EXE
HKEY_CLASSES_ROOT\IntelliConnect Search.BackgroundHostObject.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
IntelliConnect Search.BackgroundHostObject.1\CLSID
HKEY_CLASSES_ROOT\IntelliConnect Search.BackgroundHostObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
IntelliConnect Search.BackgroundHostObject\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
IntelliConnect Search.BackgroundHostObject\CurVer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{B1039E2E-E4AF-40A0-9094-81C031D14A22}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{B1039E2E-E4AF-40A0-9094-81C031D14A22}\ProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{B1039E2E-E4AF-40A0-9094-81C031D14A22}\VersionIndependentProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{B1039E2E-E4AF-40A0-9094-81C031D14A22}\Programmable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{B1039E2E-E4AF-40A0-9094-81C031D14A22}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{B1039E2E-E4AF-40A0-9094-81C031D14A22}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{450F902B-A690-4DB7-BD66-B77E525F75FD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{450F902B-A690-4DB7-BD66-B77E525F75FD}\1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{450F902B-A690-4DB7-BD66-B77E525F75FD}\1.0\
FLAGS
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{450F902B-A690-4DB7-BD66-B77E525F75FD}\1.0\
0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{450F902B-A690-4DB7-BD66-B77E525F75FD}\1.0\
0\win32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{450F902B-A690-4DB7-BD66-B77E525F75FD}\1.0\
HELPDIR
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{43969E3F-3E7C-4911-A8F1-79C6CA6AC731}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{43969E3F-3E7C-4911-A8F1-79C6CA6AC731}\ProxyStubClsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{43969E3F-3E7C-4911-A8F1-79C6CA6AC731}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{43969E3F-3E7C-4911-A8F1-79C6CA6AC731}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{19975B78-1907-4DD6-A437-4C48120F46A4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\AddonsFramework.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{0D30A607-2ACE-4028-AC3D-E78BDDF97EB8}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{0D30A607-2ACE-4028-AC3D-E78BDDF97EB8}\1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{0D30A607-2ACE-4028-AC3D-E78BDDF97EB8}\1.0\
FLAGS
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{0D30A607-2ACE-4028-AC3D-E78BDDF97EB8}\1.0\
0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{0D30A607-2ACE-4028-AC3D-E78BDDF97EB8}\1.0\
0\win32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{0D30A607-2ACE-4028-AC3D-E78BDDF97EB8}\1.0\
HELPDIR
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{94CADA2E-1D3F-419F-8A3D-06C58EDF53C8}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{94CADA2E-1D3F-419F-8A3D-06C58EDF53C8}\ProxyStubClsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{94CADA2E-1D3F-419F-8A3D-06C58EDF53C8}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{94CADA2E-1D3F-419F-8A3D-06C58EDF53C8}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C1995F88-1C7F-40D7-B0FA-6F107F6308B8}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C1995F88-1C7F-40D7-B0FA-6F107F6308B8}\ProxyStubClsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C1995F88-1C7F-40D7-B0FA-6F107F6308B8}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C1995F88-1C7F-40D7-B0FA-6F107F6308B8}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{9E52EB8B-8DD9-4605-AD36-D352BCD482F2}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{9E52EB8B-8DD9-4605-AD36-D352BCD482F2}\ProxyStubClsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{9E52EB8B-8DD9-4605-AD36-D352BCD482F2}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{9E52EB8B-8DD9-4605-AD36-D352BCD482F2}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{A1440EC3-F0FA-407A-B811-DE6668C06D29}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{A1440EC3-F0FA-407A-B811-DE6668C06D29}\ProxyStubClsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{A1440EC3-F0FA-407A-B811-DE6668C06D29}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{A1440EC3-F0FA-407A-B811-DE6668C06D29}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{B9A84AD0-5777-46FD-8B8F-1EBD06750FBC}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{B9A84AD0-5777-46FD-8B8F-1EBD06750FBC}\ProxyStubClsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{B9A84AD0-5777-46FD-8B8F-1EBD06750FBC}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{B9A84AD0-5777-46FD-8B8F-1EBD06750FBC}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{395AFE6E-8308-48DB-89BE-ED5F4AA3D3EC}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{395AFE6E-8308-48DB-89BE-ED5F4AA3D3EC}\ProxyStubClsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{395AFE6E-8308-48DB-89BE-ED5F4AA3D3EC}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{395AFE6E-8308-48DB-89BE-ED5F4AA3D3EC}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{045F91B3-695F-423A-98C7-8DE3C47AA020}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{045F91B3-695F-423A-98C7-8DE3C47AA020}\ProxyStubClsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{045F91B3-695F-423A-98C7-8DE3C47AA020}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{045F91B3-695F-423A-98C7-8DE3C47AA020}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{BBBE01ED-0F1E-44DB-88C1-5CC1AEE3B462}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{BBBE01ED-0F1E-44DB-88C1-5CC1AEE3B462}\ProxyStubClsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{BBBE01ED-0F1E-44DB-88C1-5CC1AEE3B462}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{BBBE01ED-0F1E-44DB-88C1-5CC1AEE3B462}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{F9EB11AB-9384-4736-9B33-993940F88895}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{F9EB11AB-9384-4736-9B33-993940F88895}\ProxyStubClsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{F9EB11AB-9384-4736-9B33-993940F88895}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{F9EB11AB-9384-4736-9B33-993940F88895}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{43B390F0-6BA2-45CA-ABF2-5DB0CEE9B49D}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{43B390F0-6BA2-45CA-ABF2-5DB0CEE9B49D}\ProxyStubClsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{43B390F0-6BA2-45CA-ABF2-5DB0CEE9B49D}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{43B390F0-6BA2-45CA-ABF2-5DB0CEE9B49D}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{E4A994B0-5550-4680-A4C6-B9470B888069}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{E4A994B0-5550-4680-A4C6-B9470B888069}\ProxyStubClsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{E4A994B0-5550-4680-A4C6-B9470B888069}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{E4A994B0-5550-4680-A4C6-B9470B888069}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{EE95078D-518C-4FD2-8093-FD1D4E33D3CA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{EE95078D-518C-4FD2-8093-FD1D4E33D3CA}\ProxyStubClsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{EE95078D-518C-4FD2-8093-FD1D4E33D3CA}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{EE95078D-518C-4FD2-8093-FD1D4E33D3CA}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C815E3DA-0823-49B0-9270-D1771D58B317}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C815E3DA-0823-49B0-9270-D1771D58B317}\ProxyStubClsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C815E3DA-0823-49B0-9270-D1771D58B317}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C815E3DA-0823-49B0-9270-D1771D58B317}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{1348BD1B-C32A-41A7-9BD4-5377AA1AB925}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{1348BD1B-C32A-41A7-9BD4-5377AA1AB925}\ProxyStubClsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{1348BD1B-C32A-41A7-9BD4-5377AA1AB925}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{1348BD1B-C32A-41A7-9BD4-5377AA1AB925}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{562B9316-C08A-444A-9482-62080DD851AE}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\ScriptHost.DLL
