Trend Micro Security

TROJ_PAM_0000050366.T3

2012年10月13日

 別名:

Generic Downloader.x!gk3 (McAfee); Trojan.Adclicker (Symantec); ARC:NSIS (Kaspersky); Trojan.Adclicker (Sunbelt)

 プラットフォーム:

Windows 2000, Windows XP, Windows Server 2003

 危険度:
 ダメージ度:
 感染力:
 感染確認数:


  • マルウェアタイプ: トロイの木馬型
  • 破壊活動の有無: なし
  • 暗号化:  
  • 感染報告の有無: はい

  概要


マルウェアは、他のマルウェアに作成されるか、悪意あるWebサイトからユーザが誤ってダウンロードすることによりコンピュータに侵入します。


  詳細

ファイルサイズ 185,278 bytes
タイプ EXE
メモリ常駐 なし
発見日 2012年7月21日

侵入方法

マルウェアは、他のマルウェアに作成されるか、悪意あるWebサイトからユーザが誤ってダウンロードすることによりコンピュータに侵入します。

インストール

マルウェアは、以下のフォルダを作成します。

  • %System Root%\DOCUME~1
  • %System Root%\DOCUME~1\ADMINI~1
  • %User Profile%\LOCALS~1
  • %User Temp%\nsz2.tmp
  • %Program Files%\1ClickDownload
  • %System Root%\Documents and Settings\Administrator
  • %User Profile%\Application Data\Mozilla
  • %User Profile%\Mozilla\Firefox
  • %User Profile%\Firefox\Profiles
  • %User Profile%\Profiles\extensions
  • %Desktop%\IPL (All teams theme songs)
  • %User Temp%\F7BCB783-BAB0-7891-A2D4-A55145871553
  • HtmlScreens
  • %User Profile%\Application Data\Babylon
  • %Program Files%\Babylon
  • %Program Files%\Babylon\Babylon-Pro
  • %Application Data%\Babylon
  • %Application Data%\Babylon\Setup
  • %User Temp%\nsz7.tmp
  • %User Profile%\Profiles\extensions
  • %User Profile%\extensions \extensions
  • %Program Files%\Mozilla Firefox
  • %Program Files%\Mozilla Firefox\extensions
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com
  • %User Temp%\BabylonToolbar
  • %User Temp%\BabylonToolbar\BabylonToolbar
  • %User Temp%\BabylonToolbar\BabylonToolbar\1.5.3.17
  • %User Temp%\nsc18.tmp
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\components
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\defaults
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\defaults\preferences
  • %Program Files%\Mozilla Firefox\searchplugins
  • %User Temp%\nsa1E.tmp
  • %Program Files%\BabylonToolbar
  • %Program Files%\BabylonToolbar\BabylonToolbar
  • %Program Files%\BabylonToolbar\BabylonToolbar\1.5.3.17
  • %Program Files%\BabylonToolbar\BabylonToolbar\1.5.3.17\bh

自動実行方法

マルウェアは、以下のレジストリキーを追加し、自身をBrowser Helper Object(BHO)として登録します。これにより、Internet Explorer(IE)が起動するとマルウェアが自動実行されます。

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Explorer\
Browser Helper Objects\{2EECD738-5844-4a99-B4B6-146BF802613B}

他のシステム変更

マルウェアは、以下のファイルを削除します。

  • %User Temp%\nsk1.tmp
  • %User Temp%\nsz2.tmp
  • %User Temp%\nse4.tmp
  • %User Temp%\nse5.tmp
  • %User Temp%\nst3.tmp
  • %User Profile%\Babylon\BabAll.dat.tmp
  • %User Temp%\nsk6.tmp
  • %User Temp%\nsz7.tmp
  • %User Temp%\nsn17.tmp
  • %User Temp%\nsc18.tmp
  • %Program Files%\Mozilla Firefox\user.js
  • %User Temp%\nsk1D.tmp
  • %User Temp%\nsa1E.tmp

(註:%User Temp%はWindowsの種類とインストール時の設定などにより異なります。標準設定では、Windows 98 および MEの場合、"C:\Windows\Temp"、Windows NT の場合、"C:\Profiles\<ユーザー名>\TEMP"、Windows 2000、XP、Server 2003 の場合、"C:\Documents and Settings\<ユーザー名>\Local Settings\TEMP" です。. %User Profile% フォルダは、Windows 98 および MEの場合、"C:\Windows\Profiles\<ユーザ名>"、Windows NTでは、"C:\WINNT\Profiles\<ユーザ名>"、Windows 2000, XP, Server 2003の場合は、"C:\Documents and Settings\<ユーザ名>" です。. %Program Files%は、標準設定では "C:\Program Files" です。)

マルウェアは、以下のレジストリキーを追加します。

HKEY_CURRENT_USER\SOFTWARE\1ClickDownload

HKEY_LOCAL_MACHINE\Software\Microsoft\
Windows\CurrentVersion\Uninstall\
1ClickDownloader

HKEY_LOCAL_MACHINE\Software\Google\
Chrome\Extensions\jplinpmadfkdgipabgcdchbdikologlh

HKEY_CLASSES_ROOT\AppID\{5B1881D1-D9C7-46df-B041-1E593282C7D0}\
Instl\Data

HKEY_CLASSES_ROOT\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}\
Instl\Data

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
BabylonToolbar

HKEY_CURRENT_USER\Software\SweetIM

HKEY_LOCAL_MACHINE\Software\SweetIM

HKEY_CURRENT_USER\Software\BabyTest

HKEY_LOCAL_MACHINE\Software\BabyTest

HKEY_CLASSES_ROOT\Test.cap

HKEY_LOCAL_MACHINE\Software\Babylon\
Babylon Client

HKEY_LOCAL_MACHINE\Software\Babylon\
Babylon Client\DefaultSettings

HKEY_CLASSES_ROOT\Prod.cap

HKEY_LOCAL_MACHINE\SOFTWARE\BabylonToolbar\
BabylonToolbar\Instl

HKEY_CURRENT_USER\SOFTWARE\BabylonToolbar\
BabylonToolbar

HKEY_CLASSES_ROOT\AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}\
instl\data

HKEY_CURRENT_USER\Software\BabylonToolbar\
BabylonToolbar\user

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\escorTlbr.DLL

HKEY_CLASSES_ROOT\Babylon.dskBnd.1

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Babylon.dskBnd.1\CLSID

HKEY_CLASSES_ROOT\Babylon.dskBnd

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Babylon.dskBnd\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Babylon.dskBnd\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{98889811-442D-49dd-99D7-DC866BE87DBC}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{98889811-442D-49dd-99D7-DC866BE87DBC}\ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{98889811-442D-49dd-99D7-DC866BE87DBC}\VersionIndependentProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{98889811-442D-49dd-99D7-DC866BE87DBC}\Programmable

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{98889811-442D-49dd-99D7-DC866BE87DBC}\InprocServer32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{98889811-442D-49dd-99D7-DC866BE87DBC}\TypeLib

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}\1.0

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}\1.0\
FLAGS

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}\1.0\
0

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}\1.0\
0\win32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}\1.0\
HELPDIR

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Internet Explorer\Low Rights\ElevationPolicy\
{8375D9C8-634F-4ECB-8CF5-C7416BA5D542}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Explorer\
Browser Helper Objects

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{09C554C3-109B-483C-A06B-F14172F1A947}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\escort.DLL

HKEY_CLASSES_ROOT\escort.escortIEPane.1

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
escort.escortIEPane.1\CLSID

HKEY_CLASSES_ROOT\escort.escortIEPane

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
escort.escortIEPane\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
escort.escortIEPane\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{97F2FF5B-260C-4ccf-834A-2DDA4E29E39E}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{97F2FF5B-260C-4ccf-834A-2DDA4E29E39E}\ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{97F2FF5B-260C-4ccf-834A-2DDA4E29E39E}\VersionIndependentProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{97F2FF5B-260C-4ccf-834A-2DDA4E29E39E}\Programmable

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{97F2FF5B-260C-4ccf-834A-2DDA4E29E39E}\InprocServer32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{97F2FF5B-260C-4ccf-834A-2DDA4E29E39E}\TypeLib

HKEY_CLASSES_ROOT\escort.escrtBtn.1

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
escort.escrtBtn.1\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
escort.escrtBtn.1\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{E46C8196-B634-44a1-AF6E-957C64278AB1}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{E46C8196-B634-44a1-AF6E-957C64278AB1}\ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{E46C8196-B634-44a1-AF6E-957C64278AB1}\VersionIndependentProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{E46C8196-B634-44a1-AF6E-957C64278AB1}\Programmable

