Trend Micro Security

TROJ_BANBRA.WWO

2014年11月6日

 別名:

PUA.Gen.2 (Symantec); Trojan-Banker.Win32.Banbra.bhqq (Kaspersky); Trojan.Win32.Generic!BT (Sunbelt); Trojan horse Proxy.BEUS (AVG)

 プラットフォーム:

Windows

 危険度:
 ダメージ度:
 感染力:
 感染確認数:


  • マルウェアタイプ: トロイの木馬型
  • 破壊活動の有無: なし
  • 暗号化:  
  • 感染報告の有無: はい

  概要


マルウェアは、他のマルウェアに作成されるか、悪意あるWebサイトからユーザが誤ってダウンロードすることによりコンピュータに侵入します。


  詳細

ファイルサイズ 505,856 bytes
タイプ EXE
メモリ常駐 はい
発見日 2014年11月6日

侵入方法

マルウェアは、他のマルウェアに作成されるか、悪意あるWebサイトからユーザが誤ってダウンロードすることによりコンピュータに侵入します。

インストール

マルウェアは、以下のフォルダを作成します。

  • %Program Files%\GUM2.tmp
  • %Application Data%\Google
  • %Application Data%\Google\CrashReports
  • %Program Files%\Google
  • %Program Files%\Google\CrashReports
  • %Program Files%\Google\Update
  • %Program Files%\Google\Update\1.3.21.165
  • %Program Files%\Google\Update\Offline
  • %Program Files%\Google\Update\Offline\{5E76E45C-A5D5-4C8D-AF56-6A88291554A0}
  • %Program Files%\Google\Update\Download
  • %Program Files%\Google\Update\Install

(註:%Program Files%フォルダは、Windows 2000、Server 2003、XP (32ビット)、通常 Vista (32ビット) および 7 (32ビット) の場合、通常 "C:\Program Files"、Windows XP (64ビット)、Vista (64ビット) および 7 (64ビット) の場合、通常 "C:\Program Files (x86)" です。. %Application Data%フォルダは、Windows 2000、XP および Server 2003 の場合、通常 "C:\Documents and Settings\<ユーザ名>\Local Settings\Application Data"、Windows Vista および 7 の場合、"C:\Users\<ユーザ名>\AppData\Roaming" です。)

他のシステム変更

マルウェアは、以下のファイルを削除します。

  • %Program Files%\GUM2.tmp
  • %Program Files%\GUT5.tmp
  • %Windows%\Tasks\GoogleUpdateTask.job
  • %Windows%\Tasks\GoogleUpdateTaskMachine.job

(註:%Program Files%フォルダは、Windows 2000、Server 2003、XP (32ビット)、通常 Vista (32ビット) および 7 (32ビット) の場合、通常 "C:\Program Files"、Windows XP (64ビット)、Vista (64ビット) および 7 (64ビット) の場合、通常 "C:\Program Files (x86)" です。. %Windows%フォルダはWindowsの種類とインストール時の設定などにより異なります。標準設定では、"C:\Windows" です。)

マルウェアは、以下のレジストリキーを追加します。

HKEY_LOCAL_MACHINE\Software\Google\
Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}

HKEY_LOCAL_MACHINE\Software\Google\
Update\network

HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Update\network\secure

HKEY_LOCAL_MACHINE\Software\Google\
Update\Clients

HKEY_LOCAL_MACHINE\Software\Google\
Update\Clients\{430FD4D0-B729-4F61-AA34-91526481799D}

HKEY_LOCAL_MACHINE\Software\Google\
Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}

HKEY_LOCAL_MACHINE\Software\Google\
Update\ClientStateMedium

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows NT\CurrentVersion\Image File Execution Options\
GoogleUpdate.exe

HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\
@tools.google.com/Google Update;version=9

HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\
@tools.google.com/Google Update;version=9\MimeTypes

HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\
@tools.google.com/Google Update;version=9\MimeTypes\application/x-vnd.google.oneclickctrl.9

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Ext

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Ext\
PreApproved

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Ext\
PreApproved\{C442AC41-9200-4770-8CC0-7CDB4F245C55}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Ext\
Stats

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Ext\
Stats\{C442AC41-9200-4770-8CC0-7CDB4F245C55}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Ext\
Stats\{C442AC41-9200-4770-8CC0-7CDB4F245C55}\iexplore

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Ext\
Stats\{C442AC41-9200-4770-8CC0-7CDB4F245C55}\iexplore\
AllowedDomains

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Ext\
Stats\{C442AC41-9200-4770-8CC0-7CDB4F245C55}\iexplore\
AllowedDomains\*

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Internet Explorer\Low Rights\ElevationPolicy\
{C442AC41-9200-4770-8CC0-7CDB4F245C55}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Google.OneClickCtrl.9

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Google.OneClickCtrl.9\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{C442AC41-9200-4770-8CC0-7CDB4F245C55}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{C442AC41-9200-4770-8CC0-7CDB4F245C55}\ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{C442AC41-9200-4770-8CC0-7CDB4F245C55}\InprocServer32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{C442AC41-9200-4770-8CC0-7CDB4F245C55}\Implemented Categories

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{C442AC41-9200-4770-8CC0-7CDB4F245C55}\Implemented Categories\
{59FB2056-D625-48D0-A944-1A85B5AB2640}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
MIME\Database\Content Type\
application/x-vnd.google.oneclickctrl.9

HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\
@tools.google.com/Google Update;version=3

HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\
@tools.google.com/Google Update;version=3\MimeTypes

HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\
@tools.google.com/Google Update;version=3\MimeTypes\application/x-vnd.google.update3webcontrol.3

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Ext\
PreApproved\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Ext\
Stats\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Ext\
Stats\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}\iexplore

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Ext\
Stats\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}\iexplore\
AllowedDomains

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Ext\
Stats\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}\iexplore\
AllowedDomains\*

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Internet Explorer\Low Rights\ElevationPolicy\
{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Google.Update3WebControl.3

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Google.Update3WebControl.3\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}\ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}\InprocServer32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}\Implemented Categories

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}\Implemented Categories\
{59FB2056-D625-48D0-A944-1A85B5AB2640}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
MIME\Database\Content Type\
application/x-vnd.google.update3webcontrol.3

HKEY_LOCAL_MACHINE\Software\Google\
Update\uid

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{4EB61BAC-A3B6-4760-9581-655041EF4D69}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\GoogleUpdate.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.Update3COMClassService.1.0

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.Update3COMClassService.1.0\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.Update3COMClassService

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.Update3COMClassService\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.Update3COMClassService\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{4EB61BAC-A3B6-4760-9581-655041EF4D69}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{4EB61BAC-A3B6-4760-9581-655041EF4D69}\ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{4EB61BAC-A3B6-4760-9581-655041EF4D69}\VersionIndependentProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{9465B4B4-5216-4042-9A2C-754D3BCDC410}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.OnDemandCOMClassSvc.1.0

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.OnDemandCOMClassSvc.1.0\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.OnDemandCOMClassSvc

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.OnDemandCOMClassSvc\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.OnDemandCOMClassSvc\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{9465B4B4-5216-4042-9A2C-754D3BCDC410}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{9465B4B4-5216-4042-9A2C-754D3BCDC410}\ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{9465B4B4-5216-4042-9A2C-754D3BCDC410}\VersionIndependentProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.Update3WebSvc.1.0

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.Update3WebSvc.1.0\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.Update3WebSvc

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.Update3WebSvc\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.Update3WebSvc\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{534F5323-3569-4F42-919D-1E1CF93E5BF6}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{534F5323-3569-4F42-919D-1E1CF93E5BF6}\ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{534F5323-3569-4F42-919D-1E1CF93E5BF6}\VersionIndependentProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.CoreClass.1

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.CoreClass.1\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.CoreClass

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.CoreClass\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.CoreClass\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{E225E692-4B47-4777-9BED-4FD7FE257F0E}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{E225E692-4B47-4777-9BED-4FD7FE257F0E}\ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{E225E692-4B47-4777-9BED-4FD7FE257F0E}\VersionIndependentProgID

HKEY_LOCAL_MACHINE\Software\Google\
Update\UsageStats\Daily

HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Update\UsageStats\Daily\
Counts

HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Update\UsageStats\Daily\
Integers

