Adware.Win32.Crossrider.A


 PLATFORM:

Windows

 OVERALL RISK RATING:
 REPORTED INFECTION:
 SYSTEM IMPACT RATING:
 INFORMATION EXPOSURE:

  • Threat Type: Adware

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW

This Adware arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

  TECHNICAL DETAILS

File Size:

8,020,416 bytes

File Type:

EXE

Memory Resident:

Yes

Initial Samples Received Date:

13 Jan 2020

Arrival Details

This Adware arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

Installation

This Adware adds the following processes:

  • "%User Temp%\nso8B30.tmp\Waeeujeil.exe"
  • %User Temp%\{GUID}.exe -s 300 -t 600 -r http://errors.{BLOCKED}statsservice.com/utility.gif?{random characters}
  • %User Temp%\comh.18754\GoogleUpdate.exe /silent /install "appguid={{GUID}}&appname={GUID}&needsadmin=True&lang=en"
  • %Program Files%\MPMP\{GUID}-3.exe /fIwyYjReh='MPMP' /MaVSES='%Program Files%\MPMP\54246.crx' /IIrLlIXDh=54246 /mbQigCM='001359' /nEATq='0' /mAMgNgLyD='0' /fCVstquGS=354A91DE7DC14C2A980B5427C0148BABIE /ROpwC=be6aa8aa1574234ad24e003e9b0dc90a /Urvihe=1_34_05_22 /fZulGR=1.34.5.22 /YDpNA=1562855042 /wJkGOed=http://stats.{BLOCKED}statsservice.com /Gffoh=http://errors.{BLOCKED}statsservice.com /yESOfh=300 /BGUJSPx=ie /LMFCR='{"asw":[0, 8197]}' /EurvNvZhi /RFOFJLcHn /sNvWRz /CZWhcFa=majjphhgppkndjjkmhhnbgafooenebhd /BMiSM=1.26.38 /TZtXhoTG=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDNoah7iM3oReLLaSfyvVCabRVMp55YZBmufkB4ZcTC1BqtOPtP9BvjxBgILPqIKglk4CyccXwgBK2C28bEQiWG7sG3fl1urw/KHfXOg1Xsybf8Oxx+jBOWKoVoKavSUsPnSXdvOvzgOkyihHQ7F30sBiy6suIv6nI4upG1zgLoDwIDAQAB /jwfdaYIy='http://update.{BLOCKED}statsservice.com/validator/{CAMP_ID}/update.json' /pebnyseX=1 /wDjpuFP={{GUID}} /jacVj='%Program Files%\MPMP\1293297481.mxaddon' /DflSga='1293297481.mxaddon' /sPzkmasYM='%Program Files%\MPMP\360-54246.crx' /ymswtHoM /gupYtn='installer' /uQPcK='%User Temp%\MPMPInstaller_1562855042.log'
  • %Program Files%\MPMP\MPMP-novainstaller.exe /rStPb /fIwyYjReh='MPMP' /IIrLlIXDh=54246 /mbQigCM='001359' /nEATq='0' /mAMgNgLyD='0' /fCVstquGS=354A91DE7DC14C2A980B5427C0148BABIE /ROpwC=be6aa8aa1574234ad24e003e9b0dc90a /Urvihe=1_34_05_22 /fZulGR=1.34.5.22 /YDpNA=1562855042 /wJkGOed=http://stats.{BLOCKED}statsservice.com /Gffoh=http://errors.{BLOCKED}statsservice.com /jHfBjGCsu=http://js.{BLOCKED}statsservice.com /BGUJSPx=ie /jPMHvFxp /friKgE='nova' /gupYtn=installer /uQPcK='%User Temp%\MPMPInstaller_1562855042.log' /aDjByNf='file://%User Temp%\nst9695.tmp\novaExtensionData'
  • %Program Files%\MPMP\MPMP-novainstaller.exe /BVUzW /YEpjJ /fIwyYjReh='MPMP' /IIrLlIXDh=54246 /mbQigCM='001359' /nEATq='0' /mAMgNgLyD='0' /fCVstquGS=354A91DE7DC14C2A980B5427C0148BABIE /ROpwC=be6aa8aa1574234ad24e003e9b0dc90a /Urvihe=1_34_05_22 /fZulGR=1.34.5.22 /YDpNA=1562855042 /wJkGOed=http://stats.{BLOCKED}statsservice.com /Gffoh=http://errors.{BLOCKED}statsservice.com /jHfBjGCsu=http://js.{BLOCKED}statsservice.com /BGUJSPx=ie /jPMHvFxp /friKgE='nova' /gupYtn=installer-update /uQPcK='%User Temp%\MPMPInstaller_1562855042.log'
  • %Program Files%\MPMP\{GUID}-4.exe /gVlfG /fIwyYjReh='MPMP' /MaVSES='%Program Files%\MPMP\54246.xpi' /IIrLlIXDh=54246 /mbQigCM='001359' /nEATq='0' /mAMgNgLyD='0' /fCVstquGS=354A91DE7DC14C2A980B5427C0148BABIE /ROpwC=be6aa8aa1574234ad24e003e9b0dc90a /Urvihe=1_34_05_22 /fZulGR=1.34.5.22 /YDpNA=1562855042 /wJkGOed=http://stats.{BLOCKED}statsservice.com /Gffoh=http://errors.{BLOCKED}statsservice.com /yESOfh=300 /CZWhcFa={GUID}@{GUID}.com /BMiSM=0.94 /MuXqEfQp=aa9719e64232b4695ae9ca89cd7f2aa84ca1279dfbc0d44a897ef19301c922b68com54246 /CzgwGkyDN= /wiehZWr='MPMP' /wMuQUM='MediaPlayerEnhance Extension' /ObgWby='Freeven' /BGUJSPx=ie /LMFCR='{"asw":[0, 8197]}' /RFOFJLcHn /sNvWRz /WcCzsYN /jwfdaYIy='http://update.{BLOCKED}statsservice.com/ff_agent_updates/{CAMP_ID}/update.json' /ymswtHoM /gupYtn='installer' /uQPcK='%User Temp%\MPMPInstaller_1562855042.log'
  • %Program Files%\MPMP\MPMP-codedownloader.exe /rStPb /fIwyYjReh='MPMP' /IIrLlIXDh=54246 /mbQigCM='001359' /nEATq='0' /mAMgNgLyD='0' /fCVstquGS=354A91DE7DC14C2A980B5427C0148BABIE /ROpwC=be6aa8aa1574234ad24e003e9b0dc90a /Urvihe=1_34_05_22 /fZulGR=1.34.5.22 /YDpNA=1562855042 /wJkGOed=http://stats.{BLOCKED}statsservice.com /Gffoh=http://errors.{BLOCKED}statsservice.com /jHfBjGCsu=http://js.{BLOCKED}statsservice.com /BGUJSPx=ie /RFOFJLcHn /gupYtn=installer /uQPcK='%User Temp%\MPMPInstaller_1562855042.log' /aDjByNf='file://%User Temp%\nst9695.tmp\extensionData'
  • %Program Files%\MPMP\MPMP-codedownloader.exe /BVUzW /YEpjJ /fIwyYjReh='MPMP' /IIrLlIXDh=54246 /mbQigCM='001359' /nEATq='0' /mAMgNgLyD='0' /fCVstquGS=354A91DE7DC14C2A980B5427C0148BABIE /ROpwC=be6aa8aa1574234ad24e003e9b0dc90a /Urvihe=1_34_05_22 /fZulGR=1.34.5.22 /YDpNA=1562855042 /wJkGOed=http://stats.{BLOCKED}statsservice.com /Gffoh=http://errors.{BLOCKED}statsservice.com /jHfBjGCsu=http://js.{BLOCKED}statsservice.com /BGUJSPx=ie /RFOFJLcHn /gupYtn=installer-update /uQPcK='%User Temp%\MPMPInstaller_1562855042.log'
  • regsvr32 /s "%Program Files%\MPMP\MPMP-bho.dll"
  • regsvr32 /s "%Program Files%\MPMP\MPMP-bho64.dll"
  • AF1.exe -d
  • "%Program Files%\globalUpdate\Update\GoogleUpdate.exe" /regsvc
  • "%Program Files%\globalUpdate\Update\GoogleUpdate.exe" /regserver
  • %Program Files%\globalUpdate\Update\GoogleUpdate.exe /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB2ZXJzaW9uPSIxLjMuMjUuMCIgaXNtYWNoaW5lPSIxIiBzZXNzaW9uaWQ9Ins2Q0U2QUNDMC0yNEY0LTQzNTctQjg2Qy0wQ0ZEMEM4NTFEQTh9IiBpbnN0YWxsc291cmNlPSJvdGhlcmluc3RhbGxjbWQiIHRlc3Rzb3VyY2U9ImF1dG8iIHJlcXVlc3RpZD0iezU4MENGNUQzLUI2RTQtNEI2QS1BOTk0LUYzMjhDNjUyQjE4MX0iPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSI2LjEiIHNwPSJTZXJ2aWNlIFBhY2sgMSIgYXJjaD0ieDY0Ii8-PGFwcCBhcHBpZD0iezQzMEZENEQwLUI3MjktNEY2MS1BQTM0LTkxNTI2NDgxNzk5RH0iIHZlcnNpb249IiIgbmV4dHZlcnNpb249IjEuMy4yNS4wIiBsYW5nPSJlbiIgYnJhbmQ9IiIgY2xpZW50PSIiPjxldmVudCBldmVudHR5cGU9IjIiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjAiLz48L2FwcD48L3JlcXVlc3Q-
  • %Program Files%\globalUpdate\Update\GoogleUpdate.exe /handoff "appguid={{GUID}}&appname={GUID}&needsadmin=True&lang=en" /installsource otherinstallcmd /sessionid "{6CE6ACC0-24F4-4357-B86C-0CFD0C851DA8}" /silent
  • taskeng.exe {963A14C8-F016-4C9C-8E12-5457B9EC281B} S-1-5-18:NT AUTHORITY\System:Service:
  • net
  • %System%\regsvr32.exe /s "%Program Files%\MPMP\MPMP-bho64.dll"
  • %System%\svchost.exe -k WerSvcGroup

It creates the following folders:

  • %Program Files%\globalUpdate\Update
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins
  • %AppDataLocal%\globalUpdate
  • %AppDataLocal%\globalUpdate\CrashReports
  • %Program Files%\MPMP
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\locale\en-US
  • %User Temp%\comh.18754
  • %User Profile%\AppData
  • %Program Files%\globalUpdate\Update\Offline
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\userCode
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\defaults
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\locale
  • %Program Files%\globalUpdate
  • %Program Files%\globalUpdate\Update\1.3.25.0
  • %System Root%\Users
  • %Program Files%\globalUpdate\Update\Offline\{27F2D2DB-7D37-4E11-92F6-67B10F86EC61}
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\defaults\preferences
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome
  • %Program Files%\globalUpdate\CrashReports

Autostart Technique

This Adware registers itself as a system service to ensure its automatic execution at every system startup by adding the following registry entries:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\globalUpdate
ImagePath = "%Program Files%\globalUpdate\Update\GoogleUpdate.exe /svc"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\globalUpdatem
ImagePath = "%Program Files%\globalUpdate\Update\GoogleUpdate.exe /medsvc"

Other System Modifications

This Adware modifies the following file(s):

  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions.json

(Note: %Application Data% is the current user's Application Data folder, which is usually C:\Documents and Settings\{user name}\Application Data on Windows 2000(32-bit), XP, and Server 2003(32-bit), or C:\Users\{user name}\AppData\Roaming on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit).)

It deletes the following files:

  • %User Temp%\nst9695.tmp
  • %Windows%\Tasks\GoogleUpdateTask.job
  • %Windows%\Tasks\GoogleUpdateTaskMachine.job

(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000(32-bit), XP, and Server 2003(32-bit), or C:\Users\{user name}\AppData\Local\Temp on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit).. %Windows% is the Windows folder, where it usually is C:\Windows on all Windows operating system versions.)

It deletes the following folders:

  • %User Temp%\nst9695.tmp
  • %User Temp%\nso8B30.tmp

(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000(32-bit), XP, and Server 2003(32-bit), or C:\Users\{user name}\AppData\Local\Temp on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit).)

It adds the following registry keys:

HKEY_LOCAL_MACHINE\Software\Microsoft\
Windows\CurrentVersion\Uninstall\
MPMP

HKEY_LOCAL_MACHINE\Software\GlobalUpdate\
Update\Clients\{{GUID}}

HKEY_LOCAL_MACHINE\Software\GlobalUpdate\
UpdateDev

HKEY_LOCAL_MACHINE\Software\MPMP\
Installer

HKEY_LOCAL_MACHINE\Software\Microsoft\
Internet Explorer\Low Rights\ElevationPolicy\
{{GUID}}

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
Microsoft\Internet Explorer\Low Rights\
ElevationPolicy\{{GUID}}

HKEY_LOCAL_MACHINE\Software\globalUpdate\
Update\network

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
GlobalUpdate\Update\network\
secure

HKEY_LOCAL_MACHINE\Software\globalUpdate\
Update\ClientState

HKEY_LOCAL_MACHINE\Software\globalUpdate\
Update\Clients\{430FD4D0-B729-4F61-AA34-91526481799D}

HKEY_LOCAL_MACHINE\Software\globalUpdate\
Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}

HKEY_LOCAL_MACHINE\Software\globalUpdate\
Update\ClientStateMedium

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MozillaPlugins\@staging.google.com/globalUpdate Update;version=10

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MozillaPlugins\@staging.google.com/globalUpdate Update;version=10\MimeTypes

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MozillaPlugins\@staging.google.com/globalUpdate Update;version=10\MimeTypes\
application/x-vnd.google.oneclickctrl.10

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Ext\Stats\{5645E0E7-FC12-43BF-A6E4-F9751942B298}

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Ext\Stats\{5645E0E7-FC12-43BF-A6E4-F9751942B298}\
iexplore

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Ext\Stats\{5645E0E7-FC12-43BF-A6E4-F9751942B298}\
iexplore\AllowedDomains

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Ext\Stats\{5645E0E7-FC12-43BF-A6E4-F9751942B298}\
iexplore\AllowedDomains\*

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Internet Explorer\Low Rights\
ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdate.OneClickCtrl.10

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdate.OneClickCtrl.10\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}\
ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}\
InprocServer32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
MIME\Database\Content Type\
application/x-vnd.google.oneclickctrl.10

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MozillaPlugins\@staging.google.com/globalUpdate Update;version=4

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MozillaPlugins\@staging.google.com/globalUpdate Update;version=4\MimeTypes

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MozillaPlugins\@staging.google.com/globalUpdate Update;version=4\MimeTypes\
application/x-vnd.google.update3webcontrol.4

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Ext\Stats\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Ext\Stats\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}\
iexplore

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Ext\Stats\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}\
iexplore\AllowedDomains

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Ext\Stats\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}\
iexplore\AllowedDomains\*

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Internet Explorer\Low Rights\
ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdate.Update3WebControl.4

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdate.Update3WebControl.4\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}\
ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}\
InprocServer32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
MIME\Database\Content Type\
application/x-vnd.google.update3webcontrol.4

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\GoogleUpdate.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3COMClassService.1.0

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3COMClassService.1.0\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3COMClassService

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3COMClassService\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3COMClassService\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}\
ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}\
VersionIndependentProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassSvc.1.0

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassSvc.1.0\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassSvc

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassSvc\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassSvc\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}\
ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}\
VersionIndependentProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebSvc.1.0

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebSvc.1.0\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebSvc

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebSvc\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebSvc\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}\
ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}\
VersionIndependentProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoreClass.1

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoreClass.1\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoreClass

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoreClass\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoreClass\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}\
ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}\
VersionIndependentProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}\
InprocHandler32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}\
InprocServer32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}\
InProcServer32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{3CC60715-D6C5-429D-830E-43FA3F86C61D}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{3CC60715-D6C5-429D-830E-43FA3F86C61D}\
ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{3CC60715-D6C5-429D-830E-43FA3F86C61D}\
NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{3A807417-B46D-4D37-8C9A-19AC6DE204F9}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{3A807417-B46D-4D37-8C9A-19AC6DE204F9}\
ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{3A807417-B46D-4D37-8C9A-19AC6DE204F9}\
NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{07F41522-AF7D-4F26-B394-094F059FDB8A}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{07F41522-AF7D-4F26-B394-094F059FDB8A}\
ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{07F41522-AF7D-4F26-B394-094F059FDB8A}\
NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{DD1F043F-ABC8-4643-8B95-D2C5B22BB019}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{DD1F043F-ABC8-4643-8B95-D2C5B22BB019}\
ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{DD1F043F-ABC8-4643-8B95-D2C5B22BB019}\
NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{212E6D43-6062-492A-B8CC-144669FF11ED}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{212E6D43-6062-492A-B8CC-144669FF11ED}\
ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{212E6D43-6062-492A-B8CC-144669FF11ED}\
NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{555D7146-94A8-4C94-AE76-C39CDC7F7705}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{555D7146-94A8-4C94-AE76-C39CDC7F7705}\
ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{555D7146-94A8-4C94-AE76-C39CDC7F7705}\
NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{4517D94C-19BA-46FA-BE66-2A30CEAC4A85}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{4517D94C-19BA-46FA-BE66-2A30CEAC4A85}\
ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{4517D94C-19BA-46FA-BE66-2A30CEAC4A85}\
NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{224FE662-1E6D-4BC0-AEBB-9E2FB4057BE9}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{224FE662-1E6D-4BC0-AEBB-9E2FB4057BE9}\
ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{224FE662-1E6D-4BC0-AEBB-9E2FB4057BE9}\
NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{0C40F472-7407-4467-8914-1DEA7C326972}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{0C40F472-7407-4467-8914-1DEA7C326972}\
ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{0C40F472-7407-4467-8914-1DEA7C326972}\
NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{A6D54287-7939-466A-8579-92546D946C8C}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{A6D54287-7939-466A-8579-92546D946C8C}\
ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{A6D54287-7939-466A-8579-92546D946C8C}\
NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{0522D9A4-4D57-437D-978D-E5B3B6C9005D}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{0522D9A4-4D57-437D-978D-E5B3B6C9005D}\
ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{0522D9A4-4D57-437D-978D-E5B3B6C9005D}\
NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{A8F7D0A5-7074-40B8-9BDC-1174BDD0A132}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{A8F7D0A5-7074-40B8-9BDC-1174BDD0A132}\
ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{A8F7D0A5-7074-40B8-9BDC-1174BDD0A132}\
NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{D14D64BC-A0E4-42E3-BB72-FB41EA43C198}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{D14D64BC-A0E4-42E3-BB72-FB41EA43C198}\
ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{D14D64BC-A0E4-42E3-BB72-FB41EA43C198}\
NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{023E9EC8-B147-40EB-B0B3-DF90618FB371}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{023E9EC8-B147-40EB-B0B3-DF90618FB371}\
ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{023E9EC8-B147-40EB-B0B3-DF90618FB371}\
NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{ED0B64D4-BF27-4521-AD27-190F49BF5EA7}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{ED0B64D4-BF27-4521-AD27-190F49BF5EA7}\
ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{ED0B64D4-BF27-4521-AD27-190F49BF5EA7}\
NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{8120D9D6-785C-4413-9C0C-DF2028C56FAD}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{8120D9D6-785C-4413-9C0C-DF2028C56FAD}\
ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{8120D9D6-785C-4413-9C0C-DF2028C56FAD}\
NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{823AE2EB-E62C-4847-B192-C99B91B92416}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{823AE2EB-E62C-4847-B192-C99B91B92416}\
ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{823AE2EB-E62C-4847-B192-C99B91B92416}\
NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{9B9A45F4-18FC-484A-BACA-076D78273D8E}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{9B9A45F4-18FC-484A-BACA-076D78273D8E}\
ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{9B9A45F4-18FC-484A-BACA-076D78273D8E}\
NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{E3F3E8F9-F747-4DD6-BA6B-82A6CE1E0860}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{E3F3E8F9-F747-4DD6-BA6B-82A6CE1E0860}\
ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{E3F3E8F9-F747-4DD6-BA6B-82A6CE1E0860}\
NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{59D188FA-757A-424E-8C93-F58FFD896BD7}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{59D188FA-757A-424E-8C93-F58FFD896BD7}\
ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{59D188FA-757A-424E-8C93-F58FFD896BD7}\
NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{A78EDAFB-926F-4D93-AB13-8232D7378EB1}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{A78EDAFB-926F-4D93-AB13-8232D7378EB1}\
ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{A78EDAFB-926F-4D93-AB13-8232D7378EB1}\
NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{9B4F7CFE-987D-410E-A8E4-20182E0B3C24}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{9B4F7CFE-987D-410E-A8E4-20182E0B3C24}\
ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{9B4F7CFE-987D-410E-A8E4-20182E0B3C24}\
NumMethods

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassMachine.1.0

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassMachine.1.0\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassMachine

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassMachine\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassMachine\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}\
ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}\
VersionIndependentProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}\
LocalServer32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}\
Elevation

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebMachine.1.0

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebMachine.1.0\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebMachine

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebMachine\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebMachine\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}\
ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}\
VersionIndependentProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}\
LocalServer32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}\
Elevation

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoCreateAsync.1.0

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoCreateAsync.1.0\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoCreateAsync

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoCreateAsync\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoCreateAsync\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}\
ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}\
VersionIndependentProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}\
LocalServer32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdate.OneClickProcessLauncherMachine.1.0

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdate.OneClickProcessLauncherMachine.1.0\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdate.OneClickProcessLauncherMachine

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdate.OneClickProcessLauncherMachine\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdate.OneClickProcessLauncherMachine\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}\
ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}\
VersionIndependentProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}\
LocalServer32

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Internet Explorer\Low Rights\
ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.ProcessLauncher.1.0

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.ProcessLauncher.1.0\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.ProcessLauncher

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.ProcessLauncher\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.ProcessLauncher\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}\
ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}\
VersionIndependentProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}\
LocalServer32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoreMachineClass.1

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoreMachineClass.1\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoreMachineClass

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoreMachineClass\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoreMachineClass\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}\
ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}\
VersionIndependentProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}\
LocalServer32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}\
Elevation

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
{random key}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassMachineFallback

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassMachineFallback\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassMachineFallback\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}\
ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}\
VersionIndependentProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}\
LocalServer32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}\
Elevation

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebMachineFallback.1.0

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebMachineFallback.1.0\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebMachineFallback

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebMachineFallback\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebMachineFallback\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}\
ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}\
VersionIndependentProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}\
LocalServer32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}\
Elevation

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CredentialDialogMachine.1.0

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CredentialDialogMachine.1.0\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CredentialDialogMachine

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CredentialDialogMachine\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CredentialDialogMachine\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}\
ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}\
VersionIndependentProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}\
LocalServer32

HKEY_LOCAL_MACHINE\Software\MPMP\
Chrome-Profiles

HKEY_LOCAL_MACHINE\Software\MPMP\
Chrome

HKEY_LOCAL_MACHINE\Software\MPMP\
ErrorLists-crchromeinstaller

HKEY_CURRENT_USER\Software\globalUpdate\
Update\proxy

HKEY_LOCAL_MACHINE\Software\Classes\
Local Settings

HKEY_LOCAL_MACHINE\Software\Classes\
Local Settings\Software

HKEY_LOCAL_MACHINE\Software\Classes\
Local Settings\Software\Microsoft

HKEY_LOCAL_MACHINE\Software\Classes\
Local Settings\Software\Microsoft\
Windows

HKEY_LOCAL_MACHINE\Software\Classes\
Local Settings\Software\Microsoft\
Windows\CurrentVersion

HKEY_LOCAL_MACHINE\Software\Classes\
Local Settings\Software\Microsoft\
Windows\CurrentVersion\AppContainer

HKEY_LOCAL_MACHINE\Software\Classes\
Local Settings\Software\Microsoft\
Windows\CurrentVersion\AppContainer\
Storage

HKEY_LOCAL_MACHINE\Software\Classes\
Local Settings\Software\Microsoft\
Windows\CurrentVersion\AppContainer\
Storage\windows_ie_ac_001

HKEY_LOCAL_MACHINE\Software\Classes\
Local Settings\Software\Microsoft\
Windows\CurrentVersion\AppContainer\
Storage\windows_ie_ac_001\Software

HKEY_LOCAL_MACHINE\Software\MPMP\
Update

HKEY_LOCAL_MACHINE\Software\MPMP\
Manifest

HKEY_LOCAL_MACHINE\Software\MPMP\
Code

HKEY_LOCAL_MACHINE\Software\MPMP\
Plugins

HKEY_LOCAL_MACHINE\Software\MPMP\
Plugins\251

HKEY_LOCAL_MACHINE\Software\MPMP\
Plugins\249

HKEY_LOCAL_MACHINE\Software\MPMP\
Plugins\250

HKEY_LOCAL_MACHINE\Software\MPMP\
Plugins\14

HKEY_LOCAL_MACHINE\Software\MPMP\
Plugins\78

HKEY_LOCAL_MACHINE\Software\MPMP\
Plugins\233

HKEY_LOCAL_MACHINE\Software\MPMP\
Plugins\253

HKEY_LOCAL_MACHINE\Software\MPMP\
Plugins\242

HKEY_LOCAL_MACHINE\Software\MPMP\
Plugins\211

HKEY_LOCAL_MACHINE\Software\MPMP\
Plugins\191

HKEY_LOCAL_MACHINE\Software\MPMP\
Plugins\184

HKEY_LOCAL_MACHINE\Software\MPMP\
Plugins\155

HKEY_LOCAL_MACHINE\Software\MPMP\
Plugins\102

HKEY_LOCAL_MACHINE\Software\MPMP\
Plugins\93

HKEY_LOCAL_MACHINE\Software\MPMP\
Plugins\91

HKEY_LOCAL_MACHINE\Software\MPMP\
Plugins\246

HKEY_LOCAL_MACHINE\Software\MPMP\
Plugins\4

HKEY_LOCAL_MACHINE\Software\MPMP\
Firefox\Profiles

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP

HKEY_CURRENT_USER\Software\Classes\
Local Settings\Software\Microsoft\
Windows\CurrentVersion\AppContainer

HKEY_CURRENT_USER\Software\Classes\
Local Settings\Software\Microsoft\
Windows\CurrentVersion\AppContainer\
Storage

HKEY_CURRENT_USER\Software\Classes\
Local Settings\Software\Microsoft\
Windows\CurrentVersion\AppContainer\
Storage\windows_ie_ac_001

HKEY_CURRENT_USER\Software\Classes\
Local Settings\Software\Microsoft\
Windows\CurrentVersion\AppContainer\
Storage\windows_ie_ac_001\Software

HKEY_CURRENT_USER\Software\Classes\
Local Settings\Software\Microsoft\
Windows\CurrentVersion\AppContainer\
Storage\windows_ie_ac_001\Software\
MPMP

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Update

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\Crossrider

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Installer

HKEY_LOCAL_MACHINE\Software\MPMP\
IE\Profiles

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Manifest

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Code

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\183

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\182

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\177

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\94

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\78

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\207

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\64

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\72

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\46

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\45

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\44

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\43

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\42

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\41

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\40

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\39

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\38

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\37

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\36

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\35

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\17

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\14

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\13

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\253

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\242

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\233

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\226

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\221

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\211

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\195

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\220

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\7

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\9

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\191

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\190

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\155

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\104

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\184

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\103

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\102

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\93

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\91

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\246

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\47

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\22

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\28

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\3

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\21

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\2

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\4

HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\
AppDataLow\Software\MPMP\
Plugins\1

HKEY_CLASSES_ROOT\CrossriderApp0054246.Sandbox.1

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp0054246.Sandbox.1\CLSID

HKEY_CLASSES_ROOT\CrossriderApp0054246.BHO.1

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp0054246.BHO.1\CLSID

HKEY_CLASSES_ROOT\CrossriderApp0054246.Sandbox

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp0054246.Sandbox\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp0054246.Sandbox\CurVer

HKEY_CLASSES_ROOT\CrossriderApp0054246.BHO

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp0054246.BHO\CLSID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp0054246.BHO\CurVer

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{{GUID}}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{{GUID}}\
ProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{{GUID}}\
VersionIndependentProgID

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{{GUID}}\
Programmable

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{{GUID}}\
InprocServer32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{{GUID}}\
TypeLib

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{{GUID}}\
Implemented Categories

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{{GUID}}\
Implemented Categories\{{GUID}}

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
explorer\Browser Helper Objects\{{GUID}}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{{GUID}}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{{GUID}}\
ProxyStubClsid32

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{{GUID}}\
TypeLib

It adds the following registry entries:

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\MPMP
DisplayName = "MPMP"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\MPMP
DisplayIcon = "%Program Files%\MPMP\utils.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\MPMP
DisplayVersion = "1.34.5.22"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\MPMP
Publisher = "Freeven"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\MPMP
CrPublisherId = "21636"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\MPMP
CrAppId = "54246"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Uninstall\MPMP
UninstallString = "%Program Files%\MPMP\Uninstall.exe /fcp=1"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
GlobalUpdate\Update\Clients\
{{GUID}}
pv = "1.3.25.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
GlobalUpdate\Update\Clients\
{{GUID}}
name = "Freeven"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
GlobalUpdate\Update\Clients\
{{GUID}}
bic = "354A91DE7DC14C2A980B5427C0148BABIE"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
GlobalUpdate\Update\Clients\
{{GUID}}
verifier = "be6aa8aa1574234ad24e003e9b0dc90a"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
GlobalUpdate\Update\Clients\
{{GUID}}
srcid_var = "001359"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
GlobalUpdate\UpdateDev
AuCheckPeriodMs = "21600000"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Installer
BundledChrome = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Installer
BundledNova = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Internet Explorer\MAIN\
FeatureControl\FEATURE_BROWSER_EMULATION\%Program Files%\
MPMP
MPMP-nova.exe = "8000"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Installer
BundledFirefox = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Installer
BundledIe = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Internet Explorer\Low Rights\
ElevationPolicy\{{GUID}}
AppName = "MPMP-codedownloader.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Internet Explorer\Low Rights\
ElevationPolicy\{{GUID}}
AppPath = "%Program Files%\MPMP"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Internet Explorer\Low Rights\
ElevationPolicy\{{GUID}}
Policy = "3"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Internet Explorer\Low Rights\ElevationPolicy\
{{GUID}}
AppName = "MPMP-codedownloader.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Internet Explorer\Low Rights\ElevationPolicy\
{{GUID}}
AppPath = "%Program Files%\MPMP"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Internet Explorer\Low Rights\ElevationPolicy\
{{GUID}}
Policy = "3"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
GlobalUpdate\Update
path = "%Program Files%\globalUpdate\Update\GoogleUpdate.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
GlobalUpdate\Update\Clients\
{430FD4D0-B729-4F61-AA34-91526481799D}
pv = "1.3.25.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
GlobalUpdate\Update\Clients\
{430FD4D0-B729-4F61-AA34-91526481799D}
name = "globalUpdate Update"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
GlobalUpdate\Update\ClientState\
{430FD4D0-B729-4F61-AA34-91526481799D}
pv = "1.3.25.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows NT\CurrentVersion\Image File Execution Options\
GoogleUpdate.exe
DisableExceptionChainValidation = "0"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
GlobalUpdate\Update
version = "1.3.25.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Path = "%Program Files%\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Description = "globalUpdate Update"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
ProductName = "globalUpdate Update"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Vendor = "globalUpdate"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Version = "10"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Internet Explorer\Low Rights\
ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
AppName = "GoogleUpdate.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Internet Explorer\Low Rights\
ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
AppPath = "%Program Files%\globalUpdate\Update"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Internet Explorer\Low Rights\
ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Policy = "3"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdate.OneClickCtrl.10
(Default) = "globalUpdate Update Plugin"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdate.OneClickCtrl.10\CLSID
(Default) = "{5645E0E7-FC12-43BF-A6E4-F9751942B298}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
(Default) = "globalUpdate Update Plugin"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}\
ProgID
(Default) = "globalUpdate.OneClickCtrl.10"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}\
InprocServer32
(Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}\
InprocServer32
ThreadingModel = "Apartment"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
MIME\Database\Content Type\
application/x-vnd.google.oneclickctrl.10
CLSID = "{5645E0E7-FC12-43BF-A6E4-F9751942B298}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Path = "%Program Files%\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Description = "globalUpdate Update"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
ProductName = "globalUpdate Update"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Vendor = "globalUpdate"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Version = "4"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Internet Explorer\Low Rights\
ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
AppName = "GoogleUpdateBroker.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Internet Explorer\Low Rights\
ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
AppPath = "%Program Files%\globalUpdate\Update\1.3.25.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Internet Explorer\Low Rights\
ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Policy = "3"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdate.Update3WebControl.4
(Default) = "globalUpdate Update Plugin"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdate.Update3WebControl.4\CLSID
(Default) = "{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
(Default) = "globalUpdate Update Plugin"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}\
ProgID
(Default) = "globalUpdate.Update3WebControl.4"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}\
InprocServer32
(Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}\
InprocServer32
ThreadingModel = "Apartment"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
MIME\Database\Content Type\
application/x-vnd.google.update3webcontrol.4
CLSID = "{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
GlobalUpdate\Update\ClientState\
{430FD4D0-B729-4F61-AA34-91526481799D}
brand = "GGLS"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
GlobalUpdate\Update\ClientState\
{430FD4D0-B729-4F61-AA34-91526481799D}
InstallTime = "1562855189"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
(Default) = "ServiceModule"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\GoogleUpdate.exe
AppID = "{577975B8-C40E-43E6-B0DE-4C6B44088B52}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
LocalService = "globalUpdate"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
ServiceParameters = "/comsvc"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3COMClassService.1.0
(Default) = "Update3COMClass"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3COMClassService.1.0\CLSID
(Default) = "{577975B8-C40E-43E6-B0DE-4C6B44088B52}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3COMClassService
(Default) = "Update3COMClass"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3COMClassService\CLSID
(Default) = "{577975B8-C40E-43E6-B0DE-4C6B44088B52}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3COMClassService\CurVer
(Default) = "globalUpdateUpdate.Update3COMClassService.1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
(Default) = "Update3COMClass"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}\
ProgID
(Default) = "globalUpdateUpdate.Update3COMClassService.1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}\
VersionIndependentProgID
(Default) = "globalUpdateUpdate.Update3COMClassService"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
AppID = "{577975B8-C40E-43E6-B0DE-4C6B44088B52}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
(Default) = "ServiceModule"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\GoogleUpdate.exe
AppID = "{3278F5CF-48F3-4253-A6BB-004CE84AF492}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
LocalService = "globalUpdatem"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
ServiceParameters = "/comsvc"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassSvc.1.0
(Default) = "Google Update Legacy On Demand"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassSvc.1.0\CLSID
(Default) = "{3278F5CF-48F3-4253-A6BB-004CE84AF492}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassSvc
(Default) = "Google Update Legacy On Demand"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassSvc\CLSID
(Default) = "{3278F5CF-48F3-4253-A6BB-004CE84AF492}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassSvc\CurVer
(Default) = "globalUpdateUpdate.OnDemandCOMClassSvc.1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
(Default) = "Google Update Legacy On Demand"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}\
ProgID
(Default) = "globalUpdateUpdate.OnDemandCOMClassSvc.1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}\
VersionIndependentProgID
(Default) = "globalUpdateUpdate.OnDemandCOMClassSvc"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
AppID = "{3278F5CF-48F3-4253-A6BB-004CE84AF492}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebSvc.1.0
(Default) = "GoogleUpdate Update3Web"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebSvc.1.0\CLSID
(Default) = "{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebSvc
(Default) = "GoogleUpdate Update3Web"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebSvc\CLSID
(Default) = "{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebSvc\CurVer
(Default) = "globalUpdateUpdate.Update3WebSvc.1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
(Default) = "GoogleUpdate Update3Web"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}\
ProgID
(Default) = "globalUpdateUpdate.Update3WebSvc.1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}\
VersionIndependentProgID
(Default) = "globalUpdateUpdate.Update3WebSvc"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
AppID = "{3278F5CF-48F3-4253-A6BB-004CE84AF492}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoreClass.1
(Default) = "Google Update Core Class"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoreClass.1\CLSID
(Default) = "{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoreClass
(Default) = "Google Update Core Class"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoreClass\CLSID
(Default) = "{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoreClass\CurVer
(Default) = "globalUpdateUpdate.CoreClass.1"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
(Default) = "Google Update Core Class"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}\
ProgID
(Default) = "globalUpdateUpdate.CoreClass.1"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}\
VersionIndependentProgID
(Default) = "globalUpdateUpdate.CoreClass"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
AppID = "{3278F5CF-48F3-4253-A6BB-004CE84AF492}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}\
InprocHandler32
(Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\psmachine.dll"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}\
InprocHandler32
ThreadingModel = "Both"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}\
InprocServer32
(Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\psmachine.dll"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}\
InprocServer32
ThreadingModel = "Both"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}\
InProcServer32
(Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\psmachine.dll"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}\
InProcServer32
ThreadingModel = "Both"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
(Default) = "PSFactoryBuffer"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{3CC60715-D6C5-429D-830E-43FA3F86C61D}\
ProxyStubClsid32
(Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{3CC60715-D6C5-429D-830E-43FA3F86C61D}
(Default) = "IProgressWndEvents"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{3CC60715-D6C5-429D-830E-43FA3F86C61D}\
NumMethods
(Default) = "9"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{3A807417-B46D-4D37-8C9A-19AC6DE204F9}\
ProxyStubClsid32
(Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{3A807417-B46D-4D37-8C9A-19AC6DE204F9}
(Default) = "IBrowserHttpRequest2"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{3A807417-B46D-4D37-8C9A-19AC6DE204F9}\
NumMethods
(Default) = "4"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{07F41522-AF7D-4F26-B394-094F059FDB8A}\
ProxyStubClsid32
(Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{07F41522-AF7D-4F26-B394-094F059FDB8A}
(Default) = "IAppBundleWeb"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{07F41522-AF7D-4F26-B394-094F059FDB8A}\
NumMethods
(Default) = "24"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{DD1F043F-ABC8-4643-8B95-D2C5B22BB019}\
ProxyStubClsid32
(Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{DD1F043F-ABC8-4643-8B95-D2C5B22BB019}
(Default) = "IProcessLauncher"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{DD1F043F-ABC8-4643-8B95-D2C5B22BB019}\
NumMethods
(Default) = "6"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{212E6D43-6062-492A-B8CC-144669FF11ED}\
ProxyStubClsid32
(Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{212E6D43-6062-492A-B8CC-144669FF11ED}
(Default) = "IAppVersion"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{212E6D43-6062-492A-B8CC-144669FF11ED}\
NumMethods
(Default) = "10"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{555D7146-94A8-4C94-AE76-C39CDC7F7705}\
ProxyStubClsid32
(Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{555D7146-94A8-4C94-AE76-C39CDC7F7705}
(Default) = "ICoCreateAsyncStatus"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{555D7146-94A8-4C94-AE76-C39CDC7F7705}\
NumMethods
(Default) = "10"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{4517D94C-19BA-46FA-BE66-2A30CEAC4A85}\
ProxyStubClsid32
(Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{4517D94C-19BA-46FA-BE66-2A30CEAC4A85}
(Default) = "IAppBundle"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{4517D94C-19BA-46FA-BE66-2A30CEAC4A85}\
NumMethods
(Default) = "39"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{224FE662-1E6D-4BC0-AEBB-9E2FB4057BE9}\
ProxyStubClsid32
(Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{224FE662-1E6D-4BC0-AEBB-9E2FB4057BE9}
(Default) = "ICoCreateAsync"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{224FE662-1E6D-4BC0-AEBB-9E2FB4057BE9}\
NumMethods
(Default) = "4"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{0C40F472-7407-4467-8914-1DEA7C326972}\
ProxyStubClsid32
(Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{0C40F472-7407-4467-8914-1DEA7C326972}
(Default) = "IAppWeb"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{0C40F472-7407-4467-8914-1DEA7C326972}\
NumMethods
(Default) = "14"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{A6D54287-7939-466A-8579-92546D946C8C}\
ProxyStubClsid32
(Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{A6D54287-7939-466A-8579-92546D946C8C}
(Default) = "IOneClickProcessLauncher"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{A6D54287-7939-466A-8579-92546D946C8C}\
NumMethods
(Default) = "4"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{0522D9A4-4D57-437D-978D-E5B3B6C9005D}\
ProxyStubClsid32
(Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{0522D9A4-4D57-437D-978D-E5B3B6C9005D}
(Default) = "IAppVersionWeb"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{0522D9A4-4D57-437D-978D-E5B3B6C9005D}\
NumMethods
(Default) = "10"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{A8F7D0A5-7074-40B8-9BDC-1174BDD0A132}\
ProxyStubClsid32
(Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{A8F7D0A5-7074-40B8-9BDC-1174BDD0A132}
(Default) = "IGoogleUpdate3WebSecurity"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{A8F7D0A5-7074-40B8-9BDC-1174BDD0A132}\
NumMethods
(Default) = "4"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{D14D64BC-A0E4-42E3-BB72-FB41EA43C198}\
ProxyStubClsid32
(Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{D14D64BC-A0E4-42E3-BB72-FB41EA43C198}
(Default) = "IPackage"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{D14D64BC-A0E4-42E3-BB72-FB41EA43C198}\
NumMethods
(Default) = "10"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{023E9EC8-B147-40EB-B0B3-DF90618FB371}\
ProxyStubClsid32
(Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{023E9EC8-B147-40EB-B0B3-DF90618FB371}
(Default) = "ICurrentState"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{023E9EC8-B147-40EB-B0B3-DF90618FB371}\
NumMethods
(Default) = "24"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{ED0B64D4-BF27-4521-AD27-190F49BF5EA7}\
ProxyStubClsid32
(Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{ED0B64D4-BF27-4521-AD27-190F49BF5EA7}
(Default) = "IJobObserver"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{ED0B64D4-BF27-4521-AD27-190F49BF5EA7}\
NumMethods
(Default) = "13"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{8120D9D6-785C-4413-9C0C-DF2028C56FAD}\
ProxyStubClsid32
(Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{8120D9D6-785C-4413-9C0C-DF2028C56FAD}
(Default) = "IGoogleUpdate"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{8120D9D6-785C-4413-9C0C-DF2028C56FAD}\
NumMethods
(Default) = "5"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{823AE2EB-E62C-4847-B192-C99B91B92416}\
ProxyStubClsid32
(Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{823AE2EB-E62C-4847-B192-C99B91B92416}
(Default) = "IApp"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{823AE2EB-E62C-4847-B192-C99B91B92416}\
NumMethods
(Default) = "40"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{9B9A45F4-18FC-484A-BACA-076D78273D8E}\
ProxyStubClsid32
(Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{9B9A45F4-18FC-484A-BACA-076D78273D8E}
(Default) = "IGoogleUpdateCore"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{9B9A45F4-18FC-484A-BACA-076D78273D8E}\
NumMethods
(Default) = "4"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{E3F3E8F9-F747-4DD6-BA6B-82A6CE1E0860}\
ProxyStubClsid32
(Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{E3F3E8F9-F747-4DD6-BA6B-82A6CE1E0860}
(Default) = "IRegistrationUpdateHook"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{E3F3E8F9-F747-4DD6-BA6B-82A6CE1E0860}\
NumMethods
(Default) = "8"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{59D188FA-757A-424E-8C93-F58FFD896BD7}\
ProxyStubClsid32
(Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{59D188FA-757A-424E-8C93-F58FFD896BD7}
(Default) = "ICredentialDialog"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{59D188FA-757A-424E-8C93-F58FFD896BD7}\
NumMethods
(Default) = "4"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{A78EDAFB-926F-4D93-AB13-8232D7378EB1}\
ProxyStubClsid32
(Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{A78EDAFB-926F-4D93-AB13-8232D7378EB1}
(Default) = "IGoogleUpdate3"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{A78EDAFB-926F-4D93-AB13-8232D7378EB1}\
NumMethods
(Default) = "10"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{9B4F7CFE-987D-410E-A8E4-20182E0B3C24}\
ProxyStubClsid32
(Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{9B4F7CFE-987D-410E-A8E4-20182E0B3C24}
(Default) = "IGoogleUpdate3Web"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{9B4F7CFE-987D-410E-A8E4-20182E0B3C24}\
NumMethods
(Default) = "8"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassMachine.1.0
(Default) = "Google Update Broker Class Factory"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassMachine.1.0\CLSID
(Default) = "{ADBC39BE-3D20-4333-8D99-E91EB1B62474}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassMachine
(Default) = "Google Update Broker Class Factory"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassMachine\CLSID
(Default) = "{ADBC39BE-3D20-4333-8D99-E91EB1B62474}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassMachine\CurVer
(Default) = "globalUpdateUpdate.OnDemandCOMClassMachine.1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
(Default) = "Google Update Broker Class Factory"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}\
ProgID
(Default) = "globalUpdateUpdate.OnDemandCOMClassMachine.1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}\
VersionIndependentProgID
(Default) = "globalUpdateUpdate.OnDemandCOMClassMachine"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}\
LocalServer32
(Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
LocalizedString = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-3000"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}\
Elevation
Enabled = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}\
Elevation
IconReference = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-1004"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebMachine.1.0
(Default) = "Google Update Broker Class Factory"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebMachine.1.0\CLSID
(Default) = "{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebMachine
(Default) = "Google Update Broker Class Factory"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebMachine\CLSID
(Default) = "{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebMachine\CurVer
(Default) = "globalUpdateUpdate.Update3WebMachine.1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
(Default) = "Google Update Broker Class Factory"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}\
ProgID
(Default) = "globalUpdateUpdate.Update3WebMachine.1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}\
VersionIndependentProgID
(Default) = "globalUpdateUpdate.Update3WebMachine"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}\
LocalServer32
(Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
LocalizedString = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-3000"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}\
Elevation
Enabled = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}\
Elevation
IconReference = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-1004"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoCreateAsync.1.0
(Default) = "CoCreateAsync"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoCreateAsync.1.0\CLSID
(Default) = "{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoCreateAsync
(Default) = "CoCreateAsync"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoCreateAsync\CLSID
(Default) = "{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoCreateAsync\CurVer
(Default) = "globalUpdateUpdate.CoCreateAsync.1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
(Default) = "CoCreateAsync"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}\
ProgID
(Default) = "globalUpdateUpdate.CoCreateAsync.1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}\
VersionIndependentProgID
(Default) = "globalUpdateUpdate.CoCreateAsync"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}\
LocalServer32
(Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdate.OneClickProcessLauncherMachine.1.0
(Default) = "globalUpdate.OneClickProcessLauncher"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdate.OneClickProcessLauncherMachine.1.0\CLSID
(Default) = "{5E89ACE9-E16B-499A-87B4-0DBF742404C1}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdate.OneClickProcessLauncherMachine
(Default) = "globalUpdate.OneClickProcessLauncher"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdate.OneClickProcessLauncherMachine\CLSID
(Default) = "{5E89ACE9-E16B-499A-87B4-0DBF742404C1}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdate.OneClickProcessLauncherMachine\CurVer
(Default) = "globalUpdate.OneClickProcessLauncherMachine.1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
(Default) = "globalUpdate.OneClickProcessLauncher"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}\
ProgID
(Default) = "globalUpdate.OneClickProcessLauncherMachine.1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}\
VersionIndependentProgID
(Default) = "globalUpdate.OneClickProcessLauncherMachine"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}\
LocalServer32
(Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Internet Explorer\Low Rights\
ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
CLSID = "{5E89ACE9-E16B-499A-87B4-0DBF742404C1}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Internet Explorer\Low Rights\
ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Policy = "3"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.ProcessLauncher.1.0
(Default) = "Google Update Process Launcher Class"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.ProcessLauncher.1.0\CLSID
(Default) = "{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.ProcessLauncher
(Default) = "Google Update Process Launcher Class"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.ProcessLauncher\CLSID
(Default) = "{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.ProcessLauncher\CurVer
(Default) = "globalUpdateUpdate.ProcessLauncher.1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
(Default) = "Google Update Process Launcher Class"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}\
ProgID
(Default) = "globalUpdateUpdate.ProcessLauncher.1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}\
VersionIndependentProgID
(Default) = "globalUpdateUpdate.ProcessLauncher"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}\
LocalServer32
(Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoreMachineClass.1
(Default) = "Google Update Core Class"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoreMachineClass.1\CLSID
(Default) = "{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoreMachineClass
(Default) = "Google Update Core Class"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoreMachineClass\CLSID
(Default) = "{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CoreMachineClass\CurVer
(Default) = "globalUpdateUpdate.CoreMachineClass.1"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
(Default) = "Google Update Core Class"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}\
ProgID
(Default) = "globalUpdateUpdate.CoreMachineClass.1"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}\
VersionIndependentProgID
(Default) = "globalUpdateUpdate.CoreMachineClass"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}\
LocalServer32
(Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
LocalizedString = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-3000"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}\
Elevation
Enabled = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}\
Elevation
IconReference = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-1004"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
{random key}
(Default) = "Google Update Legacy On Demand"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0\CLSID
(Default) = "{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassMachineFallback
(Default) = "Google Update Legacy On Demand"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassMachineFallback\CLSID
(Default) = "{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.OnDemandCOMClassMachineFallback\CurVer
(Default) = "globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
(Default) = "Google Update Legacy On Demand"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}\
ProgID
(Default) = "globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}\
VersionIndependentProgID
(Default) = "globalUpdateUpdate.OnDemandCOMClassMachineFallback"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}\
LocalServer32
(Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
LocalizedString = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-3000"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}\
Elevation
Enabled = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}\
Elevation
IconReference = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-1004"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebMachineFallback.1.0
(Default) = "GoogleUpdate Update3Web"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebMachineFallback.1.0\CLSID
(Default) = "{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebMachineFallback
(Default) = "GoogleUpdate Update3Web"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebMachineFallback\CLSID
(Default) = "{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.Update3WebMachineFallback\CurVer
(Default) = "globalUpdateUpdate.Update3WebMachineFallback.1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
(Default) = "GoogleUpdate Update3Web"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}\
ProgID
(Default) = "globalUpdateUpdate.Update3WebMachineFallback.1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}\
VersionIndependentProgID
(Default) = "globalUpdateUpdate.Update3WebMachineFallback"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}\
LocalServer32
(Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
LocalizedString = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-3000"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}\
Elevation
Enabled = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}\
Elevation
IconReference = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-1004"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CredentialDialogMachine.1.0
(Default) = "GoogleUpdate CredentialDialog"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CredentialDialogMachine.1.0\CLSID
(Default) = "{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CredentialDialogMachine
(Default) = "GoogleUpdate CredentialDialog"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CredentialDialogMachine\CLSID
(Default) = "{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
globalUpdateUpdate.CredentialDialogMachine\CurVer
(Default) = "globalUpdateUpdate.CredentialDialogMachine.1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
(Default) = "GoogleUpdate CredentialDialog"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}\
ProgID
(Default) = "globalUpdateUpdate.CredentialDialogMachine.1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}\
VersionIndependentProgID
(Default) = "globalUpdateUpdate.CredentialDialogMachine"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}\
LocalServer32
(Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Chrome-Profiles\%AppDataLocal%\
Google\Chrome\User Data
Default = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Chrome
TotalProfiles = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\ErrorLists-crchromeinstaller
post_for_sign_Invalid HTTP(S) status code = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\ErrorLists-crchromeinstaller
insert_cook_db_1_table cookies has no column named secure = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\ErrorLists-crchromeinstaller
insert_cook_db_1_table cookies has no column named secure = "2"

HKEY_CURRENT_USER\Software\globalUpdate\
Update\proxy
source = "IE"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP
ActiveAppId = "54246"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Update
LastCheck = "1562855063"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Installer
Bic = "354A91DE7DC14C2A980B5427C0148BABIE"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Installer
Verifier = "be6aa8aa1574234ad24e003e9b0dc90a"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Installer
Time = "1562855042"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Installer
StatsDomain = "http://stats.{BLOCKED}statsservice.com"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Installer
ErrorsDomain = "http://errors.{BLOCKED}statsservice.com"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Installer
CodeDownloadDomain = "http://js.{BLOCKED}statsservice.com"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Installer
FullVersion = "1.34.5.22"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Installer
FullVersionForUrl = "1_34_05_22"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Installer
SrcId = "001359"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Installer
SubId = "0"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Installer
ZData = "0"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Installer
DefaultBrowser = "ie"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Installer
OsName = "7"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Installer
Params = "{ source_id : 001359, sub_id : 0, uzid : 0}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Manifest
Name = "MPMP"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Manifest
Manifest = "NA"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Manifest
Description = "MediaPlayerEnhance Extension"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Manifest
PublisherName = "Freeven"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Manifest
HomePageUrl = "NA"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Manifest
RunInFrame = "false"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Manifest
ThanksUrl = "NA"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Manifest
DisableIe = "true"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Manifest
EnableSearchIE = "false"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Manifest
Version = "38"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Manifest
UpdateInterval = "360"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Manifest
BgVersion = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Manifest
AddressbarURL = "NA"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Manifest
ChangePrevious = "false"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Manifest
SetNewTab = "false"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Manifest
PublisherId = "21636"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Manifest
ModeType = "production"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Manifest
PluginsManifestVersion = "30"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Manifest
IsButtonEnabled = "false"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Manifest
UninstallerOfferUrl = "NA"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Manifest
UninstallerOfferAction = "NA"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Code
AppJavaScript = "{random characters}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Code
BgJavaScript = "{random characters}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Code
NewTabJavaScript = ""