HKEY_CLASSES_ROOT\IntelliConnect Search.ScriptHostObject.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
IntelliConnect Search.ScriptHostObject.1\CLSID
HKEY_CLASSES_ROOT\IntelliConnect Search.ScriptHostObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
IntelliConnect Search.ScriptHostObject\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
IntelliConnect Search.ScriptHostObject\CurVer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{D26D85EB-E331-40D9-A4C5-FE975A11EC59}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{D26D85EB-E331-40D9-A4C5-FE975A11EC59}\ProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{D26D85EB-E331-40D9-A4C5-FE975A11EC59}\VersionIndependentProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{D26D85EB-E331-40D9-A4C5-FE975A11EC59}\Programmable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{D26D85EB-E331-40D9-A4C5-FE975A11EC59}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{D26D85EB-E331-40D9-A4C5-FE975A11EC59}\TypeLib
HKEY_CLASSES_ROOT\IntelliConnect Search.Tool.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
IntelliConnect Search.Tool.1\CLSID
HKEY_CLASSES_ROOT\IntelliConnect Search.Tool
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
IntelliConnect Search.Tool\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
IntelliConnect Search.Tool\CurVer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{39D4315D-D55B-431B-BF4B-97122C514BC7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{39D4315D-D55B-431B-BF4B-97122C514BC7}\ProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{39D4315D-D55B-431B-BF4B-97122C514BC7}\VersionIndependentProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{39D4315D-D55B-431B-BF4B-97122C514BC7}\Programmable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{39D4315D-D55B-431B-BF4B-97122C514BC7}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{39D4315D-D55B-431B-BF4B-97122C514BC7}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{3E8745A9-50B0-4099-AC2E-E29BC3D1ED2D}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{3E8745A9-50B0-4099-AC2E-E29BC3D1ED2D}\1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{3E8745A9-50B0-4099-AC2E-E29BC3D1ED2D}\1.0\
FLAGS
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{3E8745A9-50B0-4099-AC2E-E29BC3D1ED2D}\1.0\
0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{3E8745A9-50B0-4099-AC2E-E29BC3D1ED2D}\1.0\
0\win32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{3E8745A9-50B0-4099-AC2E-E29BC3D1ED2D}\1.0\
HELPDIR
HKEY_CLASSES_ROOT\IntelliConnect Search.Navbar.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
IntelliConnect Search.Navbar.1\CLSID
HKEY_CLASSES_ROOT\IntelliConnect Search.Navbar
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
IntelliConnect Search.Navbar\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
IntelliConnect Search.Navbar\CurVer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{7DFF2557-208E-4581-90D9-0B84D3DEC35A}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{7DFF2557-208E-4581-90D9-0B84D3DEC35A}\ProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{7DFF2557-208E-4581-90D9-0B84D3DEC35A}\VersionIndependentProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{7DFF2557-208E-4581-90D9-0B84D3DEC35A}\Programmable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{7DFF2557-208E-4581-90D9-0B84D3DEC35A}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{7DFF2557-208E-4581-90D9-0B84D3DEC35A}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{562B9317-C08A-444A-9482-62080DD851AE}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\ButtonSite.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{CB11C844-9744-482E-9CF4-AFF116F8618E}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{CB11C844-9744-482E-9CF4-AFF116F8618E}\1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{CB11C844-9744-482E-9CF4-AFF116F8618E}\1.0\
FLAGS
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{CB11C844-9744-482E-9CF4-AFF116F8618E}\1.0\
0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{CB11C844-9744-482E-9CF4-AFF116F8618E}\1.0\
0\win32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{CB11C844-9744-482E-9CF4-AFF116F8618E}\1.0\
HELPDIR
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{544C2426-48FD-4C40-AE3B-31257FF334D0}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\RegistryHelper.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{A4341726-E922-47bb-86A6-23F4F4F67342}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{A4341726-E922-47bb-86A6-23F4F4F67342}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{A4341726-E922-47bb-86A6-23F4F4F67342}\TypeLib
HKEY_CLASSES_ROOT\RegistryHelper.RegistryHelperObject.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
RegistryHelper.RegistryHelperObject.1\CLSID
HKEY_CLASSES_ROOT\RegistryHelper.RegistryHelperObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
RegistryHelper.RegistryHelperObject\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
RegistryHelper.RegistryHelperObject\CurVer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{1917AB4C-E2E9-42ae-A51E-B5750F160BFB}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{1917AB4C-E2E9-42ae-A51E-B5750F160BFB}\ProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{1917AB4C-E2E9-42ae-A51E-B5750F160BFB}\VersionIndependentProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{1917AB4C-E2E9-42ae-A51E-B5750F160BFB}\Programmable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{1917AB4C-E2E9-42ae-A51E-B5750F160BFB}\Implemented Categories
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{1917AB4C-E2E9-42ae-A51E-B5750F160BFB}\Implemented Categories\
{7DD95801-9882-11CF-9FA9-00AA006C42C4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{1917AB4C-E2E9-42ae-A51E-B5750F160BFB}\Implemented Categories\
{7DD95802-9882-11CF-9FA9-00AA006C42C4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{1917AB4C-E2E9-42ae-A51E-B5750F160BFB}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{1917AB4C-E2E9-42ae-A51E-B5750F160BFB}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{567A1ED0-A437-401F-9D84-A2B19CD697B5}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{567A1ED0-A437-401F-9D84-A2B19CD697B5}\1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{567A1ED0-A437-401F-9D84-A2B19CD697B5}\1.0\
FLAGS
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{567A1ED0-A437-401F-9D84-A2B19CD697B5}\1.0\
0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{567A1ED0-A437-401F-9D84-A2B19CD697B5}\1.0\
0\win32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{567A1ED0-A437-401F-9D84-A2B19CD697B5}\1.0\
HELPDIR
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{E809EB5C-E1A2-4CD0-AF2B-705CB533F7B8}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{E809EB5C-E1A2-4CD0-AF2B-705CB533F7B8}\ProxyStubClsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{E809EB5C-E1A2-4CD0-AF2B-705CB533F7B8}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{E809EB5C-E1A2-4CD0-AF2B-705CB533F7B8}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{B887CA3B-D82B-4A01-AD29-E97444D01CE6}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{B887CA3B-D82B-4A01-AD29-E97444D01CE6}\ProxyStubClsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{B887CA3B-D82B-4A01-AD29-E97444D01CE6}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{B887CA3B-D82B-4A01-AD29-E97444D01CE6}\TypeLib
マルウェアは、以下のレジストリ値を追加します。
HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\LowRegistry\IntelliConnect
Version = "1.0.10.29"
HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\LowRegistry\IntelliConnect
InstallUpdate = "msie;chrome;firefox"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Activities\Search Accelerator
DefaultActivity = "cch.com"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Activities\Search Accelerator\cch.com
Description = "Find Friends on google."