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{E46C8196-B634-44a1-AF6E-957C64278AB1}\InprocServer32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{E46C8196-B634-44a1-AF6E-957C64278AB1}\TypeLib

HKEY_CLASSES_ROOT\bbylntlbr.bbylntlbrHlpr.1

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
bbylntlbr.bbylntlbrHlpr.1\CLSID

HKEY_CLASSES_ROOT\bbylntlbr.bbylntlbrHlpr

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
bbylntlbr.bbylntlbrHlpr\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
bbylntlbr.bbylntlbrHlpr\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{2EECD738-5844-4a99-B4B6-146BF802613B}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{2EECD738-5844-4a99-B4B6-146BF802613B}\ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{2EECD738-5844-4a99-B4B6-146BF802613B}\VersionIndependentProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{2EECD738-5844-4a99-B4B6-146BF802613B}\Programmable

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{2EECD738-5844-4a99-B4B6-146BF802613B}\InprocServer32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{2EECD738-5844-4a99-B4B6-146BF802613B}\TypeLib

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{97F2FF5B-260C-4ccf-834A-2DDA4E29E39E}\Implemented Categories

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{97F2FF5B-260C-4ccf-834A-2DDA4E29E39E}\Implemented Categories\
{00021493-0000-0000-C000-000000000046}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{97F2FF5B-260C-4ccf-834A-2DDA4E29E39E}\Instance

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{97F2FF5B-260C-4ccf-834A-2DDA4E29E39E}\Instance\
InitPropertyBag

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\escortApp.DLL

HKEY_CLASSES_ROOT\bbylnApp.appCore.1

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
bbylnApp.appCore.1\CLSID

HKEY_CLASSES_ROOT\bbylnApp.appCore

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
bbylnApp.appCore\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
bbylnApp.appCore\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{FFB9ADCB-8C79-4C29-81D3-74D46A93D370}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{FFB9ADCB-8C79-4C29-81D3-74D46A93D370}\ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{FFB9ADCB-8C79-4C29-81D3-74D46A93D370}\VersionIndependentProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{FFB9ADCB-8C79-4C29-81D3-74D46A93D370}\Programmable

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{FFB9ADCB-8C79-4C29-81D3-74D46A93D370}\InprocServer32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{FFB9ADCB-8C79-4C29-81D3-74D46A93D370}\TypeLib

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}\1.0

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}\1.0\
FLAGS

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}\1.0\
0

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}\1.0\
0\win32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}\1.0\
HELPDIR

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{6E8BF012-2C85-4834-B10A-1B31AF173D70}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{6E8BF012-2C85-4834-B10A-1B31AF173D70}\1.0

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{6E8BF012-2C85-4834-B10A-1B31AF173D70}\1.0\
FLAGS

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{6E8BF012-2C85-4834-B10A-1B31AF173D70}\1.0\
0

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{6E8BF012-2C85-4834-B10A-1B31AF173D70}\1.0\
0\win32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{6E8BF012-2C85-4834-B10A-1B31AF173D70}\1.0\
HELPDIR

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E}\ProxyStubClsid

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E}\ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E}\TypeLib

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A}\ProxyStubClsid

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A}\ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A}\TypeLib

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997}\ProxyStubClsid

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997}\ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997}\TypeLib

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1}\ProxyStubClsid

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1}\ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1}\TypeLib

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F}\ProxyStubClsid

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F}\ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F}\TypeLib

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599}\ProxyStubClsid

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599}\ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599}\TypeLib

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{B32672B3-F656-46E0-B584-FE61C0BB6037}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{B32672B3-F656-46E0-B584-FE61C0BB6037}\ProxyStubClsid

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{B32672B3-F656-46E0-B584-FE61C0BB6037}\ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{B32672B3-F656-46E0-B584-FE61C0BB6037}\TypeLib

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{706D4A4B-184A-4434-B331-296B07493D2D}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{706D4A4B-184A-4434-B331-296B07493D2D}\ProxyStubClsid

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{706D4A4B-184A-4434-B331-296B07493D2D}\ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{706D4A4B-184A-4434-B331-296B07493D2D}\TypeLib

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C2996524-2187-441F-A398-CD6CB6B3D020}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C2996524-2187-441F-A398-CD6CB6B3D020}\ProxyStubClsid

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C2996524-2187-441F-A398-CD6CB6B3D020}\ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C2996524-2187-441F-A398-CD6CB6B3D020}\TypeLib

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD}\ProxyStubClsid

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD}\ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD}\TypeLib

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{BFE569F7-646C-4512-969B-9BE3E580D393}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{BFE569F7-646C-4512-969B-9BE3E580D393}\ProxyStubClsid

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{BFE569F7-646C-4512-969B-9BE3E580D393}\ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{BFE569F7-646C-4512-969B-9BE3E580D393}\TypeLib

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{B173667F-8395-4317-8DD6-45AD1FE00047}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{B173667F-8395-4317-8DD6-45AD1FE00047}\ProxyStubClsid

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{B173667F-8395-4317-8DD6-45AD1FE00047}\ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{B173667F-8395-4317-8DD6-45AD1FE00047}\TypeLib

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{8BE10F21-185F-4CA0-B789-9921674C3993}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{8BE10F21-185F-4CA0-B789-9921674C3993}\ProxyStubClsid

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{8BE10F21-185F-4CA0-B789-9921674C3993}\ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{8BE10F21-185F-4CA0-B789-9921674C3993}\TypeLib

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68}\ProxyStubClsid

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68}\ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68}\TypeLib

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\escortEng.DLL

HKEY_CLASSES_ROOT\b

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
b\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
b\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{B8276A94-891D-453C-9FF3-715C042A2575}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{B8276A94-891D-453C-9FF3-715C042A2575}\ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{B8276A94-891D-453C-9FF3-715C042A2575}\VersionIndependentProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{B8276A94-891D-453C-9FF3-715C042A2575}\Programmable

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{B8276A94-891D-453C-9FF3-715C042A2575}\InprocServer32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{B8276A94-891D-453C-9FF3-715C042A2575}\TypeLib

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{35C1605E-438B-4D64-AAB1-8885F097A9B1}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\esrv.EXE

HKEY_CLASSES_ROOT\esrv.BabylonESrvc.1

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
esrv.BabylonESrvc.1\CLSID

HKEY_CLASSES_ROOT\esrv.BabylonESrvc

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
esrv.BabylonESrvc\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
esrv.BabylonESrvc\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{291BCCC1-6890-484a-89D3-318C928DAC1B}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{291BCCC1-6890-484a-89D3-318C928DAC1B}\ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{291BCCC1-6890-484a-89D3-318C928DAC1B}\VersionIndependentProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{291BCCC1-6890-484a-89D3-318C928DAC1B}\Programmable

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{291BCCC1-6890-484a-89D3-318C928DAC1B}\LocalServer32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{291BCCC1-6890-484a-89D3-318C928DAC1B}\TypeLib

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{35C1605E-438B-4D64-AAB1-8885F097A9B1}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{35C1605E-438B-4D64-AAB1-8885F097A9B1}\1.0

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{35C1605E-438B-4D64-AAB1-8885F097A9B1}\1.0\
FLAGS

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{35C1605E-438B-4D64-AAB1-8885F097A9B1}\1.0\
0

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{35C1605E-438B-4D64-AAB1-8885F097A9B1}\1.0\
0\win32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{35C1605E-438B-4D64-AAB1-8885F097A9B1}\1.0\
HELPDIR

マルウェアは、以下のレジストリ値を追加します。

HKEY_CURRENT_USER\Software\1ClickDownload
UID = "403898365"

HKEY_CURRENT_USER\Software\1ClickDownload
LastInstall = "30226544"

HKEY_CURRENT_USER\Software\1ClickDownload
LastInstall2 = "30226544"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
1ClickDownloader
DisplayName = "1ClickDownloader"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
1ClickDownloader
UninstallString = "%Program Files%\1ClickDownload\uninstall.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
1ClickDownloader
DisplayVersion = "2.1 Build 26473"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
1ClickDownloader
Publisher = "1ClickDownload"

HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Chrome\Extensions\jplinpmadfkdgipabgcdchbdikologlh
path = "%Program Files%\1ClickDownload\1click11.crx"

HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Chrome\Extensions\jplinpmadfkdgipabgcdchbdikologlh
version = "1.1"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{5B1881D1-D9C7-46df-B041-1E593282C7D0}\Instl\
Data
afltId = "11111111"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{5B1881D1-D9C7-46df-B041-1E593282C7D0}\Instl\
Data
hrdId = "11111111"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{5B1881D1-D9C7-46df-B041-1E593282C7D0}\Instl\
Data
prtnrId = "11111111"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}\Instl\
Data
afltId = "11111111"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}\Instl\
Data
hrdId = "11111111"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}\Instl\
Data
prtnrId = "11111111"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
BabylonToolbar
InstallDate = "20120308"

HKEY_CURRENT_USER\Software\SweetIM
simapp_id = "11111111"

HKEY_LOCAL_MACHINE\SOFTWARE\SweetIM
simapp_id = "11111111"

HKEY_LOCAL_MACHINE\SOFTWARE\Babylon\
Babylon Client\DefaultSettings
SetSearch = "3"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Prod.cap
tb = "mntr903"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Prod.cap
Info = "{random values}"

HKEY_LOCAL_MACHINE\SOFTWARE\BabylonToolbar\
BabylonToolbar\Instl
babTrack = "affID=109217"

HKEY_LOCAL_MACHINE\SOFTWARE\BabylonToolbar\
BabylonToolbar\Instl
srcExt = "ss"

HKEY_CURRENT_USER\Software\BabylonToolbar\
BabylonToolbar
tlbrSrchUrl = "${TLBRSRCH_URL}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}\instl\
data
tlbrSrchUrl = "${TLBRSRCH_URL}"

HKEY_CURRENT_USER\Software\BabylonToolbar\
BabylonToolbar\user
dfltLng = "en"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}\instl\
data
dfltLng = "en"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}\instl\
data
instlRef = "sst"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\escorTlbr.DLL
AppID = "{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{98889811-442D-49dd-99D7-DC866BE87DBC}\InprocServer32
ThreadingModel = "apartment"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{98889811-442D-49dd-99D7-DC866BE87DBC}
AppID = "{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Internet Explorer\Toolbar
{98889811-442D-49dd-99D7-DC866BE87DBC} = "Babylon Toolbar"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Internet Explorer\Low Rights\ElevationPolicy\
{8375D9C8-634F-4ECB-8CF5-C7416BA5D542}
Policy = "3"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Internet Explorer\Low Rights\ElevationPolicy\
{8375D9C8-634F-4ECB-8CF5-C7416BA5D542}
AppName = "BabylonToolbarsrv.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Internet Explorer\Low Rights\ElevationPolicy\
{8375D9C8-634F-4ECB-8CF5-C7416BA5D542}
AppPath = "%Program Files%\BabylonToolbar\BabylonToolbar\1.5.3.17"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Explorer\
Browser Helper Objects\{2EECD738-5844-4a99-B4B6-146BF802613B}
NoExplorer = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\escort.DLL
AppID = "{09C554C3-109B-483C-A06B-F14172F1A947}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{97F2FF5B-260C-4ccf-834A-2DDA4E29E39E}\InprocServer32
ThreadingModel = "apartment"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{97F2FF5B-260C-4ccf-834A-2DDA4E29E39E}
AppID = "{09C554C3-109B-483C-A06B-F14172F1A947}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{E46C8196-B634-44a1-AF6E-957C64278AB1}\InprocServer32
ThreadingModel = "apartment"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{E46C8196-B634-44a1-AF6E-957C64278AB1}
AppID = "{09C554C3-109B-483C-A06B-F14172F1A947}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{2EECD738-5844-4a99-B4B6-146BF802613B}\InprocServer32
ThreadingModel = "apartment"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{2EECD738-5844-4a99-B4B6-146BF802613B}
AppID = "{09C554C3-109B-483C-A06B-F14172F1A947}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{97F2FF5B-260C-4ccf-834A-2DDA4E29E39E}\Instance
CLSID = "{97F2FF5B-260C-4ccf-834A-2DDA4E29E39E}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{97F2FF5B-260C-4ccf-834A-2DDA4E29E39E}\Instance\
InitPropertyBag
URL = "about:blank"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\escortApp.DLL
AppID = "{D7EE8177-D51E-4F89-92B6-83EA2EC40800}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{FFB9ADCB-8C79-4C29-81D3-74D46A93D370}\InprocServer32
ThreadingModel = "apartment"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{FFB9ADCB-8C79-4C29-81D3-74D46A93D370}
AppID = "{D7EE8177-D51E-4F89-92B6-83EA2EC40800}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}\instl\
data
afltId = "orgnl"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}\instl\
data
cntrlId = "f0bdff950000000000000050568e00d9"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}\instl\
data
hrdId = "f0bdff950000000000000050568e00d9"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}\instl\
data
instlDay = "3c7b"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}\instl\
data
prtnrId = "BabylonToolbar"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}\instl\
data
sftId = "f36d58294bf541c59e3506a513a4fe12"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E}\TypeLib
Version = "1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A}\TypeLib
Version = "1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997}\TypeLib
Version = "1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1}\TypeLib
Version = "1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F}\TypeLib
Version = "1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599}\TypeLib
Version = "1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{B32672B3-F656-46E0-B584-FE61C0BB6037}\TypeLib
Version = "1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{706D4A4B-184A-4434-B331-296B07493D2D}\TypeLib
Version = "1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C2996524-2187-441F-A398-CD6CB6B3D020}\TypeLib
Version = "1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD}\TypeLib
Version = "1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{BFE569F7-646C-4512-969B-9BE3E580D393}\TypeLib
Version = "1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{B173667F-8395-4317-8DD6-45AD1FE00047}\TypeLib
Version = "1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{8BE10F21-185F-4CA0-B789-9921674C3993}\TypeLib
Version = "1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68}\TypeLib
Version = "1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\escortEng.DLL
AppID = "{B12E99ED-69BD-437C-86BE-C862B9E5444D}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{B8276A94-891D-453C-9FF3-715C042A2575}\InprocServer32
ThreadingModel = "apartment"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{B8276A94-891D-453C-9FF3-715C042A2575}
AppID = "{B12E99ED-69BD-437C-86BE-C862B9E5444D}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}\instl\
data
vrsni = "1.5.3.17"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}\instl\
data
afltId = "babsst"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}\instl\
data
smplGrp = "none"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}\instl\
data
tlbrId = "base"

HKEY_LOCAL_MACHINE\SOFTWARE\BabylonToolbar\
BabylonToolbar\Instl
InstallDir = "%Program Files%\BabylonToolbar\BabylonToolbar\1.5.3.17"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
BabylonToolbar
DisplayName = "Babylon toolbar on IE"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
BabylonToolbar
UninstallString = "%Program Files%\BabylonToolbar\BabylonToolbar\1.5.3.17\uninstall.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
BabylonToolbar
NoModify = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
BabylonToolbar
NoRepair = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\esrv.EXE
AppID = "{35C1605E-438B-4D64-AAB1-8885F097A9B1}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{291BCCC1-6890-484a-89D3-318C928DAC1B}\LocalServer32
ThreadingModel = "apartment"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{291BCCC1-6890-484a-89D3-318C928DAC1B}
AppID = "{35C1605E-438B-4D64-AAB1-8885F097A9B1}"

マルウェアは、以下のレジストリ値を変更します。

HKEY_CURRENT_USER\Software\Microsoft\
Internet Explorer\Main
Start Page = "{random characters}"

(註:変更前の上記レジストリ値は、「http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome」となります。)

マルウェアは、以下のレジストリキーを削除します。

HKEY_LOCAL_MACHINE\Software\Babylon

HKEY_LOCAL_MACHINE\Software\BabylonToolbar\
BabylonToolbar\SearchRestore

HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Explorer\
Discardable\PostSetup\Component Categories\
{00021494-0000-0000-C000-000000000046}\Enum

HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Explorer\
Discardable\PostSetup\Component Categories\
{00021493-0000-0000-C000-000000000046}\Enum

