Send us feedback
We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
MonitoringTool:Win32/SecondSight
Aliases: Win-Trojan/Keylogger.53248.C (AhnLab) Trojan.Delf.FD (AVG) Trojan.Spy.Ssight.A (BitDefender) Trojan.Delf-1678 (Clam AV) not-a-virus:Monitor.Win32.KeyLogger.o (Kaspersky) Generic Keylog (McAfee) W32/Agent.QRL (Norman) Second Sight (Sunbelt Software) Trojan Horse (Symantec) Dialer_Win32Dial (Trend Micro)
Summary
Threat behavior
Installation
%windir%\system32\KBDMONITOR.OCX
%windir%\system32\KTKbdHk3.dll
%windir%\system32\SSvxd\AXSSMTP.OCX
%windir%\system32\SSvxd\CAPSCRN.OCX
%windir%\system32\SSvxd\CCRPFD6.OCX
%windir%\system32\SSvxd\KSDPANEL.OCX
%windir%\system32\SSvxd\SSgrid32.ddt
%windir%\system32\SSvxd\sshostap.exe
%windir%\system32\SSvxd\SSUBTMR6.DLL
%windir%\system32\SSvxd\SSUnwise.exe
%windir%\system32\SSvxd\TOOLBAR2.OCX
%windir%\system32\SSvxd\wgrid32.dat
%windir%\system32\SSvxd\XIMGEDIT30.OCX
%windir%\system32\SSvxd\_DEISREG.ISR
%windir%\system32\SSvxd\_ISREG32.DLL
%windir%\system32\Trlpro.ocx
Additional Information
HKEY_CLASSES_ROOT\Interface\{24C90DA9-FAA5-4DD4-A75F-860EEBA084CE}
HKEY_CLASSES_ROOT\TypeLib\{1FAA49C4-16B7-4D28-8930-31BE1810D943}
HKEY_CLASSES_ROOT\TypeLib\{249FCAA5-5488-4B89-B216-E05DC09DF237}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{1FAA49C4-16B7-4D28-8930-31BE1810D943}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{249FCAA5-5488-4B89-B216-E05DC09DF237}
HKEY_CLASSES_ROOT\AIFCmp1.asxToolbar
HKEY_CLASSES_ROOT\AIFCmp1.clsIFceComp
HKEY_CLASSES_ROOT\axsCaptureScrn.axsCapScreen
HKEY_CLASSES_ROOT\axsSMTP.axsSMTPSock
HKEY_CLASSES_ROOT\ccrFileDialogs6.ccrpFileDialogs
HKEY_CLASSES_ROOT\DataGuardEncrytion.DataGuard
HKEY_CLASSES_ROOT\KbdMonitor.KeyMon
HKEY_CLASSES_ROOT\SSubTimer6.CTimer
HKEY_CLASSES_ROOT\SSubTimer6.GSubclass
HKEY_CLASSES_ROOT\SSubTimer6.ISubclass
HKEY_CLASSES_ROOT\TrialProActiveX.SystemDetect
HKEY_CLASSES_ROOT\TrialProActiveX.TrialPro
HKEY_CLASSES_ROOT\XImgEdit20.XImgEdit
HKEY_CLASSES_ROOT\CLSID\{446BA88B-5DA1-11D3-BD95-9497CA1D1132}
HKEY_CLASSES_ROOT\CLSID\{572110FB-7FC4-11D5-B57F-0050BAE7FEC4}
HKEY_CLASSES_ROOT\CLSID\{5C4592C0-A01B-11D3-AFAF-BF3F431B043C}
HKEY_CLASSES_ROOT\CLSID\{681A54C9-1AA8-4F02-A80B-28016562A546}
HKEY_CLASSES_ROOT\CLSID\{71A2702F-C7D8-11D2-BEF8-525400DFB47A}
HKEY_CLASSES_ROOT\CLSID\{7435B1E5-1132-11D4-881C-FE73F1277977}
HKEY_CLASSES_ROOT\CLSID\{8622CF73-1059-4F1E-BE61-2774421FEAF6}
HKEY_CLASSES_ROOT\CLSID\{89E24949-B9C2-11D5-B580-0050BAE7FEC4}
HKEY_CLASSES_ROOT\CLSID\{9FBD19BA-0C67-4CA8-9620-42C1F106E5BB}
HKEY_CLASSES_ROOT\CLSID\{C4D77E94-252D-11D4-B358-C9A9F1AA7152}
HKEY_CLASSES_ROOT\CLSID\{C9AC6C7F-FF07-40D9-A782-99B06991E0DC}
HKEY_CLASSES_ROOT\CLSID\{CF424AF9-6EBC-4EF6-8B51-BB39452043DC}
HKEY_CLASSES_ROOT\CLSID\{D3CD7E76-F46E-4D4D-8A37-6E1D9B915CD9}
HKEY_CLASSES_ROOT\CLSID\{DE5C2449-65D5-4413-BFCF-6BFCDF294665}
HKEY_CLASSES_ROOT\Interface\{24C90DA9-FAA5-4DD4-A75F-860EEBA084CE}
HKEY_CLASSES_ROOT\Interface\{2E643D36-F83B-4654-9C7E-2FD3EB5FCC67}
HKEY_CLASSES_ROOT\Interface\{52A1DC9C-2B44-4579-9210-1AED9EFB068C}
HKEY_CLASSES_ROOT\Interface\{572110FA-7FC4-11D5-B57F-0050BAE7FEC4}
HKEY_CLASSES_ROOT\Interface\{5C4592BF-A01B-11D3-AFAF-BF3F431B043C}
HKEY_CLASSES_ROOT\Interface\{5ED7EF55-5417-4316-9FCA-5AE7EDA37E3C}
HKEY_CLASSES_ROOT\Interface\{71A2702E-C7D8-11D2-BEF8-525400DFB47A}
HKEY_CLASSES_ROOT\Interface\{7435B1E1-1132-11D4-881C-FE73F1277977}
