| OBJECT NAME | GUID | STATUS | FILENAME | DESCRIPTION |
|---|
| (no name) | {28B6F144-3F8D-6D2C-8D89-13546601B19D} | X BHO | OinBHO.dll | ClickSpring.Oinadserver adware component, responsable for Outerinfo.com popups |
| (no name) | {********-****-****-****-************} | X BHO | openwin.dll (random Class ID) | CoolWebSearch parasite variant |
| (no name) | {58B28244-4FFE-6324-8D88-1054167DB192} | X SH | OinBHO.dll | ClickSpring.Oinadserver adware component, responsable for Outerinfo.com popups |
| Player | {D989E9EA-8F56-4864-A1EA-2F9059A421BE} | X BHO | orgnavi.dll | Downloader trojan causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family |
| Player | {83FD1F86-B40A-41EE-8512-929F005ED2A8} | X BHO | orgnavi.dll | Downloader trojan causing false spyware warnings and connecting to fake "security sites", member of the FakeAlert aka SmitFraud malware family |
| URLSearch Class | {965A592F-8EFA-4250-8630-7960230792F1} | X SH | omdsn.dll | PowerStrip adware component |
| ONSPEED Toolbar | {4E7BD74F-2B8D-469E-84BA-B830E8D4E122} | L BHO TB | onspeed_toolbar.dll, ONSPEE~1.DLL | OnSpeed toolbar |
| Player | {FC2458DB-B263-48C5-A106-0651B05DF38C} | X BHO | orgnavi.dll | Downloader trojan causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family |
| OLWebProfile.Block | {2F7C3A7D-380A-4960-853C-C7980F6D816E} | L BHO | OlWebProfile.dll | MultiResource Client "Onelog" authentication plugin |
| IEHelperObj Class | {6754A456-BAD9-11D4-93D3-00B0D03A2F91} | O BHO | Odigobho.dll | Odigo |
| CPopupControl Object | {4B764F4A-BC63-4CE4-AF5E-B24F76DA5B22} | L BHO | oqoieplugin.dll | Browser Plugin for OQO_docking_station |
| VPN-OEM Extension | {11D003B5-B3B5-4BCC-A974-71148786E968} | O BHO | olescn16.dll, nvrcr16.dll, msuieng.dll, msexchdr.dll | SpectorSoft computer monitoring software |
| okcashback system | {C3C7C84F-2E47-47E7-A596-6919C30662FE} | X BHO | okcashbackmallr.dll, OKCASH~1.DLL | Parasite of Korean origin hailing from okcashbackmall.com and identified as Adware.OKcashBackMall |
| MSVPS System | {2D42D689-4B94-4734-92C2-606FC5F4C15D} | X BHO | oprevtdp.dll | Zlob downloader variant, a member of the SmitFraud malware family |
| {267D5BD3-0DC2-4724-A196-7F4794FBB9EB} | X BHO | outones.dll, newones.dll | Whazit adware variant |
| iehpr | {44946F7A-C48C-482F-8ECF-52FA3280C09A} | ? BHO | osolgil.dll | Unidentified browser plugin of Korean origin - should you have any information about this application, such as its homepage or the site where it was downloaded or installed, its exact purpose and whether you did or did not install it wittingly, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks! |
| Yahoo Bar | {F60FAB6F-115D-4797-9ED1-89793B930876} | X BHO | ODBINT.dll | TROJ_CLICKER.ET downloader trojan |
| MBC Toolbar | {E74BC74F-F470-4AD7-9FB4-1A4170A06082} | X TB | OTWiz.dll | Parasite of Korean origin detected as SBSToolBar spyware |
| oembios32.msdn_hlp | {D79E1D43-C805-40EF-8ACB-DFFB17E9A4AF} | X BHO | oembios32.dll | Downloader trojan, member of the FakeAlert aka SmitFraud malware family |