作成活動

マルウェアは、以下のファイルを作成します。

  • %User Temp%\nsz2.tmp\System.dll
  • %User Temp%\nsz2.tmp\NSISdl.dll
  • %User Temp%\nsz2.tmp\getCountry
  • %User Temp%\nsz2.tmp\inetc3.dll
  • %User Temp%\nsz2.tmp\gC0
  • 35
  • %Program Files%\1ClickDownload\IPL_(All_teams_theme_songs).magnet
  • mainpacklt.exe
  • %User Temp%\nsz2.tmp\nsDialogs.dll
  • %User Temp%\nsz2.tmp\skip.bmp
  • %User Temp%\nsz2.tmp\accept.bmp
  • %User Temp%\nsz2.tmp\accept1.bmp
  • %User Temp%\nsz2.tmp\accept2.bmp
  • %User Temp%\nsz2.tmp\accept3.bmp
  • %User Temp%\nsz2.tmp\decline.bmp
  • %User Temp%\nsz2.tmp\save.bmp
  • %User Temp%\nsz2.tmp\anon.bmp
  • %User Temp%\nsz2.tmp\1clogo.bmp
  • %User Temp%\nsz2.tmp\yontoo.bmp
  • %User Temp%\nsz2.tmp\1clogobvd.bmp
  • %User Temp%\nsz2.tmp\bab_on.bmp
  • %User Temp%\nsz2.tmp\bab_off.bmp
  • %User Temp%\nsz2.tmp\bab.bmp
  • %User Temp%\nsz2.tmp\fm.bmp
  • %User Temp%\nsz2.tmp\inc.bmp
  • %User Temp%\nsz2.tmp\EBanner.dll
  • %User Temp%\nsz2.tmp\getGFGCountry13
  • %Desktop%\Download IPL_(All_teams_theme_songs).lnk
  • %Program Files%\1ClickDownload\uninstall.exe
  • 1click11.crx
  • 1clicktemp.xpi
  • %User Temp%\nsz2.tmp\KillProcDLL.dll
  • BabDSetup.exe
  • %User Temp%\nsz2.tmp\getGFGCountry6
  • BVDDSetup.exe
  • %Program Files%\1ClickDownload\1ClickDownloader.exe
  • %Program Files%\1ClickDownload\1Click.cfg
  • bab033.tbinst.dat
  • bab091.norecovericon.dat
  • Babylon.dat
  • BExternal.dll
  • cmbx.png
  • common.js
  • eula.html
  • lngs.png
  • page1.css
  • page1.html
  • page1.js
  • page1Lrg.css
  • page2.css
  • page2.html
  • page2.js
  • page2Lrg.css
  • page9.html
  • pBar.gif
  • title1.png
  • title2.png
  • toolBar.jpg
  • vIcn.png
  • IECookieLow.dll
  • Setup.exe
  • SetupStrings.dat
  • sqlite3.dll
  • %User Temp%\F7BCB783-BAB0-7891-A2D4-A55145871553\Welcome.html
  • %Application Data%\Babylon\Setup\BExternal.zpb
  • %Application Data%\Babylon\Setup\Setup-tbmntr903.zpb
  • BabylonTB.xpi
  • MyBabylonTB.exe
  • TBConfig.inf
  • %User Temp%\nsz7.tmp\UserInfo.dll
  • %User Temp%\nsz7.tmp\System.dll
  • %User Temp%\nsz7.tmp\nsisos.dll
  • %User Temp%\F7BCB783-BAB0-7891-A2D4-A55145871553\nsa8.tmp
  • %User Temp%\F7BCB783-BAB0-7891-A2D4-A55145871553\nsq9.tmp
  • %User Temp%\nsz7.tmp\mt.dll
  • %User Temp%\nsz7.tmp\Time.dll
  • %User Temp%\F7BCB783-BAB0-7891-A2D4-A55145871553\nsgA.tmp
  • %User Temp%\F7BCB783-BAB0-7891-A2D4-A55145871553\nsgB.tmp
  • %User Temp%\F7BCB783-BAB0-7891-A2D4-A55145871553\nsvC.tmp
  • %User Temp%\F7BCB783-BAB0-7891-A2D4-A55145871553\nslD.tmp
  • %User Temp%\F7BCB783-BAB0-7891-A2D4-A55145871553\nsaE.tmp
  • %User Temp%\F7BCB783-BAB0-7891-A2D4-A55145871553\nsqF.tmp
  • %User Temp%\F7BCB783-BAB0-7891-A2D4-A55145871553\nsg10.tmp
  • %User Temp%\F7BCB783-BAB0-7891-A2D4-A55145871553\nsg11.tmp
  • %User Temp%\F7BCB783-BAB0-7891-A2D4-A55145871553\nsv12.tmp
  • %User Temp%\F7BCB783-BAB0-7891-A2D4-A55145871553\nsl13.tmp
  • %User Temp%\F7BCB783-BAB0-7891-A2D4-A55145871553\nsb14.tmp
  • %User Temp%\F7BCB783-BAB0-7891-A2D4-A55145871553\nsq15.tmp
  • %User Temp%\F7BCB783-BAB0-7891-A2D4-A55145871553\nsg16.tmp
  • %User Temp%\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbar4ffx.exe
  • %User Temp%\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbar4ie.exe
  • %User Temp%\F7BCB783-BAB0-7891-A2D4-A55145871553\nsq1F.tmp
  • %User Temp%\nsz7.tmp\InetLoad.dll
  • %User Temp%\BabylonToolbar\BabylonToolbar\1.5.3.17\nsis.js
  • %User Temp%\nsc18.tmp\nsisos.dll
  • %User Temp%\nsc18.tmp\System.dll
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\chrome.manifest
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\install.rdf
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\components\acplus-autocomplete.js
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\babylon.css
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\babylon.xul
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\server.js
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\tmplt.js
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\arwDwn.gif
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\bbyln.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\help_16.gif
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\home.gif
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\logo.PNG
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\privecy_16_hot.gif
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\tellafriend.gif
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\vssver.scc
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\Thumbs.db
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ae.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\bg.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ch.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\cn.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\cz.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\de.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\eg.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\en.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\es.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\fr.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\gr.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\he.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\il.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\it.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ja.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\jp.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\nl.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\no.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\pl.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\pt.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ro.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ru.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\sa.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\se.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\sv.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\tr.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ua.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\us.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\defaults\preferences\instlPref.js
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\mtstart.js
  • %User Temp%\BabylonToolbar\BabylonToolbar\1.5.3.17\nsx19.tmp
  • %User Temp%\BabylonToolbar\BabylonToolbar\1.5.3.17\nsd1A.tmp
  • %User Temp%\BabylonToolbar\BabylonToolbar\1.5.3.17\nss1B.tmp
  • %User Temp%\BabylonToolbar\BabylonToolbar\1.5.3.17\nsx1C.tmp
  • %User Temp%\nsa1E.tmp\UserInfo.dll
  • %User Temp%\nsa1E.tmp\System.dll
  • %User Temp%\nsa1E.tmp\nsisos.dll
  • %User Temp%\nsa1E.tmp\mt.dll
  • %User Temp%\nsa1E.tmp\Time.dll
  • %Program Files%\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll
  • %Program Files%\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarApp.dll
  • %Program Files%\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarEng.dll
  • %Program Files%\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll
  • %Program Files%\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarsrv.exe
  • %User Temp%\BabylonToolbar\BabylonToolbar\1.5.3.17\nst20.tmp
  • %User Temp%\BabylonToolbar\BabylonToolbar\1.5.3.17\nsi21.tmp
  • %User Temp%\BabylonToolbar\BabylonToolbar\1.5.3.17\nsf22.tmp
  • %Program Files%\BabylonToolbar\BabylonToolbar\1.5.3.17\uninstall.exe
  • %User Temp%\F7BCB783-BAB0-7891-A2D4-A55145871553\BExternal-9.0.3.35.zpb
  • %User Temp%\F7BCB783-BAB0-7891-A2D4-A55145871553\Setup-tbmntr903-9.0.3.35.zpb

その他

マルウェアは、以下の不正なWebサイトにアクセスします。

  • http://data.{BLOCKED}tware.com/country.asp?{random characters}
  • http://data.{BLOCKED}tware.com/MainPackLT.exe
  • http://www.{BLOCKED}n.com/redirects/redir.cgi?{random characters}
  • http://info.{BLOCKED}n.com/setup/downloader.php?{random characters}
  • http://info.{BLOCKED}n.com/{random path}
  • http://data.{BLOCKED}tware.com/reports/jsRprt.srf?{random characters}

このウイルス情報は、自動解析システムにより作成されました。


  対応方法

対応検索エンジン: 9.200

手順 1

Windows XP および Windows Server 2003 のユーザは、コンピュータからマルウェアもしくはアドウェア等を完全に削除するために、ウイルス検索の実行前には必ず「システムの復元」を無効にしてください。

手順 2

起動中ブラウザのウインドウを全て閉じてください。

手順 3

このレジストリキーを削除します。

[ 詳細 ]