HKEY_CLASSES_ROOT\Interface\{83843E00-1D01-49CD-A47F-B6570A81443F}
HKEY_CLASSES_ROOT\Interface\{9C985253-7ABC-4803-85C5-0EBCDD69B59C}
HKEY_CLASSES_ROOT\Interface\{A02CA67E-8EBF-488D-A5D9-B8AACEC5CBE0}
HKEY_CLASSES_ROOT\Interface\{AB14F05E-4C1D-49DC-8BD5-9E6B510B3EBA}
HKEY_CLASSES_ROOT\Interface\{B17640CA-B591-11D5-B580-0050BAE7FEC4}
HKEY_CLASSES_ROOT\Interface\{B78B0E98-0431-4A6B-8C3D-F240FE8725F5}
HKEY_CLASSES_ROOT\Interface\{C4D77E93-252D-11D4-B358-C9A9F1AA7152}
HKEY_CLASSES_ROOT\Interface\{C4D77E97-252D-11D4-B358-C9A9F1AA7152}
HKEY_CLASSES_ROOT\Interface\{E6F2F7A9-B593-11D5-B580-0050BAE7FEC4}
HKEY_CLASSES_ROOT\Interface\{F54174AF-6546-11D3-BD95-8870DE7D2E30}
HKEY_CLASSES_ROOT\TypeLib\{249FCAA5-5488-4B89-B216-E05DC09DF237}
HKEY_CLASSES_ROOT\TypeLib\{446BA877-5DA1-11D3-BD95-9497CA1D1132}
HKEY_CLASSES_ROOT\TypeLib\{572110ED-7FC4-11D5-B57F-0050BAE7FEC4}
HKEY_CLASSES_ROOT\TypeLib\{5C4592BE-A01B-11D3-AFAF-BF3F431B043C}
HKEY_CLASSES_ROOT\TypeLib\{71A2702D-C7D8-11D2-BEF8-525400DFB47A}
HKEY_CLASSES_ROOT\TypeLib\{7435B1E0-1132-11D4-881C-FE73F1277977}
HKEY_CLASSES_ROOT\TypeLib\{B78D1D17-8176-11D5-B57F-0050BAE7FEC4}
HKEY_CLASSES_ROOT\TypeLib\{C4D77E92-252D-11D4-B358-C9A9F1AA7152}
HKEY_LOCAL_MACHINE\SOFTWARE\iQuesoft
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AIFCmp1.asxToolbar
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AIFCmp1.clsIFceComp
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\axsCaptureScrn.axsCapScreen
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\axsSMTP.axsSMTPSock
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ccrFileDialogs6.ccrpFileDialogs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DataGuardEncrytion.DataGuard
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\KbdMonitor.KeyMon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSubTimer6.CTimer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSubTimer6.GSubclass
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSubTimer6.ISubclass
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TrialProActiveX.SystemDetect
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TrialProActiveX.TrialPro
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\XImgEdit20.XImgEdit
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{446BA88B-5DA1-11D3-BD95-9497CA1D1132}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{572110FB-7FC4-11D5-B57F-0050BAE7FEC4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C4592C0-A01B-11D3-AFAF-BF3F431B043C}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{681A54C9-1AA8-4F02-A80B-28016562A546}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71A2702F-C7D8-11D2-BEF8-525400DFB47A}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7435B1E5-1132-11D4-881C-FE73F1277977}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8622CF73-1059-4F1E-BE61-2774421FEAF6}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{89E24949-B9C2-11D5-B580-0050BAE7FEC4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9FBD19BA-0C67-4CA8-9620-42C1F106E5BB}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C4D77E94-252D-11D4-B358-C9A9F1AA7152}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C9AC6C7F-FF07-40D9-A782-99B06991E0DC}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CF424AF9-6EBC-4EF6-8B51-BB39452043DC}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D3CD7E76-F46E-4D4D-8A37-6E1D9B915