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\251
Version = "8"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\251
Name = "versionBinaryString"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\251
JavaScript = "{random characters}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\251
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/Nova/versionBinaryString.js"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\249
Version = "6"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\249
Name = "native"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\249
JavaScript = "{random characters}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\249
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/Nova/native.js"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\250
Version = "5"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\250
Name = "api"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\250
JavaScript = "{random characters}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\250
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/Nova/api.js"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\14
Version = "11"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\14
Name = "CrossriderUtils"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\14
JavaScript = "{random characters}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\14
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/CrossriderUtils.js"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\78
Version = "5"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\78
Name = "CrossriderInfo"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\78
JavaScript = "{random characters}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\78
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/CrossriderInfo.js"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\233
Version = "5"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\233
Name = "revizer_p_dynamic_b2b_2_m"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\233
JavaScript = "{random characters}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\233
Url = "{random characters}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\253
Version = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\253
Name = "pixel_inject"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\253
JavaScript = "{random characters}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\253
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/pixel_inject.js"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\242
Version = "3"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\242
Name = "price_gong_m"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\242
JavaScript = "{random characters}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\242
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/price_gong_m.js"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\211
Version = "5"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\211
Name = "revizer_ws_dynamic_b2b_light_m"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\211
JavaScript = "{random characters}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\211
Url = "{random characters}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\191
Version = "5"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\191
Name = "ciuvo_m"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\191
JavaScript = "{random characters}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\191
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/ciuvo_m.js"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\184
Version = "9"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\184
Name = "noproblemppc_m"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\184
JavaScript = "{random characters}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\184
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/noproblemppc_m.js"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\155
Version = "3"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\155
Name = "ibario_pops_m"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\155
JavaScript = "{random characters}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\155
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/ibario_pops_m.js"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\102
Version = "7"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\102
Name = "dealply_m"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\102
JavaScript = "{random characters}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\102
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/dealply_m.js"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\93
Version = "10"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\93
Name = "superfish_no_coupons_m"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\93
JavaScript = "{random characters}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\93
Url = "{random characters}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\91
Version = "49"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\91
Name = "monetizationLoader.js"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\91
JavaScript = "{random characters}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\91
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/monetizationLoader.js"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\246
Version = "10"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\246
Name = "setup"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\246
JavaScript = "{random characters}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\246
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/setup.js"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\4
Version = "4"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\4
Name = "jquery_1_7_1"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\4
JavaScript = "{random characters}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins\4
Url = "http://js.{BLOCKED}statsservice.com/plugins/javascripts/jquery-1_7_1_min.js"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins
AppPluginList = "246,14,78,4,93,102,155,184,191,211,233,242,253,91"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins
BgPluginList = "246,4,14,78,251,249,250,93,102,155,184,191,211,233,242,253,91"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins
NewTabPluginList = "14,78,4"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins
OnRequestPluginList = "14"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins
BrowserEventPluginList = "14"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Plugins
PopupPluginList = "4,14,78"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Update
LastCheck = "1562855064"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Firefox\Profiles\
%Application Data%\Mozilla\Firefox\
Profiles
lj5mikyj.default = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\Firefox
TotalProfiles = "1"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP
ActiveAppId = "54246"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Update
LastCheck = "1562855079"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\Crossrider
Bic = "354A91DE7DC14C2A980B5427C0148BABIE"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\Crossrider
Verifier = "be6aa8aa1574234ad24e003e9b0dc90a"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Installer
Time = "1562855042"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Installer
StatsDomain = "http://stats.{BLOCKED}statsservice.com"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Installer
ErrorsDomain = "http://errors.{BLOCKED}statsservice.com"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Installer
CodeDownloadDomain = "http://js.{BLOCKED}statsservice.com"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Installer
FullVersion = "1.34.5.22"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Installer
FullVersionForUrl = "1_34_05_22"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Installer
SrcId = "001359"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Installer
SubId = "0"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Installer
ZData = "0"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Installer
DefaultBrowser = "ie"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Installer
OsName = "7"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Installer
Params = "{ source_id : 001359, sub_id : 0, uzid : 0}"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\IE\Profiles
S-1-5-21-2407829820-1079796033-203259571-500 = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
MPMP\IE
TotalProfiles = "1"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Manifest
Name = "MPMP"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Manifest
Manifest = "NA"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Manifest
Description = "MediaPlayerEnhance Extension"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Manifest
PublisherName = "Freeven"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Manifest
HomePageUrl = "NA"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Manifest
RunInFrame = "false"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Manifest
ThanksUrl = "NA"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Manifest
DisableIe = "true"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Manifest
EnableSearchIE = "false"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Manifest
Version = "38"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Manifest
UpdateInterval = "360"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Manifest
BgVersion = "1"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Manifest
AddressbarURL = "NA"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Manifest
ChangePrevious = "false"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Manifest
SetNewTab = "false"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Manifest
PublisherId = "21636"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Manifest
ModeType = "production"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Manifest
PluginsManifestVersion = "30"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Manifest
IsButtonEnabled = "false"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Manifest
UninstallerOfferUrl = "NA"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Manifest
UninstallerOfferAction = "NA"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Code
AppJavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Code
BgJavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Code
NewTabJavaScript = ""

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
183
Version = "4"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
183
Name = "tabsWrapper"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
183
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
183
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/tabsWrapper.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
182
Version = "3"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
182
Name = "openUrl"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
182
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
182
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/openUrl.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
177
Version = "2"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
177
Name = "crossriderDashboard"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
177
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
177
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/crossriderDashboard.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
94
Version = "2"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
94
Name = "IEPopup"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
94
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
94
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IEPopup.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
78
Version = "5"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
78
Name = "CrossriderInfo"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
78
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
78
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/CrossriderInfo.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
207
Version = "2"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
207
Name = "dbWrapper"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
207
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
207
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/dbWrapper.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
64
Version = "3"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
64
Name = "appApiMessage"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
64
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
64
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/appApiMessage.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
72
Version = "5"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
72
Name = "appApiValidation"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
72
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
72
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/appApiValidation.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
46
Version = "5"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
46
Name = "IETimers"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
46
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
46
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IETimers.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
45
Version = "4"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
45
Name = "IEOnRequest"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
45
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
45
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IEOnRequest.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
44
Version = "6"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
44
Name = "IEMisc"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
44
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
44
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IEMisc.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
43
Version = "5"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
43
Name = "IEMessaging"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
43
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
43
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IEMessaging.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
42
Version = "9"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
42
Name = "IEInternal"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
42
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
42
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IEInternal.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
41
Version = "7"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
41
Name = "IEInfo"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
41
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
41
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IEInfo.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
40
Version = "4"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
40
Name = "IEExtension"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
40
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
40
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IEExtension.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
39
Version = "5"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
39
Name = "IEDatabase"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
39
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
39
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IEDatabase.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
38
Version = "4"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
38
Name = "IECallbacks"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
38
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
38
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IECallbacks.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
37
Version = "6"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
37
Name = "IEBrowserEvents"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
37
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
37
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IEBrowserEvents.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
36
Version = "8"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
36
Name = "IEBackground"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
36
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
36
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IEBackground.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
35
Version = "4"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
35
Name = "IEAjax"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
35
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
35
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IEAjax.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
17
Version = "4"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
17
Name = "jQuery"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
17
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
17
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/jQuery.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
14
Version = "11"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
14
Name = "CrossriderUtils"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
14
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
14
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/CrossriderUtils.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
13
Version = "7"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
13
Name = "CrossriderAppUtils"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
13
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
13
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/CrossriderAppUtils.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
253
Version = "1"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
253
Name = "pixel_inject"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
253
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
253
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/pixel_inject.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
242
Version = "3"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
242
Name = "price_gong_m"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
242
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
242
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/price_gong_m.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
233
Version = "5"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
233
Name = "revizer_p_dynamic_b2b_2_m"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
233
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
233
Url = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
226
Version = "4"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
226
Name = "set_campaign_id_m"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
226
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
226
Url = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
221
Version = "2"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
221
Name = "icm_downloads_m"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
221
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
221
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/icm_downloads_m.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
211
Version = "5"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
211
Name = "revizer_ws_dynamic_b2b_light_m"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
211
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
211
Url = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
195
Version = "25"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
195
Name = "icm_convertmedia_m"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
195
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
195
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/icm_convertmedia_m.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
220
Version = "8"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
220
Name = "icm_base_m"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
220
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
220
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/icm_base_m.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
7
Version = "2"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
7
Name = "hooks"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
7
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
7
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/hooks.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
9
Version = "3"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
9
Name = "search_engine_hook"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
9
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
9
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/searchengines_hook.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
191
Version = "5"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
191
Name = "ciuvo_m"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
191
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
191
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/ciuvo_m.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
190
Version = "3"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
190
Name = "pops_5_m"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
190
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
190
Url = "http://js.{BLOCKED}statsservice.com/plugins/javascripts/monetization/geo/pops_5_m.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
155
Version = "3"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
155
Name = "ibario_pops_m"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
155
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
155
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/ibario_pops_m.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
104
Version = "9"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
104
Name = "jollywallet_m"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
104
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
104
Url = "http://js.{BLOCKED}statsservice.com/plugins/javascripts/monetization/geo/jollywallet_m.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
184
Version = "9"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
184
Name = "noproblemppc_m"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
184
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
184
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/noproblemppc_m.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
103
Version = "8"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
103
Name = "intext_5_m"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
103
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
103
Url = "http://js.{BLOCKED}statsservice.com/plugins/javascripts/monetization/geo/intext_5_m.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
102
Version = "7"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
102
Name = "dealply_m"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
102
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
102
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/dealply_m.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
93
Version = "10"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
93
Name = "superfish_no_coupons_m"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
93
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
93
Url = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
91
Version = "49"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
91
Name = "monetizationLoader.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
91
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
91
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/monetizationLoader.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
246
Version = "10"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
246
Name = "setup"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
246
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
246
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/setup.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
47
Version = "3"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
47
Name = "resources_background"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
47
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
47
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/resources_background.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
22
Version = "5"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
22
Name = "resources"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
22
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
22
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/resources.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
28
Version = "4"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
28
Name = "initializer"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
28
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
28
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/initializer.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
3
Version = "2"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
3
Name = "ie8_fix_2"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
3
JavaScript = "(function(){var b=dummy so this plugin won't be empty;})();"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
3
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie8_fix_2.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
21
Version = "5"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
21
Name = "debug"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
21
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
21
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/debug.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
2
Version = "2"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
2
Name = "ie8_fix_1"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
2
JavaScript = "(function(){var b=dummy so this plugin won't be empty;})();"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
2
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie8_fix_1.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
4
Version = "4"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
4
Name = "jquery_1_7_1"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
4
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
4
Url = "http://js.{BLOCKED}statsservice.com/plugins/javascripts/jquery-1_7_1_min.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
1
Version = "10"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
1
Name = "base"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
1
JavaScript = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins\
1
Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/base.js"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins
AppPluginList = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins
BgPluginList = "{random characters}"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins
NewTabPluginList = "42,38,46,17,14,78,13,41,44,39,35,43,40,64,2,4,3,1,21,22,72,28"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins
OnRequestPluginList = "14,42,41,39,38,43,45,64,72"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins
BrowserEventPluginList = "14,42,41,44,39,38,43,37,64,72"

HKEY_CURRENT_USER\Software\AppDataLow\
Software\MPMP\Plugins
PopupPluginList = "42,38,46,41,44,39,35,43,36,4,14,78,13,64,207,47,182,72,94"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp0054246.Sandbox.1
(Default) = "CrossriderApp0054246.Sandbox"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp0054246.Sandbox.1\CLSID
(Default) = "{{GUID}}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp0054246.BHO.1
(Default) = "CrossriderApp0054246"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp0054246.BHO.1\CLSID
(Default) = "{{GUID}}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp0054246.Sandbox
(Default) = "CrossriderApp0054246.Sandbox"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp0054246.Sandbox\CLSID
(Default) = "{{GUID}}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp0054246.Sandbox\CurVer
(Default) = "CrossriderApp0054246.Sandbox"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp0054246.BHO
(Default) = "CrossriderApp0054246"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp0054246.BHO\CLSID
(Default) = "{{GUID}}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp0054246.BHO\CurVer
(Default) = "CrossriderApp0054246"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{{GUID}}
(Default) = "MPMP"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{{GUID}}\
ProgID
(Default) = "CrossriderApp0054246.BHO.1"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{{GUID}}\
VersionIndependentProgID
(Default) = "CrossriderApp0054246"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{{GUID}}\
InprocServer32
(Default) = "%Program Files%\MPMP\MPMP-bho.dll"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{{GUID}}\
InprocServer32
ThreadingModel = "Apartment"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{{GUID}}\
TypeLib
(Default) = "{{GUID}}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{{GUID}}\
Implemented Categories
(Default) = ""

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{{GUID}}\
Implemented Categories\{{GUID}}
(Default) = ""

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{{GUID}}
(Default) = "CrossriderApp0054246.Sandbox"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{{GUID}}\
ProgID
(Default) = "CrossriderApp0054246.Sandbox.1"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\CLSID\{{GUID}}\
VersionIndependentProgID
(Default) = "CrossriderApp0054246.Sandbox"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
explorer\Browser Helper Objects\{{GUID}}
(Default) = "CrossriderApp0054246"

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
explorer\Browser Helper Objects\{{GUID}}
NoExplorer = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{{GUID}}
(Default) = "ICrossriderBHO"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{{GUID}}\
ProxyStubClsid32
(Default) = "{00020424-0000-0000-C000-000000000046}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{{GUID}}\
TypeLib
(Default) = "{{GUID}}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{{GUID}}\
TypeLib
Version = "1.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Wow6432Node\Interface\{{GUID}}
(Default) = "ISandBox"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\globalUpdate
DisplayName = "globalUpdate Update Service (globalUpdate)"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\globalUpdate
Start = "SERVICE_AUTO_START"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\globalUpdatem
DisplayName = "globalUpdate Update Service (globalUpdatem)"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\globalUpdatem
Start = "SERVICE_DEMAND_START"

It deletes the following registry keys:

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
GlobalUpdate\Update\eulaaccepted

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
GlobalUpdate\Update\mi

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
GlobalUpdate\Update\ui

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
GlobalUpdate\Update\LastChecked

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
GlobalUpdate\Update\ClientState\
{430FD4D0-B729-4F61-AA34-91526481799D}\UpdateAvailableCount

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
GlobalUpdate\Update\ClientState\
{430FD4D0-B729-4F61-AA34-91526481799D}\UpdateAvailableSince

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
GlobalUpdate\Update\uid

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
GlobalUpdate\Update\network\
secure\sk

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
GlobalUpdate\Update\network\
secure\c

Dropping Routine

This Adware drops the following files:

  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\21.js
  • %Program Files%\MPMP\54246.crx
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\3e24ea90dedf010dd73864ad8afb9842.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\4f1f2311b6dfe8dc9398b9e63abadc95.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\680792568ec55a86a7e80045e550e236.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe.old
  • %Windows%\Tasks\{GUID}-1.job
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\28.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\popup.html
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\4.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\userCode\extension.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\psuser.dll.old
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\7.js
  • %User Temp%\comh.18754\GoogleUpdateBroker.exe
  • %Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\18be4636f65b5a79a226b006ca76a4e2.js
  • %User Temp%\comh.18754\GoogleUpdateHelper.msi
  • %Program Files%\MPMP\MPMP.ico
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\91.js
  • %User Temp%\AF2.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\221.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateHelper.msi.old
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\45d83464f48807f918f66018f5438b9e.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\183.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\64.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\9.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\search_dialog.xul
  • %Program Files%\MPMP\MPMP-bho.dll
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\installer.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\98.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\5028e2cbf92f3b87b57c694503c57e72.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\37993b8abf06e383d7ef53385525f010.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\787e77f8d7ecc7156be99bd0b0fde217.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\47.js
  • %All Users Profile%\Microsoft\Network\Downloader\qmgr0.dat
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\253.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\190.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\panelarrow-up.png
  • %User Temp%\comh.18754\goopdateres_en.dll
  • %Windows%\Tasks\{GUID}-3.job
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\dialog.js
  • %Windows%\Tasks\{GUID}-6.job
  • %Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe.old
  • %User Temp%\AF1.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\3cdbe045a4a0d3f50bd7b4f8b905fc1d.js
  • %User Temp%\comh.18754\npGoogleUpdate4.dll
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\d011f9d6a8671d3a2bc2b558decdb410.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\button3.png
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\2778ebbf69e285e413df59bb58a8fca9.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\background.html
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\102.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\93.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\userCode\background.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\13.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\4b4b6daaa6ac343ffc1b119ddb0b246c.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\2d5d68b375151fbed320fd2c0181c191.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions.json
  • %User Temp%\comh.18754\goopdate.dll
  • %User Temp%\comh.18754\GoogleUpdate.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\icon48.png
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\bd82ad0f96fb35e02c077edbf2b9f8c6.js
  • %Windows%\Tasks\globalUpdateUpdateTaskMachineUA.job
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\246.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\49566522acce9f80ebb86c35dfb155d3.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\78.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\update.css
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\icon24.png
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\191.js
  • %Program Files%\globalUpdate\Update\GoogleUpdate.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\16.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\5ef7cf534cdbca51efd63b695e3d0f62.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe
  • %Program Files%\MPMP\54246.xpi
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\1370ab8db88b6403223ec11e7a236c84.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\50d601b837ee9834f42c82ddcb1d0c65.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\177.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\icon16.png
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\options.js
  • %All Users Profile%\Microsoft\Network\Downloader\qmgr1.dat
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\d35d0bca3d387bec73e98493bae4bebe.js
  • %User Temp%\comh.18754\GoogleCrashHandler.exe
  • %Program Files%\MPMP\MPMP-nova.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\226.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\defaults\preferences\prefs.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\182.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\9caf939c72d899c9467323bea849b4a3.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\goopdateres_en.dll
  • %Program Files%\MPMP\utils.exe
  • %Program Files%\MPMP\Uninstall.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\6f5764ff79aeb23978e9db22d7981041.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins.json
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\207.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\icon128.png
  • %Program Files%\globalUpdate\Update\1.3.25.0\GoogleCrashHandler.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\button4.png
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\72.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\crossrider_statusbar.png
  • %Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll.old
  • %Program Files%\MPMP\MPMP-codedownloader.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\ceec657593dea2fb9978c177d58f364c.js
  • %User Temp%\comh.18754\psuser.dll
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\104.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\bdbd33145ab7dbb7b5175dc29e13a54f.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\211.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\3438e9cee6f289fe93d7d8abe705ba24.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdate.exe
  • %User Temp%\comh.18754\GoogleUpdateOnDemand.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\ffCoreFilesIndex.txt
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\install.rdf
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\browser.xul
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\8cf406521b5bdabeda6c9b01aad99f51.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\6589406f5c43cdd372d3b9893fe94669.js
  • %Program Files%\MPMP\{GUID}-3.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\184.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\1.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\f04545df6da39e41ae904087d7b3a91c.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\goopdateres_en.dll.old
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\manifest.xml
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\9dba55b4f2557e03aca1fe863b4a9f9e.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\c1ab6a0d65c6bdb80c05eb57261a3d55.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateHelper.msi
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\24e5241137ac099bd0069f5361058525.js
  • %Program Files%\MPMP\MPMP-nova.dll
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\242.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\155.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\22.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\17.js
  • %Program Files%\MPMP\1293297481.mxaddon
  • %Windows%\Tasks\{GUID}-7.job
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\skin.css
  • %Program Files%\globalUpdate\Update\1.3.25.0\psmachine.dll
  • %Program Files%\globalUpdate\Update\1.3.25.0\GoogleCrashHandler.exe.old
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\195.js
  • %User Temp%\{GUID}.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\3dad8746f8926aafde94171b87503811.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\14.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\options.xul
  • %Program Files%\MPMP\360-54246.crx
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\a3e7c3935aee4f766e6a9b9f5e92c869.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\button1.png
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\c5379747c774cf9228f58cd8633a488f.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll.old
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome.manifest
  • %Windows%\Tasks\temp_{GUID}-7.job
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\f44fe937f6668d4047fb81235269a0e1.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\d827b91b474a06b7771997ad452f2201.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\b51ab7bc967684e1c1f0c290f11ebd30.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\53251c7e83b57e1fb7e90172c5dda028.js
  • %Windows%\Tasks\{GUID}-4.job
  • %Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdate.exe.old
  • %User Temp%\comh.18754\psmachine.dll
  • %Program Files%\MPMP\MPMP-novainstaller.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\3030fc4f3b901802369e95d81dda52be.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\bdeaae1663cfe8266d0bfbc7678dc967.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\babbc84c37010a7be8cf9c5b17340fab.js
  • %AppDataLocal%\Google\Chrome\User Data\Local State
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\103.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\button2.png
  • %Program Files%\globalUpdate\Update\1.3.25.0\psmachine.dll.old
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\af0d6e867c53d6d02549f5c2a1a1c625.js
  • %Windows%\Tasks\globalUpdateUpdateTaskMachineCore.job
  • %Program Files%\MPMP\bgNova.html
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\button5.png
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\220.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\psuser.dll
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\locale\en-US\translations.dtd
  • %Program Files%\MPMP\{GUID}-4.exe
  • %Program Files%\MPMP\MPMP-bho64.dll
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\233.js

Other Details

This Adware connects to the following possibly malicious URL:

  • http://update.{BLOCKED}statsservice.com/installer_updates/001359/update.json
  • http://errors.{BLOCKED}statsservice.com/installer-error.gif?{random characters}
  • http://stats.{BLOCKED}statsservice.com/installer.gif?{random characters}
  • http://logs.{BLOCKED}statsservice.com/monetization.gif?{random characters}
  • http://update.{BLOCKED}statsservice.com/omaha/430FD4D0-B729-4F61-AA34-91526481799D/1/ping.xml?rand=11039
  • http://errors.{BLOCKED}statsservice.com/ch-agent-error.gif?{random characters}
  • http://update.{BLOCKED}statsservice.com/omaha/B13CB685-2858-4509-BB2E-34E3545B73F9/1/update.xml?{random characters}
  • http://update.{BLOCKED}statsservice.com/omaha/B13CB685-2858-4509-BB2E-34E3545B73F9/1/update.xml?rand=11378
  • http://stats.{BLOCKED}statsservice.com/stats.gif?{random characters}
  • http://js.{BLOCKED}statsservice.com/plugin/apps/54246/manifest/1_34_05_22/nova/manifest.xml?ver=38&rnd=1990
  • http://update.{BLOCKED}statsservice.com/omaha/B13CB685-2858-4509-BB2E-34E3545B73F9/1/ping.xml?rand=11405
  • http://update.{BLOCKED}statsservice.com/omaha/B13CB685-2858-4509-BB2E-34E3545B73F9/1/ping.xml?rand=19984
  • http://js.{BLOCKED}statsservice.com/plugin/apps/54246/manifest/1_34_05_22/ie11/manifest.xml?ver=38&rnd=125
  • http://www.{BLOCKED}apis.com

This report is generated via an automated analysis system.

  SOLUTION

Minimum Scan Engine:

9.850

Step 1

Before doing any scans, Windows 7, Windows 8, Windows 8.1, and Windows 10 users must disable System Restore to allow full scanning of their computers.

Step 2

Identify and terminate files detected as Adware.Win32.Crossrider.A

[ Learn More ]
  1. Windows Task Manager may not display all running processes. In this case, please use a third-party process viewer, preferably Process Explorer, to terminate the malware/grayware/spyware file. You may download the said tool here.
  2. If the detected file is displayed in either Windows Task Manager or Process Explorer but you cannot delete it, restart your computer in safe mode. To do this, refer to this link for the complete steps.
  3. If the detected file is not displayed in either Windows Task Manager or Process Explorer, continue doing the next steps.

Step 3

Delete this registry key

[ Learn More ]

Important: Editing the Windows Registry incorrectly can lead to irreversible system malfunction. Please do this step only if you know how or you can ask assistance from your system administrator. Else, check this Microsoft article first before modifying your computer's registry.

  • In HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall
    • MPMP
  • In HKEY_LOCAL_MACHINE\Software\GlobalUpdate\Update\Clients
    • {{GUID}}
  • In HKEY_LOCAL_MACHINE\Software\GlobalUpdate
    • UpdateDev
  • In HKEY_LOCAL_MACHINE\Software\MPMP
    • Installer
  • In HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy
    • {{GUID}}
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy
    • {{GUID}}
  • In HKEY_LOCAL_MACHINE\Software\globalUpdate\Update
    • network
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GlobalUpdate\Update\network
    • secure
  • In HKEY_LOCAL_MACHINE\Software\globalUpdate\Update
    • ClientState
  • In HKEY_LOCAL_MACHINE\Software\globalUpdate\Update\Clients
    • {430FD4D0-B729-4F61-AA34-91526481799D}
  • In HKEY_LOCAL_MACHINE\Software\globalUpdate\Update\ClientState
    • {430FD4D0-B729-4F61-AA34-91526481799D}
  • In HKEY_LOCAL_MACHINE\Software\globalUpdate\Update
    • ClientStateMedium
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins
    • @staging.google.com/globalUpdate Update;version=10
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
    • MimeTypes
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10\MimeTypes
    • application/x-vnd.google.oneclickctrl.10
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved
    • {5645E0E7-FC12-43BF-A6E4-F9751942B298}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\Stats
    • {5645E0E7-FC12-43BF-A6E4-F9751942B298}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\Stats\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
    • iexplore
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\Stats\{5645E0E7-FC12-43BF-A6E4-F9751942B298}\iexplore
    • AllowedDomains
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\Stats\{5645E0E7-FC12-43BF-A6E4-F9751942B298}\iexplore\AllowedDomains
    • *
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy
    • {5645E0E7-FC12-43BF-A6E4-F9751942B298}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdate.OneClickCtrl.10
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID
    • {5645E0E7-FC12-43BF-A6E4-F9751942B298}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
    • InprocServer32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type
    • application/x-vnd.google.oneclickctrl.10
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins
    • @staging.google.com/globalUpdate Update;version=4
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
    • MimeTypes
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4\MimeTypes
    • application/x-vnd.google.update3webcontrol.4
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved
    • {C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\Stats
    • {C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\Stats\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
    • iexplore
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\Stats\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}\iexplore
    • AllowedDomains
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\Stats\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}\iexplore\AllowedDomains
    • *
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy
    • {C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdate.Update3WebControl.4
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID
    • {C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
    • InprocServer32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type
    • application/x-vnd.google.update3webcontrol.4
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID
    • {577975B8-C40E-43E6-B0DE-4C6B44088B52}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID
    • GoogleUpdate.exe
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdateUpdate.Update3COMClassService.1.0
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdateUpdate.Update3COMClassService
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID
    • {577975B8-C40E-43E6-B0DE-4C6B44088B52}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID
    • {3278F5CF-48F3-4253-A6BB-004CE84AF492}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdateUpdate.OnDemandCOMClassSvc.1.0
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdateUpdate.OnDemandCOMClassSvc
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID
    • {3278F5CF-48F3-4253-A6BB-004CE84AF492}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdateUpdate.Update3WebSvc.1.0
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdateUpdate.Update3WebSvc
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID
    • {7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdateUpdate.CoreClass.1
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdateUpdate.CoreClass
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID
    • {3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID
    • {02A96331-0CA6-40E2-A87D-C224601985EB}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
    • InprocHandler32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID
    • {E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
    • InprocServer32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID
    • {CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
    • InProcServer32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface
    • {3CC60715-D6C5-429D-830E-43FA3F86C61D}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{3CC60715-D6C5-429D-830E-43FA3F86C61D}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{3CC60715-D6C5-429D-830E-43FA3F86C61D}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface
    • {3A807417-B46D-4D37-8C9A-19AC6DE204F9}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{3A807417-B46D-4D37-8C9A-19AC6DE204F9}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{3A807417-B46D-4D37-8C9A-19AC6DE204F9}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface
    • {07F41522-AF7D-4F26-B394-094F059FDB8A}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{07F41522-AF7D-4F26-B394-094F059FDB8A}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{07F41522-AF7D-4F26-B394-094F059FDB8A}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface
    • {DD1F043F-ABC8-4643-8B95-D2C5B22BB019}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DD1F043F-ABC8-4643-8B95-D2C5B22BB019}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DD1F043F-ABC8-4643-8B95-D2C5B22BB019}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface
    • {212E6D43-6062-492A-B8CC-144669FF11ED}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{212E6D43-6062-492A-B8CC-144669FF11ED}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{212E6D43-6062-492A-B8CC-144669FF11ED}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface
    • {555D7146-94A8-4C94-AE76-C39CDC7F7705}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{555D7146-94A8-4C94-AE76-C39CDC7F7705}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{555D7146-94A8-4C94-AE76-C39CDC7F7705}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface
    • {4517D94C-19BA-46FA-BE66-2A30CEAC4A85}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{4517D94C-19BA-46FA-BE66-2A30CEAC4A85}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{4517D94C-19BA-46FA-BE66-2A30CEAC4A85}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface
    • {224FE662-1E6D-4BC0-AEBB-9E2FB4057BE9}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{224FE662-1E6D-4BC0-AEBB-9E2FB4057BE9}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{224FE662-1E6D-4BC0-AEBB-9E2FB4057BE9}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface
    • {0C40F472-7407-4467-8914-1DEA7C326972}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{0C40F472-7407-4467-8914-1DEA7C326972}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{0C40F472-7407-4467-8914-1DEA7C326972}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface
    • {A6D54287-7939-466A-8579-92546D946C8C}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{A6D54287-7939-466A-8579-92546D946C8C}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{A6D54287-7939-466A-8579-92546D946C8C}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface
    • {0522D9A4-4D57-437D-978D-E5B3B6C9005D}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{0522D9A4-4D57-437D-978D-E5B3B6C9005D}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{0522D9A4-4D57-437D-978D-E5B3B6C9005D}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface
    • {A8F7D0A5-7074-40B8-9BDC-1174BDD0A132}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{A8F7D0A5-7074-40B8-9BDC-1174BDD0A132}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{A8F7D0A5-7074-40B8-9BDC-1174BDD0A132}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface
    • {D14D64BC-A0E4-42E3-BB72-FB41EA43C198}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D14D64BC-A0E4-42E3-BB72-FB41EA43C198}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D14D64BC-A0E4-42E3-BB72-FB41EA43C198}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface
    • {023E9EC8-B147-40EB-B0B3-DF90618FB371}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{023E9EC8-B147-40EB-B0B3-DF90618FB371}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{023E9EC8-B147-40EB-B0B3-DF90618FB371}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface
    • {ED0B64D4-BF27-4521-AD27-190F49BF5EA7}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{ED0B64D4-BF27-4521-AD27-190F49BF5EA7}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{ED0B64D4-BF27-4521-AD27-190F49BF5EA7}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface
    • {8120D9D6-785C-4413-9C0C-DF2028C56FAD}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{8120D9D6-785C-4413-9C0C-DF2028C56FAD}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{8120D9D6-785C-4413-9C0C-DF2028C56FAD}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface
    • {823AE2EB-E62C-4847-B192-C99B91B92416}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{823AE2EB-E62C-4847-B192-C99B91B92416}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{823AE2EB-E62C-4847-B192-C99B91B92416}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface
    • {9B9A45F4-18FC-484A-BACA-076D78273D8E}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9B9A45F4-18FC-484A-BACA-076D78273D8E}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9B9A45F4-18FC-484A-BACA-076D78273D8E}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface
    • {E3F3E8F9-F747-4DD6-BA6B-82A6CE1E0860}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F3E8F9-F747-4DD6-BA6B-82A6CE1E0860}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F3E8F9-F747-4DD6-BA6B-82A6CE1E0860}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface
    • {59D188FA-757A-424E-8C93-F58FFD896BD7}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{59D188FA-757A-424E-8C93-F58FFD896BD7}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{59D188FA-757A-424E-8C93-F58FFD896BD7}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface
    • {A78EDAFB-926F-4D93-AB13-8232D7378EB1}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{A78EDAFB-926F-4D93-AB13-8232D7378EB1}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{A78EDAFB-926F-4D93-AB13-8232D7378EB1}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface
    • {9B4F7CFE-987D-410E-A8E4-20182E0B3C24}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9B4F7CFE-987D-410E-A8E4-20182E0B3C24}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9B4F7CFE-987D-410E-A8E4-20182E0B3C24}
    • NumMethods
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdateUpdate.OnDemandCOMClassMachine.1.0
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdateUpdate.OnDemandCOMClassMachine
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID
    • {ADBC39BE-3D20-4333-8D99-E91EB1B62474}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
    • LocalServer32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
    • Elevation
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdateUpdate.Update3WebMachine.1.0
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdateUpdate.Update3WebMachine
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID
    • {FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
    • LocalServer32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
    • Elevation
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdateUpdate.CoCreateAsync.1.0
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdateUpdate.CoCreateAsync
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID
    • {E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
    • LocalServer32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdate.OneClickProcessLauncherMachine.1.0
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdate.OneClickProcessLauncherMachine
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID
    • {5E89ACE9-E16B-499A-87B4-0DBF742404C1}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
    • LocalServer32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy
    • {5E89ACE9-E16B-499A-87B4-0DBF742404C1}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdateUpdate.ProcessLauncher.1.0
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdateUpdate.ProcessLauncher
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID
    • {8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
    • LocalServer32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdateUpdate.CoreMachineClass.1
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdateUpdate.CoreMachineClass
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID
    • {6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
    • LocalServer32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
    • Elevation
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • {random key}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdateUpdate.OnDemandCOMClassMachineFallback
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID
    • {69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
    • LocalServer32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
    • Elevation
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdateUpdate.Update3WebMachineFallback.1.0
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdateUpdate.Update3WebMachineFallback
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID
    • {F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
    • LocalServer32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
    • Elevation
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdateUpdate.CredentialDialogMachine.1.0
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    • globalUpdateUpdate.CredentialDialogMachine
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID
    • {834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
    • LocalServer32
  • In HKEY_LOCAL_MACHINE\Software\MPMP
    • Chrome-Profiles
  • In HKEY_LOCAL_MACHINE\Software\MPMP
    • Chrome
  • In HKEY_LOCAL_MACHINE\Software\MPMP
    • ErrorLists-crchromeinstaller
  • In HKEY_CURRENT_USER\Software\globalUpdate\Update
    • proxy
  • In HKEY_LOCAL_MACHINE\Software\Classes
    • Local Settings
  • In HKEY_LOCAL_MACHINE\Classes\Local Settings
    • Software
  • In HKEY_LOCAL_MACHINE\Software\Classes\Local Settings\Software
    • Microsoft
  • In HKEY_LOCAL_MACHINE\Software\Classes\Local Settings\Software\Microsoft
    • Windows
  • In HKEY_LOCAL_MACHINE\Software\Classes\Local Settings\Software\Microsoft\Windows
    • CurrentVersion
  • In HKEY_LOCAL_MACHINE\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion
    • AppContainer
  • In HKEY_LOCAL_MACHINE\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer
    • Storage
  • In HKEY_LOCAL_MACHINE\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage
    • windows_ie_ac_001
  • In HKEY_LOCAL_MACHINE\Classes\Local Settings\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001
    • Software
  • In HKEY_LOCAL_MACHINE\Software\MPMP
    • Update
  • In HKEY_LOCAL_MACHINE\Software\MPMP
    • Manifest
  • In HKEY_LOCAL_MACHINE\Software\MPMP
    • Code
  • In HKEY_LOCAL_MACHINE\Software\MPMP
    • Plugins
  • In HKEY_LOCAL_MACHINE\Software\MPMP\Plugins
    • 251
  • In HKEY_LOCAL_MACHINE\Software\MPMP\Plugins
    • 249
  • In HKEY_LOCAL_MACHINE\Software\MPMP\Plugins
    • 250
  • In HKEY_LOCAL_MACHINE\Software\MPMP\Plugins
    • 14
  • In HKEY_LOCAL_MACHINE\Software\MPMP\Plugins
    • 78
  • In HKEY_LOCAL_MACHINE\Software\MPMP\Plugins
    • 233
  • In HKEY_LOCAL_MACHINE\Software\MPMP\Plugins
    • 253
  • In HKEY_LOCAL_MACHINE\Software\MPMP\Plugins
    • 242
  • In HKEY_LOCAL_MACHINE\Software\MPMP\Plugins
    • 211
  • In HKEY_LOCAL_MACHINE\Software\MPMP\Plugins
    • 191
  • In HKEY_LOCAL_MACHINE\Software\MPMP\Plugins
    • 184
  • In HKEY_LOCAL_MACHINE\Software\MPMP\Plugins
    • 155
  • In HKEY_LOCAL_MACHINE\Software\MPMP\Plugins
    • 102
  • In HKEY_LOCAL_MACHINE\Software\MPMP\Plugins
    • 93
  • In HKEY_LOCAL_MACHINE\Software\MPMP\Plugins
    • 91
  • In HKEY_LOCAL_MACHINE\Software\MPMP\Plugins
    • 246
  • In HKEY_LOCAL_MACHINE\Software\MPMP\Plugins
    • 4
  • In HKEY_LOCAL_MACHINE\Software\MPMP\Firefox
    • Profiles
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software
    • MPMP
  • In HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion
    • AppContainer
  • In HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer
    • Storage
  • In HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage
    • windows_ie_ac_001
  • In HKEY_CURRENT_USER\Classes\Local Settings\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001
    • Software
  • In HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software
    • MPMP
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP
    • Update
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software
    • Crossrider
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP
    • Installer
  • In HKEY_LOCAL_MACHINE\Software\MPMP\IE
    • Profiles
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP
    • Manifest
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP
    • Code
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP
    • Plugins
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 183
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 182
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 177
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 94
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 78
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 207
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 64
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 72
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 46
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 45
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 44
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 43
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 42
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 41
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 40
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 39
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 38
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 37
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 36
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 35
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 17
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 14
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 13
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 253
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 242
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 233
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 226
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 221
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 211
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 195
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 220
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 7
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 9
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 191
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 190
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 155
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 104
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 184
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 103
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 102
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 93
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 91
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 246
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 47
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 22
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 28
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 3
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 21
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 2
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 4
  • In HKEY_USERS\S-1-5-21-2407829820-1079796033-203259571-500\Software\AppDataLow\Software\MPMP\Plugins
    • 1
  • In HKEY_CLASSES_ROOT
    • CrossriderApp0054246.Sandbox.1
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0054246.Sandbox.1
    • CLSID
  • In HKEY_CLASSES_ROOT
    • CrossriderApp0054246.BHO.1
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0054246.BHO.1
    • CLSID
  • In HKEY_CLASSES_ROOT
    • CrossriderApp0054246.Sandbox
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0054246.Sandbox
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0054246.Sandbox
    • CurVer
  • In HKEY_CLASSES_ROOT
    • CrossriderApp0054246.BHO
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0054246.BHO
    • CLSID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0054246.BHO
    • CurVer
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID
    • {{GUID}}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{{GUID}}
    • ProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{{GUID}}
    • VersionIndependentProgID
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{{GUID}}
    • Programmable
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{{GUID}}
    • InprocServer32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{{GUID}}
    • TypeLib
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{{GUID}}
    • Implemented Categories
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\Implemented Categories
    • {{GUID}}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects
    • {{GUID}}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface
    • {{GUID}}
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{{GUID}}
    • ProxyStubClsid32
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{{GUID}}
    • TypeLib