警告:レジストリはWindowsの構成情報が格納されているデータベースであり、レジストリの編集内容に問題があると、システムが正常に動作しなくなる場合があります。
レジストリの編集はお客様の責任で行っていただくようお願いいたします。弊社ではレジストリの編集による如何なる問題に対しても補償いたしかねます。
レジストリの編集前にこちらをご参照ください。

  • In HKEY_CURRENT_USER\SOFTWARE
    • 1ClickDownload
  • In HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall
    • 1ClickDownloader
  • In HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions
    • jplinpmadfkdgipabgcdchbdikologlh
  • In HKEY_CLASSES_ROOT\AppID\{5B1881D1-D9C7-46df-B041-1E593282C7D0}\Instl
    • Data
  • In HKEY_CLASSES_ROOT\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}\Instl
    • Data
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
    • BabylonToolbar
  • In HKEY_CURRENT_USER\Software
    • SweetIM
  • In HKEY_LOCAL_MACHINE\Software
    • SweetIM
  • In HKEY_CURRENT_USER\Software
    • BabyTest
  • In HKEY_LOCAL_MACHINE\Software
    • BabyTest
  • In HKEY_CLASSES_ROOT
    • Test.cap
  • In HKEY_LOCAL_MACHINE\Software\Babylon
    • Babylon Client
  • In HKEY_LOCAL_MACHINE\Software\Babylon\Babylon Client
    • DefaultSettings
  • In HKEY_CLASSES_ROOT
    • Prod.cap
  • In HKEY_LOCAL_MACHINE\SOFTWARE\BabylonToolbar\BabylonToolbar
    • Instl
  • In HKEY_CURRENT_USER\SOFTWARE
    • BabylonToolbar
  • In HKEY_CLASSES_ROOT\AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}\instl
    • data
  • In HKEY_CURRENT_USER\Software\BabylonToolbar\BabylonToolbar
    • user
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID
    • {4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID
    • escorTlbr.DLL
  • In HKEY_CLASSES_ROOT
    • Babylon.dskBnd.1
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Babylon.dskBnd.1
    • CLSID
  • In HKEY_CLASSES_ROOT
    • Babylon.dskBnd
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Babylon.dskBnd
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Babylon.dskBnd
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
    • {98889811-442D-49dd-99D7-DC866BE87DBC}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{98889811-442D-49dd-99D7-DC866BE87DBC}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{98889811-442D-49dd-99D7-DC866BE87DBC}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{98889811-442D-49dd-99D7-DC866BE87DBC}
    • Programmable
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{98889811-442D-49dd-99D7-DC866BE87DBC}
    • InprocServer32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{98889811-442D-49dd-99D7-DC866BE87DBC}
    • TypeLib
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib
    • {4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
    • 1.0
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}\1.0
    • FLAGS
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}\1.0
    • 0
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}\1.0\0
    • win32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}\1.0
    • HELPDIR
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy
    • {8375D9C8-634F-4ECB-8CF5-C7416BA5D542}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
    • Browser Helper Objects
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID
    • {09C554C3-109B-483C-A06B-F14172F1A947}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID
    • escort.DLL
  • In HKEY_CLASSES_ROOT
    • escort.escortIEPane.1
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\escort.escortIEPane.1
    • CLSID
  • In HKEY_CLASSES_ROOT
    • escort.escortIEPane
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\escort.escortIEPane
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\escort.escortIEPane
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
    • {97F2FF5B-260C-4ccf-834A-2DDA4E29E39E}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{97F2FF5B-260C-4ccf-834A-2DDA4E29E39E}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{97F2FF5B-260C-4ccf-834A-2DDA4E29E39E}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{97F2FF5B-260C-4ccf-834A-2DDA4E29E39E}
    • Programmable
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{97F2FF5B-260C-4ccf-834A-2DDA4E29E39E}
    • InprocServer32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{97F2FF5B-260C-4ccf-834A-2DDA4E29E39E}
    • TypeLib
  • In HKEY_CLASSES_ROOT
    • escort.escrtBtn.1
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\escort.escrtBtn.1
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\escort.escrtBtn.1
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
    • {E46C8196-B634-44a1-AF6E-957C64278AB1}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E46C8196-B634-44a1-AF6E-957C64278AB1}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E46C8196-B634-44a1-AF6E-957C64278AB1}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E46C8196-B634-44a1-AF6E-957C64278AB1}
    • Programmable
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E46C8196-B634-44a1-AF6E-957C64278AB1}
    • InprocServer32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E46C8196-B634-44a1-AF6E-957C64278AB1}
    • TypeLib
  • In HKEY_CLASSES_ROOT
    • bbylntlbr.bbylntlbrHlpr.1
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1
    • CLSID
  • In HKEY_CLASSES_ROOT
    • bbylntlbr.bbylntlbrHlpr
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
    • {2EECD738-5844-4a99-B4B6-146BF802613B}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2EECD738-5844-4a99-B4B6-146BF802613B}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2EECD738-5844-4a99-B4B6-146BF802613B}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2EECD738-5844-4a99-B4B6-146BF802613B}
    • Programmable
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2EECD738-5844-4a99-B4B6-146BF802613B}
    • InprocServer32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2EECD738-5844-4a99-B4B6-146BF802613B}
    • TypeLib
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{97F2FF5B-260C-4ccf-834A-2DDA4E29E39E}
    • Implemented Categories
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{97F2FF5B-260C-4ccf-834A-2DDA4E29E39E}\Implemented Categories
    • {00021493-0000-0000-C000-000000000046}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{97F2FF5B-260C-4ccf-834A-2DDA4E29E39E}
    • Instance
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{97F2FF5B-260C-4ccf-834A-2DDA4E29E39E}\Instance
    • InitPropertyBag
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID
    • {D7EE8177-D51E-4F89-92B6-83EA2EC40800}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID
    • escortApp.DLL
  • In HKEY_CLASSES_ROOT
    • bbylnApp.appCore.1
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\bbylnApp.appCore.1
    • CLSID
  • In HKEY_CLASSES_ROOT
    • bbylnApp.appCore
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\bbylnApp.appCore
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\bbylnApp.appCore
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
    • {FFB9ADCB-8C79-4C29-81D3-74D46A93D370}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FFB9ADCB-8C79-4C29-81D3-74D46A93D370}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FFB9ADCB-8C79-4C29-81D3-74D46A93D370}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FFB9ADCB-8C79-4C29-81D3-74D46A93D370}
    • Programmable
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FFB9ADCB-8C79-4C29-81D3-74D46A93D370}
    • InprocServer32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FFB9ADCB-8C79-4C29-81D3-74D46A93D370}
    • TypeLib
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib
    • {D7EE8177-D51E-4F89-92B6-83EA2EC40800}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
    • 1.0
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}\1.0
    • FLAGS
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}\1.0
    • 0
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}\1.0\0
    • win32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}\1.0
    • HELPDIR
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib
    • {6E8BF012-2C85-4834-B10A-1B31AF173D70}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6E8BF012-2C85-4834-B10A-1B31AF173D70}
    • 1.0
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6E8BF012-2C85-4834-B10A-1B31AF173D70}\1.0
    • FLAGS
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6E8BF012-2C85-4834-B10A-1B31AF173D70}\1.0
    • 0
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6E8BF012-2C85-4834-B10A-1B31AF173D70}\1.0\0
    • win32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6E8BF012-2C85-4834-B10A-1B31AF173D70}\1.0
    • HELPDIR
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
    • {E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E}
    • ProxyStubClsid
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E}
    • TypeLib
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
    • {44C3C1DB-2127-433C-98EC-4C9412B5FC3A}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A}
    • ProxyStubClsid
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A}
    • TypeLib
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
    • {E77EEF95-3E83-4BB8-9C0D-4A5163774997}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997}
    • ProxyStubClsid
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997}
    • TypeLib
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
    • {4D5132DD-BB2B-4249-B5E0-D145A8C982E1}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1}
    • ProxyStubClsid
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1}
    • TypeLib
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
    • {94C0B25D-3359-4B10-B227-F96A77DB773F}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F}
    • ProxyStubClsid
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F}
    • TypeLib
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
    • {B0B75FBA-7288-4FD3-A9EB-7EE27FA65599}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599}
    • ProxyStubClsid
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599}
    • TypeLib
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
    • {B32672B3-F656-46E0-B584-FE61C0BB6037}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B32672B3-F656-46E0-B584-FE61C0BB6037}
    • ProxyStubClsid
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B32672B3-F656-46E0-B584-FE61C0BB6037}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B32672B3-F656-46E0-B584-FE61C0BB6037}
    • TypeLib
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
    • {706D4A4B-184A-4434-B331-296B07493D2D}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{706D4A4B-184A-4434-B331-296B07493D2D}
    • ProxyStubClsid
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{706D4A4B-184A-4434-B331-296B07493D2D}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{706D4A4B-184A-4434-B331-296B07493D2D}
    • TypeLib
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
    • {C2996524-2187-441F-A398-CD6CB6B3D020}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C2996524-2187-441F-A398-CD6CB6B3D020}
    • ProxyStubClsid
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C2996524-2187-441F-A398-CD6CB6B3D020}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C2996524-2187-441F-A398-CD6CB6B3D020}
    • TypeLib
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
    • {E047E227-5342-4D94-80F7-CFB154BF55BD}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD}
    • ProxyStubClsid
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD}
    • TypeLib
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
    • {BFE569F7-646C-4512-969B-9BE3E580D393}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BFE569F7-646C-4512-969B-9BE3E580D393}
    • ProxyStubClsid
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BFE569F7-646C-4512-969B-9BE3E580D393}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BFE569F7-646C-4512-969B-9BE3E580D393}
    • TypeLib
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
    • {B173667F-8395-4317-8DD6-45AD1FE00047}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B173667F-8395-4317-8DD6-45AD1FE00047}
    • ProxyStubClsid
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B173667F-8395-4317-8DD6-45AD1FE00047}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B173667F-8395-4317-8DD6-45AD1FE00047}
    • TypeLib
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
    • {8BE10F21-185F-4CA0-B789-9921674C3993}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8BE10F21-185F-4CA0-B789-9921674C3993}
    • ProxyStubClsid
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8BE10F21-185F-4CA0-B789-9921674C3993}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8BE10F21-185F-4CA0-B789-9921674C3993}
    • TypeLib
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface
    • {C2434722-5C85-4CA0-BA69-1B67E7AB3D68}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68}
    • ProxyStubClsid
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68}
    • TypeLib
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID
    • {B12E99ED-69BD-437C-86BE-C862B9E5444D}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID
    • escortEng.DLL
  • In HKEY_CLASSES_ROOT
    • b
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\b
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\b
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
    • {B8276A94-891D-453C-9FF3-715C042A2575}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B8276A94-891D-453C-9FF3-715C042A2575}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B8276A94-891D-453C-9FF3-715C042A2575}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B8276A94-891D-453C-9FF3-715C042A2575}
    • Programmable
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B8276A94-891D-453C-9FF3-715C042A2575}
    • InprocServer32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B8276A94-891D-453C-9FF3-715C042A2575}
    • TypeLib
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID
    • {35C1605E-438B-4D64-AAB1-8885F097A9B1}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID
    • esrv.EXE
  • In HKEY_CLASSES_ROOT
    • esrv.BabylonESrvc.1
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\esrv.BabylonESrvc.1
    • CLSID
  • In HKEY_CLASSES_ROOT
    • esrv.BabylonESrvc
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\esrv.BabylonESrvc
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\esrv.BabylonESrvc
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
    • {291BCCC1-6890-484a-89D3-318C928DAC1B}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{291BCCC1-6890-484a-89D3-318C928DAC1B}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{291BCCC1-6890-484a-89D3-318C928DAC1B}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{291BCCC1-6890-484a-89D3-318C928DAC1B}
    • Programmable
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{291BCCC1-6890-484a-89D3-318C928DAC1B}
    • LocalServer32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{291BCCC1-6890-484a-89D3-318C928DAC1B}
    • TypeLib
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib
    • {35C1605E-438B-4D64-AAB1-8885F097A9B1}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{35C1605E-438B-4D64-AAB1-8885F097A9B1}
    • 1.0
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{35C1605E-438B-4D64-AAB1-8885F097A9B1}\1.0
    • FLAGS
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{35C1605E-438B-4D64-AAB1-8885F097A9B1}\1.0
    • 0
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{35C1605E-438B-4D64-AAB1-8885F097A9B1}\1.0\0
    • win32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{35C1605E-438B-4D64-AAB1-8885F097A9B1}\1.0
    • HELPDIR