CD9}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DE5C2449-65D5-4413-BFCF-6BFCDF294665}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{17A3B6BA-2C73-4F1E-84EB-0BC4B4FEB3DD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1B11F4B0-6B89-4E43-9421-0F94E24DDBA0}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{24C90DA9-FAA5-4DD4-A75F-860EEBA084CE}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2E643D36-F83B-4654-9C7E-2FD3EB5FCC67}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{52A1DC9C-2B44-4579-9210-1AED9EFB068C}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{572110FA-7FC4-11D5-B57F-0050BAE7FEC4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5C4592BF-A01B-11D3-AFAF-BF3F431B043C}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5ED7EF55-5417-4316-9FCA-5AE7EDA37E3C}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{71A2702E-C7D8-11D2-BEF8-525400DFB47A}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7435B1E1-1132-11D4-881C-FE73F1277977}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{83843E00-1D01-49CD-A47F-B6570A81443F}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{89E24948-B9C2-11D5-B580-0050BAE7FEC4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9C985253-7ABC-4803-85C5-0EBCDD69B59C}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A02CA67E-8EBF-488D-A5D9-B8AACEC5CBE0}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AB14F05E-4C1D-49DC-8BD5-9E6B510B3EBA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B17640CA-B591-11D5-B580-0050BAE7FEC4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B78B0E98-0431-4A6B-8C3D-F240FE8725F5}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C4D77E93-252D-11D4-B358-C9A9F1AA7152}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E6F2F7A9-B593-11D5-B580-0050BAE7FEC4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E6F2F7AA-B593-11D5-B580-0050BAE7FEC4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F54174AF-6546-11D3-BD95-8870DE7D2E30}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{249FCAA5-5488-4B89-B216-E05DC09DF237}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{572110ED-7FC4-11D5-B57F-0050BAE7FEC4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{5C4592BE-A01B-11D3-AFAF-BF3F431B043C}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{71A2702D-C7D8-11D2-BEF8-525400DFB47A}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{7435B1E0-1132-11D4-881C-FE73F1277977}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{B78D1D17-8176-11D5-B57F-0050BAE7FEC4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C4D77E92-252D-11D4-B358-C9A9F1AA7152}
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_STISVC\0000\Control
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\_SS_exec.exe
With data: "0x00000001 (1)"
To subkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
With data: "0x00000001 (1)"
To subkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
With data: "0x00000001 (1)"
To subkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
With data: "0x00000001 (1)"
To subkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
With data: "0x00000001 (1)"
To subkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
With data: "0x00000001 (1)"
To subkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
With data: "0x00000001 (1)"
To subkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
