CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

spacer spacer

The CLSID / BHO List / Toolbar Master List

Currently 54019 entries and growing...

This is the Master BHO and Toolbar list copyrighted by Tony Klein and CastleCops. For expert assistance, please post here. The information is collected across the Internet by the CastleCops Team. Usage: please leave feedback requesting permission if you are interested in using this data beyond the approved channels.

BHOList - ToolbarList

KEY:
  • "X" - Certified spyware/foistware, or other malware
  • "L" - Legitimate items
  • "O" - Open to debate
  • "?" - Unknown Status
  • "BHO" - Browser Helper Object
  • "TB" - Toolbar
  • "SH" - R3 URL SearchHook
  • "EB" - IE Explorer Bar

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z

    Random sampling...
    OBJECT NAMEGUIDSTATUSFILENAMEDESCRIPTION
    Her{2A7102DE-1F71-4146-86FD-A722E8AB3489}X BHO lorinhib.dll, procins.dllKeyword hijacker and trojan connecting to meoryprof.info and using seobiz.us as click referer
    np Class{0A073DD6-195E-4217-97B6-BB6AECEC9AA5}X BHO ljk.dll OpenSearch adware
    (no name){648592A3-44B7-9AF8-BACA-02859776A1CD}X BHO llkyzqd.dllVariant of the DisableKey.A aka Busky downloader trojan
    {3C6A1597-3058-481A-8884-684A01988815}L BHO Linkmgr.dlliLOR
    Libero{2170AE22-BED6-4BD8-8A30-775F233B45C0}L BHO LiberoDll.dllLibero Toolbar
    mssgr Object{EC564D32-0F1A-4367-8A9B-4A9F57688D03}X BHO lsmgr.dllParasite of Chinese origin, detected as Adware.Elodu
    Longdo Toolbar{8BF27F8B-236F-4b81-AC69-8EB7690E5845}L TB LongdoBar.dllLongdo Toolbar
    LI Toolbar{067C5591-C9FB-4dcc-835F-6CB5DC169D41}O TB LIToolbar.dll"Li Toolbar", a toolbar of Russian origin hailing from Li.ru
    [full path to file] or " - "{********-****-****-****-************}X BHO lbbho.dll (random Class ID)RelatedLinks adware
    Editor plugin{9F4BC278-AA12-4716-A1EC-F1888B200F89}X BHO loadplg.dllVariant of the Infostealer.Banker.D trojan
    Cumseeker Toolbar{EB68C5CB-2694-44AE-9FE5-9F97F3144834}X TB like_dogpile.dllCasino-Onlineguide.com Toolbar
    (no name){337C54C9-80C1-4de2-93CD-AAA510834074}X BHO laf**.dll , laf***.dll (* = random char or digit)Trojan dropper, detected by ESET's Nod32 antivirus as Win32/Hoax.Renos.NAV - a member of the SmitFraud malware family
    NickToolbarInstall Class{11AF48E4-CA6C-45ee-A181-282CD7A5BFCD}L BHO launchpadtoolbar.dll Nick.com_Launchpad
    linkprohelper{11E78485-C932-4944-BDCD-3B57CD676E5C}X BHO LinkProHelper.dllParasite of Korean origin, detected as Win32.Spyware.linkpro
    ÎÀ¡°ÌÀåµ 3.0{11DD68B7-215C-4781-8DE1-03EC83FCBB3B}L TB LniEKGate30.dll EnGuide3.0 - Software provided by LNISOFT
    (no name){53B5F2B1-94DD-43E5-8187-EB4E31F00701}X BHO l3acdb.dll, d3acdb.dll, l3acdb2.dll, l4acdb2.dll, random filename (examples: jynsnsra.dll, 6HEiWaAr.dll)Trojan-Downloader, a Win32.Delf variant
    Skyhook Wireless Loki{43537A86-707C-46E7-B408-82588B7993D3}L BHO LokiIe.dllSkyhook Wireless Loki
    lpobj Class{23CB460A-BA87-4588-8494-DDE1600450DE}X BHO linkplus.dll Parasite of Korean origin identified as LinkPlus adware