手順 4

このレジストリ値を削除します。

[ 詳細 ]

警告:レジストリはWindowsの構成情報が格納されているデータベースであり、レジストリの編集内容に問題があると、システムが正常に動作しなくなる場合があります。
レジストリの編集はお客様の責任で行っていただくようお願いいたします。弊社ではレジストリの編集による如何なる問題に対しても補償いたしかねます。
レジストリの編集前にこちらをご参照ください。

  • In HKEY_CURRENT_USER\Software\1ClickDownload
    • UID = "403898365"
  • In HKEY_CURRENT_USER\Software\1ClickDownload
    • LastInstall = "30226544"
  • In HKEY_CURRENT_USER\Software\1ClickDownload
    • LastInstall2 = "30226544"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\1ClickDownloader
    • DisplayName = "1ClickDownloader"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\1ClickDownloader
    • UninstallString = "%Program Files%\1ClickDownload\uninstall.exe"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\1ClickDownloader
    • DisplayVersion = "2.1 Build 26473"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\1ClickDownloader
    • Publisher = "1ClickDownload"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\jplinpmadfkdgipabgcdchbdikologlh
    • path = "%Program Files%\1ClickDownload\1click11.crx"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\jplinpmadfkdgipabgcdchbdikologlh
    • version = "1.1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46df-B041-1E593282C7D0}\Instl\Data
    • afltId = "11111111"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46df-B041-1E593282C7D0}\Instl\Data
    • hrdId = "11111111"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46df-B041-1E593282C7D0}\Instl\Data
    • prtnrId = "11111111"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}\Instl\Data
    • afltId = "11111111"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}\Instl\Data
    • hrdId = "11111111"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}\Instl\Data
    • prtnrId = "11111111"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BabylonToolbar
    • InstallDate = "20120308"
  • In HKEY_CURRENT_USER\Software\SweetIM
    • simapp_id = "11111111"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\SweetIM
    • simapp_id = "11111111"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Babylon\Babylon Client\DefaultSettings
    • SetSearch = "3"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Prod.cap
    • tb = "mntr903"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Prod.cap
    • Info = "{random values}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\BabylonToolbar\BabylonToolbar\Instl
    • babTrack = "affID=109217"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\BabylonToolbar\BabylonToolbar\Instl
    • srcExt = "ss"
  • In HKEY_CURRENT_USER\Software\BabylonToolbar\BabylonToolbar
    • tlbrSrchUrl = "${TLBRSRCH_URL}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}\instl\data
    • tlbrSrchUrl = "${TLBRSRCH_URL}"
  • In HKEY_CURRENT_USER\Software\BabylonToolbar\BabylonToolbar\user
    • dfltLng = "en"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}\instl\data
    • dfltLng = "en"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}\instl\data
    • instlRef = "sst"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\escorTlbr.DLL
    • AppID = "{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{98889811-442D-49dd-99D7-DC866BE87DBC}\InprocServer32
    • ThreadingModel = "apartment"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{98889811-442D-49dd-99D7-DC866BE87DBC}
    • AppID = "{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar
    • {98889811-442D-49dd-99D7-DC866BE87DBC} = "Babylon Toolbar"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8375D9C8-634F-4ECB-8CF5-C7416BA5D542}
    • Policy = "3"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8375D9C8-634F-4ECB-8CF5-C7416BA5D542}
    • AppName = "BabylonToolbarsrv.exe"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8375D9C8-634F-4ECB-8CF5-C7416BA5D542}
    • AppPath = "%Program Files%\BabylonToolbar\BabylonToolbar\1.5.3.17"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4a99-B4B6-146BF802613B}
    • NoExplorer = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\escort.DLL
    • AppID = "{09C554C3-109B-483C-A06B-F14172F1A947}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{97F2FF5B-260C-4ccf-834A-2DDA4E29E39E}\InprocServer32
    • ThreadingModel = "apartment"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{97F2FF5B-260C-4ccf-834A-2DDA4E29E39E}
    • AppID = "{09C554C3-109B-483C-A06B-F14172F1A947}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E46C8196-B634-44a1-AF6E-957C64278AB1}\InprocServer32
    • ThreadingModel = "apartment"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E46C8196-B634-44a1-AF6E-957C64278AB1}
    • AppID = "{09C554C3-109B-483C-A06B-F14172F1A947}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2EECD738-5844-4a99-B4B6-146BF802613B}\InprocServer32
    • ThreadingModel = "apartment"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2EECD738-5844-4a99-B4B6-146BF802613B}
    • AppID = "{09C554C3-109B-483C-A06B-F14172F1A947}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{97F2FF5B-260C-4ccf-834A-2DDA4E29E39E}\Instance
    • CLSID = "{97F2FF5B-260C-4ccf-834A-2DDA4E29E39E}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{97F2FF5B-260C-4ccf-834A-2DDA4E29E39E}\Instance\InitPropertyBag
    • URL = "about:blank"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\escortApp.DLL
    • AppID = "{D7EE8177-D51E-4F89-92B6-83EA2EC40800}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FFB9ADCB-8C79-4C29-81D3-74D46A93D370}\InprocServer32
    • ThreadingModel = "apartment"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FFB9ADCB-8C79-4C29-81D3-74D46A93D370}
    • AppID = "{D7EE8177-D51E-4F89-92B6-83EA2EC40800}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}\instl\data
    • afltId = "orgnl"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}\instl\data
    • cntrlId = "f0bdff950000000000000050568e00d9"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}\instl\data
    • hrdId = "f0bdff950000000000000050568e00d9"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}\instl\data
    • instlDay = "3c7b"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}\instl\data
    • prtnrId = "BabylonToolbar"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}\instl\data
    • sftId = "f36d58294bf541c59e3506a513a4fe12"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E}\TypeLib
    • Version = "1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A}\TypeLib
    • Version = "1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997}\TypeLib
    • Version = "1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1}\TypeLib
    • Version = "1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F}\TypeLib
    • Version = "1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599}\TypeLib
    • Version = "1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B32672B3-F656-46E0-B584-FE61C0BB6037}\TypeLib
    • Version = "1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{706D4A4B-184A-4434-B331-296B07493D2D}\TypeLib
    • Version = "1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C2996524-2187-441F-A398-CD6CB6B3D020}\TypeLib
    • Version = "1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD}\TypeLib
    • Version = "1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BFE569F7-646C-4512-969B-9BE3E580D393}\TypeLib
    • Version = "1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B173667F-8395-4317-8DD6-45AD1FE00047}\TypeLib
    • Version = "1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8BE10F21-185F-4CA0-B789-9921674C3993}\TypeLib
    • Version = "1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68}\TypeLib
    • Version = "1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\escortEng.DLL
    • AppID = "{B12E99ED-69BD-437C-86BE-C862B9E5444D}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B8276A94-891D-453C-9FF3-715C042A2575}\InprocServer32
    • ThreadingModel = "apartment"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B8276A94-891D-453C-9FF3-715C042A2575}
    • AppID = "{B12E99ED-69BD-437C-86BE-C862B9E5444D}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}\instl\data
    • vrsni = "1.5.3.17"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}\instl\data
    • afltId = "babsst"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}\instl\data
    • smplGrp = "none"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}\instl\data
    • tlbrId = "base"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\BabylonToolbar\BabylonToolbar\Instl
    • InstallDir = "%Program Files%\BabylonToolbar\BabylonToolbar\1.5.3.17"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BabylonToolbar
    • DisplayName = "Babylon toolbar on IE"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BabylonToolbar
    • UninstallString = "%Program Files%\BabylonToolbar\BabylonToolbar\1.5.3.17\uninstall.exe"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BabylonToolbar
    • NoModify = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BabylonToolbar
    • NoRepair = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\esrv.EXE
    • AppID = "{35C1605E-438B-4D64-AAB1-8885F097A9B1}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{291BCCC1-6890-484a-89D3-318C928DAC1B}\LocalServer32
    • ThreadingModel = "apartment"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{291BCCC1-6890-484a-89D3-318C928DAC1B}
    • AppID = "{35C1605E-438B-4D64-AAB1-8885F097A9B1}"