With data: "0x00000001 (1)"
To subkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
With data: "0x00000001 (1)"
To subkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
With data: "0x00000001 (1)"
To subkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
With data: "0x00000001 (1)"
To subkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
With data: "0x00000001 (1)"
To subkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
With data: "0x00000001 (1)"
To subkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
With data: "0x00000001 (1)"
To subkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
With data: "0x00000001 (1)"
To subkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Prevention
System Changes
- Presence of the following files:
%windir%\system32\DGuard2.ocx
%windir%\system32\KBDMONITOR.OCX
%windir%\system32\KTKbdHk3.dll
%windir%\system32\SSvxd\AXSSMTP.OCX
%windir%\system32\SSvxd\CAPSCRN.OCX
%windir%\system32\SSvxd\CCRPFD6.OCX
%windir%\system32\SSvxd\KSDPANEL.OCX
%windir%\system32\SSvxd\SSgrid32.ddt
%windir%\system32\SSvxd\sshostap.exe
%windir%\system32\SSvxd\SSUBTMR6.DLL
%windir%\system32\SSvxd\SSUnwise.exe
%windir%\system32\SSvxd\TOOLBAR2.OCX
%windir%\system32\SSvxd\wgrid32.dat
%windir%\system32\SSvxd\XIMGEDIT30.OCX
%windir%\system32\SSvxd\_DEISREG.ISR
%windir%\system32\SSvxd\_ISREG32.DLL
%windir%\system32\Trlpro.ocx - Presence of this registry values and data:
Value: Netdrver.vxe
With data: "C:\WINDOWS\system32\SSvxd\sshostap -s"
In subkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run - Presence of the following registry values:
HKEY_CLASSES_ROOT\Interface\{17A3B6BA-2C73-4F1E-84EB-0BC4B4FEB3DD}
HKEY_CLASSES_ROOT\Interface\{24C90DA9-FAA5-4DD4-A75F-860EEBA084CE}
HKEY_CLASSES_ROOT\TypeLib\{1FAA49C4-16B7-4D28-8930-31BE1810D943}
HKEY_CLASSES_ROOT\TypeLib\{249FCAA5-5488-4B89-B216-E05DC09DF237}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{1FAA49C4-16B7-4D28-8930-31BE1810D943}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{249FCAA5-5488-4B89-B216-E05DC09DF237}
HKEY_CLASSES_ROOT\AIFCmp1.asxToolbar
HKEY_CLASSES_ROOT\AIFCmp1.clsIFceComp
HKEY_CLASSES_ROOT\axsCaptureScrn.axsCapScreen
HKEY_CLASSES_ROOT\axsSMTP.axsSMTPSock
HKEY_CLASSES_ROOT\ccrFileDialogs6.ccrpFileDialogs
HKEY_CLASSES_ROOT\DataGuardEncrytion.DataGuard
HKEY_CLASSES_ROOT\KbdMonitor.KeyMon
HKEY_CLASSES_ROOT\SSubTimer6.CTimer
HKEY_CLASSES_ROOT\SSubTimer6.GSubclass
HKEY_CLASSES_ROOT\SSubTimer6.ISubclass
HKEY_CLASSES_ROOT\TrialProActiveX.SystemDetect
HKEY_CLASSES_ROOT\TrialProActiveX.TrialPro
HKEY_CLASSES_ROOT\XImgEdit20.XImgEdit
HKEY_CLASSES_ROOT\CLSID\{446BA88B-5DA1-11D3-BD95-9497CA1D1132}
HKEY_CLASSES_ROOT\CLSID\{572110FB-7FC4-11D5-B57F-0050BAE7FEC4}
HKEY_CLASSES_ROOT\CLSID\{5C4592C0-A01B-11D3-AFAF-BF3F431B043C}
HKEY_CLASSES_ROOT\CLSID\{681A54C9-1AA8-4F02-A80B-28016562A546}
HKEY_CLASSES_ROOT\CLSID\{71A2702F-C7D8-11D2-BEF8-525400DFB47A}
HKEY_CLASSES_ROOT\CLSID\{7435B1E5-1132-11D4-881C-FE73F1277977}
HKEY_CLASSES_ROOT\CLSID\{8622CF73-1059-4F1E-BE61-2774421FEAF6}
HKEY_CLASSES_ROOT\CLSID\{89E24949-B9C2-11D5-B580-0050BAE7FEC4}
HKEY_CLASSES_ROOT\CLSID\{9FBD19BA-0C67-4CA8-9620-42C1F106E5BB}
HKEY_CLASSES_ROOT\CLSID\{C4D77E94-252D-11D4-B358-C9A9F1AA7152}
HKEY_CLASSES_ROOT\CLSID\{C9AC6C7F-FF07-40D9-A782-99B06991E0DC}
HKEY_CLASSES_ROOT\CLSID\{CF424AF9-6EBC-4EF6-8B51-BB39452043DC}
HKEY_CLASSES_ROOT\CLSID\{D3CD7E76-F46E-4D4D-8A37-6E1D9B915CD9}
