CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

spacer spacer

The CLSID / BHO List / Toolbar Master List

Currently 54019 entries and growing...

This is the Master BHO and Toolbar list copyrighted by Tony Klein and CastleCops. For expert assistance, please post here. The information is collected across the Internet by the CastleCops Team. Usage: please leave feedback requesting permission if you are interested in using this data beyond the approved channels.

BHOList - ToolbarList

KEY:
  • "X" - Certified spyware/foistware, or other malware
  • "L" - Legitimate items
  • "O" - Open to debate
  • "?" - Unknown Status
  • "BHO" - Browser Helper Object
  • "TB" - Toolbar
  • "SH" - R3 URL SearchHook
  • "EB" - IE Explorer Bar

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z

    Random sampling...
    OBJECT NAMEGUIDSTATUSFILENAMEDESCRIPTION
    Class{2E3A3B08-5120-1970-507C-FEABCB55C2E0}X BHO D3**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{24BF9601-89AC-C428-79E2-5F25AEF61F74}X BHO D3**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    DeskalertsBHO{5121B863-FAE8-4935-BA76-0ABE0239AECA}X BHO deskbar.dllDeskAlerts, a Softomate toolbar and DeskBar adware variant - also see here - NOTE: the file may be installed in a "Program Files\DeskBar" or "DeskAlerts" folder, but it must NOT be confused with the legitimate DeskBar software, which does NOT install a BHO!
    Class{0A8EC764-DFC9-33AC-16CE-09308452FB81}X BHO D3**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{AAD9AEF3-8539-0B85-7DB0-C229B4C8B041}X BHO D3**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{43F3BDB3-7464-3C16-AC5B-5DD4883C394C}X BHO D3**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{EC5F4B05-E9D7-4907-A0CD-DD260CADFBF6}X BHO D3**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    SXG Advisor{9C22FF6B-11B2-43B0-9F1A-8B0C209C1FAB}X BHO dpvtportwf.dllAdware downloader causing false spyware warnings, a member of the Trojan-Downloader.Zlob.Media-Codec aka NewMediaCodec malware family
    (no name){6C6B8C69-9285-4D94-8492-9E920C8C2B65}X BHO dfgaert.dll, krnl32.dll, mssvmdll.dll, mstsk32.dll, mxcrtp.dll, param32.ocx, posterm.dll, regdll32.exe, sthbdm32.dll, stubext.dll, svhc32.dll, systerm.exe, uncwqs.dll, winhid64.dll, winsys32.exe, wintst.dllInstalled by a variant of the FakeAle trojan - detected by AntiVir antivirus as TR/Tiny.I
    SXG Advisor {3B052632-AF24-41A1-B518-448E9E8D0D99}X BHO dopfwrlrdp.dll Adware downloader causing false spyware warnings, a member of the Trojan-Downloader.Zlob.Media-Codec aka NewMediaCodec malware family
    (no name){3B35D985-7648-4521-83BE-1E16AE5CD05F}X BHO driverb.dllVariant of the Kolweb.Y downloader trojan
    Class{EAC3A391-5E5B-A18F-B597-936B5BE69D5F}X BHO D3**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{056815F0-7405-21CA-6044-79346CAF5517}X BHO D3**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{33A02D60-2A36-BAA2-3BCC-0B80AB149B32}X BHO D3**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    dpevflbg {D3C5B940-BC27-4E3C-A37B-E09C7A57EC40}X TB dpevflbg.dllParasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    Class{02FFD786-624F-CC5B-7820-BCDEE66D486F}X BHO D3**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    ٹη¡°â±(&D){08C906B4-AE61-40C1-A1E8-4A6D4BBEAD23}X TB directgo.dllParasite of Korean origin detected as Win-Adware/ToolBar.Directgo
    Class{F22ABCC8-DA46-6EFF-B0D2-2B1D0647AB7A}X BHO D3**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{7F4FF738-FD6F-935B-5E8A-DD28208D60F2}X BHO D3**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    (no name){FDEA2C12-A476-A13C-2B4C-A3BD546315C2}X BHO D_4362.dll, vd3_sys.datDownloader and hijacker redirecting searches to rogue sites (2--google.com, tipablog.com, kandidatov.net and others) - identified by F-Secure antivirus as Trojan.Win32.Small.tz
    Class{0B343453-C6BF-0DE2-AA49-52A97DE08547}X BHO D3**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    SXG Advisor{FC516858-0D83-408E-9A76-B16DD182ADAA}X BHO dmdqdrxpsr.dllAdware downloader causing false spyware warnings, a member of the Trojan-Downloader.Zlob.Media-Codec aka NewMediaCodec malware family