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{50AC8ACB-D28F-4082-A1BC-C04054B5A5AC}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{50AC8ACB-D28F-4082-A1BC-C04054B5A5AC}\InprocHandler32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{9D6AA569-9F30-41AD-885A-346685C74928}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{9D6AA569-9F30-41AD-885A-346685C74928}\InprocServer32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{D0CD6E57-FBA5-4F71-98DF-3AAEB8CB8118}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{D0CD6E57-FBA5-4F71-98DF-3AAEB8CB8118}\InProcServer32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{2E629606-312A-482F-9B12-2C4ABF6F0B6D}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{2E629606-312A-482F-9B12-2C4ABF6F0B6D}\ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{2E629606-312A-482F-9B12-2C4ABF6F0B6D}\NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{31AC3F11-E5EA-4A85-8A3D-8E095A39C27B}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{31AC3F11-E5EA-4A85-8A3D-8E095A39C27B}\ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{31AC3F11-E5EA-4A85-8A3D-8E095A39C27B}\NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{8476CE12-AE1F-4198-805C-BA0F9B783F57}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{8476CE12-AE1F-4198-805C-BA0F9B783F57}\ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{8476CE12-AE1F-4198-805C-BA0F9B783F57}\NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{0CD01D1E-4A1C-489D-93B9-9B6672877C57}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{0CD01D1E-4A1C-489D-93B9-9B6672877C57}\ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{0CD01D1E-4A1C-489D-93B9-9B6672877C57}\NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{4E223325-C16B-4EEB-AEDC-19AA99A237FA}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{4E223325-C16B-4EEB-AEDC-19AA99A237FA}\ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{4E223325-C16B-4EEB-AEDC-19AA99A237FA}\NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{BCDCB538-01C0-46D1-A6A7-52F4D021C272}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{BCDCB538-01C0-46D1-A6A7-52F4D021C272}\ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{BCDCB538-01C0-46D1-A6A7-52F4D021C272}\NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{49D7563B-2DDB-4831-88C8-768A53833837}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{49D7563B-2DDB-4831-88C8-768A53833837}\ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{49D7563B-2DDB-4831-88C8-768A53833837}\NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{DAB1D343-1B2A-47F9-B445-93DC50704BFE}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{DAB1D343-1B2A-47F9-B445-93DC50704BFE}\ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{DAB1D343-1B2A-47F9-B445-93DC50704BFE}\NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{3D05F64F-71E3-48A5-BF6B-83315BC8AE1F}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{3D05F64F-71E3-48A5-BF6B-83315BC8AE1F}\ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{3D05F64F-71E3-48A5-BF6B-83315BC8AE1F}\NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{6DB17455-4E85-46E7-9D23-E555E4B005AF}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{6DB17455-4E85-46E7-9D23-E555E4B005AF}\ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{6DB17455-4E85-46E7-9D23-E555E4B005AF}\NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{DD42475D-6D46-496A-924E-BD5630B4CBBA}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{DD42475D-6D46-496A-924E-BD5630B4CBBA}\ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{DD42475D-6D46-496A-924E-BD5630B4CBBA}\NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{D106AB5F-A70E-400E-A21B-96208C1D8DBB}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{D106AB5F-A70E-400E-A21B-96208C1D8DBB}\ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{D106AB5F-A70E-400E-A21B-96208C1D8DBB}\NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{B3A47570-0A85-4AEA-8270-529D47899603}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{B3A47570-0A85-4AEA-8270-529D47899603}\ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{B3A47570-0A85-4AEA-8270-529D47899603}\NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{18D0F672-18B4-48E6-AD36-6E6BF01DBBC4}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{18D0F672-18B4-48E6-AD36-6E6BF01DBBC4}\ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{18D0F672-18B4-48E6-AD36-6E6BF01DBBC4}\NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{2D363682-561D-4C3A-81C6-F2F82107562A}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{2D363682-561D-4C3A-81C6-F2F82107562A}\ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{2D363682-561D-4C3A-81C6-F2F82107562A}\NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{DCAB8386-4F03-4DBD-A366-D90BC9F68DE6}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{DCAB8386-4F03-4DBD-A366-D90BC9F68DE6}\ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{DCAB8386-4F03-4DBD-A366-D90BC9F68DE6}\NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{76F7B787-A67C-4C73-82C7-31F5E3AABC5C}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{76F7B787-A67C-4C73-82C7-31F5E3AABC5C}\ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{76F7B787-A67C-4C73-82C7-31F5E3AABC5C}\NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{128C2DA6-2BC0-44C0-B3F6-4EC22E647964}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{128C2DA6-2BC0-44C0-B3F6-4EC22E647964}\ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{128C2DA6-2BC0-44C0-B3F6-4EC22E647964}\NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{084D78A8-B084-4E14-A629-A2C419B0E3D9}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{084D78A8-B084-4E14-A629-A2C419B0E3D9}\ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{084D78A8-B084-4E14-A629-A2C419B0E3D9}\NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{909489C2-85A6-4322-AA56-D25278649D67}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{909489C2-85A6-4322-AA56-D25278649D67}\ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{909489C2-85A6-4322-AA56-D25278649D67}\NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{494B20CF-282E-4BDD-9F5D-B70CB09D351E}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{494B20CF-282E-4BDD-9F5D-B70CB09D351E}\ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{494B20CF-282E-4BDD-9F5D-B70CB09D351E}\NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{5B25A8DC-1780-4178-A629-6BE8B8DEFAA2}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{5B25A8DC-1780-4178-A629-6BE8B8DEFAA2}\ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{5B25A8DC-1780-4178-A629-6BE8B8DEFAA2}\NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{FE908CDD-22BB-472A-9870-1A0390E42F36}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{FE908CDD-22BB-472A-9870-1A0390E42F36}\ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{FE908CDD-22BB-472A-9870-1A0390E42F36}\NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{1C642CED-CA3B-4013-A9DF-CA6CE5FF6503}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{1C642CED-CA3B-4013-A9DF-CA6CE5FF6503}\ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{1C642CED-CA3B-4013-A9DF-CA6CE5FF6503}\NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{5CCCB0EF-7073-4516-8028-4C628D0C8AAB}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{5CCCB0EF-7073-4516-8028-4C628D0C8AAB}\ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{5CCCB0EF-7073-4516-8028-4C628D0C8AAB}\NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{247954F9-9EDC-4E68-8CC3-150C2B89EADF}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{247954F9-9EDC-4E68-8CC3-150C2B89EADF}\ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{247954F9-9EDC-4E68-8CC3-150C2B89EADF}\NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{4DE778FE-F195-4EE3-9DAB-FE446C239221}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{4DE778FE-F195-4EE3-9DAB-FE446C239221}\ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{4DE778FE-F195-4EE3-9DAB-FE446C239221}\NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.OnDemandCOMClassMachine.1.0

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.OnDemandCOMClassMachine.1.0\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.OnDemandCOMClassMachine

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.OnDemandCOMClassMachine\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.OnDemandCOMClassMachine\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{6F8BD55B-E83D-4A47-85BE-81FFA8057A69}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{6F8BD55B-E83D-4A47-85BE-81FFA8057A69}\ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{6F8BD55B-E83D-4A47-85BE-81FFA8057A69}\VersionIndependentProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{6F8BD55B-E83D-4A47-85BE-81FFA8057A69}\LocalServer32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{6F8BD55B-E83D-4A47-85BE-81FFA8057A69}\Elevation

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.Update3WebMachine.1.0

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.Update3WebMachine.1.0\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.Update3WebMachine

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.Update3WebMachine\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.Update3WebMachine\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{8A1D4361-2C08-4700-A351-3EAA9CBFF5E4}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{8A1D4361-2C08-4700-A351-3EAA9CBFF5E4}\ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{8A1D4361-2C08-4700-A351-3EAA9CBFF5E4}\VersionIndependentProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{8A1D4361-2C08-4700-A351-3EAA9CBFF5E4}\LocalServer32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{8A1D4361-2C08-4700-A351-3EAA9CBFF5E4}\Elevation

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.CoCreateAsync.1.0

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.CoCreateAsync.1.0\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.CoCreateAsync

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.CoCreateAsync\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.CoCreateAsync\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{7DE94008-8AFD-4C70-9728-C6FBFFF6A73E}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{7DE94008-8AFD-4C70-9728-C6FBFFF6A73E}\ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{7DE94008-8AFD-4C70-9728-C6FBFFF6A73E}\VersionIndependentProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{7DE94008-8AFD-4C70-9728-C6FBFFF6A73E}\LocalServer32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Google.OneClickProcessLauncherMachine.1.0

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Google.OneClickProcessLauncherMachine.1.0\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Google.OneClickProcessLauncherMachine

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Google.OneClickProcessLauncherMachine\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Google.OneClickProcessLauncherMachine\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{AAD4AE2E-D834-46D4-8B09-490FAC9C722B}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{AAD4AE2E-D834-46D4-8B09-490FAC9C722B}\ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{AAD4AE2E-D834-46D4-8B09-490FAC9C722B}\VersionIndependentProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{AAD4AE2E-D834-46D4-8B09-490FAC9C722B}\LocalServer32

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Internet Explorer\Low Rights\ElevationPolicy\
{AAD4AE2E-D834-46D4-8B09-490FAC9C722B}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.ProcessLauncher.1.0

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.ProcessLauncher.1.0\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.ProcessLauncher

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.ProcessLauncher\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.ProcessLauncher\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{ABC01078-F197-4B0B-ADBC-CFE684B39C82}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{ABC01078-F197-4B0B-ADBC-CFE684B39C82}\ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{ABC01078-F197-4B0B-ADBC-CFE684B39C82}\VersionIndependentProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{ABC01078-F197-4B0B-ADBC-CFE684B39C82}\LocalServer32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.CoreMachineClass.1

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.CoreMachineClass.1\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.CoreMachineClass

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.CoreMachineClass\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.CoreMachineClass\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{9B2340A0-4068-43D6-B404-32E27217859D}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{9B2340A0-4068-43D6-B404-32E27217859D}\ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{9B2340A0-4068-43D6-B404-32E27217859D}\VersionIndependentProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{9B2340A0-4068-43D6-B404-32E27217859D}\LocalServer32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{9B2340A0-4068-43D6-B404-32E27217859D}\Elevation

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.OnDemandCOMClassMachineFallback.1.0

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.OnDemandCOMClassMachineFallback.1.0\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.OnDemandCOMClassMachineFallback

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.OnDemandCOMClassMachineFallback\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.OnDemandCOMClassMachineFallback\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{B3D28DBD-0DFA-40E4-8071-520767BADC7E}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{B3D28DBD-0DFA-40E4-8071-520767BADC7E}\ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{B3D28DBD-0DFA-40E4-8071-520767BADC7E}\VersionIndependentProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{B3D28DBD-0DFA-40E4-8071-520767BADC7E}\LocalServer32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{B3D28DBD-0DFA-40E4-8071-520767BADC7E}\Elevation

