CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

spacer spacer

The CLSID / BHO List / Toolbar Master List

Currently 54019 entries and growing...

This is the Master BHO and Toolbar list copyrighted by Tony Klein and CastleCops. For expert assistance, please post here. The information is collected across the Internet by the CastleCops Team. Usage: please leave feedback requesting permission if you are interested in using this data beyond the approved channels.

BHOList - ToolbarList

KEY:
  • "X" - Certified spyware/foistware, or other malware
  • "L" - Legitimate items
  • "O" - Open to debate
  • "?" - Unknown Status
  • "BHO" - Browser Helper Object
  • "TB" - Toolbar
  • "SH" - R3 URL SearchHook
  • "EB" - IE Explorer Bar

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z

    Random sampling...
    OBJECT NAMEGUIDSTATUSFILENAMEDESCRIPTION
    Shareaza Web Download Hook{0EEDB912-C5FA-486F-8334-57288578C627}O BHO RazaWebHook.dllShareaza
    realestate.com.au lite Toolbar{D8958E48-205B-4D96-9D30-74EEBF12C6EB}O TB realestate_lite2.dll, REALES~*.DLL Realestate.com.au_Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Remove unless you both trust it and expressly meant to install it.
    rtsplgob{8E1F6C9A-86C0-4811-B45A-278E754B457F}X TB rtsplgob.dllParasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    Recipe Rewards Toolbar{77FBF9B8-1D37-4FF2-9CED-192D8E3ABA6F}X TB rr-toolbar.dll, RR-TOO~1.DLLRecipe Rewards Toolbar - a Traffix_inc EZTracks/aavalue.com foistware variant
    WriteFileware Class{33E8230A-AFA8-4db4-8684-CBA061C98D1E}X BHO rwl.dll, ash2.dll BankAsh-Q trojan
    Flash Module{C87FA4A3-2474-4a3f-B413-67D515905024}X BHO rasmoesa.dll, akun54.dllPassword stealer, a variant of Win32.Trojan-Spy.Banker.EGJ - also see here
    {99C06C01-BB1C-11D4-9A4A-00C04F018885}L BHO resolver.dllCNRI Handle System Resolver
    Recados Para Orkut{BFB5F154-9212-46F3-B547-AC6106030A54}O TB recados.dll Recados_Para_Orkut - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Your choice
    {2B3452C5-1B9A-440F-A203-F6ED0F64C895}X BHO rem00001.dll BookedSpace adware variant
    RSBar7BHO{57317FFA-6567-47A7-8B90-EB466EE61C11}X BHO RSBar7.dllParasite of Korean origin detected as Win-Adware/BHO.RsBar
    The Radio Toolbar{BFB5F154-9212-46F3-B547-AC6106030A54}X TB radio-toolbar.dll, RADIO-~*.DLL The_Radio_Toolbar - a Softomate Toolbar variant detected by Kaspersky antivirus as Adware.Win32.Mostofate.ab
    rijxbkin.dll{25FD6584-698F-BCD2-602C-698745210352}X BHO rijxbkin.dllPassword stealer of Chinese origin detected by Trend Micro as TSPY_ONLINEG.FOK
    (no name){AEC4B333-7A09-4CB7-9171-3C3E1CA51C8A}X BHO reginix86f.dllDownloader, a variant of the Win32.Kolweb aka Durvil trojan
    H{63170A8C-B4A4-4242-810A-1F3ABE7797DA}X BHO ra1.dllVariant of the Infostealer.Banker.D trojan
    realconnect {51351DDA-02A4-4919-AB1F-8C4307A889FA}? BHO realconnect.dllUnidentified browser plugin - should you have any information about this application, such as its homepage or the site where it was downloaded or installed, its exact purpose and whether you did or did not install it wittingly, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks!