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Activities\Search Accelerator\cch.com
HomepageURL = "http://{BLOCKED}h.com"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Activities\Search Accelerator\cch.com
Domain = "cch.com"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Activities\Search Accelerator\cch.com
Verb = "Search Accelerator"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Activities\Search Accelerator\cch.com
DisplayName = "Search with IntelliConnect"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Activities\Search Accelerator\cch.com
Type = "1"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Activities\Search Accelerator\cch.com
Enabled = "1"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Activities\Search Accelerator\cch.com
Deleted = "0"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Activities\Search Accelerator\cch.com
ActionCount = "2"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Activities\Search Accelerator\cch.com
ContentMask = "6"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Activities\Search Accelerator\cch.com
Icon = "%Program Files%\IntelliConnect Search\img\green-16.ico"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Activities\Search Accelerator\cch.com\
Action1
Context = "selection"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Activities\Search Accelerator\cch.com\
Action1
HasPreview = "0"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Activities\Search Accelerator\cch.com\
Action1\execute
Action = "https://{BLOCKED}hconnect.{BLOCKED}h.com/icsearch/SearchRedirect.aspx"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Activities\Search Accelerator\cch.com\
Action1\execute
Method = "get"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Activities\Search Accelerator\cch.com\
Action1\execute
Enctype = "application/x-www-form-urlencoded"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Activities\Search Accelerator\cch.com\
Action1\execute
Accept-charset = "utf-8"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Activities\Search Accelerator\cch.com\
Action1\execute
ParamCount = "5"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Activities\Search Accelerator\cch.com\
Action1\execute\Parameter1
Name = "userid"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Activities\Search Accelerator\cch.com\
Action1\execute\Parameter2
Name = "env"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Activities\Search Accelerator\cch.com\
Action1\execute\Parameter2
Value = "prod"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Activities\Search Accelerator\cch.com\
Action1\execute\Parameter3
Name = "searchtype"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Activities\Search Accelerator\cch.com\
Action1\execute\Parameter3
Value = "context"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Activities\Search Accelerator\cch.com\
Action1\execute\Parameter4
Name = "version"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Activities\Search Accelerator\cch.com\
Action1\execute\Parameter4
Value = "1.0.10.29"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Activities\Search Accelerator\cch.com\
Action1\execute\Parameter5
Name = "query"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Activities\Search Accelerator\cch.com\
Action1\execute\Parameter5
Value = "{selection}"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Activities\Search Accelerator\cch.com\
Action2
Context = "link"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Activities\Search Accelerator\cch.com\
Action2
HasPreview = "0"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Activities\Search Accelerator\cch.com\
Action2\execute
Action = "https://{BLOCKED}hconnect.{BLOCKED}h.com/icsearch/SearchRedirect.aspx"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Activities\Search Accelerator\cch.com\
Action2\execute
Method = "get"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Activities\Search Accelerator\cch.com\
Action2\execute
Enctype = "application/x-www-form-urlencoded"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Activities\Search Accelerator\cch.com\
Action2\execute
Accept-charset = "utf-8"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Activities\Search Accelerator\cch.com\
Action2\execute
ParamCount = "5"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Activities\Search Accelerator\cch.com\
Action2\execute\Parameter1
Name = "userid"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Activities\Search Accelerator\cch.com\
Action2\execute\Parameter2
Name = "env"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Activities\Search Accelerator\cch.com\
Action2\execute\Parameter2
Value = "prod"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Activities\Search Accelerator\cch.com\
Action2\execute\Parameter3
Name = "searchtype"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Activities\Search Accelerator\cch.com\
Action2\execute\Parameter3
Value = "context"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Activities\Search Accelerator\cch.com\
Action2\execute\Parameter4
Name = "version"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Activities\Search Accelerator\cch.com\
Action2\execute\Parameter4
Value = "1.0.10.29"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Activities\Search Accelerator\cch.com\
Action2\execute\Parameter5
Name = "query"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings\
Activities\Search Accelerator\cch.com\
Action2\execute\Parameter5
Value = "{linkText}"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
IntelliConnect Search
DisplayName = "IntelliConnect® Search"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
IntelliConnect Search
UninstallString = "%Program Files%\IntelliConnect Search\uninstall.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
IntelliConnect Search
DisplayVersion = "1.0.10.29"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
IntelliConnect Search
Publisher = "Wolters Kluwer"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
IntelliConnect Search
URLInfoAbout = "https://intelliconnect.{BLOCKED}h.com"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
IntelliConnect Search
DisplayIcon = "%Program Files%\IntelliConnect Search\uninstall.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
IntelliConnect Search
InstDir = "%Program Files%\IntelliConnect Search"
HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\MINIE
CommandBarEnabled = "1"
HKEY_CURRENT_USER\Software\IntelliConnect Search
elevationPolicyGuid = "{83BC8A3A-5770-4b45-87A3-02D65C3076C3}"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Internet Explorer\Low Rights\ElevationPolicy\
{83BC8A3A-5770-4b45-87A3-02D65C3076C3}
Policy = "3"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Internet Explorer\Low Rights\ElevationPolicy\
{83BC8A3A-5770-4b45-87A3-02D65C3076C3}
AppPath = "%Program Files%\IntelliConnect Search"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Internet Explorer\Low Rights\ElevationPolicy\
{83BC8A3A-5770-4b45-87A3-02D65C3076C3}
AppName = "BackgroundHost.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Internet Explorer\Main\FeatureControl\
FEATURE_WEBOC_MOVESIZECHILD
BackgroundHost.exe = "1"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\BackgroundHost.EXE
AppID = "{18B9B16E-716F-43DF-A6AD-512C7D2EB983}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{43969E3F-3E7C-4911-A8F1-79C6CA6AC731}\TypeLib
Version = "1.0"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\AddonsFramework.DLL
AppID = "{19975B78-1907-4DD6-A437-4C48120F46A4}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{94CADA2E-1D3F-419F-8A3D-06C58EDF53C8}\TypeLib
Version = "1.0"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C1995F88-1C7F-40D7-B0FA-6F107F6308B8}\TypeLib
Version = "1.0"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{9E52EB8B-8DD9-4605-AD36-D352BCD482F2}\TypeLib
Version = "1.0"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{A1440EC3-F0FA-407A-B811-DE6668C06D29}\TypeLib
Version = "1.0"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{B9A84AD0-5777-46FD-8B8F-1EBD06750FBC}\TypeLib
Version = "1.0"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{395AFE6E-8308-48DB-89BE-ED5F4AA3D3EC}\TypeLib
Version = "1.0"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{045F91B3-695F-423A-98C7-8DE3C47AA020}\TypeLib
Version = "1.0"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{BBBE01ED-0F1E-44DB-88C1-5CC1AEE3B462}\TypeLib
Version = "1.0"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{F9EB11AB-9384-4736-9B33-993940F88895}\TypeLib
Version = "1.0"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{43B390F0-6BA2-45CA-ABF2-5DB0CEE9B49D}\TypeLib
Version = "1.0"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{E4A994B0-5550-4680-A4C6-B9470B888069}\TypeLib
Version = "1.0"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{EE95078D-518C-4FD2-8093-FD1D4E33D3CA}\TypeLib
Version = "1.0"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C815E3DA-0823-49B0-9270-D1771D58B317}\TypeLib
Version = "1.0"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{1348BD1B-C32A-41A7-9BD4-5377AA1AB925}\TypeLib
Version = "1.0"
HKEY_CURRENT_USER\Software\IntelliConnect Search
installId = "E5323541-FA37-4f42-A64A-12A5B1B18BEA"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\ScriptHost.DLL
AppID = "{562B9316-C08A-444A-9482-62080DD851AE}"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Explorer\