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.Update3WebMachineFallback.1.0

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.Update3WebMachineFallback.1.0\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.Update3WebMachineFallback

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.Update3WebMachineFallback\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.Update3WebMachineFallback\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{598FE0E5-E02D-465D-9A9D-37974A28FD42}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{598FE0E5-E02D-465D-9A9D-37974A28FD42}\ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{598FE0E5-E02D-465D-9A9D-37974A28FD42}\VersionIndependentProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{598FE0E5-E02D-465D-9A9D-37974A28FD42}\LocalServer32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{598FE0E5-E02D-465D-9A9D-37974A28FD42}\Elevation

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.CredentialDialogMachine.1.0

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.CredentialDialogMachine.1.0\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.CredentialDialogMachine

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.CredentialDialogMachine\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
GoogleUpdate.CredentialDialogMachine\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{25461599-633D-42B1-84FB-7CD68D026E53}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{25461599-633D-42B1-84FB-7CD68D026E53}\ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{25461599-633D-42B1-84FB-7CD68D026E53}\VersionIndependentProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{25461599-633D-42B1-84FB-7CD68D026E53}\LocalServer32

HKEY_CURRENT_USER\Software\Google\
Update\proxy

HKEY_LOCAL_MACHINE\Software\Google\
Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}

マルウェアは、以下のレジストリ値を追加します。

HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}
usagestats = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Update
path = "%Program Files%\Google\Update\GoogleUpdate.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Update
UninstallCmdLine = "%Program Files%\Google\Update\GoogleUpdate.exe /uninstall"

HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Update\Clients\{430FD4D0-B729-4F61-AA34-91526481799D}
pv = "1.3.21.165"

HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Update\Clients\{430FD4D0-B729-4F61-AA34-91526481799D}
name = "Google Update"

HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}
pv = "1.3.21.165"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows NT\CurrentVersion\Image File Execution Options\
GoogleUpdate.exe
DisableExceptionChainValidation = "0"

HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Update
IsMSIHelperRegistered = "0"

HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Update
LastOSVersion = "{random values}"

HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Update
version = "1.3.21.165"

HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\
@tools.google.com/Google Update;version=9
Path = "%Program Files%\Google\Update\1.3.21.165\npGoogleUpdate3.dll"

HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\
@tools.google.com/Google Update;version=9
Description = "Google Update"

HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\
@tools.google.com/Google Update;version=9
ProductName = "Google Update"

HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\
@tools.google.com/Google Update;version=9
Vendor = "Google Inc."

HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\
@tools.google.com/Google Update;version=9
Version = "9"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Internet Explorer\Low Rights\ElevationPolicy\
{C442AC41-9200-4770-8CC0-7CDB4F245C55}
AppName = "GoogleUpdate.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Internet Explorer\Low Rights\ElevationPolicy\
{C442AC41-9200-4770-8CC0-7CDB4F245C55}
AppPath = "%Program Files%\Google\Update"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Internet Explorer\Low Rights\ElevationPolicy\
{C442AC41-9200-4770-8CC0-7CDB4F245C55}
Policy = "3"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{C442AC41-9200-4770-8CC0-7CDB4F245C55}\InprocServer32
ThreadingModel = "Apartment"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
MIME\Database\Content Type\
application/x-vnd.google.oneclickctrl.9
CLSID = "{C442AC41-9200-4770-8CC0-7CDB4F245C55}"

HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\
@tools.google.com/Google Update;version=3
Path = "%Program Files%\Google\Update\1.3.21.165\npGoogleUpdate3.dll"

HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\
@tools.google.com/Google Update;version=3
Description = "Google Update"

HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\
@tools.google.com/Google Update;version=3
ProductName = "Google Update"

HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\
@tools.google.com/Google Update;version=3
Vendor = "Google Inc."

HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\
@tools.google.com/Google Update;version=3
Version = "3"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Internet Explorer\Low Rights\ElevationPolicy\
{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}
AppName = "GoogleUpdateBroker.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Internet Explorer\Low Rights\ElevationPolicy\
{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}
AppPath = "%Program Files%\Google\Update\1.3.21.165"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Internet Explorer\Low Rights\ElevationPolicy\
{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}
Policy = "3"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}\InprocServer32
ThreadingModel = "Apartment"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
MIME\Database\Content Type\
application/x-vnd.google.update3webcontrol.3
CLSID = "{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}"

HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}
brand = "GTPM"

HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}
InstallTime = "54454152"

HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Update\UsageStats\Daily
LastTransmission = "5445418e"

HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Update
uid = "{3D8E9508-B7FE-4962-9FB4-A42EE38059FA}"

HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Update
uid-create-time = "54454148"

HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Update
uid-num-rotations = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\GoogleUpdate.exe
AppID = "{4EB61BAC-A3B6-4760-9581-655041EF4D69}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{4EB61BAC-A3B6-4760-9581-655041EF4D69}
LocalService = "gupdate"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{4EB61BAC-A3B6-4760-9581-655041EF4D69}
ServiceParameters = "/comsvc"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{4EB61BAC-A3B6-4760-9581-655041EF4D69}
AppID = "{4EB61BAC-A3B6-4760-9581-655041EF4D69}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\GoogleUpdate.exe
AppID = "{9465B4B4-5216-4042-9A2C-754D3BCDC410}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{9465B4B4-5216-4042-9A2C-754D3BCDC410}
LocalService = "gupdatem"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{9465B4B4-5216-4042-9A2C-754D3BCDC410}
ServiceParameters = "/comsvc"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{9465B4B4-5216-4042-9A2C-754D3BCDC410}
AppID = "{9465B4B4-5216-4042-9A2C-754D3BCDC410}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{534F5323-3569-4F42-919D-1E1CF93E5BF6}
AppID = "{9465B4B4-5216-4042-9A2C-754D3BCDC410}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{E225E692-4B47-4777-9BED-4FD7FE257F0E}
AppID = "{9465B4B4-5216-4042-9A2C-754D3BCDC410}"

HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Update\UsageStats\Daily\
Counts
opt_in_uid_generated = "{random values}"

HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Update\UsageStats\Daily\
Counts
goopdate_main = "{random values}"

HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Update\UsageStats\Daily\
Counts
goopdate_constructor = "{random values}"

HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Update\UsageStats\Daily\
Integers
windows_sp_major_version = "{random values}"

HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Update\UsageStats\Daily\
Integers
windows_minor_version = "{random values}"

HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Update\UsageStats\Daily\
Integers
windows_major_version = "{random values}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{50AC8ACB-D28F-4082-A1BC-C04054B5A5AC}\InprocHandler32
ThreadingModel = "Both"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{9D6AA569-9F30-41AD-885A-346685C74928}\InprocServer32
ThreadingModel = "Both"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{D0CD6E57-FBA5-4F71-98DF-3AAEB8CB8118}\InProcServer32
ThreadingModel = "Both"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{6F8BD55B-E83D-4A47-85BE-81FFA8057A69}
LocalizedString = "@%Program Files%\Google\Update\1.3.21.165\goopdate.dll,-3000"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{6F8BD55B-E83D-4A47-85BE-81FFA8057A69}\Elevation
Enabled = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{6F8BD55B-E83D-4A47-85BE-81FFA8057A69}\Elevation
IconReference = "@%Program Files%\Google\Update\1.3.21.165\goopdate.dll,-1004"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{8A1D4361-2C08-4700-A351-3EAA9CBFF5E4}
LocalizedString = "@%Program Files%\Google\Update\1.3.21.165\goopdate.dll,-3000"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{8A1D4361-2C08-4700-A351-3EAA9CBFF5E4}\Elevation
Enabled = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{8A1D4361-2C08-4700-A351-3EAA9CBFF5E4}\Elevation
IconReference = "@%Program Files%\Google\Update\1.3.21.165\goopdate.dll,-1004"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Internet Explorer\Low Rights\ElevationPolicy\
{AAD4AE2E-D834-46D4-8B09-490FAC9C722B}
CLSID = "{AAD4AE2E-D834-46D4-8B09-490FAC9C722B}"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Internet Explorer\Low Rights\ElevationPolicy\
{AAD4AE2E-D834-46D4-8B09-490FAC9C722B}
Policy = "3"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{9B2340A0-4068-43D6-B404-32E27217859D}
LocalizedString = "@%Program Files%\Google\Update\1.3.21.165\goopdate.dll,-3000"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{9B2340A0-4068-43D6-B404-32E27217859D}\Elevation
Enabled = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{9B2340A0-4068-43D6-B404-32E27217859D}\Elevation
IconReference = "@%Program Files%\Google\Update\1.3.21.165\goopdate.dll,-1004"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{B3D28DBD-0DFA-40E4-8071-520767BADC7E}
LocalizedString = "@%Program Files%\Google\Update\1.3.21.165\goopdate.dll,-3000"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{B3D28DBD-0DFA-40E4-8071-520767BADC7E}\Elevation
Enabled = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{B3D28DBD-0DFA-40E4-8071-520767BADC7E}\Elevation
IconReference = "@%Program Files%\Google\Update\1.3.21.165\goopdate.dll,-1004"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{598FE0E5-E02D-465D-9A9D-37974A28FD42}
LocalizedString = "@%Program Files%\Google\Update\1.3.21.165\goopdate.dll,-3000"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{598FE0E5-E02D-465D-9A9D-37974A28FD42}\Elevation
Enabled = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{598FE0E5-E02D-465D-9A9D-37974A28FD42}\Elevation
IconReference = "@%Program Files%\Google\Update\1.3.21.165\goopdate.dll,-1004"

