| OBJECT NAME | GUID | STATUS | FILENAME | DESCRIPTION |
|---|
| WebFetch.co.uk Toolbar | {D0A7F513-5128-4643-8F47-3973B4BC2E92} | O TB EB | insptbar.dll | WebFetch.co.uk_Toolbar - an InfoSpace toolbar detected by Kaspersky antivirus as AdWare.Win32.Dogpile.a |
| IE Booster Toolbar | {38D2A281-0444-433C-9ED6-A2851795F32A} | L TB | iebbar.dll | Paessler IE Booster 2 |
| Class | {7AC4ED96-5D2A-C75F-1817-E095A3DF83C6} | X BHO | IE**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {605BB929-10FB-81EB-196F-7822E1EA2567} | X BHO | IP**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {8DF6C727-8E87-A143-C21F-E7E4262AC50A} | X BHO | IP**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| IBHO | {D60AB9BC-0ACF-4778-86D7-B991F2C6E48F} | X BHO | ibho.dll | Parasite of Korean origin, detected as IeGuide adware |
| IExplorr27.clsIS | {94326E3F-F51F-4863-A832-4ACD0D7D4BC3} | X BHO | iexplorr27.dll | InetSpeak/ESDIexplorr adware variant
|
| Class | {CC15449D-564B-BFBD-010F-5C0D90856CC3} | X BHO | IE**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {FA1147B8-7ABB-B7CE-A604-55A1C91D2636} | X BHO | IP**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {CF532F04-8C95-1B6E-C3C3-AE92B411CA46} | X BHO | IE**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Barre d'outils imagehotel.net | {C49DD894-C6DE-4910-8C41-BA20F852D8BC} | X TB | imagehotel.dll | Imagehotel.net_Toolbar - a Softomate Toolbar variant detected by Panda antivirus as Adware/ActiveSearch |
| Class | {24A47C18-4C17-2AC4-710A-F949DD49082D} | X BHO | IP**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| InternetProgram | {C58810EE-6B56-BDD6-5FAE-D204717DA8F6} | X BHO | InternetProgram-1.dll, InternetProgram-2.dll, InternetProgram-3.dll | PlayMP3Z.biz adware variant
|
| Class | {E2206C5C-A3AE-1960-7FEE-E2D7D04FD24C} | X BHO | IE**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {4BCAD990-46A1-8C59-B4AA-BE08A9CE4C7D} | X BHO | IP**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| IE Custom Tools | {EFAF6EA3-615D-4F83-8748-2F7A576FCEA6} | X TB | ictmdl.dll, sysdivx.dll | Parasite connecting to rogue "security sites", a member of the Trojan-Downloader.Zlob.Media-Codec malware family |
| Class | {01150869-6EAA-DBD5-EC6D-97E0570E4D55} | X BHO | IP**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Login Mgr Helper Object | {BF468356-BB7E-42D7-9F15-4F3B9BCFCED2} | X BHO | IeHelper008.dll, hostsrv.dll, dbxinet.dll, w32inet.dll, LoginMgr.dll | Password stealer, detected by Kaspersky antivirus as Trojan-Spy.Win32.Goldun.mn |
| Class | {CD02FF74-6A9B-D0F0-9FF8-8F1A538B0927} | X BHO | IP**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {03FF7663-C35E-6699-5A28-2CF30D6E3BE5} | X BHO | IE**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {46627ADD-649A-091B-8A47-C872CCE5F33E} | X BHO | IE**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {43433E94-7430-6ABF-36CC-1C4F9B24A6FB} | X BHO | IE**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {71D24BE6-063F-43B8-9E6B-4B63A3AF2DF0} | X BHO | IE**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {88289C47-A645-EF58-D2AA-35D1F783C7D6} | X BHO | IP**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {F9D7B838-0128-DA47-424A-9E6B5C35E7D6} | X BHO | IE**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {82716D87-4C8B-7BAB-6F6E-D1EEC8286823} | X BHO | IE**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {035AB507-A454-30C0-7879-F028430BA8A3} | X BHO | IP**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {934F52F5-7431-6F8D-CF03-508A60646BCC} | X BHO | IE**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {A645334F-FEE6-4734-366C-BD7C0DB2B254} | X BHO | IP**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {10FDEDF6-5C2E-2BF6-B4FA-8A09E1233D01} | X BHO | IP**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| {9C777253-3E17-42d6-897A-11B8617A8F7C} | X BHO | IELib.dll | RedV Protector Suite |
