CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

spacer spacer

The CLSID / BHO List / Toolbar Master List

Currently 54019 entries and growing...

This is the Master BHO and Toolbar list copyrighted by Tony Klein and CastleCops. For expert assistance, please post here. The information is collected across the Internet by the CastleCops Team. Usage: please leave feedback requesting permission if you are interested in using this data beyond the approved channels.

BHOList - ToolbarList

KEY:
  • "X" - Certified spyware/foistware, or other malware
  • "L" - Legitimate items
  • "O" - Open to debate
  • "?" - Unknown Status
  • "BHO" - Browser Helper Object
  • "TB" - Toolbar
  • "SH" - R3 URL SearchHook
  • "EB" - IE Explorer Bar

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z

    Random sampling...
    OBJECT NAMEGUIDSTATUSFILENAMEDESCRIPTION
    DUIE Class{CECD8E44-D53E-427B-89FB-3DF0A5C8BECD}L BHO DU_BHO.dll DownUp2U - Chinese Downloadmanager
    SXG Advisor{BC165164-78D0-4209-A878-8E6692C768FF}X BHO dpvtporrdw.dllAdware downloader causing false spyware warnings, a member of the Trojan-Downloader.Zlob.Media-Codec aka NewMediaCodec malware family
    Class{D574263D-3927-4338-E8B8-5BA8F174EB59}X BHO D3**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{73552EB6-28B2-A889-71F2-05AE594B33B9}X BHO D3**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{8D4D6EDD-3BE2-C07E-77E5-EE66F53997FC}X BHO D3**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{A823E8D3-49E2-C685-F5CE-FA97B7B8A428}X BHO D3**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{707DCCE4-6D01-94F7-97FE-819597AEDA53}X BHO D3**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    SKbarBHO{0F233D99-B03A-4c4d-8CAB-D14ACE8671AD}O BHO deskbar.dll Searchkut_Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Some of the toolbars are fine to have, so every case is different. Your choice.
    ViewSource Class {BA489AD0-0A60-4AD5-B681-DB5AECFC1E67}X BHO donkeytb.dllParasite of Korean origin, detected as Win32.Spyware.donkeytb
    Class{1BCBA8DE-0A5A-1B10-5D83-D3AEC6AA0794}X BHO D3**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{05EC6A69-684D-8BE0-FDEE-2B01F30E35CF}X BHO D3**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{8A3702AE-375F-72C9-4CF2-CD064BED729F}X BHO D3**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    DeskalertsBHO{CC79522A-9E3B-4bc9-9218-D95EC5DA5349}X BHO deskbar.dllDeskAlerts, a Softomate toolbar and DeskBar adware variant - also see here - NOTE: the file may be installed in a "Program Files\DeskBar" or "DeskAlerts" folder, but it must NOT be confused with the legitimate DeskBar software, which does NOT install a BHO!
    Class{0D059602-AC41-5879-7153-9877F3E4CAFF}X BHO D3**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{802A649E-3116-B069-41CB-4D33F17750FD}X BHO D3**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    DDClickObj Class{4DDA8855-2860-430a-96E4-34BE9F8F864A}X BHO DDClick.dllParasite of Korean origin detected as Win32.Grayware.ddclick
    Class{F4ABE202-FC73-BE08-3C16-FA18008D8421}X BHO D3**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    DsHelper{0D42E1BD-09DD-4873-A826-9C7E793EB7B6}O BHO DSIeHelper.dll Xunlei "Thunder" download manager
    Class{B7AE5988-3688-C06D-F636-5509DAD63F01}X BHO D3**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{13B605DF-1E8A-69E3-30F0-9C4603AF0367}X BHO D3**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    MSVPS System{ECBD04D1-1133-4480-8A8C-BC9FDD54D6C1}X BHO div32.dll, afxp.dll MyGeek/Cpvfeed.com adware variant, detected by Kaspersky antivirus as Trojan-Downloader.Win32.BHO.af - Also see here
    Class{B6538DD6-4537-7114-B27B-08CAEDEDD4E2}X BHO D3**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    DeskalertsBHO{20D58178-A7F9-47fe-A1B3-1CD46A030E20}X BHO SH deskbar.dllDeskAlerts, a Softomate toolbar and DeskBar adware variant - also see here - NOTE: the file may be installed in a "Program Files\DeskBar" or "DeskAlerts" folder, but it must NOT be confused with the legitimate DeskBar software, which does NOT install a BHO!