HKEY_CURRENT_USER\Software\Google\
Update\proxy
source = "auto"

マルウェアは、以下のレジストリキーを削除します。

HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Update\UsageStats\Daily\
Timings

HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Update\UsageStats\Daily\
Booleans

HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Update\Clients\{430FD4D0-B729-4F61-AA34-91526481799D}

HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Update\Clients

HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}

HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}

HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Update\ClientState

HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}

HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Update\ClientStateMedium

HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Update\network

HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Update\uid

HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Update\UsageStats\Daily

HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Update\UsageStats

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{2E629606-312A-482F-9B12-2C4ABF6F0B6D}\AsynchronousInterface

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{31AC3F11-E5EA-4A85-8A3D-8E095A39C27B}\AsynchronousInterface

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{8476CE12-AE1F-4198-805C-BA0F9B783F57}\AsynchronousInterface

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{0CD01D1E-4A1C-489D-93B9-9B6672877C57}\AsynchronousInterface

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{4E223325-C16B-4EEB-AEDC-19AA99A237FA}\AsynchronousInterface

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{BCDCB538-01C0-46D1-A6A7-52F4D021C272}\AsynchronousInterface

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{49D7563B-2DDB-4831-88C8-768A53833837}\AsynchronousInterface

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{DAB1D343-1B2A-47F9-B445-93DC50704BFE}\AsynchronousInterface

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{3D05F64F-71E3-48A5-BF6B-83315BC8AE1F}\AsynchronousInterface

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{6DB17455-4E85-46E7-9D23-E555E4B005AF}\AsynchronousInterface

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{DD42475D-6D46-496A-924E-BD5630B4CBBA}\AsynchronousInterface

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{D106AB5F-A70E-400E-A21B-96208C1D8DBB}\AsynchronousInterface

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{B3A47570-0A85-4AEA-8270-529D47899603}\AsynchronousInterface

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{18D0F672-18B4-48E6-AD36-6E6BF01DBBC4}\AsynchronousInterface

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{2D363682-561D-4C3A-81C6-F2F82107562A}\AsynchronousInterface

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{DCAB8386-4F03-4DBD-A366-D90BC9F68DE6}\AsynchronousInterface

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{76F7B787-A67C-4C73-82C7-31F5E3AABC5C}\AsynchronousInterface

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{128C2DA6-2BC0-44C0-B3F6-4EC22E647964}\AsynchronousInterface

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{084D78A8-B084-4E14-A629-A2C419B0E3D9}\AsynchronousInterface

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{909489C2-85A6-4322-AA56-D25278649D67}\AsynchronousInterface

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{494B20CF-282E-4BDD-9F5D-B70CB09D351E}\AsynchronousInterface

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{5B25A8DC-1780-4178-A629-6BE8B8DEFAA2}\AsynchronousInterface

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{FE908CDD-22BB-472A-9870-1A0390E42F36}\AsynchronousInterface

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{1C642CED-CA3B-4013-A9DF-CA6CE5FF6503}\AsynchronousInterface

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{5CCCB0EF-7073-4516-8028-4C628D0C8AAB}\AsynchronousInterface

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{247954F9-9EDC-4E68-8CC3-150C2B89EADF}\AsynchronousInterface

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{4DE778FE-F195-4EE3-9DAB-FE446C239221}\AsynchronousInterface

HKEY_CURRENT_USER\Software\Google\
Update\uid

作成活動

マルウェアは、以下のファイルを作成します。

  • %User Temp%\chrome_installer.exe
  • %Program Files%\GUM2.tmp\GoogleUpdate.exe
  • %Program Files%\GUM2.tmp\GoogleCrashHandler.exe
  • %Program Files%\GUM2.tmp\goopdate.dll
  • %Program Files%\GUM2.tmp\npGoogleUpdate3.dll
  • %Program Files%\GUM2.tmp\GoogleUpdateHelper.msi
  • %Program Files%\GUM2.tmp\GoogleUpdateBroker.exe
  • %Program Files%\GUM2.tmp\GoogleUpdateOnDemand.exe
  • %Program Files%\GUM2.tmp\psmachine.dll
  • %Program Files%\GUM2.tmp\psuser.dll
  • %Program Files%\GUM2.tmp\GoogleCrashHandler64.exe
  • %Program Files%\GUM2.tmp\goopdateres_am.dll
  • %Program Files%\GUM2.tmp\goopdateres_ar.dll
  • %Program Files%\GUM2.tmp\goopdateres_bg.dll
  • %Program Files%\GUM2.tmp\goopdateres_bn.dll
  • %Program Files%\GUM2.tmp\goopdateres_ca.dll
  • %Program Files%\GUM2.tmp\goopdateres_cs.dll
  • %Program Files%\GUM2.tmp\goopdateres_da.dll
  • %Program Files%\GUM2.tmp\goopdateres_de.dll
  • %Program Files%\GUM2.tmp\goopdateres_el.dll
  • %Program Files%\GUM2.tmp\goopdateres_en.dll
  • %Program Files%\GUM2.tmp\goopdateres_en-GB.dll
  • %Program Files%\GUM2.tmp\goopdateres_es.dll
  • %Program Files%\GUM2.tmp\goopdateres_es-419.dll
  • %Program Files%\GUM2.tmp\goopdateres_et.dll
  • %Program Files%\GUM2.tmp\goopdateres_fa.dll
  • %Program Files%\GUM2.tmp\goopdateres_fi.dll
  • %Program Files%\GUM2.tmp\goopdateres_fil.dll
  • %Program Files%\GUM2.tmp\goopdateres_fr.dll
  • %Program Files%\GUM2.tmp\goopdateres_gu.dll
  • %Program Files%\GUM2.tmp\goopdateres_hi.dll
  • %Program Files%\GUM2.tmp\goopdateres_hr.dll
  • %Program Files%\GUM2.tmp\goopdateres_hu.dll
  • %Program Files%\GUM2.tmp\goopdateres_id.dll
  • %Program Files%\GUM2.tmp\goopdateres_is.dll
  • %Program Files%\GUM2.tmp\goopdateres_it.dll
  • %Program Files%\GUM2.tmp\goopdateres_iw.dll
  • %Program Files%\GUM2.tmp\goopdateres_ja.dll
  • %Program Files%\GUM2.tmp\goopdateres_kn.dll
  • %Program Files%\GUM2.tmp\goopdateres_ko.dll
  • %Program Files%\GUM2.tmp\goopdateres_lt.dll
  • %Program Files%\GUM2.tmp\goopdateres_lv.dll
  • %Program Files%\GUM2.tmp\goopdateres_ml.dll
  • %Program Files%\GUM2.tmp\goopdateres_mr.dll
  • %Program Files%\GUM2.tmp\goopdateres_ms.dll
  • %Program Files%\GUM2.tmp\goopdateres_nl.dll
  • %Program Files%\GUM2.tmp\goopdateres_no.dll
  • %Program Files%\GUM2.tmp\goopdateres_pl.dll
  • %Program Files%\GUM2.tmp\goopdateres_pt-BR.dll
  • %Program Files%\GUM2.tmp\goopdateres_pt-PT.dll
  • %Program Files%\GUM2.tmp\goopdateres_ro.dll
  • %Program Files%\GUM2.tmp\goopdateres_ru.dll
  • %Program Files%\GUM2.tmp\goopdateres_sk.dll
  • %Program Files%\GUM2.tmp\goopdateres_sl.dll
  • %Program Files%\GUM2.tmp\goopdateres_sr.dll
  • %Program Files%\GUM2.tmp\goopdateres_sv.dll
  • %Program Files%\GUM2.tmp\goopdateres_sw.dll
  • %Program Files%\GUM2.tmp\goopdateres_ta.dll
  • %Program Files%\GUM2.tmp\goopdateres_te.dll
  • %Program Files%\GUM2.tmp\goopdateres_th.dll
  • %Program Files%\GUM2.tmp\goopdateres_tr.dll
  • %Program Files%\GUM2.tmp\goopdateres_uk.dll
  • %Program Files%\GUM2.tmp\goopdateres_ur.dll
  • %Program Files%\GUM2.tmp\goopdateres_vi.dll
  • %Program Files%\GUM2.tmp\goopdateres_zh-CN.dll
  • %Program Files%\GUM2.tmp\goopdateres_zh-TW.dll
  • %Windows%\Tasks\GoogleUpdateTaskMachineCore.job
  • %Windows%\Tasks\GoogleUpdateTaskMachineUA.job

(註:%User Temp%フォルダはWindowsの種類とインストール時の設定などにより異なります。標準設定では、Windows 2000、XP および Server 2003 の場合、"C:\Documents and Settings\<ユーザー名>\Local Settings\Temp"、Windows Vista および 7 の場合、"C:\Users\<ユーザ名>\AppData\Local\Temp" です。. %Program Files%フォルダは、Windows 2000、Server 2003、XP (32ビット)、通常 Vista (32ビット) および 7 (32ビット) の場合、通常 "C:\Program Files"、Windows XP (64ビット)、Vista (64ビット) および 7 (64ビット) の場合、通常 "C:\Program Files (x86)" です。. %Windows%フォルダはWindowsの種類とインストール時の設定などにより異なります。標準設定では、"C:\Windows" です。)