    Class{2852A986-DABA-3DEB-696E-AA3A2FA5E362}X BHO D3**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{A287067A-D984-E929-3B81-6572CE5C53D0}X BHO D3**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    (no name){96BE1D9A-9E54-4344-A27A-37C088D64FB4}X BHO dnsrep*******.dll , (* = random character), Mseffm.dll ClientMan adware component - also see here
    (no name){F70231A8-C197-496B-A3E5-CF62FB5C246C}X BHO DIEMON~1.DLLUnidentified parasite of Chinese origin - should you have any information about this application, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks!
    (no name){********-****-****-****-************}X BHO davcln.dllDownloader, detected by Kaspersky antivirus as Trojan-Downloader.Win32.Delf.emb
    Class{2B10DBFB-8E93-F539-8D03-D28608958BEF}X BHO D3**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{8849FD03-210F-3BC3-0713-DAC7CE7DD7AA}X BHO D3**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    GNX Rolex{F3D1AF65-65C3-4C96-86AE-2A54E481C0D1}X BHO drnpfdxsmk.dllAdware downloader causing false spyware warnings and connecting to rogue "security sites", a member of the Trojan-Downloader.Zlob.Media-Codec aka NewMediaCodec malware family
    Class{AA13C75F-4D40-4F94-C063-E16B31370931}X BHO D3**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{172D19B9-FEAD-2D68-1E67-461C96603108}X BHO D3**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{9B6F61D4-C995-3451-2DBF-E3A22ACA0DC7}X BHO D3**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    SXG Advisor{C1AEEDB2-C2BA-4F27-B591-44EA89388299}X BHO dwrmntsvrm.dllAdware downloader causing false spyware warnings, a member of the Trojan-Downloader.Zlob.Media-Codec aka NewMediaCodec malware family
    Class{0E0ABE69-7345-8741-938E-5DCCA13C4284}X BHO D3**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{7F1738DF-16B2-2588-2CDC-480A65E50CC6}X BHO D3**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Downloader app.{2EA061B2-11B5-4C4B-B385-F378B4B48648}X BHO down.dll, down1.dll Troj/Dloadr-AML trojan
    Class{4C664D49-FBB2-E3BE-597A-22B340FCF82E}X BHO D3**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{E9122E44-8E17-57FA-6C71-EC00AF6C5D1E}X BHO D3**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Microsoft Explorer{30569401-8721-8345-2CA1-873581CF4101}X BHO dswctl32.dllBackdoor trojan, detected by Kaspersky antivirus and by CounterSpy as Trojan-Spy.Win32.Agent.ir
    XBTB07626 {1F6B967F-27ED-49a6-B51F-246D77526E22}O BHO dpl_toolbar.dll, DPL_TO~1.DLL Denver_Public_Library_Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Your choice.
    Class{1F6BBD3D-4D92-B6C9-0D86-67BC18D25967}X BHO D3**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{10CB9ED8-DE3E-49E2-5735-9F1B7A0CC365}X BHO D3**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{AAD10086-21DC-6E87-74D2-FD6F5D9A9B4A}X BHO D3**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{3F52B4EC-64FC-175B-6173-38DF7625BB23}X BHO D3**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{EDC70A01-B9A8-BBFA-AC7D-D3C2C1A60592}X BHO D3**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{4FC94B1F-F066-F80C-485F-C0DA5FF9D913}X BHO D3**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    {4650480D-72DA-40D0-BCF7-D4FF5304C750}L BHO DiABLO.dllAblazesoft
    Class{24EF33EA-EE7F-BE3D-A23F-D28794BFB154}X BHO D3**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{69E11644-F09B-69E1-F1D4-F3EB7AB7AD2B}X BHO D3**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{A7F8BA73-322B-30CD-A83E-AF577424E397}X BHO D3**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{D74EF1BA-9E44-CB6B-6CC0-9035E64ABD6A}X BHO D3**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{78BF8F1B-D598-6BEF-4AED-6FCC68169F03}X BHO D3**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Media Player Codec{B4EF0D13-5359-457D-BA85-C110AEC377B5}X BHO dsaip32b.dllDownloader trojan, member of the FakeAlert aka SmitFraud malware family - produces IEDefender or similar popups - also see here
    Class{B04055DF-45FD-576B-7E87-283A1EF0072F}X BHO d3**.dll (* = random char) CoolWebSearch/HomeSearch adware component

    spacer spacer