    Class{1C53941D-477F-6263-5B87-CAAEBC229396}X BHO d3**32.dll (* = random char) CoolWebSearch/HomeSearch adware component
    dpevflbg {547D68A0-5DA7-46A9-AF9A-AF8E80321F8C}X TB dpevflbg.dllParasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    Class{69CDF539-1EC5-30E5-E75C-40EFB9DA4482}X BHO D3**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{0372D18D-A96E-C7D5-7B89-21D041F7710F}X BHO D3**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    (no name){B426F491-094C-43D4-8F16-ED4AE190032D}X BHO driverl.dll, driverm.dllVariant of the Kolweb.Y aka Durvil or Druvil downloader trojan
    Class{CDA457DA-DF5F-3D28-F203-C6CC3C8F7278}X BHO D3**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    RDL Rolex{B8C5A2C9-639D-4A41-991C-005412790C99}X BHO dkxrstqgxt.dllAdware downloader causing false spyware warnings, a member of the Trojan-Downloader.Zlob.Media-Codec aka NewMediaCodec malware family
    Class{55B602D6-4282-BE22-DEE6-C95DFCA166A1}X BHO D3**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{4B05C084-12D2-0FF6-D490-A0CF45280E50}X BHO D3**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{BB26EC6D-86CC-D35F-619C-93731180E706}X BHO D3**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{0587668D-040D-B46A-070A-C11489B3391F}X BHO D3**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{77057387-19AF-7AA4-5A3E-00408CBA9C49}X BHO D3**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{C96846BD-D164-2B23-8DE1-A0AC4FA69CC4}X BHO D3**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{86D4852C-B1D2-EE87-2B2C-572D82340F98}X BHO D3**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{286B2AD0-92FB-11D2-10FE-2602C19AF756}X BHO D3**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    (no name){566C2B45-015E-43BE-AF6D-30F204494EE7}X BHO driverc.dllVariant of the Kolweb.Y downloader trojan
    DiigoBHO Class{84053DA7-03DE-4FB6-80AE-202C04691D8A}L BHO DiigoToolbar-**********.dll Diigo "Social Annotation" software
    Class{A97FF80C-C3C6-1C7D-18BA-35E8A45FAF0E}X BHO D3**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{ABEFC8A2-1733-F386-48F3-B861F6CBA8BC}X BHO D3**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{E908A374-1683-3463-4B58-B04FA802CF30}X BHO D3**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    RDL Rolex{87F99AD1-22A9-46AD-8BCD-DEF34C065CA6}X BHO drnpfdxvsl.dllAdware downloader causing false spyware warnings and connecting to rogue "security sites", a member of the Trojan-Downloader.Zlob.Media-Codec aka NewMediaCodec malware family
    BHO.tbl2{76086C05-4D0A-4B92-9219-2E3FE8C553F9}X BHO domie.dll, homie.dll, sofiebho.dll, other semi-random filenames made up from the following fragments: dom, hom, sof, ie, bho, iebhoParasite redirecting to fake security sites, member of the FakeAlert aka SmitFraud malware family - produces IEDefender , FilesSecure , MalwareBell , IE_Antivirus or similar popups - also see here
    Class{AA774627-1C11-9FEE-63C0-58C6AA455AF4}X BHO D3**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{4AD27BAD-4A75-729A-D632-63239B86AA6E}X BHO D3**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{A859B6BB-8EAA-7883-53AE-5736A16A96D3}X BHO D3**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Delicious Toolbar{61D1C847-DF80-423A-8C6D-DC03B97E6EBE}L TB DeliciousExtension.dll Delicious_Toolbar for Internet Explorer
    Class{95E7F4A6-F484-9562-183E-FA99F8F8267F}X BHO D3**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    (no name){277B59E7-BC2C-454D-B6AF-1D113768C274}X BHO diskcop.dllPassword stealer detected as Win32.Trojan-Spy.BZub.BTV
    RDL Rolex{F2D6DA3F-061A-42FB-83E8-80FBDE005898}X BHO dgtxrdfnfq.dllAdware downloader causing false spyware warnings and connecting to rogue "security sites", a member of the Trojan-Downloader.Zlob.Media-Codec aka NewMediaCodec malware family
    Class{CD026C37-3A3C-08C8-544D-E7060E463F1C}X BHO D3**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    (no name){********-****-****-****-************}X SH Dest068.dll WareOut malware component, using a random Class ID
    Class{6267AD1B-B223-0089-C5DF-C12346F87BA8}X BHO D3**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component

    spacer spacer