    H{21F6EE00-FEC3-4a0e-BA2E-F919CF11D87E}X BHO rsssewe_.dll, rtywem.dllVariant of the Infostealer.Banker.D trojan
    Resept IE BHO{B40D0B13-9A70-4394-8F21-E2E4AE3A9BC4}L BHO ReseptIeClient.dll Resept/Trustalert Identity and Access management software
    XBTB02559 Class{151A7846-0140-4379-BD22-D413D946100A}X BHO rr-toolbar.dll, RR-TOO~1.DLLRecipe Rewards Toolbar - a Traffix_inc EZTracks/aavalue.com foistware variant
    TBSB08747 {7485D0BB-313E-435D-9BF3-011626721D3A}O BHO risaleara toolbar Projesi.dll Risaleara.com Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Remove unless you both trust it and expressly meant to install it.
    rtsplgob{BDC832B3-37F6-4C6A-8B06-E1123700413F}X TB rtsplgob.dllParasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    {79C9FDA0-0A67-4C56-BC89-6AB3FEC2752F}L TB racbar.dllRent a Coder Toolbar
    Rmn plugin{930247B4-16BE-48d2-87DD-86D7FB314639}X BHO ritz8.dllPassword stealer aka "Banker" trojan, a variant of Trojan.Nethell - also detected as Troj/Alpha-H
    Real Estate Toolbox{26A1CBE4-13EC-424B-854C-CCDA191FBA26}O TB realestatetoolbox.dllReal Estate Toolbox Toolbar by CRWork.com - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Installer detected by Kaspersky antivirus as AdWare.Win32.Mostofate.ap
    RssBho Class{9BC6ABD4-63C4-41E0-9C96-77D7F0AF78CE}L BHO rsstoolbar.dllBuilt-in RSS Client
    [full path to file]{B5AF0562-94F3-42BD-F434-2604812C297D}X BHO random filenames (example: Bvdsf4g.dll , S7dsf4g.dll)Parasite, detected by Kaspersky antivirus as Trojan-Downloader.Win32.Small.ddx
    The retnsrp{573E45AC-F20E-4DAF-AF6C-0775714BA0C1}X TB retnsrp.dllParasite connecting to rogue "security sites", member of the FakeAlert aka SmitFraud malware family
    TBSB03746 {054152F3-7D1B-424E-BA14-4002F78E5019}O BHO rxpop.dll RxPop.com_Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Installer detected by Kaspersky antivirus as AdWare.Win32.Mostofate.dj
    (no name){C40624B4-CCDB-4F00-8888-7896032D234A}X BHO redir.dll SpyGuarder - rogue "security software" using false positives as goad to purchase.
    Rhiebh.MyBHO{EE54478B-BD76-444E-A545-E095D88F9D86}? BHO Rhiebh.dllUnidentified browser plugin - should you have any information about this application, such as its exact purpose and whether you did or did not install it wittingly, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks!
    CRnPluginSite Object{0050A87F-CF26-41AE-9C0A-C32307C941CB}L BHO rnieplug.dll ReturnReceipt ActiveTracker plugin
    PopStop Class{9C777253-3E17-42d6-897A-11B8617A8F7B}X BHO RVPS.dllRedV Protector Suite
    H{43000075-124D-4697-A2A5-AF8FE8AF1376}X BHO r223e.dll, c3224m.dllVariant of the Infostealer.Banker.D trojan
    Related Site Search{D7258ABE-571F-4DC2-ABD1-8393B13B1269}X TB RSSToolbar.dll BrowserAid adware component
    RepliGoIEHelperCtl Class{91DE4477-9CDC-4806-9BCB-28A963988E94}L BHO RepliGoIEHelper.dll, RepliGoIEBar.dllRepliGo
    RBCContents ToolBar{5A0261B2-DB44-467B-83AE-496D5B2FC3D0}L TB RBCContents.dll RBCContents_ToolBar - Site management tool