その他

マルウェアは、以下の不正なWebサイトにアクセスします。

  • {BLOCKED}.228.226
  • {BLOCKED}0.1
  • {BLOCKED}.228.199

このウイルス情報は、自動解析システムにより作成されました。


  対応方法

対応検索エンジン: 9.700

手順 1

Windows XP、Windows Vista および Windows 7 のユーザは、コンピュータからマルウェアもしくはアドウェア等を完全に削除するために、ウイルス検索の実行前には必ず「システムの復元」を無効にしてください。

手順 2

不明なレジストリ値を削除します。

[ 詳細 ]

警告:レジストリはWindowsの構成情報が格納されているデータベースであり、レジストリの編集内容に問題があると、システムが正常に動作しなくなる場合があります。
レジストリの編集はお客様の責任で行っていただくようお願いいたします。弊社ではレジストリの編集による如何なる問題に対しても補償いたしかねます。
レジストリの編集前にこちらをご参照ください。

  • In HKEY_LOCAL_MACHINE\Software\Google\Update\ClientState
    • {8A69D345-D564-463C-AFF1-A69D9E530F96}
  • In HKEY_LOCAL_MACHINE\Software\Google\Update
    • network
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\network
    • secure
  • In HKEY_LOCAL_MACHINE\Software\Google\Update
    • Clients
  • In HKEY_LOCAL_MACHINE\Software\Google\Update\Clients
    • {430FD4D0-B729-4F61-AA34-91526481799D}
  • In HKEY_LOCAL_MACHINE\Software\Google\Update\ClientState
    • {430FD4D0-B729-4F61-AA34-91526481799D}
  • In HKEY_LOCAL_MACHINE\Software\Google\Update
    • ClientStateMedium
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
    • GoogleUpdate.exe
  • In HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins
    • @tools.google.com/Google Update;version=9
  • In HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9
    • MimeTypes
  • In HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9\MimeTypes
    • application/x-vnd.google.oneclickctrl.9
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion
    • Ext
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext
    • PreApproved
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved
    • {C442AC41-9200-4770-8CC0-7CDB4F245C55}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext
    • Stats
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats
    • {C442AC41-9200-4770-8CC0-7CDB4F245C55}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C442AC41-9200-4770-8CC0-7CDB4F245C55}
    • iexplore
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C442AC41-9200-4770-8CC0-7CDB4F245C55}\iexplore
    • AllowedDomains
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C442AC41-9200-4770-8CC0-7CDB4F245C55}\iexplore\AllowedDomains
    • *
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy
    • {C442AC41-9200-4770-8CC0-7CDB4F245C55}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • Google.OneClickCtrl.9
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Google.OneClickCtrl.9
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
    • {C442AC41-9200-4770-8CC0-7CDB4F245C55}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C442AC41-9200-4770-8CC0-7CDB4F245C55}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C442AC41-9200-4770-8CC0-7CDB4F245C55}
    • InprocServer32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C442AC41-9200-4770-8CC0-7CDB4F245C55}
    • Implemented Categories
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C442AC41-9200-4770-8CC0-7CDB4F245C55}\Implemented Categories
    • {59FB2056-D625-48D0-A944-1A85B5AB2640}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type
    • application/x-vnd.google.oneclickctrl.9
  • In HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins
    • @tools.google.com/Google Update;version=3
  • In HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3
    • MimeTypes
  • In HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3\MimeTypes
    • application/x-vnd.google.update3webcontrol.3
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved
    • {C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats
    • {C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}
    • iexplore
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}\iexplore
    • AllowedDomains
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}\iexplore\AllowedDomains
    • *
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy
    • {C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • Google.Update3WebControl.3
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Google.Update3WebControl.3
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
    • {C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}
    • InprocServer32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}
    • Implemented Categories
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}\Implemented Categories
    • {59FB2056-D625-48D0-A944-1A85B5AB2640}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type
    • application/x-vnd.google.update3webcontrol.3
  • In HKEY_LOCAL_MACHINE\Software\Google\Update
    • uid
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID
    • {4EB61BAC-A3B6-4760-9581-655041EF4D69}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID
    • GoogleUpdate.exe
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • GoogleUpdate.Update3COMClassService.1.0
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GoogleUpdate.Update3COMClassService.1.0
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • GoogleUpdate.Update3COMClassService
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GoogleUpdate.Update3COMClassService
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GoogleUpdate.Update3COMClassService
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
    • {4EB61BAC-A3B6-4760-9581-655041EF4D69}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4EB61BAC-A3B6-4760-9581-655041EF4D69}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4EB61BAC-A3B6-4760-9581-655041EF4D69}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID
    • {9465B4B4-5216-4042-9A2C-754D3BCDC410}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • GoogleUpdate.OnDemandCOMClassSvc.1.0
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GoogleUpdate.OnDemandCOMClassSvc.1.0
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • GoogleUpdate.OnDemandCOMClassSvc
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GoogleUpdate.OnDemandCOMClassSvc
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GoogleUpdate.OnDemandCOMClassSvc
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
    • {9465B4B4-5216-4042-9A2C-754D3BCDC410}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9465B4B4-5216-4042-9A2C-754D3BCDC410}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9465B4B4-5216-4042-9A2C-754D3BCDC410}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • GoogleUpdate.Update3WebSvc.1.0
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GoogleUpdate.Update3WebSvc.1.0
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • GoogleUpdate.Update3WebSvc
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GoogleUpdate.Update3WebSvc
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GoogleUpdate.Update3WebSvc
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
    • {534F5323-3569-4F42-919D-1E1CF93E5BF6}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{534F5323-3569-4F42-919D-1E1CF93E5BF6}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{534F5323-3569-4F42-919D-1E1CF93E5BF6}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • GoogleUpdate.CoreClass.1
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GoogleUpdate.CoreClass.1
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • GoogleUpdate.CoreClass
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GoogleUpdate.CoreClass
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GoogleUpdate.CoreClass
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
    • {E225E692-4B47-4777-9BED-4FD7FE257F0E}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E225E692-4B47-4777-9BED-4FD7FE257F0E}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E225E692-4B47-4777-9BED-4FD7FE257F0E}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\Software\Google\Update\UsageStats
    • Daily
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\UsageStats\Daily
    • Counts
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\UsageStats\Daily
    • Integers
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
    • {50AC8ACB-D28F-4082-A1BC-C04054B5A5AC}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50AC8ACB-D28F-4082-A1BC-C04054B5A5AC}
    • InprocHandler32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
    • {9D6AA569-9F30-41AD-885A-346685C74928}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9D6AA569-9F30-41AD-885A-346685C74928}
    • InprocServer32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
    • {D0CD6E57-FBA5-4F71-98DF-3AAEB8CB8118}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D0CD6E57-FBA5-4F71-98DF-3AAEB8CB8118}
    • InProcServer32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
    • {2E629606-312A-482F-9B12-2C4ABF6F0B6D}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2E629606-312A-482F-9B12-2C4ABF6F0B6D}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2E629606-312A-482F-9B12-2C4ABF6F0B6D}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
    • {31AC3F11-E5EA-4A85-8A3D-8E095A39C27B}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{31AC3F11-E5EA-4A85-8A3D-8E095A39C27B}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{31AC3F11-E5EA-4A85-8A3D-8E095A39C27B}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
    • {8476CE12-AE1F-4198-805C-BA0F9B783F57}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8476CE12-AE1F-4198-805C-BA0F9B783F57}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8476CE12-AE1F-4198-805C-BA0F9B783F57}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
    • {0CD01D1E-4A1C-489D-93B9-9B6672877C57}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0CD01D1E-4A1C-489D-93B9-9B6672877C57}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0CD01D1E-4A1C-489D-93B9-9B6672877C57}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
    • {4E223325-C16B-4EEB-AEDC-19AA99A237FA}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4E223325-C16B-4EEB-AEDC-19AA99A237FA}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4E223325-C16B-4EEB-AEDC-19AA99A237FA}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
    • {BCDCB538-01C0-46D1-A6A7-52F4D021C272}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BCDCB538-01C0-46D1-A6A7-52F4D021C272}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BCDCB538-01C0-46D1-A6A7-52F4D021C272}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
    • {49D7563B-2DDB-4831-88C8-768A53833837}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{49D7563B-2DDB-4831-88C8-768A53833837}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{49D7563B-2DDB-4831-88C8-768A53833837}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
    • {DAB1D343-1B2A-47F9-B445-93DC50704BFE}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DAB1D343-1B2A-47F9-B445-93DC50704BFE}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DAB1D343-1B2A-47F9-B445-93DC50704BFE}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
    • {3D05F64F-71E3-48A5-BF6B-83315BC8AE1F}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3D05F64F-71E3-48A5-BF6B-83315BC8AE1F}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3D05F64F-71E3-48A5-BF6B-83315BC8AE1F}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
    • {6DB17455-4E85-46E7-9D23-E555E4B005AF}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6DB17455-4E85-46E7-9D23-E555E4B005AF}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6DB17455-4E85-46E7-9D23-E555E4B005AF}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
    • {DD42475D-6D46-496A-924E-BD5630B4CBBA}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DD42475D-6D46-496A-924E-BD5630B4CBBA}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DD42475D-6D46-496A-924E-BD5630B4CBBA}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
    • {D106AB5F-A70E-400E-A21B-96208C1D8DBB}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D106AB5F-A70E-400E-A21B-96208C1D8DBB}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D106AB5F-A70E-400E-A21B-96208C1D8DBB}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
    • {B3A47570-0A85-4AEA-8270-529D47899603}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B3A47570-0A85-4AEA-8270-529D47899603}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B3A47570-0A85-4AEA-8270-529D47899603}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