Step 4

Delete this registry value

[ Learn More ]

Important: Editing the Windows Registry incorrectly can lead to irreversible system malfunction. Please do this step only if you know how or you can ask assistance from your system administrator. Else, check this Microsoft article first before modifying your computer's registry.

  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\MPMP
    • DisplayName = "MPMP"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\MPMP
    • DisplayIcon = "%Program Files%\MPMP\utils.exe"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\MPMP
    • DisplayVersion = "1.34.5.22"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\MPMP
    • Publisher = "Freeven"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\MPMP
    • CrPublisherId = "21636"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\MPMP
    • CrAppId = "54246"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\MPMP
    • UninstallString = "%Program Files%\MPMP\Uninstall.exe /fcp=1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GlobalUpdate\Update\Clients\{{GUID}}
    • pv = "1.3.25.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GlobalUpdate\Update\Clients\{{GUID}}
    • name = "Freeven"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GlobalUpdate\Update\Clients\{{GUID}}
    • bic = "354A91DE7DC14C2A980B5427C0148BABIE"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GlobalUpdate\Update\Clients\{{GUID}}
    • verifier = "be6aa8aa1574234ad24e003e9b0dc90a"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GlobalUpdate\Update\Clients\{{GUID}}
    • srcid_var = "001359"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GlobalUpdate\UpdateDev
    • AuCheckPeriodMs = "21600000"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Installer
    • BundledChrome = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Installer
    • BundledNova = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\%Program Files%\MPMP
    • MPMP-nova.exe = "8000"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Installer
    • BundledFirefox = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Installer
    • BundledIe = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{{GUID}}
    • AppName = "MPMP-codedownloader.exe"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{{GUID}}
    • AppPath = "%Program Files%\MPMP"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{{GUID}}
    • Policy = "3"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{{GUID}}
    • AppName = "MPMP-codedownloader.exe"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{{GUID}}
    • AppPath = "%Program Files%\MPMP"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{{GUID}}
    • Policy = "3"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GlobalUpdate\Update
    • path = "%Program Files%\globalUpdate\Update\GoogleUpdate.exe"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GlobalUpdate\Update\Clients\{430FD4D0-B729-4F61-AA34-91526481799D}
    • pv = "1.3.25.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GlobalUpdate\Update\Clients\{430FD4D0-B729-4F61-AA34-91526481799D}
    • name = "globalUpdate Update"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GlobalUpdate\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}
    • pv = "1.3.25.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GoogleUpdate.exe
    • DisableExceptionChainValidation = "0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GlobalUpdate\Update
    • version = "1.3.25.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
    • Path = "%Program Files%\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
    • Description = "globalUpdate Update"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
    • ProductName = "globalUpdate Update"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
    • Vendor = "globalUpdate"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
    • Version = "10"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
    • AppName = "GoogleUpdate.exe"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
    • AppPath = "%Program Files%\globalUpdate\Update"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
    • Policy = "3"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
    • (Default) = "globalUpdate Update Plugin"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10\CLSID
    • (Default) = "{5645E0E7-FC12-43BF-A6E4-F9751942B298}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
    • (Default) = "globalUpdate Update Plugin"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}\ProgID
    • (Default) = "globalUpdate.OneClickCtrl.10"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}\InprocServer32
    • (Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}\InprocServer32
    • ThreadingModel = "Apartment"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-vnd.google.oneclickctrl.10
    • CLSID = "{5645E0E7-FC12-43BF-A6E4-F9751942B298}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
    • Path = "%Program Files%\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
    • Description = "globalUpdate Update"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
    • ProductName = "globalUpdate Update"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
    • Vendor = "globalUpdate"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
    • Version = "4"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
    • AppName = "GoogleUpdateBroker.exe"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
    • AppPath = "%Program Files%\globalUpdate\Update\1.3.25.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
    • Policy = "3"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
    • (Default) = "globalUpdate Update Plugin"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdate.Update3WebControl.4\CLSID
    • (Default) = "{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
    • (Default) = "globalUpdate Update Plugin"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}\ProgID
    • (Default) = "globalUpdate.Update3WebControl.4"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}\InprocServer32
    • (Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}\InprocServer32
    • ThreadingModel = "Apartment"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-vnd.google.update3webcontrol.4
    • CLSID = "{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GlobalUpdate\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}
    • brand = "GGLS"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GlobalUpdate\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}
    • InstallTime = "1562855189"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
    • (Default) = "ServiceModule"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\GoogleUpdate.exe
    • AppID = "{577975B8-C40E-43E6-B0DE-4C6B44088B52}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
    • LocalService = "globalUpdate"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
    • ServiceParameters = "/comsvc"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
    • (Default) = "Update3COMClass"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0\CLSID
    • (Default) = "{577975B8-C40E-43E6-B0DE-4C6B44088B52}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
    • (Default) = "Update3COMClass"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService\CLSID
    • (Default) = "{577975B8-C40E-43E6-B0DE-4C6B44088B52}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService\CurVer
    • (Default) = "globalUpdateUpdate.Update3COMClassService.1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
    • (Default) = "Update3COMClass"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}\ProgID
    • (Default) = "globalUpdateUpdate.Update3COMClassService.1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}\VersionIndependentProgID
    • (Default) = "globalUpdateUpdate.Update3COMClassService"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
    • AppID = "{577975B8-C40E-43E6-B0DE-4C6B44088B52}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
    • (Default) = "ServiceModule"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\GoogleUpdate.exe
    • AppID = "{3278F5CF-48F3-4253-A6BB-004CE84AF492}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
    • LocalService = "globalUpdatem"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
    • ServiceParameters = "/comsvc"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
    • (Default) = "Google Update Legacy On Demand"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0\CLSID
    • (Default) = "{3278F5CF-48F3-4253-A6BB-004CE84AF492}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
    • (Default) = "Google Update Legacy On Demand"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc\CLSID
    • (Default) = "{3278F5CF-48F3-4253-A6BB-004CE84AF492}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc\CurVer
    • (Default) = "globalUpdateUpdate.OnDemandCOMClassSvc.1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
    • (Default) = "Google Update Legacy On Demand"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}\ProgID
    • (Default) = "globalUpdateUpdate.OnDemandCOMClassSvc.1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}\VersionIndependentProgID
    • (Default) = "globalUpdateUpdate.OnDemandCOMClassSvc"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
    • AppID = "{3278F5CF-48F3-4253-A6BB-004CE84AF492}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
    • (Default) = "GoogleUpdate Update3Web"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0\CLSID
    • (Default) = "{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
    • (Default) = "GoogleUpdate Update3Web"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc\CLSID
    • (Default) = "{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc\CurVer
    • (Default) = "globalUpdateUpdate.Update3WebSvc.1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
    • (Default) = "GoogleUpdate Update3Web"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}\ProgID
    • (Default) = "globalUpdateUpdate.Update3WebSvc.1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}\VersionIndependentProgID
    • (Default) = "globalUpdateUpdate.Update3WebSvc"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
    • AppID = "{3278F5CF-48F3-4253-A6BB-004CE84AF492}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
    • (Default) = "Google Update Core Class"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1\CLSID
    • (Default) = "{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
    • (Default) = "Google Update Core Class"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoreClass\CLSID
    • (Default) = "{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoreClass\CurVer
    • (Default) = "globalUpdateUpdate.CoreClass.1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
    • (Default) = "Google Update Core Class"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}\ProgID
    • (Default) = "globalUpdateUpdate.CoreClass.1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}\VersionIndependentProgID
    • (Default) = "globalUpdateUpdate.CoreClass"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
    • AppID = "{3278F5CF-48F3-4253-A6BB-004CE84AF492}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}\InprocHandler32
    • (Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\psmachine.dll"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}\InprocHandler32
    • ThreadingModel = "Both"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}\InprocServer32
    • (Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\psmachine.dll"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}\InprocServer32
    • ThreadingModel = "Both"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}\InProcServer32
    • (Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\psmachine.dll"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}\InProcServer32
    • ThreadingModel = "Both"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
    • (Default) = "PSFactoryBuffer"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{3CC60715-D6C5-429D-830E-43FA3F86C61D}\ProxyStubClsid32
    • (Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{3CC60715-D6C5-429D-830E-43FA3F86C61D}
    • (Default) = "IProgressWndEvents"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{3CC60715-D6C5-429D-830E-43FA3F86C61D}\NumMethods
    • (Default) = "9"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{3A807417-B46D-4D37-8C9A-19AC6DE204F9}\ProxyStubClsid32
    • (Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{3A807417-B46D-4D37-8C9A-19AC6DE204F9}
    • (Default) = "IBrowserHttpRequest2"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{3A807417-B46D-4D37-8C9A-19AC6DE204F9}\NumMethods
    • (Default) = "4"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{07F41522-AF7D-4F26-B394-094F059FDB8A}\ProxyStubClsid32
    • (Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{07F41522-AF7D-4F26-B394-094F059FDB8A}
    • (Default) = "IAppBundleWeb"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{07F41522-AF7D-4F26-B394-094F059FDB8A}\NumMethods
    • (Default) = "24"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DD1F043F-ABC8-4643-8B95-D2C5B22BB019}\ProxyStubClsid32
    • (Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DD1F043F-ABC8-4643-8B95-D2C5B22BB019}
    • (Default) = "IProcessLauncher"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DD1F043F-ABC8-4643-8B95-D2C5B22BB019}\NumMethods
    • (Default) = "6"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{212E6D43-6062-492A-B8CC-144669FF11ED}\ProxyStubClsid32
    • (Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{212E6D43-6062-492A-B8CC-144669FF11ED}
    • (Default) = "IAppVersion"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{212E6D43-6062-492A-B8CC-144669FF11ED}\NumMethods
    • (Default) = "10"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{555D7146-94A8-4C94-AE76-C39CDC7F7705}\ProxyStubClsid32
    • (Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{555D7146-94A8-4C94-AE76-C39CDC7F7705}
    • (Default) = "ICoCreateAsyncStatus"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{555D7146-94A8-4C94-AE76-C39CDC7F7705}\NumMethods
    • (Default) = "10"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{4517D94C-19BA-46FA-BE66-2A30CEAC4A85}\ProxyStubClsid32
    • (Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{4517D94C-19BA-46FA-BE66-2A30CEAC4A85}
    • (Default) = "IAppBundle"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{4517D94C-19BA-46FA-BE66-2A30CEAC4A85}\NumMethods
    • (Default) = "39"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{224FE662-1E6D-4BC0-AEBB-9E2FB4057BE9}\ProxyStubClsid32
    • (Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{224FE662-1E6D-4BC0-AEBB-9E2FB4057BE9}
    • (Default) = "ICoCreateAsync"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{224FE662-1E6D-4BC0-AEBB-9E2FB4057BE9}\NumMethods
    • (Default) = "4"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{0C40F472-7407-4467-8914-1DEA7C326972}\ProxyStubClsid32
    • (Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{0C40F472-7407-4467-8914-1DEA7C326972}
    • (Default) = "IAppWeb"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{0C40F472-7407-4467-8914-1DEA7C326972}\NumMethods
    • (Default) = "14"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{A6D54287-7939-466A-8579-92546D946C8C}\ProxyStubClsid32
    • (Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{A6D54287-7939-466A-8579-92546D946C8C}
    • (Default) = "IOneClickProcessLauncher"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{A6D54287-7939-466A-8579-92546D946C8C}\NumMethods
    • (Default) = "4"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{0522D9A4-4D57-437D-978D-E5B3B6C9005D}\ProxyStubClsid32
    • (Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{0522D9A4-4D57-437D-978D-E5B3B6C9005D}
    • (Default) = "IAppVersionWeb"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{0522D9A4-4D57-437D-978D-E5B3B6C9005D}\NumMethods
    • (Default) = "10"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{A8F7D0A5-7074-40B8-9BDC-1174BDD0A132}\ProxyStubClsid32
    • (Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{A8F7D0A5-7074-40B8-9BDC-1174BDD0A132}
    • (Default) = "IGoogleUpdate3WebSecurity"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{A8F7D0A5-7074-40B8-9BDC-1174BDD0A132}\NumMethods
    • (Default) = "4"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D14D64BC-A0E4-42E3-BB72-FB41EA43C198}\ProxyStubClsid32
    • (Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D14D64BC-A0E4-42E3-BB72-FB41EA43C198}
    • (Default) = "IPackage"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D14D64BC-A0E4-42E3-BB72-FB41EA43C198}\NumMethods
    • (Default) = "10"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{023E9EC8-B147-40EB-B0B3-DF90618FB371}\ProxyStubClsid32
    • (Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{023E9EC8-B147-40EB-B0B3-DF90618FB371}
    • (Default) = "ICurrentState"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{023E9EC8-B147-40EB-B0B3-DF90618FB371}\NumMethods
    • (Default) = "24"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{ED0B64D4-BF27-4521-AD27-190F49BF5EA7}\ProxyStubClsid32
    • (Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{ED0B64D4-BF27-4521-AD27-190F49BF5EA7}
    • (Default) = "IJobObserver"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{ED0B64D4-BF27-4521-AD27-190F49BF5EA7}\NumMethods
    • (Default) = "13"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{8120D9D6-785C-4413-9C0C-DF2028C56FAD}\ProxyStubClsid32
    • (Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{8120D9D6-785C-4413-9C0C-DF2028C56FAD}
    • (Default) = "IGoogleUpdate"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{8120D9D6-785C-4413-9C0C-DF2028C56FAD}\NumMethods
    • (Default) = "5"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{823AE2EB-E62C-4847-B192-C99B91B92416}\ProxyStubClsid32
    • (Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{823AE2EB-E62C-4847-B192-C99B91B92416}
    • (Default) = "IApp"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{823AE2EB-E62C-4847-B192-C99B91B92416}\NumMethods
    • (Default) = "40"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9B9A45F4-18FC-484A-BACA-076D78273D8E}\ProxyStubClsid32
    • (Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9B9A45F4-18FC-484A-BACA-076D78273D8E}
    • (Default) = "IGoogleUpdateCore"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9B9A45F4-18FC-484A-BACA-076D78273D8E}\NumMethods
    • (Default) = "4"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F3E8F9-F747-4DD6-BA6B-82A6CE1E0860}\ProxyStubClsid32
    • (Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F3E8F9-F747-4DD6-BA6B-82A6CE1E0860}
    • (Default) = "IRegistrationUpdateHook"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F3E8F9-F747-4DD6-BA6B-82A6CE1E0860}\NumMethods
    • (Default) = "8"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{59D188FA-757A-424E-8C93-F58FFD896BD7}\ProxyStubClsid32
    • (Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{59D188FA-757A-424E-8C93-F58FFD896BD7}
    • (Default) = "ICredentialDialog"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{59D188FA-757A-424E-8C93-F58FFD896BD7}\NumMethods
    • (Default) = "4"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{A78EDAFB-926F-4D93-AB13-8232D7378EB1}\ProxyStubClsid32
    • (Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{A78EDAFB-926F-4D93-AB13-8232D7378EB1}
    • (Default) = "IGoogleUpdate3"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{A78EDAFB-926F-4D93-AB13-8232D7378EB1}\NumMethods
    • (Default) = "10"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9B4F7CFE-987D-410E-A8E4-20182E0B3C24}\ProxyStubClsid32
    • (Default) = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9B4F7CFE-987D-410E-A8E4-20182E0B3C24}
    • (Default) = "IGoogleUpdate3Web"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9B4F7CFE-987D-410E-A8E4-20182E0B3C24}\NumMethods
    • (Default) = "8"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
    • (Default) = "Google Update Broker Class Factory"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0\CLSID
    • (Default) = "{ADBC39BE-3D20-4333-8D99-E91EB1B62474}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
    • (Default) = "Google Update Broker Class Factory"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine\CLSID
    • (Default) = "{ADBC39BE-3D20-4333-8D99-E91EB1B62474}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine\CurVer
    • (Default) = "globalUpdateUpdate.OnDemandCOMClassMachine.1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
    • (Default) = "Google Update Broker Class Factory"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}\ProgID
    • (Default) = "globalUpdateUpdate.OnDemandCOMClassMachine.1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}\VersionIndependentProgID
    • (Default) = "globalUpdateUpdate.OnDemandCOMClassMachine"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}\LocalServer32
    • (Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
    • LocalizedString = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-3000"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}\Elevation
    • Enabled = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}\Elevation
    • IconReference = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-1004"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
    • (Default) = "Google Update Broker Class Factory"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0\CLSID
    • (Default) = "{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
    • (Default) = "Google Update Broker Class Factory"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine\CLSID
    • (Default) = "{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine\CurVer
    • (Default) = "globalUpdateUpdate.Update3WebMachine.1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
    • (Default) = "Google Update Broker Class Factory"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}\ProgID
    • (Default) = "globalUpdateUpdate.Update3WebMachine.1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}\VersionIndependentProgID
    • (Default) = "globalUpdateUpdate.Update3WebMachine"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}\LocalServer32
    • (Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
    • LocalizedString = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-3000"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}\Elevation
    • Enabled = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}\Elevation
    • IconReference = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-1004"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
    • (Default) = "CoCreateAsync"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0\CLSID
    • (Default) = "{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
    • (Default) = "CoCreateAsync"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync\CLSID
    • (Default) = "{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync\CurVer
    • (Default) = "globalUpdateUpdate.CoCreateAsync.1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
    • (Default) = "CoCreateAsync"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}\ProgID
    • (Default) = "globalUpdateUpdate.CoCreateAsync.1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}\VersionIndependentProgID
    • (Default) = "globalUpdateUpdate.CoCreateAsync"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}\LocalServer32
    • (Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
    • (Default) = "globalUpdate.OneClickProcessLauncher"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0\CLSID
    • (Default) = "{5E89ACE9-E16B-499A-87B4-0DBF742404C1}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
    • (Default) = "globalUpdate.OneClickProcessLauncher"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine\CLSID
    • (Default) = "{5E89ACE9-E16B-499A-87B4-0DBF742404C1}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine\CurVer
    • (Default) = "globalUpdate.OneClickProcessLauncherMachine.1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
    • (Default) = "globalUpdate.OneClickProcessLauncher"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}\ProgID
    • (Default) = "globalUpdate.OneClickProcessLauncherMachine.1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}\VersionIndependentProgID
    • (Default) = "globalUpdate.OneClickProcessLauncherMachine"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}\LocalServer32
    • (Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
    • CLSID = "{5E89ACE9-E16B-499A-87B4-0DBF742404C1}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
    • Policy = "3"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
    • (Default) = "Google Update Process Launcher Class"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0\CLSID
    • (Default) = "{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
    • (Default) = "Google Update Process Launcher Class"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher\CLSID
    • (Default) = "{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher\CurVer
    • (Default) = "globalUpdateUpdate.ProcessLauncher.1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
    • (Default) = "Google Update Process Launcher Class"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}\ProgID
    • (Default) = "globalUpdateUpdate.ProcessLauncher.1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}\VersionIndependentProgID
    • (Default) = "globalUpdateUpdate.ProcessLauncher"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}\LocalServer32
    • (Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
    • (Default) = "Google Update Core Class"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1\CLSID
    • (Default) = "{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
    • (Default) = "Google Update Core Class"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass\CLSID
    • (Default) = "{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass\CurVer
    • (Default) = "globalUpdateUpdate.CoreMachineClass.1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
    • (Default) = "Google Update Core Class"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}\ProgID
    • (Default) = "globalUpdateUpdate.CoreMachineClass.1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}\VersionIndependentProgID
    • (Default) = "globalUpdateUpdate.CoreMachineClass"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}\LocalServer32
    • (Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
    • LocalizedString = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-3000"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}\Elevation
    • Enabled = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}\Elevation
    • IconReference = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-1004"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\{random key}
    • (Default) = "Google Update Legacy On Demand"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0\CLSID
    • (Default) = "{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
    • (Default) = "Google Update Legacy On Demand"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback\CLSID
    • (Default) = "{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback\CurVer
    • (Default) = "globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
    • (Default) = "Google Update Legacy On Demand"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}\ProgID
    • (Default) = "globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}\VersionIndependentProgID
    • (Default) = "globalUpdateUpdate.OnDemandCOMClassMachineFallback"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}\LocalServer32
    • (Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
    • LocalizedString = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-3000"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}\Elevation
    • Enabled = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}\Elevation
    • IconReference = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-1004"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
    • (Default) = "GoogleUpdate Update3Web"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0\CLSID
    • (Default) = "{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
    • (Default) = "GoogleUpdate Update3Web"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback\CLSID
    • (Default) = "{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback\CurVer
    • (Default) = "globalUpdateUpdate.Update3WebMachineFallback.1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
    • (Default) = "GoogleUpdate Update3Web"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}\ProgID
    • (Default) = "globalUpdateUpdate.Update3WebMachineFallback.1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}\VersionIndependentProgID
    • (Default) = "globalUpdateUpdate.Update3WebMachineFallback"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}\LocalServer32
    • (Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
    • LocalizedString = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-3000"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}\Elevation
    • Enabled = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}\Elevation
    • IconReference = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-1004"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
    • (Default) = "GoogleUpdate CredentialDialog"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0\CLSID
    • (Default) = "{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
    • (Default) = "GoogleUpdate CredentialDialog"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine\CLSID
    • (Default) = "{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine\CurVer
    • (Default) = "globalUpdateUpdate.CredentialDialogMachine.1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
    • (Default) = "GoogleUpdate CredentialDialog"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}\ProgID
    • (Default) = "globalUpdateUpdate.CredentialDialogMachine.1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}\VersionIndependentProgID
    • (Default) = "globalUpdateUpdate.CredentialDialogMachine"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}\LocalServer32
    • (Default) = "%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Chrome-Profiles\%AppDataLocal%\Google\Chrome\User Data
    • Default = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Chrome
    • TotalProfiles = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\ErrorLists-crchromeinstaller
    • post_for_sign_Invalid HTTP(S) status code = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\ErrorLists-crchromeinstaller
    • insert_cook_db_1_table cookies has no column named secure = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\ErrorLists-crchromeinstaller
    • insert_cook_db_1_table cookies has no column named secure = "2"
  • In HKEY_CURRENT_USER\Software\globalUpdate\Update\proxy
    • source = "IE"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP
    • ActiveAppId = "54246"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Update
    • LastCheck = "1562855063"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Installer
    • Bic = "354A91DE7DC14C2A980B5427C0148BABIE"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Installer
    • Verifier = "be6aa8aa1574234ad24e003e9b0dc90a"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Installer
    • Time = "1562855042"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Installer
    • StatsDomain = "http://stats.{BLOCKED}statsservice.com"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Installer
    • ErrorsDomain = "http://errors.{BLOCKED}statsservice.com"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Installer
    • CodeDownloadDomain = "http://js.{BLOCKED}statsservice.com"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Installer
    • FullVersion = "1.34.5.22"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Installer
    • FullVersionForUrl = "1_34_05_22"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Installer
    • SrcId = "001359"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Installer
    • SubId = "0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Installer
    • ZData = "0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Installer
    • DefaultBrowser = "ie"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Installer
    • OsName = "7"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Installer
    • Params = "{ source_id : 001359, sub_id : 0, uzid : 0}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Manifest
    • Name = "MPMP"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Manifest
    • Manifest = "NA"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Manifest
    • Description = "MediaPlayerEnhance Extension"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Manifest
    • PublisherName = "Freeven"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Manifest
    • HomePageUrl = "NA"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Manifest
    • RunInFrame = "false"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Manifest
    • ThanksUrl = "NA"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Manifest
    • DisableIe = "true"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Manifest
    • EnableSearchIE = "false"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Manifest