    WebSpeechBHO Class{83A30C59-3A50-49E6-9DAF-4923C4EA3C23}L BHO LgxIEBar.dllWebSpeech
    LinkedIn Toolbar{BB670D0B-5C46-40C7-B38B-40DD26987723}L TB LinkedInIEToolbar.dllLinkedIn Toolbar
    DVA Storm{C6CF5BA3-2D76-40D1-A07F-2A0D18540255}X BHO lgmxvpatwxm.dll Adware downloader causing false spyware warnings and connecting to rogue "security sites", a member of the Trojan-Downloader.Zlob.Media-Codec aka NewMediaCodec malware family
    Longdo Toolbar{8BF27F8B-236F-4b81-AC69-8EB7690E5845}L TB longdo-98.dll Longdo Toolbar - Thai dictionary search and compilation service
    (no name){40B46A31-F568-4671-A502-AF93235A013B}X BHO LegitDheckControl.dllAdware detected by CounterSpy as AdWare.Win32.Stud.d
    The leosrv{C7A4712B-9331-4746-AD61-C675C11B89B9}X TB leosrv.dllParasite connecting to rogue "security sites", member of the FakeAlert aka SmitFraud malware family
    XBTB08909 Class{6D34AA11-39F6-48f4-B23D-3211FCB46490}O BHO logos_ie.dll Logos_Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this.
    XBTP02016 Class{7401E786-66E2-4086-9859-13F005862992}O BHO lookster.dll Lookster_Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Installer detected by Kaspersky antivirus as AdWare.Win32.Mostofate.be and by Bitdefender as Adware.Softomate.ED - also see here
    Lišta Seznam{34488680-809F-11d3-A146-0080AD02157C}L TB listicka.dll Seznam_Listic toolbar
    Local Spool support DLL{00C9D850-244D-11E1-B3C9-10805E499D95}X BHO lclspl.dllOpenWares "ContextuAd" aka MediaBack adware
    Link21Toolbar{2E0C67CB-62E6-40cd-AEE0-5EFC51B291DA}X TB link21_toolbar.dll, LINK21~1.DLLAdware of Korean origin hailing from linkprice.com
    lijzdlit.dll{4C954872-1230-6541-9548-6541025884C4}X BHO lijzdlit.dllPassword stealer of Chinese origin detected by Trend Micro as TSPY_ONLINEG.FOK
    XBTB02928 {D6EE65AF-1E53-4859-B200-BB4A185453EF}O BHO LoseWeightToolbar.dll Lose_Weight_Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Installer detected by Kaspersky antivirus as AdWare.Win32.MyTool.f and by Bitdefender as Adware.Eztrack.C
    Insomnia Toolbar{26586983-56D0-44E2-B891-26452BDCF2E5}O TB l2i_-_insomnia.dllUnidentified Softomate Toolbar - should you have any information about this application, such as its homepage, its exact purpose and whether you did or did not install it wittingly, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks!
    InfoBand{00552751-19CC-4D2D-9767-F37E2692A9FE}X BHO TB LEDWiz.dllAdware of Korean origin detected as SBSToolBar spyware
    H{1A6A262F-D7F6-4e2b-8542-7B577976E666}X BHO lkjhgfds.dllVariant of the Infostealer.Banker.D trojan
    The leosrv{A16D89EA-B695-4DDA-B31D-7FA01A57F1BD}X TB leosrv.dllParasite connecting to rogue "security sites", member of the FakeAlert aka SmitFraud malware family
    LuckyTender{5E2402A0-5F99-4188-B30D-D8743996B340}? BHO LuckyTender.dll, lt.dll Unidentified browser plugin - should you have any information about this application, such as its exact purpose and whether you did or did not install it wittingly, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks!