HKEY_CLASSES_ROOT\CLSID\{DE5C2449-65D5-4413-BFCF-6BFCDF294665}
HKEY_CLASSES_ROOT\Interface\{24C90DA9-FAA5-4DD4-A75F-860EEBA084CE}
HKEY_CLASSES_ROOT\Interface\{2E643D36-F83B-4654-9C7E-2FD3EB5FCC67}
HKEY_CLASSES_ROOT\Interface\{52A1DC9C-2B44-4579-9210-1AED9EFB068C}
HKEY_CLASSES_ROOT\Interface\{572110FA-7FC4-11D5-B57F-0050BAE7FEC4}
HKEY_CLASSES_ROOT\Interface\{5C4592BF-A01B-11D3-AFAF-BF3F431B043C}
HKEY_CLASSES_ROOT\Interface\{5ED7EF55-5417-4316-9FCA-5AE7EDA37E3C}
HKEY_CLASSES_ROOT\Interface\{71A2702E-C7D8-11D2-BEF8-525400DFB47A}
HKEY_CLASSES_ROOT\Interface\{7435B1E1-1132-11D4-881C-FE73F1277977}
HKEY_CLASSES_ROOT\Interface\{83843E00-1D01-49CD-A47F-B6570A81443F}
HKEY_CLASSES_ROOT\Interface\{9C985253-7ABC-4803-85C5-0EBCDD69B59C}
HKEY_CLASSES_ROOT\Interface\{A02CA67E-8EBF-488D-A5D9-B8AACEC5CBE0}
HKEY_CLASSES_ROOT\Interface\{AB14F05E-4C1D-49DC-8BD5-9E6B510B3EBA}
HKEY_CLASSES_ROOT\Interface\{B17640CA-B591-11D5-B580-0050BAE7FEC4}
HKEY_CLASSES_ROOT\Interface\{B78B0E98-0431-4A6B-8C3D-F240FE8725F5}
HKEY_CLASSES_ROOT\Interface\{C4D77E93-252D-11D4-B358-C9A9F1AA7152}
HKEY_CLASSES_ROOT\Interface\{C4D77E97-252D-11D4-B358-C9A9F1AA7152}
HKEY_CLASSES_ROOT\Interface\{E6F2F7A9-B593-11D5-B580-0050BAE7FEC4}
HKEY_CLASSES_ROOT\Interface\{F54174AF-6546-11D3-BD95-8870DE7D2E30}
HKEY_CLASSES_ROOT\TypeLib\{249FCAA5-5488-4B89-B216-E05DC09DF237}
HKEY_CLASSES_ROOT\TypeLib\{446BA877-5DA1-11D3-BD95-9497CA1D1132}
HKEY_CLASSES_ROOT\TypeLib\{572110ED-7FC4-11D5-B57F-0050BAE7FEC4}
HKEY_CLASSES_ROOT\TypeLib\{5C4592BE-A01B-11D3-AFAF-BF3F431B043C}
HKEY_CLASSES_ROOT\TypeLib\{71A2702D-C7D8-11D2-BEF8-525400DFB47A}
HKEY_CLASSES_ROOT\TypeLib\{7435B1E0-1132-11D4-881C-FE73F1277977}
HKEY_CLASSES_ROOT\TypeLib\{B78D1D17-8176-11D5-B57F-0050BAE7FEC4}
HKEY_CLASSES_ROOT\TypeLib\{C4D77E92-252D-11D4-B358-C9A9F1AA7152}
HKEY_LOCAL_MACHINE\SOFTWARE\iQuesoft
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AIFCmp1.asxToolbar
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AIFCmp1.clsIFceComp
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\axsCaptureScrn.axsCapScreen
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\axsSMTP.axsSMTPSock
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ccrFileDialogs6.ccrpFileDialogs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DataGuardEncrytion.DataGuard
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\KbdMonitor.KeyMon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSubTimer6.CTimer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSubTimer6.GSubclass
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SSubTimer6.ISubclass
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TrialProActiveX.SystemDetect
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TrialProActiveX.TrialPro
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\XImgEdit20.XImgEdit
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{446BA88B-5DA1-11D3-BD95-9497CA1D1132}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{572110FB-7FC4-11D5-B57F-0050BAE7FEC4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C4592C0-A01B-11D3-AFAF-BF3F431B043C}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{681A54C9-1AA8-4F02-A80B-28016562A546}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71A2702F-C7D8-11D2-BEF8-525400DFB47A}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7435B1E5-1132-11D4-881C-FE73F1277977}