    • Version = "38"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Manifest
    • UpdateInterval = "360"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Manifest
    • BgVersion = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Manifest
    • AddressbarURL = "NA"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Manifest
    • ChangePrevious = "false"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Manifest
    • SetNewTab = "false"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Manifest
    • PublisherId = "21636"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Manifest
    • ModeType = "production"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Manifest
    • PluginsManifestVersion = "30"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Manifest
    • IsButtonEnabled = "false"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Manifest
    • UninstallerOfferUrl = "NA"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Manifest
    • UninstallerOfferAction = "NA"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Code
    • AppJavaScript = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Code
    • BgJavaScript = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Code
    • NewTabJavaScript = ""
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\251
    • Version = "8"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\251
    • Name = "versionBinaryString"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\251
    • JavaScript = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\251
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/Nova/versionBinaryString.js"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\249
    • Version = "6"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\249
    • Name = "native"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\249
    • JavaScript = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\249
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/Nova/native.js"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\250
    • Version = "5"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\250
    • Name = "api"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\250
    • JavaScript = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\250
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/Nova/api.js"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\14
    • Version = "11"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\14
    • Name = "CrossriderUtils"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\14
    • JavaScript = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\14
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/CrossriderUtils.js"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\78
    • Version = "5"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\78
    • Name = "CrossriderInfo"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\78
    • JavaScript = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\78
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/CrossriderInfo.js"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\233
    • Version = "5"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\233
    • Name = "revizer_p_dynamic_b2b_2_m"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\233
    • JavaScript = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\233
    • Url = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\253
    • Version = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\253
    • Name = "pixel_inject"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\253
    • JavaScript = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\253
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/pixel_inject.js"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\242
    • Version = "3"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\242
    • Name = "price_gong_m"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\242
    • JavaScript = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\242
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/price_gong_m.js"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\211
    • Version = "5"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\211
    • Name = "revizer_ws_dynamic_b2b_light_m"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\211
    • JavaScript = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\211
    • Url = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\191
    • Version = "5"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\191
    • Name = "ciuvo_m"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\191
    • JavaScript = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\191
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/ciuvo_m.js"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\184
    • Version = "9"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\184
    • Name = "noproblemppc_m"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\184
    • JavaScript = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\184
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/noproblemppc_m.js"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\155
    • Version = "3"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\155
    • Name = "ibario_pops_m"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\155
    • JavaScript = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\155
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/ibario_pops_m.js"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\102
    • Version = "7"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\102
    • Name = "dealply_m"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\102
    • JavaScript = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\102
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/dealply_m.js"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\93
    • Version = "10"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\93
    • Name = "superfish_no_coupons_m"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\93
    • JavaScript = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\93
    • Url = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\91
    • Version = "49"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\91
    • Name = "monetizationLoader.js"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\91
    • JavaScript = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\91
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/monetizationLoader.js"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\246
    • Version = "10"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\246
    • Name = "setup"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\246
    • JavaScript = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\246
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/setup.js"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\4
    • Version = "4"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\4
    • Name = "jquery_1_7_1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\4
    • JavaScript = "{random characters}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins\4
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/javascripts/jquery-1_7_1_min.js"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins
    • AppPluginList = "246,14,78,4,93,102,155,184,191,211,233,242,253,91"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins
    • BgPluginList = "246,4,14,78,251,249,250,93,102,155,184,191,211,233,242,253,91"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins
    • NewTabPluginList = "14,78,4"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins
    • OnRequestPluginList = "14"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins
    • BrowserEventPluginList = "14"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Plugins
    • PopupPluginList = "4,14,78"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Update
    • LastCheck = "1562855064"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Firefox\Profiles\%Application Data%\Mozilla\Firefox\Profiles
    • lj5mikyj.default = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\Firefox
    • TotalProfiles = "1"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP
    • ActiveAppId = "54246"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Update
    • LastCheck = "1562855079"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\Crossrider
    • Bic = "354A91DE7DC14C2A980B5427C0148BABIE"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\Crossrider
    • Verifier = "be6aa8aa1574234ad24e003e9b0dc90a"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Installer
    • Time = "1562855042"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Installer
    • StatsDomain = "http://stats.{BLOCKED}statsservice.com"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Installer
    • ErrorsDomain = "http://errors.{BLOCKED}statsservice.com"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Installer
    • CodeDownloadDomain = "http://js.{BLOCKED}statsservice.com"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Installer
    • FullVersion = "1.34.5.22"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Installer
    • FullVersionForUrl = "1_34_05_22"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Installer
    • SrcId = "001359"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Installer
    • SubId = "0"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Installer
    • ZData = "0"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Installer
    • DefaultBrowser = "ie"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Installer
    • OsName = "7"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Installer
    • Params = "{ source_id : 001359, sub_id : 0, uzid : 0}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\IE\Profiles
    • S-1-5-21-2407829820-1079796033-203259571-500 = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MPMP\IE
    • TotalProfiles = "1"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Manifest
    • Name = "MPMP"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Manifest
    • Manifest = "NA"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Manifest
    • Description = "MediaPlayerEnhance Extension"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Manifest
    • PublisherName = "Freeven"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Manifest
    • HomePageUrl = "NA"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Manifest
    • RunInFrame = "false"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Manifest
    • ThanksUrl = "NA"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Manifest
    • DisableIe = "true"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Manifest
    • EnableSearchIE = "false"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Manifest
    • Version = "38"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Manifest
    • UpdateInterval = "360"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Manifest
    • BgVersion = "1"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Manifest
    • AddressbarURL = "NA"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Manifest
    • ChangePrevious = "false"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Manifest
    • SetNewTab = "false"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Manifest
    • PublisherId = "21636"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Manifest
    • ModeType = "production"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Manifest
    • PluginsManifestVersion = "30"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Manifest
    • IsButtonEnabled = "false"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Manifest
    • UninstallerOfferUrl = "NA"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Manifest
    • UninstallerOfferAction = "NA"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Code
    • AppJavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Code
    • BgJavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Code
    • NewTabJavaScript = ""
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\183
    • Version = "4"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\183
    • Name = "tabsWrapper"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\183
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\183
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/tabsWrapper.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\182
    • Version = "3"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\182
    • Name = "openUrl"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\182
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\182
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/openUrl.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\177
    • Version = "2"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\177
    • Name = "crossriderDashboard"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\177
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\177
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/crossriderDashboard.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\94
    • Version = "2"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\94
    • Name = "IEPopup"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\94
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\94
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IEPopup.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\78
    • Version = "5"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\78
    • Name = "CrossriderInfo"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\78
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\78
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/CrossriderInfo.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\207
    • Version = "2"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\207
    • Name = "dbWrapper"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\207
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\207
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/dbWrapper.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\64
    • Version = "3"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\64
    • Name = "appApiMessage"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\64
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\64
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/appApiMessage.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\72
    • Version = "5"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\72
    • Name = "appApiValidation"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\72
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\72
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/appApiValidation.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\46
    • Version = "5"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\46
    • Name = "IETimers"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\46
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\46
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IETimers.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\45
    • Version = "4"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\45
    • Name = "IEOnRequest"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\45
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\45
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IEOnRequest.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\44
    • Version = "6"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\44
    • Name = "IEMisc"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\44
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\44
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IEMisc.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\43
    • Version = "5"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\43
    • Name = "IEMessaging"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\43
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\43
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IEMessaging.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\42
    • Version = "9"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\42
    • Name = "IEInternal"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\42
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\42
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IEInternal.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\41
    • Version = "7"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\41
    • Name = "IEInfo"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\41
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\41
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IEInfo.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\40
    • Version = "4"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\40
    • Name = "IEExtension"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\40
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\40
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IEExtension.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\39
    • Version = "5"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\39
    • Name = "IEDatabase"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\39
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\39
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IEDatabase.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\38
    • Version = "4"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\38
    • Name = "IECallbacks"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\38
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\38
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IECallbacks.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\37
    • Version = "6"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\37
    • Name = "IEBrowserEvents"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\37
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\37
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IEBrowserEvents.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\36
    • Version = "8"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\36
    • Name = "IEBackground"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\36
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\36
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IEBackground.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\35
    • Version = "4"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\35
    • Name = "IEAjax"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\35
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\35
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie/IEAjax.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\17
    • Version = "4"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\17
    • Name = "jQuery"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\17
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\17
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/jQuery.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\14
    • Version = "11"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\14
    • Name = "CrossriderUtils"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\14
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\14
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/CrossriderUtils.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\13
    • Version = "7"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\13
    • Name = "CrossriderAppUtils"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\13
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\13
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/CrossriderAppUtils.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\253
    • Version = "1"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\253
    • Name = "pixel_inject"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\253
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\253
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/pixel_inject.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\242
    • Version = "3"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\242
    • Name = "price_gong_m"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\242
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\242
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/price_gong_m.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\233
    • Version = "5"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\233
    • Name = "revizer_p_dynamic_b2b_2_m"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\233
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\233
    • Url = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\226
    • Version = "4"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\226
    • Name = "set_campaign_id_m"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\226
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\226
    • Url = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\221
    • Version = "2"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\221
    • Name = "icm_downloads_m"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\221
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\221
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/icm_downloads_m.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\211
    • Version = "5"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\211
    • Name = "revizer_ws_dynamic_b2b_light_m"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\211
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\211
    • Url = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\195
    • Version = "25"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\195
    • Name = "icm_convertmedia_m"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\195
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\195
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/icm_convertmedia_m.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\220
    • Version = "8"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\220
    • Name = "icm_base_m"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\220
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\220
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/icm_base_m.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\7
    • Version = "2"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\7
    • Name = "hooks"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\7
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\7
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/hooks.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\9
    • Version = "3"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\9
    • Name = "search_engine_hook"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\9
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\9
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/searchengines_hook.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\191
    • Version = "5"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\191
    • Name = "ciuvo_m"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\191
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\191
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/ciuvo_m.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\190
    • Version = "3"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\190
    • Name = "pops_5_m"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\190
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\190
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/javascripts/monetization/geo/pops_5_m.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\155
    • Version = "3"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\155
    • Name = "ibario_pops_m"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\155
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\155
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/ibario_pops_m.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\104
    • Version = "9"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\104
    • Name = "jollywallet_m"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\104
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\104
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/javascripts/monetization/geo/jollywallet_m.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\184
    • Version = "9"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\184
    • Name = "noproblemppc_m"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\184
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\184
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/noproblemppc_m.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\103
    • Version = "8"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\103
    • Name = "intext_5_m"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\103
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\103
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/javascripts/monetization/geo/intext_5_m.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\102
    • Version = "7"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\102
    • Name = "dealply_m"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\102
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\102
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/geo/dealply_m.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\93
    • Version = "10"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\93
    • Name = "superfish_no_coupons_m"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\93
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\93
    • Url = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\91
    • Version = "49"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\91
    • Name = "monetizationLoader.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\91
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\91
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/monetizationLoader.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\246
    • Version = "10"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\246
    • Name = "setup"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\246
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\246
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/monetization/setup.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\47
    • Version = "3"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\47
    • Name = "resources_background"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\47
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\47
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/resources_background.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\22
    • Version = "5"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\22
    • Name = "resources"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\22
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\22
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/resources.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\28
    • Version = "4"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\28
    • Name = "initializer"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\28
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\28
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/initializer.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\3
    • Version = "2"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\3
    • Name = "ie8_fix_2"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\3
    • JavaScript = "(function(){var b=dummy so this plugin won't be empty;})();"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\3
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie8_fix_2.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\21
    • Version = "5"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\21
    • Name = "debug"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\21
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\21
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/debug.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\2
    • Version = "2"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\2
    • Name = "ie8_fix_1"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\2
    • JavaScript = "(function(){var b=dummy so this plugin won't be empty;})();"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\2
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/ie8_fix_1.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\4
    • Version = "4"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\4
    • Name = "jquery_1_7_1"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\4
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\4
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/javascripts/jquery-1_7_1_min.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\1
    • Version = "10"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\1
    • Name = "base"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\1
    • JavaScript = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins\1
    • Url = "http://js.{BLOCKED}statsservice.com/plugins/mins/base.js"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins
    • AppPluginList = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins
    • BgPluginList = "{random characters}"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins
    • NewTabPluginList = "42,38,46,17,14,78,13,41,44,39,35,43,40,64,2,4,3,1,21,22,72,28"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins
    • OnRequestPluginList = "14,42,41,39,38,43,45,64,72"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins
    • BrowserEventPluginList = "14,42,41,44,39,38,43,37,64,72"
  • In HKEY_CURRENT_USER\Software\AppDataLow\Software\MPMP\Plugins
    • PopupPluginList = "42,38,46,41,44,39,35,43,36,4,14,78,13,64,207,47,182,72,94"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0054246.Sandbox.1
    • (Default) = "CrossriderApp0054246.Sandbox"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0054246.Sandbox.1\CLSID
    • (Default) = "{{GUID}}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0054246.BHO.1
    • (Default) = "CrossriderApp0054246"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0054246.BHO.1\CLSID
    • (Default) = "{{GUID}}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0054246.Sandbox
    • (Default) = "CrossriderApp0054246.Sandbox"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0054246.Sandbox\CLSID
    • (Default) = "{{GUID}}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0054246.Sandbox\CurVer
    • (Default) = "CrossriderApp0054246.Sandbox"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0054246.BHO
    • (Default) = "CrossriderApp0054246"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0054246.BHO\CLSID
    • (Default) = "{{GUID}}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0054246.BHO\CurVer
    • (Default) = "CrossriderApp0054246"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{{GUID}}
    • (Default) = "MPMP"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{{GUID}}\ProgID
    • (Default) = "CrossriderApp0054246.BHO.1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{{GUID}}\VersionIndependentProgID
    • (Default) = "CrossriderApp0054246"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{{GUID}}\InprocServer32
    • (Default) = "%Program Files%\MPMP\MPMP-bho.dll"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{{GUID}}\InprocServer32
    • ThreadingModel = "Apartment"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{{GUID}}\TypeLib
    • (Default) = "{{GUID}}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{{GUID}}\Implemented Categories
    • (Default) = ""
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{{GUID}}\Implemented Categories\{{GUID}}
    • (Default) = ""
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{{GUID}}
    • (Default) = "CrossriderApp0054246.Sandbox"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{{GUID}}\ProgID
    • (Default) = "CrossriderApp0054246.Sandbox.1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{{GUID}}\VersionIndependentProgID
    • (Default) = "CrossriderApp0054246.Sandbox"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{{GUID}}
    • (Default) = "CrossriderApp0054246"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{{GUID}}
    • NoExplorer = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{{GUID}}
    • (Default) = "ICrossriderBHO"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{{GUID}}\ProxyStubClsid32
    • (Default) = "{00020424-0000-0000-C000-000000000046}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{{GUID}}\TypeLib
    • (Default) = "{{GUID}}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{{GUID}}\TypeLib
    • Version = "1.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{{GUID}}
    • (Default) = "ISandBox"
  • In HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\globalUpdate
    • DisplayName = "globalUpdate Update Service (globalUpdate)"
  • In HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\globalUpdate
    • Start = "SERVICE_AUTO_START"
  • In HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\globalUpdatem
    • DisplayName = "globalUpdate Update Service (globalUpdatem)"
  • In HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\globalUpdatem
    • Start = "SERVICE_DEMAND_START"