    • {18D0F672-18B4-48E6-AD36-6E6BF01DBBC4}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{18D0F672-18B4-48E6-AD36-6E6BF01DBBC4}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{18D0F672-18B4-48E6-AD36-6E6BF01DBBC4}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
    • {2D363682-561D-4C3A-81C6-F2F82107562A}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2D363682-561D-4C3A-81C6-F2F82107562A}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2D363682-561D-4C3A-81C6-F2F82107562A}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
    • {DCAB8386-4F03-4DBD-A366-D90BC9F68DE6}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DCAB8386-4F03-4DBD-A366-D90BC9F68DE6}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DCAB8386-4F03-4DBD-A366-D90BC9F68DE6}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
    • {76F7B787-A67C-4C73-82C7-31F5E3AABC5C}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{76F7B787-A67C-4C73-82C7-31F5E3AABC5C}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{76F7B787-A67C-4C73-82C7-31F5E3AABC5C}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
    • {128C2DA6-2BC0-44C0-B3F6-4EC22E647964}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{128C2DA6-2BC0-44C0-B3F6-4EC22E647964}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{128C2DA6-2BC0-44C0-B3F6-4EC22E647964}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
    • {084D78A8-B084-4E14-A629-A2C419B0E3D9}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{084D78A8-B084-4E14-A629-A2C419B0E3D9}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{084D78A8-B084-4E14-A629-A2C419B0E3D9}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
    • {909489C2-85A6-4322-AA56-D25278649D67}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{909489C2-85A6-4322-AA56-D25278649D67}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{909489C2-85A6-4322-AA56-D25278649D67}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
    • {494B20CF-282E-4BDD-9F5D-B70CB09D351E}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{494B20CF-282E-4BDD-9F5D-B70CB09D351E}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{494B20CF-282E-4BDD-9F5D-B70CB09D351E}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
    • {5B25A8DC-1780-4178-A629-6BE8B8DEFAA2}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5B25A8DC-1780-4178-A629-6BE8B8DEFAA2}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5B25A8DC-1780-4178-A629-6BE8B8DEFAA2}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
    • {FE908CDD-22BB-472A-9870-1A0390E42F36}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FE908CDD-22BB-472A-9870-1A0390E42F36}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FE908CDD-22BB-472A-9870-1A0390E42F36}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
    • {1C642CED-CA3B-4013-A9DF-CA6CE5FF6503}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C642CED-CA3B-4013-A9DF-CA6CE5FF6503}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C642CED-CA3B-4013-A9DF-CA6CE5FF6503}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
    • {5CCCB0EF-7073-4516-8028-4C628D0C8AAB}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5CCCB0EF-7073-4516-8028-4C628D0C8AAB}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5CCCB0EF-7073-4516-8028-4C628D0C8AAB}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
    • {247954F9-9EDC-4E68-8CC3-150C2B89EADF}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{247954F9-9EDC-4E68-8CC3-150C2B89EADF}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{247954F9-9EDC-4E68-8CC3-150C2B89EADF}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
    • {4DE778FE-F195-4EE3-9DAB-FE446C239221}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4DE778FE-F195-4EE3-9DAB-FE446C239221}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4DE778FE-F195-4EE3-9DAB-FE446C239221}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • GoogleUpdate.OnDemandCOMClassMachine.1.0
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GoogleUpdate.OnDemandCOMClassMachine.1.0
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • GoogleUpdate.OnDemandCOMClassMachine
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GoogleUpdate.OnDemandCOMClassMachine
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GoogleUpdate.OnDemandCOMClassMachine
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
    • {6F8BD55B-E83D-4A47-85BE-81FFA8057A69}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6F8BD55B-E83D-4A47-85BE-81FFA8057A69}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6F8BD55B-E83D-4A47-85BE-81FFA8057A69}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6F8BD55B-E83D-4A47-85BE-81FFA8057A69}
    • LocalServer32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6F8BD55B-E83D-4A47-85BE-81FFA8057A69}
    • Elevation
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • GoogleUpdate.Update3WebMachine.1.0
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GoogleUpdate.Update3WebMachine.1.0
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • GoogleUpdate.Update3WebMachine
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GoogleUpdate.Update3WebMachine
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GoogleUpdate.Update3WebMachine
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
    • {8A1D4361-2C08-4700-A351-3EAA9CBFF5E4}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8A1D4361-2C08-4700-A351-3EAA9CBFF5E4}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8A1D4361-2C08-4700-A351-3EAA9CBFF5E4}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8A1D4361-2C08-4700-A351-3EAA9CBFF5E4}
    • LocalServer32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8A1D4361-2C08-4700-A351-3EAA9CBFF5E4}
    • Elevation
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • GoogleUpdate.CoCreateAsync.1.0
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GoogleUpdate.CoCreateAsync.1.0
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • GoogleUpdate.CoCreateAsync
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GoogleUpdate.CoCreateAsync
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GoogleUpdate.CoCreateAsync
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
    • {7DE94008-8AFD-4C70-9728-C6FBFFF6A73E}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7DE94008-8AFD-4C70-9728-C6FBFFF6A73E}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7DE94008-8AFD-4C70-9728-C6FBFFF6A73E}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7DE94008-8AFD-4C70-9728-C6FBFFF6A73E}
    • LocalServer32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • Google.OneClickProcessLauncherMachine.1.0
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Google.OneClickProcessLauncherMachine.1.0
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • Google.OneClickProcessLauncherMachine
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Google.OneClickProcessLauncherMachine
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Google.OneClickProcessLauncherMachine
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
    • {AAD4AE2E-D834-46D4-8B09-490FAC9C722B}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AAD4AE2E-D834-46D4-8B09-490FAC9C722B}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AAD4AE2E-D834-46D4-8B09-490FAC9C722B}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AAD4AE2E-D834-46D4-8B09-490FAC9C722B}
    • LocalServer32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy
    • {AAD4AE2E-D834-46D4-8B09-490FAC9C722B}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • GoogleUpdate.ProcessLauncher.1.0
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GoogleUpdate.ProcessLauncher.1.0
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • GoogleUpdate.ProcessLauncher
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GoogleUpdate.ProcessLauncher
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GoogleUpdate.ProcessLauncher
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
    • {ABC01078-F197-4B0B-ADBC-CFE684B39C82}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ABC01078-F197-4B0B-ADBC-CFE684B39C82}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ABC01078-F197-4B0B-ADBC-CFE684B39C82}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ABC01078-F197-4B0B-ADBC-CFE684B39C82}
    • LocalServer32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • GoogleUpdate.CoreMachineClass.1
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GoogleUpdate.CoreMachineClass.1
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • GoogleUpdate.CoreMachineClass
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GoogleUpdate.CoreMachineClass
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GoogleUpdate.CoreMachineClass
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
    • {9B2340A0-4068-43D6-B404-32E27217859D}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9B2340A0-4068-43D6-B404-32E27217859D}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9B2340A0-4068-43D6-B404-32E27217859D}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9B2340A0-4068-43D6-B404-32E27217859D}
    • LocalServer32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9B2340A0-4068-43D6-B404-32E27217859D}
    • Elevation
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • GoogleUpdate.OnDemandCOMClassMachineFallback.1.0
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GoogleUpdate.OnDemandCOMClassMachineFallback.1.0
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • GoogleUpdate.OnDemandCOMClassMachineFallback
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GoogleUpdate.OnDemandCOMClassMachineFallback
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GoogleUpdate.OnDemandCOMClassMachineFallback
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
    • {B3D28DBD-0DFA-40E4-8071-520767BADC7E}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B3D28DBD-0DFA-40E4-8071-520767BADC7E}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B3D28DBD-0DFA-40E4-8071-520767BADC7E}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B3D28DBD-0DFA-40E4-8071-520767BADC7E}
    • LocalServer32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B3D28DBD-0DFA-40E4-8071-520767BADC7E}
    • Elevation
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • GoogleUpdate.Update3WebMachineFallback.1.0
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GoogleUpdate.Update3WebMachineFallback.1.0
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • GoogleUpdate.Update3WebMachineFallback
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GoogleUpdate.Update3WebMachineFallback
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GoogleUpdate.Update3WebMachineFallback
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
    • {598FE0E5-E02D-465D-9A9D-37974A28FD42}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{598FE0E5-E02D-465D-9A9D-37974A28FD42}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{598FE0E5-E02D-465D-9A9D-37974A28FD42}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{598FE0E5-E02D-465D-9A9D-37974A28FD42}
    • LocalServer32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{598FE0E5-E02D-465D-9A9D-37974A28FD42}
    • Elevation
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • GoogleUpdate.CredentialDialogMachine.1.0
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GoogleUpdate.CredentialDialogMachine.1.0
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • GoogleUpdate.CredentialDialogMachine
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GoogleUpdate.CredentialDialogMachine
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GoogleUpdate.CredentialDialogMachine
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
    • {25461599-633D-42B1-84FB-7CD68D026E53}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{25461599-633D-42B1-84FB-7CD68D026E53}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{25461599-633D-42B1-84FB-7CD68D026E53}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{25461599-633D-42B1-84FB-7CD68D026E53}
    • LocalServer32
  • In HKEY_CURRENT_USER\Software\Google\Update
    • proxy
  • In HKEY_LOCAL_MACHINE\Software\Google\Update\ClientStateMedium
    • {8A69D345-D564-463C-AFF1-A69D9E530F96}