    Local Spool support DLL{20C9D850-244D-11E1-B3C9-10805E499D95}X BHO loclspl.dllOpenWares "ContextuAd" aka MediaBack adware
    Lyrics {4B44E961-B842-11D9-AED1-004033A00168}X TB lyrics.dll Lyrics_Toolbar - a Softomate Toolbar variant detected by Kaspersky antivirus as AdWare.Win32.SearchIt.o - also see here
    DVA Storm{D3593B96-4822-434E-82B4-A54C29FCC7F5}X BHO lgmxvpatdbr.dllAdware downloader causing false spyware warnings and connecting to rogue "security sites", a member of the Trojan-Downloader.Zlob.Media-Codec aka NewMediaCodec malware family
    DVA Storm{CDB3DBC3-BCAD-4286-A557-D069E0DA5BD7}X BHO lgmxvpatokm.dllAdware downloader causing false spyware warnings and connecting to rogue "security sites", a member of the Trojan-Downloader.Zlob.Media-Codec aka NewMediaCodec malware family
    Local Spool Net support DLL{FCADDC50-BE46-409A-9842-CEBE1C6E37EB}X BHO localsplnet.dllOpenWares "ContextuAd" aka MediaBack adware
    TBSB02315{7F9415E6-FD58-4412-A4A0-1A091E38DFDA}O BHO Live-Foot3.dll Live-Foot.com toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this.
    Logos Toolbar{C94158E1-6151-4442-ABE6-FD53D6534CCB}O BHO TB logos_ie.dll Logos_Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this.
    Leopard Search Toolbar{E828EC21-EAA9-44B3-8021-EE89101C6ACD}X TB SH leopardsearch.dll, leopard_search.dll, LEOPAR~1.DLLLeopard Search toolbar - browser hijacker
    noep Class{660AA989-286A-46ff-9783-B991D5E68EFC}X BHO ljk.dll OpenSearch adware
    MS Explorer{105E9401-3AB1-7145-22AD-8F95813F4901}X BHO ldpctl32.dllVariant of the Trojan-Spy.Win32.Agent.ir trojan
    Local Spool Net support DLL{EF99BD50-CDFB-11E2-892F-1090271D4F78}X BHO localsplnet.dllOpenWares "ContextuAd" aka MediaBack adware
    LexisNexis(R) PatentOptimizer(TM){2710A98A-079E-4091-91A2-A00F45D4BA09}L TB LNPatOpt.dll LexisNexis_PatentOptimizer Toolbar
    LexisNexis ToolBar{E92748B4-AFCC-4533-8876-DB99FD857949}L BHO TB LNToolBar.dll LexisNexis Toolbar
    &Linx Toolbar{AB51D07A-3947-4C48-8641-728C73CB0FFA}? TB LinxTool.dllUnidentified Toolbar of Chinese origin - should you have any information about this application, such as its exact purpose and whether you did or did not install it wittingly, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks!
    MS Explorer{115E9481-8AB1-7845-28AD-8F98813F4981}X BHO logctl32.dllVariant of the Trojan-Spy.Win32.Agent.ir trojan
    The leosrv{14E52265-CCA3-4F78-A21B-88F4EE6E78C1}X TB leosrv.dllParasite connecting to rogue "security sites", member of the FakeAlert aka SmitFraud malware family
    LEC{4A241D35-F7EB-401b-8C5B-A904A50F280E}L BHO LEC IE Translation Extension.dll LEC Power Translator
    (no name){12FE2DFD-9644-42F1-AB2E-730552F028D6}X BHO lanbio.dll"ComSpy", a keystroke logger that records both sides of IM's and P2P downloads, then emails the results out - detected by Kaspersky antivirus as Backdoor.Win32.Ulrbot.f
    The leosrv{D3ADD35B-48FC-4EB5-84BB-AF7ED2795035}X TB leosrv.dllParasite connecting to rogue "security sites", member of the FakeAlert aka SmitFraud malware family

    spacer spacer