Step 5

Search and delete these components

[ Learn More ]
There may be some components that are hidden. Please make sure you check the Search Hidden Files and Folders checkbox in the "More advanced options" option to include all hidden files and folders in the search result.
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\21.js
  • %Program Files%\MPMP\54246.crx
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\3e24ea90dedf010dd73864ad8afb9842.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\4f1f2311b6dfe8dc9398b9e63abadc95.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\680792568ec55a86a7e80045e550e236.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe.old
  • %Windows%\Tasks\{GUID}-1.job
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\28.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\popup.html
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\4.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\userCode\extension.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\psuser.dll.old
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\7.js
  • %User Temp%\comh.18754\GoogleUpdateBroker.exe
  • %Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\18be4636f65b5a79a226b006ca76a4e2.js
  • %User Temp%\comh.18754\GoogleUpdateHelper.msi
  • %Program Files%\MPMP\MPMP.ico
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\91.js
  • %User Temp%\AF2.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\221.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateHelper.msi.old
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\45d83464f48807f918f66018f5438b9e.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\183.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\64.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\9.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\search_dialog.xul
  • %Program Files%\MPMP\MPMP-bho.dll
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\installer.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\98.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\5028e2cbf92f3b87b57c694503c57e72.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\37993b8abf06e383d7ef53385525f010.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\787e77f8d7ecc7156be99bd0b0fde217.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\47.js
  • %All Users Profile%\Microsoft\Network\Downloader\qmgr0.dat
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\253.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\190.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\panelarrow-up.png
  • %User Temp%\comh.18754\goopdateres_en.dll
  • %Windows%\Tasks\{GUID}-3.job
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\dialog.js
  • %Windows%\Tasks\{GUID}-6.job
  • %Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe.old
  • %User Temp%\AF1.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\3cdbe045a4a0d3f50bd7b4f8b905fc1d.js
  • %User Temp%\comh.18754\npGoogleUpdate4.dll
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\d011f9d6a8671d3a2bc2b558decdb410.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\button3.png
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\2778ebbf69e285e413df59bb58a8fca9.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\background.html
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\102.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\93.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\userCode\background.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\13.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\4b4b6daaa6ac343ffc1b119ddb0b246c.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\2d5d68b375151fbed320fd2c0181c191.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions.json
  • %User Temp%\comh.18754\goopdate.dll
  • %User Temp%\comh.18754\GoogleUpdate.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\icon48.png
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\bd82ad0f96fb35e02c077edbf2b9f8c6.js
  • %Windows%\Tasks\globalUpdateUpdateTaskMachineUA.job
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\246.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\49566522acce9f80ebb86c35dfb155d3.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\78.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\update.css
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\icon24.png
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\191.js
  • %Program Files%\globalUpdate\Update\GoogleUpdate.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\16.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\5ef7cf534cdbca51efd63b695e3d0f62.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe
  • %Program Files%\MPMP\54246.xpi
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\1370ab8db88b6403223ec11e7a236c84.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\50d601b837ee9834f42c82ddcb1d0c65.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\177.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\icon16.png
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\options.js
  • %All Users Profile%\Microsoft\Network\Downloader\qmgr1.dat
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\d35d0bca3d387bec73e98493bae4bebe.js
  • %User Temp%\comh.18754\GoogleCrashHandler.exe
  • %Program Files%\MPMP\MPMP-nova.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\226.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\defaults\preferences\prefs.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\182.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\9caf939c72d899c9467323bea849b4a3.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\goopdateres_en.dll
  • %Program Files%\MPMP\utils.exe
  • %Program Files%\MPMP\Uninstall.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\6f5764ff79aeb23978e9db22d7981041.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins.json
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\207.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\icon128.png
  • %Program Files%\globalUpdate\Update\1.3.25.0\GoogleCrashHandler.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\button4.png
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\72.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\crossrider_statusbar.png
  • %Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll.old
  • %Program Files%\MPMP\MPMP-codedownloader.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\ceec657593dea2fb9978c177d58f364c.js
  • %User Temp%\comh.18754\psuser.dll
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\104.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\bdbd33145ab7dbb7b5175dc29e13a54f.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\211.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\3438e9cee6f289fe93d7d8abe705ba24.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdate.exe
  • %User Temp%\comh.18754\GoogleUpdateOnDemand.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\ffCoreFilesIndex.txt
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\install.rdf
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\browser.xul
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\8cf406521b5bdabeda6c9b01aad99f51.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\6589406f5c43cdd372d3b9893fe94669.js
  • %Program Files%\MPMP\{GUID}-3.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\184.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\1.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\f04545df6da39e41ae904087d7b3a91c.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\goopdateres_en.dll.old
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\manifest.xml
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\9dba55b4f2557e03aca1fe863b4a9f9e.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\c1ab6a0d65c6bdb80c05eb57261a3d55.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateHelper.msi
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\24e5241137ac099bd0069f5361058525.js
  • %Program Files%\MPMP\MPMP-nova.dll
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\242.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\155.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\22.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\17.js
  • %Program Files%\MPMP\1293297481.mxaddon
  • %Windows%\Tasks\{GUID}-7.job
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\skin.css
  • %Program Files%\globalUpdate\Update\1.3.25.0\psmachine.dll
  • %Program Files%\globalUpdate\Update\1.3.25.0\GoogleCrashHandler.exe.old
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\195.js
  • %User Temp%\{GUID}.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\3dad8746f8926aafde94171b87503811.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\14.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\options.xul
  • %Program Files%\MPMP\360-54246.crx
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\a3e7c3935aee4f766e6a9b9f5e92c869.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\button1.png
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\c5379747c774cf9228f58cd8633a488f.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll.old
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome.manifest
  • %Windows%\Tasks\temp_{GUID}-7.job
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\f44fe937f6668d4047fb81235269a0e1.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\d827b91b474a06b7771997ad452f2201.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\b51ab7bc967684e1c1f0c290f11ebd30.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\53251c7e83b57e1fb7e90172c5dda028.js
  • %Windows%\Tasks\{GUID}-4.job
  • %Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdate.exe.old
  • %User Temp%\comh.18754\psmachine.dll
  • %Program Files%\MPMP\MPMP-novainstaller.exe
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\3030fc4f3b901802369e95d81dda52be.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\bdeaae1663cfe8266d0bfbc7678dc967.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core\babbc84c37010a7be8cf9c5b17340fab.js
  • %AppDataLocal%\Google\Chrome\User Data\Local State
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\103.js
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\button2.png
  • %Program Files%\globalUpdate\Update\1.3.25.0\psmachine.dll.old
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api\af0d6e867c53d6d02549f5c2a1a1c625.js
  • %Windows%\Tasks\globalUpdateUpdateTaskMachineCore.job
  • %Program Files%\MPMP\bgNova.html
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin\button5.png
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\220.js
  • %Program Files%\globalUpdate\Update\1.3.25.0\psuser.dll
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\locale\en-US\translations.dtd
  • %Program Files%\MPMP\{GUID}-4.exe
  • %Program Files%\MPMP\MPMP-bho64.dll
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins\233.js

Step 6

Search and delete these folders

[ Learn More ]
Please make sure you check the Search Hidden Files and Folders checkbox in the More advanced options option to include all hidden folders in the search result.
  • %Program Files%\globalUpdate\Update
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\plugins
  • %AppDataLocal%\globalUpdate
  • %AppDataLocal%\globalUpdate\CrashReports
  • %Program Files%\MPMP
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\locale\en-US
  • %User Temp%\comh.18754
  • %User Profile%\AppData
  • %Program Files%\globalUpdate\Update\Offline
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData\userCode
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\api
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\extensionData
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome\content\core
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\skin
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\defaults
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\locale
  • %Program Files%\globalUpdate
  • %Program Files%\globalUpdate\Update\1.3.25.0
  • %System Root%\Users
  • %Program Files%\globalUpdate\Update\Offline\{27F2D2DB-7D37-4E11-92F6-67B10F86EC61}
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\defaults\preferences
  • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions\{GUID}@{GUID}.com\chrome
  • %Program Files%\globalUpdate\CrashReports

Step 7

Scan your computer with your Trend Micro product to delete files detected as Adware.Win32.Crossrider.A. If the detected files have already been cleaned, deleted, or quarantined by your Trend Micro product, no further step is required. You may opt to simply delete the quarantined files. Please check the following Trend Micro Support pages for more information:

Step 8

Restore deleted/modified files and/or registry entries from backup

*Note: Only Microsoft-related files/keys/values will be restored. If this malware/grayware also deleted registry keys/values related to programs that are not from Microsoft, please reinstall those programs on your computer.

    • %Application Data%\Mozilla\Firefox\Profiles\lj5mikyj.default\extensions.json

Step 9

Restore this file from backup only Microsoft-related files will be restored. If this malware/grayware also deleted files related to programs that are not from Microsoft, please reinstall those programs on you computer again.

  • %User Temp%\nst9695.tmp
  • %Windows%\Tasks\GoogleUpdateTask.job
  • %Windows%\Tasks\GoogleUpdateTaskMachine.job

Step 10

Restore these deleted registry keys/values from backup

*Note: Only Microsoft-related keys/values will be restored. If the malware/grayware also deleted registry keys/values related to programs that are not from Microsoft, please reinstall those programs on your computer.

  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GlobalUpdate\Update
    • eulaaccepted
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GlobalUpdate\Update
    • mi
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GlobalUpdate\Update
    • ui
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GlobalUpdate\Update
    • LastChecked
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GlobalUpdate\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}
    • UpdateAvailableCount
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GlobalUpdate\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}
    • UpdateAvailableSince
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GlobalUpdate\Update
    • uid
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GlobalUpdate\Update\network\secure
    • sk
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\GlobalUpdate\Update\network\secure
    • c


Did this description help? Tell us how we did.