手順 5

変更されたレジストリ値を修正します。

[ 詳細 ]

警告:レジストリはWindowsの構成情報が格納されているデータベースであり、レジストリの編集内容に問題があると、システムが正常に動作しなくなる場合があります。
レジストリの編集はお客様の責任で行っていただくようお願いいたします。弊社ではレジストリの編集による如何なる問題に対しても補償いたしかねます。
レジストリの編集前にこちらをご参照ください。

  • In HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
    • From: Start Page = "{random characters}"
      To: Start Page = ""http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome""

手順 6

以下のファイルを検索し削除します。

[ 詳細 ]
コンポーネントファイルが隠しファイル属性の場合があります。[詳細設定オプション]をクリックし、[隠しファイルとフォルダの検索]のチェックボックスをオンにし、検索結果に隠しファイルとフォルダが含まれるようにしてください。
  • %User Temp%\nsz2.tmp\System.dll
  • %User Temp%\nsz2.tmp\NSISdl.dll
  • %User Temp%\nsz2.tmp\getCountry
  • %User Temp%\nsz2.tmp\inetc3.dll
  • %User Temp%\nsz2.tmp\gC0
  • 35
  • %Program Files%\1ClickDownload\IPL_(All_teams_theme_songs).magnet
  • mainpacklt.exe
  • %User Temp%\nsz2.tmp\nsDialogs.dll
  • %User Temp%\nsz2.tmp\skip.bmp
  • %User Temp%\nsz2.tmp\accept.bmp
  • %User Temp%\nsz2.tmp\accept1.bmp
  • %User Temp%\nsz2.tmp\accept2.bmp
  • %User Temp%\nsz2.tmp\accept3.bmp
  • %User Temp%\nsz2.tmp\decline.bmp
  • %User Temp%\nsz2.tmp\save.bmp
  • %User Temp%\nsz2.tmp\anon.bmp
  • %User Temp%\nsz2.tmp\1clogo.bmp
  • %User Temp%\nsz2.tmp\yontoo.bmp
  • %User Temp%\nsz2.tmp\1clogobvd.bmp
  • %User Temp%\nsz2.tmp\bab_on.bmp
  • %User Temp%\nsz2.tmp\bab_off.bmp
  • %User Temp%\nsz2.tmp\bab.bmp
  • %User Temp%\nsz2.tmp\fm.bmp
  • %User Temp%\nsz2.tmp\inc.bmp
  • %User Temp%\nsz2.tmp\EBanner.dll
  • %User Temp%\nsz2.tmp\getGFGCountry13
  • %Desktop%\Download IPL_(All_teams_theme_songs).lnk
  • %Program Files%\1ClickDownload\uninstall.exe
  • 1click11.crx
  • 1clicktemp.xpi
  • %User Temp%\nsz2.tmp\KillProcDLL.dll
  • BabDSetup.exe
  • %User Temp%\nsz2.tmp\getGFGCountry6
  • BVDDSetup.exe
  • %Program Files%\1ClickDownload\1ClickDownloader.exe
  • %Program Files%\1ClickDownload\1Click.cfg
  • bab033.tbinst.dat
  • bab091.norecovericon.dat
  • Babylon.dat
  • BExternal.dll
  • cmbx.png
  • common.js
  • eula.html
  • lngs.png
  • page1.css
  • page1.html
  • page1.js
  • page1Lrg.css
  • page2.css
  • page2.html
  • page2.js
  • page2Lrg.css
  • page9.html
  • pBar.gif
  • title1.png
  • title2.png
  • toolBar.jpg
  • vIcn.png
  • IECookieLow.dll
  • Setup.exe
  • SetupStrings.dat
  • sqlite3.dll
  • %User Temp%\F7BCB783-BAB0-7891-A2D4-A55145871553\Welcome.html
  • %Application Data%\Babylon\Setup\BExternal.zpb
  • %Application Data%\Babylon\Setup\Setup-tbmntr903.zpb
  • BabylonTB.xpi
  • MyBabylonTB.exe
  • TBConfig.inf
  • %User Temp%\nsz7.tmp\UserInfo.dll
  • %User Temp%\nsz7.tmp\System.dll
  • %User Temp%\nsz7.tmp\nsisos.dll
  • %User Temp%\F7BCB783-BAB0-7891-A2D4-A55145871553\nsa8.tmp
  • %User Temp%\F7BCB783-BAB0-7891-A2D4-A55145871553\nsq9.tmp
  • %User Temp%\nsz7.tmp\mt.dll
  • %User Temp%\nsz7.tmp\Time.dll
  • %User Temp%\F7BCB783-BAB0-7891-A2D4-A55145871553\nsgA.tmp
  • %User Temp%\F7BCB783-BAB0-7891-A2D4-A55145871553\nsgB.tmp
  • %User Temp%\F7BCB783-BAB0-7891-A2D4-A55145871553\nsvC.tmp
  • %User Temp%\F7BCB783-BAB0-7891-A2D4-A55145871553\nslD.tmp
  • %User Temp%\F7BCB783-BAB0-7891-A2D4-A55145871553\nsaE.tmp
  • %User Temp%\F7BCB783-BAB0-7891-A2D4-A55145871553\nsqF.tmp
  • %User Temp%\F7BCB783-BAB0-7891-A2D4-A55145871553\nsg10.tmp
  • %User Temp%\F7BCB783-BAB0-7891-A2D4-A55145871553\nsg11.tmp
  • %User Temp%\F7BCB783-BAB0-7891-A2D4-A55145871553\nsv12.tmp
  • %User Temp%\F7BCB783-BAB0-7891-A2D4-A55145871553\nsl13.tmp
  • %User Temp%\F7BCB783-BAB0-7891-A2D4-A55145871553\nsb14.tmp
  • %User Temp%\F7BCB783-BAB0-7891-A2D4-A55145871553\nsq15.tmp
  • %User Temp%\F7BCB783-BAB0-7891-A2D4-A55145871553\nsg16.tmp
  • %User Temp%\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbar4ffx.exe
  • %User Temp%\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbar4ie.exe
  • %User Temp%\F7BCB783-BAB0-7891-A2D4-A55145871553\nsq1F.tmp
  • %User Temp%\nsz7.tmp\InetLoad.dll
  • %User Temp%\BabylonToolbar\BabylonToolbar\1.5.3.17\nsis.js
  • %User Temp%\nsc18.tmp\nsisos.dll
  • %User Temp%\nsc18.tmp\System.dll
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\chrome.manifest
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\install.rdf
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\components\acplus-autocomplete.js
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\babylon.css
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\babylon.xul
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\server.js
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\tmplt.js
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\arwDwn.gif
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\bbyln.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\help_16.gif
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\home.gif
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\logo.PNG
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\privecy_16_hot.gif
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\tellafriend.gif
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\vssver.scc
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\Thumbs.db