Browser Helper Objects\{D26D85EB-E331-40D9-A4C5-FE975A11EC59}
NoExplorer = "1"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{D26D85EB-E331-40D9-A4C5-FE975A11EC59}\InprocServer32
ThreadingModel = "Apartment"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{39D4315D-D55B-431B-BF4B-97122C514BC7}\InprocServer32
ThreadingModel = "Apartment"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{7DFF2557-208E-4581-90D9-0B84D3DEC35A}\InprocServer32
ThreadingModel = "Apartment"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\ButtonSite.DLL
AppID = "{562B9317-C08A-444A-9482-62080DD851AE}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\RegistryHelper.DLL
AppID = "{544C2426-48FD-4C40-AE3B-31257FF334D0}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{A4341726-E922-47bb-86A6-23F4F4F67342}\InprocServer32
ThreadingModel = "Apartment"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{1917AB4C-E2E9-42ae-A51E-B5750F160BFB}\InprocServer32
ThreadingModel = "Apartment"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{1917AB4C-E2E9-42ae-A51E-B5750F160BFB}
AppID = "{544C2426-48FD-4C40-AE3B-31257FF334D0}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{E809EB5C-E1A2-4CD0-AF2B-705CB533F7B8}\TypeLib
Version = "1.0"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{B887CA3B-D82B-4A01-AD29-E97444D01CE6}\TypeLib
Version = "1.0"
作成活動
マルウェアは、以下のファイルを作成します。
- %User Temp%\nst3.tmp\System.dll
- %User Temp%\nst3.tmp\point1.bmp
- %User Temp%\nst3.tmp\point2.bmp
- %User Temp%\nst3.tmp\point3.bmp
- %User Temp%\nst3.tmp\chrome.bmp
- %User Temp%\nst3.tmp\ie9install.gif
- %User Temp%\nst3.tmp\license.txt
- %User Temp%\nst3.tmp\UserInfo.dll
- %User Temp%\nst3.tmp\UAC.dll
- %User Temp%\nst3.tmp\modern-header.bmp
- %User Temp%\nst3.tmp\modern-wizard.bmp
- %User Temp%\nst3.tmp\nsDialogs.dll
- %Program Files%\IntelliConnect Search\AddonsFramework.Typelib.dll
- %Program Files%\IntelliConnect Search\AddonsFramework.Typelib64.dll
- %Program Files%\IntelliConnect Search\BackgroundHost.exe
- %Program Files%\IntelliConnect Search\BackgroundHost64.exe
- %Program Files%\IntelliConnect Search\ButtonSite.dll
- %Program Files%\IntelliConnect Search\ButtonSite64.dll
- %Program Files%\IntelliConnect Search\CallWebService.exe
- %Program Files%\IntelliConnect Search\RegistryHelper.dll
- %Program Files%\IntelliConnect Search\RegistryHelper64.dll
- %Program Files%\IntelliConnect Search\ScriptHost.dll
- %Program Files%\IntelliConnect Search\ScriptHost64.dll
- %Program Files%\IntelliConnect Search\background.html
- %Program Files%\IntelliConnect Search\bg.js
- %Program Files%\IntelliConnect Search\browsers.js
- %Program Files%\IntelliConnect Search\config.xml
- %Program Files%\IntelliConnect Search\content.js
- %Program Files%\IntelliConnect Search\csp.js
- %Program Files%\IntelliConnect Search\icschrome.exe
- %Program Files%\IntelliConnect Search\intelliconnect.sendmessages.json
- %Program Files%\IntelliConnect Search\jquery-1.11.0.min.js
- %Program Files%\IntelliConnect Search\jquery-1.9.1.min.js
- %Program Files%\IntelliConnect Search\jquery.base64.js
- %Program Files%\IntelliConnect Search\jquery.browser.min.js
- %Program Files%\IntelliConnect Search\jquery.min.map
- %Program Files%\IntelliConnect Search\json2.min.js
- %Program Files%\IntelliConnect Search\manifest.json
- %Program Files%\IntelliConnect Search\postmessage.js
- %Program Files%\IntelliConnect Search\img\green-128.ico
- %Program Files%\IntelliConnect Search\img\green-128.png
- %Program Files%\IntelliConnect Search\img\green-16.ico
- %Program Files%\IntelliConnect Search\img\green-16.png
- %Program Files%\IntelliConnect Search\img\green-18.ico
- %Program Files%\IntelliConnect Search\img\green-18.png
- %Program Files%\IntelliConnect Search\img\green-2.png
- %Program Files%\IntelliConnect Search\img\green-24.png
- %Program Files%\IntelliConnect Search\img\green-48.ico
- %Program Files%\IntelliConnect Search\img\green-48.png
- %Program Files%\IntelliConnect Search\img\green2-128.png
- %Program Files%\IntelliConnect Search\img\green2-16.png
- %Program Files%\IntelliConnect Search\img\green2-18.png
- %Program Files%\IntelliConnect Search\img\green2-24.png
- %Program Files%\IntelliConnect Search\img\green2-48.png
- %Program Files%\IntelliConnect Search\img\large-red.png
- %Program Files%\IntelliConnect Search\img\red-128.png
- %Program Files%\IntelliConnect Search\img\red-16.png
- %Program Files%\IntelliConnect Search\img\red-18.png
- %Program Files%\IntelliConnect Search\img\red-24.png
- %Program Files%\IntelliConnect Search\img\red-48.png
- %Program Files%\IntelliConnect Search\img\right-red.png
- %Program Files%\IntelliConnect Search\img\toolbar icon v1.0.png
- %Program Files%\IntelliConnect Search\popup\intelliPopup.js
- %Program Files%\IntelliConnect Search\popup\jquery.modal.js
- %Program Files%\IntelliConnect Search\popup\popup.html
- %Program Files%\IntelliConnect Search\styles\cch.css
- %Program Files%\IntelliConnect Search\styles\menu.css
- %Program Files%\IntelliConnect Search\styles\popup.css
- %User Temp%\nst3.tmp\xml.dll
- %Program Files%\IntelliConnect Search\uninstall.exe
(註:%User Temp%フォルダは、ユーザの一時フォルダで、Windows 2000、XP および Server 2003 の場合、通常、"C:\Documents and Settings\<ユーザー名>\Local Settings\Temp"、Windows Vista 、 7 、8、8.1 、Server 2008 および Server 2012の場合、"C:\Users\<ユーザ名>\AppData\Local\Temp" です。.. %Program Files%フォルダは、プログラムファイルのフォルダで、いずれのオペレーティングシステム(OS)でも通常、 "C:\Program Files"、64bitのOS上で32bitのアプリケーションを実行している場合、 "C:\Program Files (x86)" です。.)
このウイルス情報は、自動解析システムにより作成されました。
対応方法
手順 1
Windows XP、Windows Vista および Windows 7 のユーザは、コンピュータからマルウェアもしくはアドウェア等を完全に削除するために、ウイルス検索の実行前には必ず「システムの復元」を無効にしてください。
手順 2
起動中ブラウザのウインドウを全て閉じてください。
手順 3
不明なレジストリキーを削除します。
警告:レジストリはWindowsの構成情報が格納されているデータベースであり、レジストリの編集内容に問題があると、システムが正常に動作しなくなる場合があります。
レジストリの編集はお客様の責任で行っていただくようお願いいたします。弊社ではレジストリの編集による如何なる問題に対しても補償いたしかねます。
レジストリの編集前にこちらをご参照ください。
- In HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\LowRegistry
- IntelliConnect
- In HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\LowRegistry
- IntelliConnect
- In HKEY_USERS\S-1-5-19_Classes\Software\Microsoft\Internet Explorer\LowRegistry
- IntelliConnect
- In HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\LowRegistry
- IntelliConnect
- In HKEY_USERS\S-1-5-20_Classes\Software\Microsoft\Internet Explorer\LowRegistry
- IntelliConnect
- In HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003\Software\Microsoft\Internet Explorer\LowRegistry
- IntelliConnect
- In HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003_Classes\Software\Microsoft\Internet Explorer\LowRegistry
- IntelliConnect
- In HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities
- Search Accelerator
- In HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator
- cch.com
- In HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com
- Action1
- In HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1
- execute
- In HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute
- Parameter1
- In HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute
- Parameter2
- In HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute
- Parameter3
- In HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute
- Parameter4
- In HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute
- Parameter5
- In HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com
- Action2
- In HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2
- execute
- In HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute
- Parameter1
- In HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute
- Parameter2
- In HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute
- Parameter3
- In HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute
- Parameter4
- In HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute
- Parameter5
- In HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities
- Search Accelerator
- In HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator
- cch.com
- In HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com
- Action1
- In HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1
- execute
- In HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute
- Parameter1
- In HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute
- Parameter2
- In HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute
- Parameter3
- In HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute
- Parameter4
- In HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute
- Parameter5
- In HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com
- Action2
- In HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2
- execute
- In HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute
- Parameter1
- In HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute
- Parameter2
- In HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute
- Parameter3
- In HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute
- Parameter4
- In HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute
- Parameter5
- In HKEY_USERS\S-1-5-19_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities
- Search Accelerator
- In HKEY_USERS\S-1-5-19_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator
- cch.com
- In HKEY_USERS\S-1-5-19_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com
- Action1
- In HKEY_USERS\S-1-5-19_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1
- execute