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8622CF73-1059-4F1E-BE61-2774421FEAF6}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{89E24949-B9C2-11D5-B580-0050BAE7FEC4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9FBD19BA-0C67-4CA8-9620-42C1F106E5BB}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C4D77E94-252D-11D4-B358-C9A9F1AA7152}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C9AC6C7F-FF07-40D9-A782-99B06991E0DC}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CF424AF9-6EBC-4EF6-8B51-BB39452043DC}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D3CD7E76-F46E-4D4D-8A37-6E1D9B915CD9}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DE5C2449-65D5-4413-BFCF-6BFCDF294665}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{17A3B6BA-2C73-4F1E-84EB-0BC4B4FEB3DD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1B11F4B0-6B89-4E43-9421-0F94E24DDBA0}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{24C90DA9-FAA5-4DD4-A75F-860EEBA084CE}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2E643D36-F83B-4654-9C7E-2FD3EB5FCC67}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{52A1DC9C-2B44-4579-9210-1AED9EFB068C}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{572110FA-7FC4-11D5-B57F-0050BAE7FEC4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5C4592BF-A01B-11D3-AFAF-BF3F431B043C}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5ED7EF55-5417-4316-9FCA-5AE7EDA37E3C}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{71A2702E-C7D8-11D2-BEF8-525400DFB47A}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7435B1E1-1132-11D4-881C-FE73F1277977}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{83843E00-1D01-49CD-A47F-B6570A81443F}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{89E24948-B9C2-11D5-B580-0050BAE7FEC4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9C985253-7ABC-4803-85C5-0EBCDD69B59C}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A02CA67E-8EBF-488D-A5D9-B8AACEC5CBE0}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AB14F05E-4C1D-49DC-8BD5-9E6B510B3EBA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B17640CA-B591-11D5-B580-0050BAE7FEC4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B78B0E98-0431-4A6B-8C3D-F240FE8725F5}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C4D77E93-252D-11D4-B358-C9A9F1AA7152}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E6F2F7A9-B593-11D5-B580-0050BAE7FEC4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E6F2F7AA-B593-11D5-B580-0050BAE7FEC4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F54174AF-6546-11D3-BD95-8870DE7D2E30}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{249FCAA5-5488-4B89-B216-E05DC09DF237}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{572110ED-7FC4-11D5-B57F-0050BAE7FEC4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{5C4592BE-A01B-11D3-AFAF-BF3F431B043C}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{71A2702D-C7D8-11D2-BEF8-525400DFB47A}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{7435B1E0-1132-11D4-881C-FE73F1277977}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{B78D1D17-8176-11D5-B57F-0050BAE7FEC4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C4D77E92-252D-11D4-B358-C9A9F1AA7152}
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_STISVC\0000\Control
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\_SS_exec.exe