手順 3

このレジストリ値を削除します。

[ 詳細 ]

警告:レジストリはWindowsの構成情報が格納されているデータベースであり、レジストリの編集内容に問題があると、システムが正常に動作しなくなる場合があります。
レジストリの編集はお客様の責任で行っていただくようお願いいたします。弊社ではレジストリの編集による如何なる問題に対しても補償いたしかねます。
レジストリの編集前にこちらをご参照ください。

  • In HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96}
    • usagestats = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update
    • path = "%Program Files%\Google\Update\GoogleUpdate.exe"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update
    • UninstallCmdLine = "%Program Files%\Google\Update\GoogleUpdate.exe /uninstall"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\Clients\{430FD4D0-B729-4F61-AA34-91526481799D}
    • pv = "1.3.21.165"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\Clients\{430FD4D0-B729-4F61-AA34-91526481799D}
    • name = "Google Update"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}
    • pv = "1.3.21.165"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GoogleUpdate.exe
    • DisableExceptionChainValidation = "0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update
    • IsMSIHelperRegistered = "0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update
    • LastOSVersion = "{random values}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update
    • version = "1.3.21.165"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9
    • Path = "%Program Files%\Google\Update\1.3.21.165\npGoogleUpdate3.dll"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9
    • Description = "Google Update"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9
    • ProductName = "Google Update"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9
    • Vendor = "Google Inc."
  • In HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9
    • Version = "9"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C442AC41-9200-4770-8CC0-7CDB4F245C55}
    • AppName = "GoogleUpdate.exe"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C442AC41-9200-4770-8CC0-7CDB4F245C55}
    • AppPath = "%Program Files%\Google\Update"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C442AC41-9200-4770-8CC0-7CDB4F245C55}
    • Policy = "3"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C442AC41-9200-4770-8CC0-7CDB4F245C55}\InprocServer32
    • ThreadingModel = "Apartment"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-vnd.google.oneclickctrl.9
    • CLSID = "{C442AC41-9200-4770-8CC0-7CDB4F245C55}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3
    • Path = "%Program Files%\Google\Update\1.3.21.165\npGoogleUpdate3.dll"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3
    • Description = "Google Update"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3
    • ProductName = "Google Update"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3
    • Vendor = "Google Inc."
  • In HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3
    • Version = "3"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}
    • AppName = "GoogleUpdateBroker.exe"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}
    • AppPath = "%Program Files%\Google\Update\1.3.21.165"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}
    • Policy = "3"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}\InprocServer32
    • ThreadingModel = "Apartment"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-vnd.google.update3webcontrol.3
    • CLSID = "{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}
    • brand = "GTPM"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}
    • InstallTime = "54454152"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\UsageStats\Daily
    • LastTransmission = "5445418e"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update
    • uid = "{3D8E9508-B7FE-4962-9FB4-A42EE38059FA}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update
    • uid-create-time = "54454148"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update
    • uid-num-rotations = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\GoogleUpdate.exe
    • AppID = "{4EB61BAC-A3B6-4760-9581-655041EF4D69}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{4EB61BAC-A3B6-4760-9581-655041EF4D69}
    • LocalService = "gupdate"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{4EB61BAC-A3B6-4760-9581-655041EF4D69}
    • ServiceParameters = "/comsvc"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4EB61BAC-A3B6-4760-9581-655041EF4D69}
    • AppID = "{4EB61BAC-A3B6-4760-9581-655041EF4D69}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\GoogleUpdate.exe
    • AppID = "{9465B4B4-5216-4042-9A2C-754D3BCDC410}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{9465B4B4-5216-4042-9A2C-754D3BCDC410}
    • LocalService = "gupdatem"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{9465B4B4-5216-4042-9A2C-754D3BCDC410}
    • ServiceParameters = "/comsvc"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9465B4B4-5216-4042-9A2C-754D3BCDC410}
    • AppID = "{9465B4B4-5216-4042-9A2C-754D3BCDC410}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{534F5323-3569-4F42-919D-1E1CF93E5BF6}
    • AppID = "{9465B4B4-5216-4042-9A2C-754D3BCDC410}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E225E692-4B47-4777-9BED-4FD7FE257F0E}
    • AppID = "{9465B4B4-5216-4042-9A2C-754D3BCDC410}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\UsageStats\Daily\Counts
    • opt_in_uid_generated = "{random values}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\UsageStats\Daily\Counts
    • goopdate_main = "{random values}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\UsageStats\Daily\Counts
    • goopdate_constructor = "{random values}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\UsageStats\Daily\Integers
    • windows_sp_major_version = "{random values}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\UsageStats\Daily\Integers
    • windows_minor_version = "{random values}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\UsageStats\Daily\Integers
    • windows_major_version = "{random values}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50AC8ACB-D28F-4082-A1BC-C04054B5A5AC}\InprocHandler32
    • ThreadingModel = "Both"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9D6AA569-9F30-41AD-885A-346685C74928}\InprocServer32
    • ThreadingModel = "Both"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D0CD6E57-FBA5-4F71-98DF-3AAEB8CB8118}\InProcServer32
    • ThreadingModel = "Both"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6F8BD55B-E83D-4A47-85BE-81FFA8057A69}
    • LocalizedString = "@%Program Files%\Google\Update\1.3.21.165\goopdate.dll,-3000"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6F8BD55B-E83D-4A47-85BE-81FFA8057A69}\Elevation
    • Enabled = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6F8BD55B-E83D-4A47-85BE-81FFA8057A69}\Elevation
    • IconReference = "@%Program Files%\Google\Update\1.3.21.165\goopdate.dll,-1004"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8A1D4361-2C08-4700-A351-3EAA9CBFF5E4}
    • LocalizedString = "@%Program Files%\Google\Update\1.3.21.165\goopdate.dll,-3000"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8A1D4361-2C08-4700-A351-3EAA9CBFF5E4}\Elevation
    • Enabled = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8A1D4361-2C08-4700-A351-3EAA9CBFF5E4}\Elevation
    • IconReference = "@%Program Files%\Google\Update\1.3.21.165\goopdate.dll,-1004"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AAD4AE2E-D834-46D4-8B09-490FAC9C722B}
    • CLSID = "{AAD4AE2E-D834-46D4-8B09-490FAC9C722B}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AAD4AE2E-D834-46D4-8B09-490FAC9C722B}
    • Policy = "3"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9B2340A0-4068-43D6-B404-32E27217859D}
    • LocalizedString = "@%Program Files%\Google\Update\1.3.21.165\goopdate.dll,-3000"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9B2340A0-4068-43D6-B404-32E27217859D}\Elevation
    • Enabled = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9B2340A0-4068-43D6-B404-32E27217859D}\Elevation
    • IconReference = "@%Program Files%\Google\Update\1.3.21.165\goopdate.dll,-1004"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B3D28DBD-0DFA-40E4-8071-520767BADC7E}
    • LocalizedString = "@%Program Files%\Google\Update\1.3.21.165\goopdate.dll,-3000"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B3D28DBD-0DFA-40E4-8071-520767BADC7E}\Elevation
    • Enabled = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B3D28DBD-0DFA-40E4-8071-520767BADC7E}\Elevation
    • IconReference = "@%Program Files%\Google\Update\1.3.21.165\goopdate.dll,-1004"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{598FE0E5-E02D-465D-9A9D-37974A28FD42}
    • LocalizedString = "@%Program Files%\Google\Update\1.3.21.165\goopdate.dll,-3000"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{598FE0E5-E02D-465D-9A9D-37974A28FD42}\Elevation
    • Enabled = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{598FE0E5-E02D-465D-9A9D-37974A28FD42}\Elevation
    • IconReference = "@%Program Files%\Google\Update\1.3.21.165\goopdate.dll,-1004"
  • In HKEY_CURRENT_USER\Software\Google\Update\proxy
    • source = "auto"