- In HKEY_USERS\S-1-5-19_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute
- Parameter1
- In HKEY_USERS\S-1-5-19_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute
- Parameter2
- In HKEY_USERS\S-1-5-19_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute
- Parameter3
- In HKEY_USERS\S-1-5-19_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute
- Parameter4
- In HKEY_USERS\S-1-5-19_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute
- Parameter5
- In HKEY_USERS\S-1-5-19_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com
- Action2
- In HKEY_USERS\S-1-5-19_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2
- execute
- In HKEY_USERS\S-1-5-19_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute
- Parameter1
- In HKEY_USERS\S-1-5-19_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute
- Parameter2
- In HKEY_USERS\S-1-5-19_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute
- Parameter3
- In HKEY_USERS\S-1-5-19_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute
- Parameter4
- In HKEY_USERS\S-1-5-19_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute
- Parameter5
- In HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities
- Search Accelerator
- In HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator
- cch.com
- In HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com
- Action1
- In HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1
- execute
- In HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute
- Parameter1
- In HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute
- Parameter2
- In HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute
- Parameter3
- In HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute
- Parameter4
- In HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute
- Parameter5
- In HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com
- Action2
- In HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2
- execute
- In HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute
- Parameter1
- In HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute
- Parameter2
- In HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute
- Parameter3
- In HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute
- Parameter4
- In HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute
- Parameter5
- In HKEY_USERS\S-1-5-20_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities
- Search Accelerator
- In HKEY_USERS\S-1-5-20_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator
- cch.com
- In HKEY_USERS\S-1-5-20_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com
- Action1
- In HKEY_USERS\S-1-5-20_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1
- execute
- In HKEY_USERS\S-1-5-20_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute
- Parameter1
- In HKEY_USERS\S-1-5-20_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute
- Parameter2
- In HKEY_USERS\S-1-5-20_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute
- Parameter3
- In HKEY_USERS\S-1-5-20_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute
- Parameter4
- In HKEY_USERS\S-1-5-20_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute
- Parameter5
- In HKEY_USERS\S-1-5-20_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com
- Action2
- In HKEY_USERS\S-1-5-20_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2
- execute
- In HKEY_USERS\S-1-5-20_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute
- Parameter1
- In HKEY_USERS\S-1-5-20_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute
- Parameter2
- In HKEY_USERS\S-1-5-20_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute
- Parameter3
- In HKEY_USERS\S-1-5-20_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute
- Parameter4
- In HKEY_USERS\S-1-5-20_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute
- Parameter5
- In HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities
- Search Accelerator
- In HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator
- cch.com
- In HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com
- Action1
- In HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1
- execute
- In HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute
- Parameter1
- In HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute
- Parameter2
- In HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute
- Parameter3
- In HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute
- Parameter4
- In HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute
- Parameter5
- In HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com
- Action2
- In HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2
- execute
- In HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute
- Parameter1
- In HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute
- Parameter2
- In HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute
- Parameter3
- In HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute
- Parameter4
- In HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute
- Parameter5
- In HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities
- Search Accelerator
- In HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator
- cch.com
- In HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com
- Action1
- In HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1
- execute
- In HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute
- Parameter1
- In HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute
- Parameter2
- In HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute
- Parameter3
- In HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute
- Parameter4
- In HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute
- Parameter5
- In HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com
- Action2
- In HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2
- execute
- In HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute
- Parameter1
- In HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute
- Parameter2
- In HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute
- Parameter3
- In HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute
- Parameter4
- In HKEY_USERS\S-1-5-21-1645522239-1292428093-682003330-1003_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute
- Parameter5
- In HKEY_LOCAL_MACHINE\Software\Google\Chrome\NativeMessagingHosts
- intelliconnect.sendmessages
- In HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall
- IntelliConnect Search
- In HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer
- MINIE
- In HKEY_CURRENT_USER\Software
- IntelliConnect Search
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy
- {83BC8A3A-5770-4b45-87A3-02D65C3076C3}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl
- FEATURE_BROWSER_EMULATION
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl
- FEATURE_WEBOC_MOVESIZECHILD
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID
- {18B9B16E-716F-43DF-A6AD-512C7D2EB983}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID
- BackgroundHost.EXE
- In HKEY_CLASSES_ROOT
- IntelliConnect Search.BackgroundHostObject.1
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IntelliConnect Search.BackgroundHostObject.1
- CLSID
- In HKEY_CLASSES_ROOT
- IntelliConnect Search.BackgroundHostObject
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IntelliConnect Search.BackgroundHostObject
- CLSID
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IntelliConnect Search.BackgroundHostObject
- CurVer
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
- {B1039E2E-E4AF-40A0-9094-81C031D14A22}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B1039E2E-E4AF-40A0-9094-81C031D14A22}
- ProgID
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B1039E2E-E4AF-40A0-9094-81C031D14A22}
- VersionIndependentProgID
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B1039E2E-E4AF-40A0-9094-81C031D14A22}
- Programmable
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B1039E2E-E4AF-40A0-9094-81C031D14A22}
- LocalServer32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B1039E2E-E4AF-40A0-9094-81C031D14A22}
- TypeLib
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib
- {450F902B-A690-4DB7-BD66-B77E525F75FD}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{450F902B-A690-4DB7-BD66-B77E525F75FD}
- 1.0
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{450F902B-A690-4DB7-BD66-B77E525F75FD}\1.0
- FLAGS
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{450F902B-A690-4DB7-BD66-B77E525F75FD}\1.0
- 0
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{450F902B-A690-4DB7-BD66-B77E525F75FD}\1.0\0
- win32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{450F902B-A690-4DB7-BD66-B77E525F75FD}\1.0
- HELPDIR
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
- {43969E3F-3E7C-4911-A8F1-79C6CA6AC731}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{43969E3F-3E7C-4911-A8F1-79C6CA6AC731}
- ProxyStubClsid
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{43969E3F-3E7C-4911-A8F1-79C6CA6AC731}
- ProxyStubClsid32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{43969E3F-3E7C-4911-A8F1-79C6CA6AC731}
- TypeLib
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID
- {19975B78-1907-4DD6-A437-4C48120F46A4}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID
- AddonsFramework.DLL
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib
- {0D30A607-2ACE-4028-AC3D-E78BDDF97EB8}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0D30A607-2ACE-4028-AC3D-E78BDDF97EB8}
- 1.0
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0D30A607-2ACE-4028-AC3D-E78BDDF97EB8}\1.0
- FLAGS
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0D30A607-2ACE-4028-AC3D-E78BDDF97EB8}\1.0
- 0
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0D30A607-2ACE-4028-AC3D-E78BDDF97EB8}\1.0\0
- win32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0D30A607-2ACE-4028-AC3D-E78BDDF97EB8}\1.0
- HELPDIR
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
- {94CADA2E-1D3F-419F-8A3D-06C58EDF53C8}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{94CADA2E-1D3F-419F-8A3D-06C58EDF53C8}
- ProxyStubClsid
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{94CADA2E-1D3F-419F-8A3D-06C58EDF53C8}
- ProxyStubClsid32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{94CADA2E-1D3F-419F-8A3D-06C58EDF53C8}
- TypeLib
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
- {C1995F88-1C7F-40D7-B0FA-6F107F6308B8}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C1995F88-1C7F-40D7-B0FA-6F107F6308B8}
- ProxyStubClsid
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C1995F88-1C7F-40D7-B0FA-6F107F6308B8}
- ProxyStubClsid32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C1995F88-1C7F-40D7-B0FA-6F107F6308B8}
- TypeLib
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
- {9E52EB8B-8DD9-4605-AD36-D352BCD482F2}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9E52EB8B-8DD9-4605-AD36-D352BCD482F2}
- ProxyStubClsid
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9E52EB8B-8DD9-4605-AD36-D352BCD482F2}
- ProxyStubClsid32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9E52EB8B-8DD9-4605-AD36-D352BCD482F2}
- TypeLib
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
- {A1440EC3-F0FA-407A-B811-DE6668C06D29}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A1440EC3-F0FA-407A-B811-DE6668C06D29}
- ProxyStubClsid
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A1440EC3-F0FA-407A-B811-DE6668C06D29}
- ProxyStubClsid32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A1440EC3-F0FA-407A-B811-DE6668C06D29}
- TypeLib
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
- {B9A84AD0-5777-46FD-8B8F-1EBD06750FBC}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B9A84AD0-5777-46FD-8B8F-1EBD06750FBC}
- ProxyStubClsid
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B9A84AD0-5777-46FD-8B8F-1EBD06750FBC}
- ProxyStubClsid32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B9A84AD0-5777-46FD-8B8F-1EBD06750FBC}
- TypeLib
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
- {395AFE6E-8308-48DB-89BE-ED5F4AA3D3EC}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{395AFE6E-8308-48DB-89BE-ED5F4AA3D3EC}
- ProxyStubClsid
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{395AFE6E-8308-48DB-89BE-ED5F4AA3D3EC}
- ProxyStubClsid32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{395AFE6E-8308-48DB-89BE-ED5F4AA3D3EC}
- TypeLib
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
- {045F91B3-695F-423A-98C7-8DE3C47AA020}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{045F91B3-695F-423A-98C7-8DE3C47AA020}
- ProxyStubClsid
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{045F91B3-695F-423A-98C7-8DE3C47AA020}
- ProxyStubClsid32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{045F91B3-695F-423A-98C7-8DE3C47AA020}
- TypeLib
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
- {BBBE01ED-0F1E-44DB-88C1-5CC1AEE3B462}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BBBE01ED-0F1E-44DB-88C1-5CC1AEE3B462}
- ProxyStubClsid
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BBBE01ED-0F1E-44DB-88C1-5CC1AEE3B462}
- ProxyStubClsid32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BBBE01ED-0F1E-44DB-88C1-5CC1AEE3B462}
- TypeLib
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
- {F9EB11AB-9384-4736-9B33-993940F88895}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F9EB11AB-9384-4736-9B33-993940F88895}
- ProxyStubClsid
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F9EB11AB-9384-4736-9B33-993940F88895}
- ProxyStubClsid32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F9EB11AB-9384-4736-9B33-993940F88895}
- TypeLib
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
- {43B390F0-6BA2-45CA-ABF2-5DB0CEE9B49D}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{43B390F0-6BA2-45CA-ABF2-5DB0CEE9B49D}
- ProxyStubClsid
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{43B390F0-6BA2-45CA-ABF2-5DB0CEE9B49D}
- ProxyStubClsid32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{43B390F0-6BA2-45CA-ABF2-5DB0CEE9B49D}
- TypeLib
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
- {E4A994B0-5550-4680-A4C6-B9470B888069}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E4A994B0-5550-4680-A4C6-B9470B888069}
- ProxyStubClsid
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E4A994B0-5550-4680-A4C6-B9470B888069}
- ProxyStubClsid32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E4A994B0-5550-4680-A4C6-B9470B888069}
- TypeLib
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
- {EE95078D-518C-4FD2-8093-FD1D4E33D3CA}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EE95078D-518C-4FD2-8093-FD1D4E33D3CA}
- ProxyStubClsid
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EE95078D-518C-4FD2-8093-FD1D4E33D3CA}
- ProxyStubClsid32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EE95078D-518C-4FD2-8093-FD1D4E33D3CA}
- TypeLib
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
- {C815E3DA-0823-49B0-9270-D1771D58B317}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C815E3DA-0823-49B0-9270-D1771D58B317}
- ProxyStubClsid
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C815E3DA-0823-49B0-9270-D1771D58B317}
- ProxyStubClsid32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C815E3DA-0823-49B0-9270-D1771D58B317}
- TypeLib
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
- {1348BD1B-C32A-41A7-9BD4-5377AA1AB925}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1348BD1B-C32A-41A7-9BD4-5377AA1AB925}
- ProxyStubClsid
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1348BD1B-C32A-41A7-9BD4-5377AA1AB925}
- ProxyStubClsid32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1348BD1B-C32A-41A7-9BD4-5377AA1AB925}
- TypeLib
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID
- {562B9316-C08A-444A-9482-62080DD851AE}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID
- ScriptHost.DLL
- In HKEY_CLASSES_ROOT
- IntelliConnect Search.ScriptHostObject.1
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IntelliConnect Search.ScriptHostObject.1
- CLSID
- In HKEY_CLASSES_ROOT
- IntelliConnect Search.ScriptHostObject
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IntelliConnect Search.ScriptHostObject
- CLSID
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IntelliConnect Search.ScriptHostObject
- CurVer
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
- {D26D85EB-E331-40D9-A4C5-FE975A11EC59}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D26D85EB-E331-40D9-A4C5-FE975A11EC59}
- ProgID
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D26D85EB-E331-40D9-A4C5-FE975A11EC59}
- VersionIndependentProgID
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D26D85EB-E331-40D9-A4C5-FE975A11EC59}
- Programmable
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D26D85EB-E331-40D9-A4C5-FE975A11EC59}
- InprocServer32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D26D85EB-E331-40D9-A4C5-FE975A11EC59}
- TypeLib
- In HKEY_CLASSES_ROOT
- IntelliConnect Search.Tool.1
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IntelliConnect Search.Tool.1
- CLSID
- In HKEY_CLASSES_ROOT
- IntelliConnect Search.Tool
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IntelliConnect Search.Tool
- CLSID
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IntelliConnect Search.Tool
- CurVer
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
- {39D4315D-D55B-431B-BF4B-97122C514BC7}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{39D4315D-D55B-431B-BF4B-97122C514BC7}
- ProgID
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{39D4315D-D55B-431B-BF4B-97122C514BC7}
- VersionIndependentProgID
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{39D4315D-D55B-431B-BF4B-97122C514BC7}
- Programmable
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{39D4315D-D55B-431B-BF4B-97122C514BC7}
- InprocServer32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{39D4315D-D55B-431B-BF4B-97122C514BC7}
- TypeLib
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib
- {3E8745A9-50B0-4099-AC2E-E29BC3D1ED2D}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{3E8745A9-50B0-4099-AC2E-E29BC3D1ED2D}
- 1.0
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{3E8745A9-50B0-4099-AC2E-E29BC3D1ED2D}\1.0
- FLAGS
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{3E8745A9-50B0-4099-AC2E-E29BC3D1ED2D}\1.0
- 0
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{3E8745A9-50B0-4099-AC2E-E29BC3D1ED2D}\1.0\0
- win32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{3E8745A9-50B0-4099-AC2E-E29BC3D1ED2D}\1.0
- HELPDIR
- In HKEY_CLASSES_ROOT
- IntelliConnect Search.Navbar.1
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IntelliConnect Search.Navbar.1
- CLSID
- In HKEY_CLASSES_ROOT
- IntelliConnect Search.Navbar
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IntelliConnect Search.Navbar
- CLSID