| Player | {BA2020CE-AF34-4B1A-82D4-507C7F002079} | X BHO | orgnavi.dll | Downloader trojan causing false spyware warnings and connecting to fake "security sites", member of the FakeAlert aka SmitFraud malware family |
| optcalApp Class | {B37AB40A-FB66-46AA-9AC1-8D21B51E7CFC} | X BHO | optcal.dll | Adware of Korean origin hailing from empas.com, detected by Kaspersky antivirus as Trojan.Win32.BHO.qu |
| Orange | {4E7BD74F-2B8D-469E-A3FB-F862B587B57D} | L BHO TB | orange1.dll | Orange toolbar - see here or here |
| TBSB06358 | {977BBB7A-DD26-4E47-A4C3-3242272C98FE} | O BHO | ormedunyasi.dll | Orme_Dunyasi Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Your choice. |
| {7011471D-3F74-498E-88E1-C0491200312D} | X BHO | Otglove.dll | FriendGreetings E-Card foistware |
| okcashbackmall bar | {EEEF3CF7-4A59-4157-B6C8-E80C25ACBE5F} | X EB | okcashbackmallsb.dll | Parasite of Korean origin detected as Adware.Okcashbackmall |
| GamesBar | {6F282B65-56BF-4BD1-A8B2-A4449A05863D} | X BHO TB | oberontb.dll | Oberon_Media gamesbar, a Zango/Hotbar adware variant |
| TBSB01662 | {C85390F6-8A64-496C-9405-BFB673744B82} | O BHO | oyna55.dll | Oyna55.com Toolbar - - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Your choice.
|
| (no name) | {2E9D4C81-9F27-4c14-B804-7B0F6BC88A4F} | X BHO | Outerinfo.dll | ClickSpring "Oinadserver" adware |
| OSGWinBHO | {7D714DD8-4145-45E7-AE4A-CE233B676D30} | L BHO | OSGWinBHO.dll | "Original_Software" automated software testing solution |
| MSVPS System | {D5375315-6567-4DCA-8344-C78AA4B89C11} | X BHO | oprevfqv.dll | Zlob downloader variant, a member of the SmitFraud malware family |
| DHTML View | {37A5FF76-9919-492C-98E3-EDA3502FC829} | X BHO | Oasis.dll | Oasisnet.com Hijacker/web downloader |
| Player | {FAB71C44-8C45-43EF-B1BE-2E33076166D4} | X BHO | orgnavi.dll | Downloader trojan causing false spyware warnings and connecting to fake "security sites", member of the FakeAlert aka SmitFraud malware family |
| GamesBarBHO Class | {CB0D163C-E9F4-4236-9496-0597E24B23A5} | X BHO | oberontb.dll | Oberon_Media gamesbar, a Zango/Hotbar adware variant |
| MSVPS System | {F675EED8-4A4B-4A11-801B-08297749B83D} | X BHO | oprevnpx.dll | Zlob downloader variant, a member of the SmitFraud malware family |
| OKTE | {88CFEFCD-CA04-4D50-84D9-2A7083E63AE4} | ? TB | OKTIET~1.DLL, oktieToolbar.dll | OkteSchHook/Oktie.Toolbar software from axdisk.cn - Unidentified browser plugin - should you have any information about this application, such as its exact purpose and whether you did or did not install it wittingly, do email us. Thanks! |
| &Okapiland | {6b532243-2d02-48b3-95d7-cac66acbebc3} | L TB | okapibar.dll | IE_Okapiland_Search Toolbar - also see here |
| okteba Class | {CE7C3CF0-4B15-11D1-ABED-709549C16969} | X BHO | okteba.dll | Downloader of Chinese origin connecting to netxboy.com and detected as Win-Clicker/BHO.Okteba |
| (no name) | {5FC3F136-4F88-1659-8DF2-1554677BB191} | X BHO | OinBHO.dll | ClickSpring.Oinadserver adware component, responsable for Outerinfo.com popups |