| Class | {057AA512-7751-B6EC-0B93-F0B2326890B7} | X BHO | IE**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {9B0EFD23-BE21-F9AB-FBD5-22E5F3F0FBA8} | X BHO | IE**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {C9322872-92AA-6F99-913A-9121F3BB3009} | X BHO | IE**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| IE DOM Inspector | {96CE8787-7C13-4B7C-B307-8F19A53A93D6} | L EB | IEDOMInspector.dll, IEDOMI~1.DLL | IE WebDeveloper |
| Class | {461A2653-B36A-3762-33AF-CBD520971823} | X BHO | IP**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {C2EB4CA0-38A5-FF3F-46BC-8DEB7BC0A932} | X BHO | IP**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {42541B07-7877-E057-6D18-73363B610FD2} | X BHO | IP**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| (no name) | {B58BF1FF-4311-427C-8332-BE17DD9873CF} | X BHO | ipv6monk.dll | Variant of the Cimuz-BU aka TR/Spy.BZub.GM trojan |
| Class | {474EFBA6-180B-3E94-6DF8-1D05BA9B4A44} | X BHO | IP**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Pistolstar Web SSO | {F01A34B2-0067-431C-A5E1-EFF58D85C9BE} | L BHO | IE_SSO_Toolbar.dll | PistolStar password management and authentication software |
| Class | {F75E935C-460C-2FD8-E0A7-B79321EBB7C0} | X BHO | IP**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Powermarks | {E166B4A2-83E7-11D3-B4FD-004005A47AAA} | L TB | iec.dll | Powermarks Bookmark manager |
| XBTB00664 | {BE1962AB-3E8F-422a-934D-12E1AD39AF4C} | O BHO | intermedia-services.com.dll, INTERM~*.DLL | Flatland.net Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. |
| Class | {D9E403FE-9154-878A-7820-16B2AF6C9AEE} | X BHO | IP**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {FC7FE60B-5F53-04EE-D392-70AD25A4A72D} | X BHO | IP**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {96F3D08B-30D6-1F20-9D91-80121F5F27E6} | X BHO | IP**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {75DF86D0-50B4-B58E-3F0F-546011A4DCDD} | X BHO | IE**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Infoseek toolbar | {947657DD-6584-4F4E-A26B-227B4BFE0FE4} | L TB | infoseek_2_*_*.dll | Infoseek.co.jp toolbar |
| Class | {8A1427DA-E895-5E89-B935-196EAEA15F3D} | X BHO | IP**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| VPNS System | {366B2151-E1C7-44a3-86A3-E5686C2A3D2F} | X BHO | iedrives.dll | MyGeek/Cpvfeed.com adware variant, detected by AntiVir antivirus as ADSPY/BHOApp - logs search engine queries to a %Windir%\search_res.txt file. Also see here
|
| Class | {ADFAB064-6D76-E095-1233-94E2B1BCEADA} | X BHO | IP**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {38684DAB-CE7D-692F-F285-5CE5F24E21F4} | X BHO | IE**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {E6A74FB3-3DE5-B258-DF98-F23453A49457} | X BHO | IP**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| (no name) | {5DCD5823-A374-4647-A549-042B132CA3E2} | X BHO | ipv6moni.dll | Variant of the Cimuz-BU aka TR/Spy.BZub.GM trojan |