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IntelliConnect Search.Navbar
- CurVer
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
- {7DFF2557-208E-4581-90D9-0B84D3DEC35A}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7DFF2557-208E-4581-90D9-0B84D3DEC35A}
- ProgID
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7DFF2557-208E-4581-90D9-0B84D3DEC35A}
- VersionIndependentProgID
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7DFF2557-208E-4581-90D9-0B84D3DEC35A}
- Programmable
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7DFF2557-208E-4581-90D9-0B84D3DEC35A}
- InprocServer32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7DFF2557-208E-4581-90D9-0B84D3DEC35A}
- TypeLib
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID
- {562B9317-C08A-444A-9482-62080DD851AE}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID
- ButtonSite.DLL
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib
- {CB11C844-9744-482E-9CF4-AFF116F8618E}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{CB11C844-9744-482E-9CF4-AFF116F8618E}
- 1.0
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{CB11C844-9744-482E-9CF4-AFF116F8618E}\1.0
- FLAGS
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{CB11C844-9744-482E-9CF4-AFF116F8618E}\1.0
- 0
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{CB11C844-9744-482E-9CF4-AFF116F8618E}\1.0\0
- win32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{CB11C844-9744-482E-9CF4-AFF116F8618E}\1.0
- HELPDIR
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID
- {544C2426-48FD-4C40-AE3B-31257FF334D0}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID
- RegistryHelper.DLL
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
- {A4341726-E922-47bb-86A6-23F4F4F67342}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A4341726-E922-47bb-86A6-23F4F4F67342}
- InprocServer32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A4341726-E922-47bb-86A6-23F4F4F67342}
- TypeLib
- In HKEY_CLASSES_ROOT
- RegistryHelper.RegistryHelperObject.1
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\RegistryHelper.RegistryHelperObject.1
- CLSID
- In HKEY_CLASSES_ROOT
- RegistryHelper.RegistryHelperObject
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\RegistryHelper.RegistryHelperObject
- CLSID
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\RegistryHelper.RegistryHelperObject
- CurVer
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
- {1917AB4C-E2E9-42ae-A51E-B5750F160BFB}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1917AB4C-E2E9-42ae-A51E-B5750F160BFB}
- ProgID
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1917AB4C-E2E9-42ae-A51E-B5750F160BFB}
- VersionIndependentProgID
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1917AB4C-E2E9-42ae-A51E-B5750F160BFB}
- Programmable
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1917AB4C-E2E9-42ae-A51E-B5750F160BFB}
- Implemented Categories
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1917AB4C-E2E9-42ae-A51E-B5750F160BFB}\Implemented Categories
- {7DD95801-9882-11CF-9FA9-00AA006C42C4}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1917AB4C-E2E9-42ae-A51E-B5750F160BFB}\Implemented Categories
- {7DD95802-9882-11CF-9FA9-00AA006C42C4}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1917AB4C-E2E9-42ae-A51E-B5750F160BFB}
- InprocServer32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1917AB4C-E2E9-42ae-A51E-B5750F160BFB}
- TypeLib
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib
- {567A1ED0-A437-401F-9D84-A2B19CD697B5}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{567A1ED0-A437-401F-9D84-A2B19CD697B5}
- 1.0
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{567A1ED0-A437-401F-9D84-A2B19CD697B5}\1.0
- FLAGS
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{567A1ED0-A437-401F-9D84-A2B19CD697B5}\1.0
- 0
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{567A1ED0-A437-401F-9D84-A2B19CD697B5}\1.0\0
- win32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{567A1ED0-A437-401F-9D84-A2B19CD697B5}\1.0
- HELPDIR
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
- {E809EB5C-E1A2-4CD0-AF2B-705CB533F7B8}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E809EB5C-E1A2-4CD0-AF2B-705CB533F7B8}
- ProxyStubClsid
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E809EB5C-E1A2-4CD0-AF2B-705CB533F7B8}
- ProxyStubClsid32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E809EB5C-E1A2-4CD0-AF2B-705CB533F7B8}
- TypeLib
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
- {B887CA3B-D82B-4A01-AD29-E97444D01CE6}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B887CA3B-D82B-4A01-AD29-E97444D01CE6}
- ProxyStubClsid
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B887CA3B-D82B-4A01-AD29-E97444D01CE6}
- ProxyStubClsid32
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B887CA3B-D82B-4A01-AD29-E97444D01CE6}
- TypeLib
手順 4
このレジストリ値を削除します。
警告:レジストリはWindowsの構成情報が格納されているデータベースであり、レジストリの編集内容に問題があると、システムが正常に動作しなくなる場合があります。
レジストリの編集はお客様の責任で行っていただくようお願いいたします。弊社ではレジストリの編集による如何なる問題に対しても補償いたしかねます。
レジストリの編集前にこちらをご参照ください。
- In HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\IntelliConnect
- Version = "1.0.10.29"
- In HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\IntelliConnect
- InstallUpdate = "msie;chrome;firefox"
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator
- DefaultActivity = "cch.com"
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com
- Description = "Find Friends on google."
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com
- HomepageURL = "http://{BLOCKED}h.com"
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com
- Domain = "cch.com"
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com
- Verb = "Search Accelerator"
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com
- DisplayName = "Search with IntelliConnect"
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com
- Type = "1"
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com
- Enabled = "1"
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com
- Deleted = "0"
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com
- ActionCount = "2"
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com
- ContentMask = "6"
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com
- Icon = "%Program Files%\IntelliConnect Search\img\green-16.ico"
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1
- Context = "selection"
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1
- HasPreview = "0"
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute
- Action = "https://{BLOCKED}hconnect.{BLOCKED}h.com/icsearch/SearchRedirect.aspx"
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute
- Method = "get"
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute
- Enctype = "application/x-www-form-urlencoded"
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute
- Accept-charset = "utf-8"
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute
- ParamCount = "5"
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute\Parameter1
- Name = "userid"
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute\Parameter2
- Name = "env"
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute\Parameter2
- Value = "prod"
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute\Parameter3
- Name = "searchtype"
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute\Parameter3
- Value = "context"
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute\Parameter4
- Name = "version"
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute\Parameter4
- Value = "1.0.10.29"
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute\Parameter5
- Name = "query"
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action1\execute\Parameter5
- Value = "{selection}"
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2
- Context = "link"
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2
- HasPreview = "0"
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute
- Action = "https://{BLOCKED}hconnect.{BLOCKED}h.com/icsearch/SearchRedirect.aspx"
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute
- Method = "get"
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute
- Enctype = "application/x-www-form-urlencoded"
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute
- Accept-charset = "utf-8"
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute
- ParamCount = "5"
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute\Parameter1
- Name = "userid"
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute\Parameter2
- Name = "env"
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute\Parameter2
- Value = "prod"
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute\Parameter3
- Name = "searchtype"
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute\Parameter3
- Value = "context"
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute\Parameter4
- Name = "version"
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute\Parameter4
- Value = "1.0.10.29"
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute\Parameter5
- Name = "query"
- In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search Accelerator\cch.com\Action2\execute\Parameter5
- Value = "{linkText}"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IntelliConnect Search
- DisplayName = "IntelliConnect® Search"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IntelliConnect Search