| player addon | {1E40AD15-4280-428A-9A26-AB96F9DA2ACE} | X BHO | oggview32.dll | Downloader trojan, member of the FakeAlert aka SmitFraud malware family - produces IEDefender popups - also see here |
| Player | {22347AEE-A37A-45D3-8804-FDC7F9289CE1} | X BHO | orgnavi.dll | Downloader trojan causing false spyware warnings and connecting to fake "security sites", member of the FakeAlert aka SmitFraud malware family |
| onsidebar system | {D664CBB4-AC74-4599-B456-0D774457B520} | X EB | onsidebar.dll | Parasite of Korean origin hailing from onsidebar.com and detected as Adware.OnsideBar |
| onlineTV | {63CCAACE-9D54-4149-9085-1B3BA48D0FE2} | L TB | otvtoolbar.dll, OTVTOO~1.DLL | OnlineTV toolbar |
| Internet Explorer OneGuide | {61995404-D92F-4A03-9F98-BCCB368E3DAA} | X BHO | oneguide.dll | "Internet Explorer OneGuide" web search software of Korean origin hailing from Oneguide.co.kr - detected as Win32.Spyware.OneGuide |
| opshcbty.dll | {32596546-2036-9451-6058-658402589723} | X BHO | opshcbty.dll | Password stealer trojan of Chinese origin, a variant of Infostealer.Gampass
|
| (no name) | {2FB0D3A8-6374-490f-A299-DA336EF5C586} | X BHO | oneguidehelper.dll | Parasite of Korean origin hailing from Oneguide.co.kr and detected as Win-Adware/ToolBar.OneGuide |
| OGG Viewer | {7AB85EC7-22E7-4B5D-89DA-A9EBD1AF3520} | X BHO | oggview.dll | Downloader trojan, member of the FakeAlert aka SmitFraud malware family - produces IEDefender popups - also see here |
| ozfyebyt.dll | {5A069845-2036-6084-9054-6087502480A5} | X BHO | ozfyebyt.dll | Password stealer of Chinese origin detected by Trend Micro as TSPY_ONLINEG.FOK |
| IE | {616D534C-3CA8-43AB-B439-618F850F1D2B} | X BHO | odunbegy.dll, iksaps.dll, apsagy.dll, other semi-random filenames made up from the following fragments: ap, od, ik, sa, do, unbe, gy, ps, xu | Parasite redirecting to fake security sites, member of the FakeAlert aka SmitFraud malware family - produces IEDefender , FilesSecure , MalwareBell , IE_Antivirus or similar popups - also see here
|
| (no name) | {55C2F147-498D-1058-8DF9-10541D7BB1E0} | X SH | OinBHO.dll | ClickSpring.Oinadserver adware component, responsible for Outerinfo.com popups
|
| oembios32.msdn_hlp | {04FA0716-63E1-4146-B250-E5222AE06E79} | X BHO | oembios32.dll | Downloader trojan, member of the FakeAlert aka SmitFraud malware family |
| OKCashplus | {30A3E265-0AFF-4F56-8F3D-75691F4A0B61} | X TB | okcashplus.dll | Parasite of Korean origin hailing from okcashplus.com and detected as Win-Adware/ToolBar.OkCashPlus |
| (no name) | {2E07BA49-75F2-7151-A6EE-73D58F25E492} | X BHO | owngjmv.dll | Clickspring/Oinadserver adware component |
| Onfolio Helper | {ba727652-f90e-4d82-9ce4-98766dffc375} | L BHO | onfoliox.dll | OnFolio |
| TBSB02566 | {C3BF5D6D-4C43-4D82-849F-B172BC3D6EFB} | L BHO | ozgurbarV2-9.dll, OZGURB~1.DLL | AkBank OzgurBar |
| okcashbackmall.com | {C4B993FE-74EB-4357-BF3D-B5AF493E3E32} | X BHO | okcashbackmall.dll, OKCASH~1.DLL | Parasite of Korean origin hailing from okcashbackmall.com and identified as Adware.OKcashBackMall |