    &Browser_Radio{0F08F55E-A4D7-4D3A-8264-8F85008100C2}O TB radiojockeyorg.dllRadioJockey.NET Browsertools
    Windows DNS Helper {11B1FC48-0FD0-4BC7-8C10-FF4705D0025F}X BHO random filename (examples: 45u107nv.dll, truq5e4x.dll)Parasite, detected by AntiVir as TR/BHO.DNSHelper
    {81F4066B-F330-4872-8094-3E9FBCCEC8C1}L TB RepliGoIEBar.dllCerience software
    Google Module{4C579E8B-92F1-44d1-9444-66A4355E9386}X BHO rozmchild.dll, bagetionwll.dllPassword stealer, identified as Troj/Dloadr-BGC
    RCPRIVACY{72EBDE8B-F1DC-4F6E-AA3F-13461861E239}O BHO RealConcept.dll, REALCO~1.DLL RealConcept bar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Some of the toolbars are fine to have, so every case is different. Your choice.
    RewardBHO Class{6425C3F6-6BB2-45BB-BCFD-F76D011D7D92}X BHO reward.dllParasite of Korean origin detected as CashShop or Reward adware
    ReGet MSIE handler, ReGet MSIE Helper Class{38AAF321-C5B4-11D1-B75E-400000000000}L BHO REGET.DLL, regetapi.dllReget Deluxe
    RSS-Client{63837897-A6BB-424F-ACB8-F25C93F87890}L TB rsstoolbar.dllBuilt-in RSS Client
    Editor Plugin{41F0460B-6B45-45de-8717-B27BC18360A6}X BHO restorem.dll, somelot.dllVariant of the Infostealer.Banker.D trojan
    XBTBPos00{CDCB861F-7CDD-4768-87D0-4D2FCFF3D53A}O BHO RADIO-~*.DLLUnidentified Softomate Toolbar - should you have any information about this application, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks!
    (no name){8C5D82E9-9D36-4158-B074-20A87B4928E4}X BHO reginix86d.dllDownloader, a variant of the Win32.Kolweb aka Durvil trojan
    H{875DFA42-0F20-449b-B8AE-4795E5A30B98}X BHO rtreywem.dll, rsewwssewe_.dllVariant of the Infostealer.Banker.D trojan
    Her {C4DE5B15-4FFE-4c02-8CB3-CAD24A33562B}X BHO ramtmb.dll, romtmb.dllKeyword hijacker and trojan connecting to meoryprof.info and using seobiz.us as click referer - also see here and here
    Microsoft Class{895A5924-74BA-43CD-B585-B031B44ECD66}X BHO reportUpdate.dll, UpdateFirewall.dll, dateWatch.dll, Updatewindows.dll, repairsafe.dll, Watchwindows.dll, policesystem.dll, policedriver.dll, other filenamesUnidentified parasite of Chinese origin - should you have any information about this application, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks!
    (no name){724D43A9-0D85-11D4-9908-00400523E39A}L BHO RoboForm.dllRoboForm
    XBTBPos00{30843C1C-520C-4C07-BE0A-03EB63C6058E}O BHO RealConcept.dll, REALCO~1.DLL RealConcept Bar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this.
    Rediff Toolbar{6D53ADB7-6AD5-4A59-BFE4-7B57D2F4AA89}O TB SH redifftoolbar.dll, REDIFF~1.DLL Rediff.com Toolbar - see here - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Remove unless you both trust it and expressly meant to install it.
    {4E7BD74F-2B8D-469E-C0FF-FD6DB787FA7D}L TB Rcabar.dllR/C Toolbar
    & Band{3F5A62E2-51F2-11D3-A075-CC7364CAE42F}X TB reword3.dllParasite of Korean origin hailing from pcup.co.kr and detected as Win32.Toolbar.Pcup
    {F8CC9B08-C14F-4A5C-B73B-518AFECC067A}L TB rekruter_2_43.dll, REKRUT~*.DLLRekruter-Toolbar

    spacer spacer