- UninstallString = "%Program Files%\IntelliConnect Search\uninstall.exe"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IntelliConnect Search
- DisplayVersion = "1.0.10.29"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IntelliConnect Search
- Publisher = "Wolters Kluwer"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IntelliConnect Search
- URLInfoAbout = "https://intelliconnect.{BLOCKED}h.com"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IntelliConnect Search
- DisplayIcon = "%Program Files%\IntelliConnect Search\uninstall.exe"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IntelliConnect Search
- InstDir = "%Program Files%\IntelliConnect Search"
- In HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MINIE
- CommandBarEnabled = "1"
- In HKEY_CURRENT_USER\Software\IntelliConnect Search
- elevationPolicyGuid = "{83BC8A3A-5770-4b45-87A3-02D65C3076C3}"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{83BC8A3A-5770-4b45-87A3-02D65C3076C3}
- Policy = "3"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{83BC8A3A-5770-4b45-87A3-02D65C3076C3}
- AppPath = "%Program Files%\IntelliConnect Search"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{83BC8A3A-5770-4b45-87A3-02D65C3076C3}
- AppName = "BackgroundHost.exe"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_MOVESIZECHILD
- BackgroundHost.exe = "1"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\BackgroundHost.EXE
- AppID = "{18B9B16E-716F-43DF-A6AD-512C7D2EB983}"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{43969E3F-3E7C-4911-A8F1-79C6CA6AC731}\TypeLib
- Version = "1.0"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\AddonsFramework.DLL
- AppID = "{19975B78-1907-4DD6-A437-4C48120F46A4}"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{94CADA2E-1D3F-419F-8A3D-06C58EDF53C8}\TypeLib
- Version = "1.0"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C1995F88-1C7F-40D7-B0FA-6F107F6308B8}\TypeLib
- Version = "1.0"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9E52EB8B-8DD9-4605-AD36-D352BCD482F2}\TypeLib
- Version = "1.0"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A1440EC3-F0FA-407A-B811-DE6668C06D29}\TypeLib
- Version = "1.0"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B9A84AD0-5777-46FD-8B8F-1EBD06750FBC}\TypeLib
- Version = "1.0"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{395AFE6E-8308-48DB-89BE-ED5F4AA3D3EC}\TypeLib
- Version = "1.0"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{045F91B3-695F-423A-98C7-8DE3C47AA020}\TypeLib
- Version = "1.0"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BBBE01ED-0F1E-44DB-88C1-5CC1AEE3B462}\TypeLib
- Version = "1.0"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F9EB11AB-9384-4736-9B33-993940F88895}\TypeLib
- Version = "1.0"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{43B390F0-6BA2-45CA-ABF2-5DB0CEE9B49D}\TypeLib
- Version = "1.0"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E4A994B0-5550-4680-A4C6-B9470B888069}\TypeLib
- Version = "1.0"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EE95078D-518C-4FD2-8093-FD1D4E33D3CA}\TypeLib
- Version = "1.0"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C815E3DA-0823-49B0-9270-D1771D58B317}\TypeLib
- Version = "1.0"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1348BD1B-C32A-41A7-9BD4-5377AA1AB925}\TypeLib
- Version = "1.0"
- In HKEY_CURRENT_USER\Software\IntelliConnect Search
- installId = "E5323541-FA37-4f42-A64A-12A5B1B18BEA"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\ScriptHost.DLL
- AppID = "{562B9316-C08A-444A-9482-62080DD851AE}"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D26D85EB-E331-40D9-A4C5-FE975A11EC59}
- NoExplorer = "1"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D26D85EB-E331-40D9-A4C5-FE975A11EC59}\InprocServer32
- ThreadingModel = "Apartment"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{39D4315D-D55B-431B-BF4B-97122C514BC7}\InprocServer32
- ThreadingModel = "Apartment"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7DFF2557-208E-4581-90D9-0B84D3DEC35A}\InprocServer32
- ThreadingModel = "Apartment"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\ButtonSite.DLL
- AppID = "{562B9317-C08A-444A-9482-62080DD851AE}"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\RegistryHelper.DLL
- AppID = "{544C2426-48FD-4C40-AE3B-31257FF334D0}"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A4341726-E922-47bb-86A6-23F4F4F67342}\InprocServer32
- ThreadingModel = "Apartment"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1917AB4C-E2E9-42ae-A51E-B5750F160BFB}\InprocServer32
- ThreadingModel = "Apartment"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1917AB4C-E2E9-42ae-A51E-B5750F160BFB}
- AppID = "{544C2426-48FD-4C40-AE3B-31257FF334D0}"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E809EB5C-E1A2-4CD0-AF2B-705CB533F7B8}\TypeLib
- Version = "1.0"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B887CA3B-D82B-4A01-AD29-E97444D01CE6}\TypeLib
- Version = "1.0"
手順 5
以下のファイルを検索し削除します。
- %User Temp%\nst3.tmp\System.dll
- %User Temp%\nst3.tmp\point1.bmp
- %User Temp%\nst3.tmp\point2.bmp
- %User Temp%\nst3.tmp\point3.bmp
- %User Temp%\nst3.tmp\chrome.bmp
- %User Temp%\nst3.tmp\ie9install.gif
- %User Temp%\nst3.tmp\license.txt
- %User Temp%\nst3.tmp\UserInfo.dll
- %User Temp%\nst3.tmp\UAC.dll
- %User Temp%\nst3.tmp\modern-header.bmp
- %User Temp%\nst3.tmp\modern-wizard.bmp
- %User Temp%\nst3.tmp\nsDialogs.dll
- %Program Files%\IntelliConnect Search\AddonsFramework.Typelib.dll
- %Program Files%\IntelliConnect Search\AddonsFramework.Typelib64.dll
- %Program Files%\IntelliConnect Search\BackgroundHost.exe
- %Program Files%\IntelliConnect Search\BackgroundHost64.exe
- %Program Files%\IntelliConnect Search\ButtonSite.dll
- %Program Files%\IntelliConnect Search\ButtonSite64.dll
- %Program Files%\IntelliConnect Search\CallWebService.exe
- %Program Files%\IntelliConnect Search\RegistryHelper.dll
- %Program Files%\IntelliConnect Search\RegistryHelper64.dll
- %Program Files%\IntelliConnect Search\ScriptHost.dll
- %Program Files%\IntelliConnect Search\ScriptHost64.dll
- %Program Files%\IntelliConnect Search\background.html
- %Program Files%\IntelliConnect Search\bg.js
- %Program Files%\IntelliConnect Search\browsers.js
- %Program Files%\IntelliConnect Search\config.xml
- %Program Files%\IntelliConnect Search\content.js
- %Program Files%\IntelliConnect Search\csp.js
- %Program Files%\IntelliConnect Search\icschrome.exe
- %Program Files%\IntelliConnect Search\intelliconnect.sendmessages.json
- %Program Files%\IntelliConnect Search\jquery-1.11.0.min.js
- %Program Files%\IntelliConnect Search\jquery-1.9.1.min.js
- %Program Files%\IntelliConnect Search\jquery.base64.js
- %Program Files%\IntelliConnect Search\jquery.browser.min.js
- %Program Files%\IntelliConnect Search\jquery.min.map
- %Program Files%\IntelliConnect Search\json2.min.js
- %Program Files%\IntelliConnect Search\manifest.json
- %Program Files%\IntelliConnect Search\postmessage.js
- %Program Files%\IntelliConnect Search\img\green-128.ico
- %Program Files%\IntelliConnect Search\img\green-128.png
- %Program Files%\IntelliConnect Search\img\green-16.ico
- %Program Files%\IntelliConnect Search\img\green-16.png
- %Program Files%\IntelliConnect Search\img\green-18.ico
- %Program Files%\IntelliConnect Search\img\green-18.png
- %Program Files%\IntelliConnect Search\img\green-2.png
- %Program Files%\IntelliConnect Search\img\green-24.png
- %Program Files%\IntelliConnect Search\img\green-48.ico
- %Program Files%\IntelliConnect Search\img\green-48.png
- %Program Files%\IntelliConnect Search\img\green2-128.png
- %Program Files%\IntelliConnect Search\img\green2-16.png
- %Program Files%\IntelliConnect Search\img\green2-18.png
- %Program Files%\IntelliConnect Search\img\green2-24.png
- %Program Files%\IntelliConnect Search\img\green2-48.png
- %Program Files%\IntelliConnect Search\img\large-red.png
- %Program Files%\IntelliConnect Search\img\red-128.png
- %Program Files%\IntelliConnect Search\img\red-16.png
- %Program Files%\IntelliConnect Search\img\red-18.png
- %Program Files%\IntelliConnect Search\img\red-24.png
- %Program Files%\IntelliConnect Search\img\red-48.png
- %Program Files%\IntelliConnect Search\img\right-red.png
- %Program Files%\IntelliConnect Search\img\toolbar icon v1.0.png
- %Program Files%\IntelliConnect Search\popup\intelliPopup.js
- %Program Files%\IntelliConnect Search\popup\jquery.modal.js
- %Program Files%\IntelliConnect Search\popup\popup.html
- %Program Files%\IntelliConnect Search\styles\cch.css
- %Program Files%\IntelliConnect Search\styles\menu.css
- %Program Files%\IntelliConnect Search\styles\popup.css
- %User Temp%\nst3.tmp\xml.dll
- %Program Files%\IntelliConnect Search\uninstall.exe
手順 6
以下のフォルダを検索し削除します。
- %System Root%\DOCUME~1
- %System Root%\DOCUME~1\Wilbert
- %User Profile%\LOCALS~1
- %User Temp%\nst3.tmp
- %Program Files%\IntelliConnect Search
- %Program Files%\IntelliConnect Search\img
- %Program Files%\IntelliConnect Search\popup
- %Program Files%\IntelliConnect Search\styles
手順 7
最新のバージョン(エンジン、パターンファイル)を導入したウイルス対策製品を用い、ウイルス検索を実行してください。「PUA_Besttoolbars」と検出したファイルはすべて削除してください。 検出されたファイルが、弊社ウイルス対策製品により既に駆除、隔離またはファイル削除の処理が実行された場合、ウイルスの処理は完了しており、他の削除手順は特にありません。
手順 8
以下のファイルをバックアップを用いて修復します。なお、マイクロソフト製品に関連したファイルのみ修復されます。このマルウェア/グレイウェア/スパイウェアが同社製品以外のプログラムをも削除した場合には、該当プログラムを再度インストールする必要があります。
- %User Temp%\nsy1.tmp
- %User Temp%\nst3.tmp
- %User Temp%\nst3.tmp\help_page.ini
ご利用はいかがでしたか? アンケートにご協力ください