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ae.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\bg.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ch.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\cn.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\cz.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\de.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\eg.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\en.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\es.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\fr.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\gr.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\he.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\il.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\it.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ja.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\jp.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\nl.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\no.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\pl.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\pt.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ro.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ru.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\sa.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\se.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\sv.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\tr.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ua.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs\us.png
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\defaults\preferences\instlPref.js
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\mtstart.js
  • %User Temp%\BabylonToolbar\BabylonToolbar\1.5.3.17\nsx19.tmp
  • %User Temp%\BabylonToolbar\BabylonToolbar\1.5.3.17\nsd1A.tmp
  • %User Temp%\BabylonToolbar\BabylonToolbar\1.5.3.17\nss1B.tmp
  • %User Temp%\BabylonToolbar\BabylonToolbar\1.5.3.17\nsx1C.tmp
  • %User Temp%\nsa1E.tmp\UserInfo.dll
  • %User Temp%\nsa1E.tmp\System.dll
  • %User Temp%\nsa1E.tmp\nsisos.dll
  • %User Temp%\nsa1E.tmp\mt.dll
  • %User Temp%\nsa1E.tmp\Time.dll
  • %Program Files%\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll
  • %Program Files%\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarApp.dll
  • %Program Files%\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarEng.dll
  • %Program Files%\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll
  • %Program Files%\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarsrv.exe
  • %User Temp%\BabylonToolbar\BabylonToolbar\1.5.3.17\nst20.tmp
  • %User Temp%\BabylonToolbar\BabylonToolbar\1.5.3.17\nsi21.tmp
  • %User Temp%\BabylonToolbar\BabylonToolbar\1.5.3.17\nsf22.tmp
  • %Program Files%\BabylonToolbar\BabylonToolbar\1.5.3.17\uninstall.exe
  • %User Temp%\F7BCB783-BAB0-7891-A2D4-A55145871553\BExternal-9.0.3.35.zpb
  • %User Temp%\F7BCB783-BAB0-7891-A2D4-A55145871553\Setup-tbmntr903-9.0.3.35.zpb

手順 7

以下のフォルダを検索し削除します。

[ 詳細 ]
フォルダが隠しフォルダ属性に設定されている場合があります。[詳細設定オプション]をクリックし、[隠しファイルとフォルダの検索]のチェックボックスをオンにし、検索結果に隠しファイルとフォルダが含まれるようにしてください。
  • %System Root%\DOCUME~1
  • %System Root%\DOCUME~1\ADMINI~1
  • %User Profile%\LOCALS~1
  • %User Temp%\nsz2.tmp
  • %Program Files%\1ClickDownload
  • %System Root%\Documents and Settings\Administrator
  • %User Profile%\Application Data\Mozilla
  • %User Profile%\Mozilla\Firefox
  • %User Profile%\Firefox\Profiles
  • %User Profile%\Profiles\extensions
  • %Desktop%\IPL (All teams theme songs)
  • %User Temp%\F7BCB783-BAB0-7891-A2D4-A55145871553
  • HtmlScreens
  • %User Profile%\Application Data\Babylon
  • %Program Files%\Babylon
  • %Program Files%\Babylon\Babylon-Pro
  • %Application Data%\Babylon
  • %Application Data%\Babylon\Setup
  • %User Temp%\nsz7.tmp
  • %User Profile%\Profiles\extensions
  • %User Profile%\extensions \extensions
  • %Program Files%\Mozilla Firefox
  • %Program Files%\Mozilla Firefox\extensions
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com
  • %User Temp%\BabylonToolbar
  • %User Temp%\BabylonToolbar\BabylonToolbar
  • %User Temp%\BabylonToolbar\BabylonToolbar\1.5.3.17
  • %User Temp%\nsc18.tmp
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\components
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\content\imgs\flgs
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\defaults
  • %Program Files%\Mozilla Firefox\extensions\ffxtlbr@babylon.com\defaults\preferences
  • %Program Files%\Mozilla Firefox\searchplugins
  • %User Temp%\nsa1E.tmp
  • %Program Files%\BabylonToolbar
  • %Program Files%\BabylonToolbar\BabylonToolbar
  • %Program Files%\BabylonToolbar\BabylonToolbar\1.5.3.17
  • %Program Files%\BabylonToolbar\BabylonToolbar\1.5.3.17\bh

手順 8

最新のバージョン(エンジン、パターンファイル)を導入したウイルス対策製品を用い、ウイルス検索を実行してください。「TROJ_PAM_0000050366.T3」と検出したファイルはすべて削除してください。 検出されたファイルが、弊社ウイルス対策製品により既に駆除、隔離またはファイル削除の処理が実行された場合、ウイルスの処理は完了しており、他の削除手順は特にありません。

手順 9

以下のファイルをバックアップを用いて修復します。なお、マイクロソフト製品に関連したファイルのみ修復されます。このマルウェア/グレイウェア/スパイウェアが同社製品以外のプログラムをも削除した場合には、該当プログラムを再度インストールする必要があります。

  • %User Temp%\nsk1.tmp
  • %User Temp%\nsz2.tmp
  • %User Temp%\nse4.tmp
  • %User Temp%\nse5.tmp
  • %User Temp%\nst3.tmp
  • %User Profile%\Babylon\BabAll.dat.tmp
  • %User Temp%\nsk6.tmp
  • %User Temp%\nsz7.tmp
  • %User Temp%\nsn17.tmp
  • %User Temp%\nsc18.tmp
  • %Program Files%\Mozilla Firefox\user.js
  • %User Temp%\nsk1D.tmp
  • %User Temp%\nsa1E.tmp

手順 10

以下の削除されたレジストリキーまたはレジストリ値をバックアップを用いて修復します。

※註:マイクロソフト製品に関連したレジストリキーおよびレジストリ値のみが修復されます。このマルウェアもしくはアドウェア等が同社製品以外のプログラムも削除した場合には、該当プログラムを再度インストールする必要があります。

  • In HKEY_LOCAL_MACHINE\Software
    • Babylon
  • In HKEY_LOCAL_MACHINE\Software\BabylonToolbar\BabylonToolbar
    • SearchRestore
  • In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories\{00021494-0000-0000-C000-000000000046}
    • Enum
  • In HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories\{00021493-0000-0000-C000-000000000046}
    • Enum


ご利用はいかがでしたか? アンケートにご協力ください