手順 4

以下のファイルを検索し削除します。

[ 詳細 ]
コンポーネントファイルが隠しファイル属性の場合があります。[詳細設定オプション]をクリックし、[隠しファイルとフォルダの検索]のチェックボックスをオンにし、検索結果に隠しファイルとフォルダが含まれるようにしてください。
  • %User Temp%\chrome_installer.exe
  • %Program Files%\GUM2.tmp\GoogleUpdate.exe
  • %Program Files%\GUM2.tmp\GoogleCrashHandler.exe
  • %Program Files%\GUM2.tmp\goopdate.dll
  • %Program Files%\GUM2.tmp\npGoogleUpdate3.dll
  • %Program Files%\GUM2.tmp\GoogleUpdateHelper.msi
  • %Program Files%\GUM2.tmp\GoogleUpdateBroker.exe
  • %Program Files%\GUM2.tmp\GoogleUpdateOnDemand.exe
  • %Program Files%\GUM2.tmp\psmachine.dll
  • %Program Files%\GUM2.tmp\psuser.dll
  • %Program Files%\GUM2.tmp\GoogleCrashHandler64.exe
  • %Program Files%\GUM2.tmp\goopdateres_am.dll
  • %Program Files%\GUM2.tmp\goopdateres_ar.dll
  • %Program Files%\GUM2.tmp\goopdateres_bg.dll
  • %Program Files%\GUM2.tmp\goopdateres_bn.dll
  • %Program Files%\GUM2.tmp\goopdateres_ca.dll
  • %Program Files%\GUM2.tmp\goopdateres_cs.dll
  • %Program Files%\GUM2.tmp\goopdateres_da.dll
  • %Program Files%\GUM2.tmp\goopdateres_de.dll
  • %Program Files%\GUM2.tmp\goopdateres_el.dll
  • %Program Files%\GUM2.tmp\goopdateres_en.dll
  • %Program Files%\GUM2.tmp\goopdateres_en-GB.dll
  • %Program Files%\GUM2.tmp\goopdateres_es.dll
  • %Program Files%\GUM2.tmp\goopdateres_es-419.dll
  • %Program Files%\GUM2.tmp\goopdateres_et.dll
  • %Program Files%\GUM2.tmp\goopdateres_fa.dll
  • %Program Files%\GUM2.tmp\goopdateres_fi.dll
  • %Program Files%\GUM2.tmp\goopdateres_fil.dll
  • %Program Files%\GUM2.tmp\goopdateres_fr.dll
  • %Program Files%\GUM2.tmp\goopdateres_gu.dll
  • %Program Files%\GUM2.tmp\goopdateres_hi.dll
  • %Program Files%\GUM2.tmp\goopdateres_hr.dll
  • %Program Files%\GUM2.tmp\goopdateres_hu.dll
  • %Program Files%\GUM2.tmp\goopdateres_id.dll
  • %Program Files%\GUM2.tmp\goopdateres_is.dll
  • %Program Files%\GUM2.tmp\goopdateres_it.dll
  • %Program Files%\GUM2.tmp\goopdateres_iw.dll
  • %Program Files%\GUM2.tmp\goopdateres_ja.dll
  • %Program Files%\GUM2.tmp\goopdateres_kn.dll
  • %Program Files%\GUM2.tmp\goopdateres_ko.dll
  • %Program Files%\GUM2.tmp\goopdateres_lt.dll
  • %Program Files%\GUM2.tmp\goopdateres_lv.dll
  • %Program Files%\GUM2.tmp\goopdateres_ml.dll
  • %Program Files%\GUM2.tmp\goopdateres_mr.dll
  • %Program Files%\GUM2.tmp\goopdateres_ms.dll
  • %Program Files%\GUM2.tmp\goopdateres_nl.dll
  • %Program Files%\GUM2.tmp\goopdateres_no.dll
  • %Program Files%\GUM2.tmp\goopdateres_pl.dll
  • %Program Files%\GUM2.tmp\goopdateres_pt-BR.dll
  • %Program Files%\GUM2.tmp\goopdateres_pt-PT.dll
  • %Program Files%\GUM2.tmp\goopdateres_ro.dll
  • %Program Files%\GUM2.tmp\goopdateres_ru.dll
  • %Program Files%\GUM2.tmp\goopdateres_sk.dll
  • %Program Files%\GUM2.tmp\goopdateres_sl.dll
  • %Program Files%\GUM2.tmp\goopdateres_sr.dll
  • %Program Files%\GUM2.tmp\goopdateres_sv.dll
  • %Program Files%\GUM2.tmp\goopdateres_sw.dll
  • %Program Files%\GUM2.tmp\goopdateres_ta.dll
  • %Program Files%\GUM2.tmp\goopdateres_te.dll
  • %Program Files%\GUM2.tmp\goopdateres_th.dll
  • %Program Files%\GUM2.tmp\goopdateres_tr.dll
  • %Program Files%\GUM2.tmp\goopdateres_uk.dll
  • %Program Files%\GUM2.tmp\goopdateres_ur.dll
  • %Program Files%\GUM2.tmp\goopdateres_vi.dll
  • %Program Files%\GUM2.tmp\goopdateres_zh-CN.dll
  • %Program Files%\GUM2.tmp\goopdateres_zh-TW.dll
  • %Windows%\Tasks\GoogleUpdateTaskMachineCore.job
  • %Windows%\Tasks\GoogleUpdateTaskMachineUA.job

手順 5

以下のフォルダを検索し削除します。

[ 詳細 ]
フォルダが隠しフォルダ属性に設定されている場合があります。[詳細設定オプション]をクリックし、[隠しファイルとフォルダの検索]のチェックボックスをオンにし、検索結果に隠しファイルとフォルダが含まれるようにしてください。
  • %Program Files%\GUM2.tmp
  • %Application Data%\Google
  • %Application Data%\Google\CrashReports
  • %Program Files%\Google
  • %Program Files%\Google\CrashReports
  • %Program Files%\Google\Update
  • %Program Files%\Google\Update\1.3.21.165
  • %Program Files%\Google\Update\Offline
  • %Program Files%\Google\Update\Offline\{5E76E45C-A5D5-4C8D-AF56-6A88291554A0}
  • %Program Files%\Google\Update\Download
  • %Program Files%\Google\Update\Install

手順 6

最新のバージョン(エンジン、パターンファイル)を導入したウイルス対策製品を用い、ウイルス検索を実行してください。「TROJ_BANBRA.WWO」と検出したファイルはすべて削除してください。 検出されたファイルが、弊社ウイルス対策製品により既に駆除、隔離またはファイル削除の処理が実行された場合、ウイルスの処理は完了しており、他の削除手順は特にありません。

手順 7

以下のファイルをバックアップを用いて修復します。なお、マイクロソフト製品に関連したファイルのみ修復されます。このマルウェア/グレイウェア/スパイウェアが同社製品以外のプログラムをも削除した場合には、該当プログラムを再度インストールする必要があります。

  • %Program Files%\GUM2.tmp
  • %Program Files%\GUT5.tmp
  • %Windows%\Tasks\GoogleUpdateTask.job
  • %Windows%\Tasks\GoogleUpdateTaskMachine.job

手順 8

以下の削除されたレジストリキーまたはレジストリ値をバックアップを用いて修復します。

※註:マイクロソフト製品に関連したレジストリキーおよびレジストリ値のみが修復されます。このマルウェアもしくはアドウェア等が同社製品以外のプログラムも削除した場合には、該当プログラムを再度インストールする必要があります。

  • In HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\UsageStats\Daily
    • Timings
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\UsageStats\Daily
    • Booleans
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\Clients
    • {430FD4D0-B729-4F61-AA34-91526481799D}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update
    • Clients
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState
    • {430FD4D0-B729-4F61-AA34-91526481799D}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState
    • {8A69D345-D564-463C-AFF1-A69D9E530F96}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update
    • ClientState
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium
    • {8A69D345-D564-463C-AFF1-A69D9E530F96}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update
    • ClientStateMedium
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update
    • network
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update
    • uid
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\UsageStats
    • Daily
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update
    • UsageStats
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2E629606-312A-482F-9B12-2C4ABF6F0B6D}
    • AsynchronousInterface
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{31AC3F11-E5EA-4A85-8A3D-8E095A39C27B}
    • AsynchronousInterface
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8476CE12-AE1F-4198-805C-BA0F9B783F57}
    • AsynchronousInterface
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0CD01D1E-4A1C-489D-93B9-9B6672877C57}
    • AsynchronousInterface
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4E223325-C16B-4EEB-AEDC-19AA99A237FA}
    • AsynchronousInterface
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BCDCB538-01C0-46D1-A6A7-52F4D021C272}
    • AsynchronousInterface
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{49D7563B-2DDB-4831-88C8-768A53833837}
    • AsynchronousInterface
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DAB1D343-1B2A-47F9-B445-93DC50704BFE}
    • AsynchronousInterface
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3D05F64F-71E3-48A5-BF6B-83315BC8AE1F}
    • AsynchronousInterface
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6DB17455-4E85-46E7-9D23-E555E4B005AF}
    • AsynchronousInterface
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DD42475D-6D46-496A-924E-BD5630B4CBBA}
    • AsynchronousInterface
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D106AB5F-A70E-400E-A21B-96208C1D8DBB}
    • AsynchronousInterface
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B3A47570-0A85-4AEA-8270-529D47899603}
    • AsynchronousInterface
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{18D0F672-18B4-48E6-AD36-6E6BF01DBBC4}
    • AsynchronousInterface
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2D363682-561D-4C3A-81C6-F2F82107562A}
    • AsynchronousInterface
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DCAB8386-4F03-4DBD-A366-D90BC9F68DE6}
    • AsynchronousInterface
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{76F7B787-A67C-4C73-82C7-31F5E3AABC5C}
    • AsynchronousInterface
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{128C2DA6-2BC0-44C0-B3F6-4EC22E647964}
    • AsynchronousInterface
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{084D78A8-B084-4E14-A629-A2C419B0E3D9}
    • AsynchronousInterface
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{909489C2-85A6-4322-AA56-D25278649D67}
    • AsynchronousInterface
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{494B20CF-282E-4BDD-9F5D-B70CB09D351E}
    • AsynchronousInterface
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5B25A8DC-1780-4178-A629-6BE8B8DEFAA2}
    • AsynchronousInterface
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FE908CDD-22BB-472A-9870-1A0390E42F36}
    • AsynchronousInterface
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C642CED-CA3B-4013-A9DF-CA6CE5FF6503}
    • AsynchronousInterface
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5CCCB0EF-7073-4516-8028-4C628D0C8AAB}
    • AsynchronousInterface
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{247954F9-9EDC-4E68-8CC3-150C2B89EADF}
    • AsynchronousInterface
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4DE778FE-F195-4EE3-9DAB-FE446C239221}
    • AsynchronousInterface
  • In HKEY_CURRENT_USER\Software\Google\Update
    • uid


ご利用はいかがでしたか? アンケートにご協力ください