CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

spacer spacer

The CLSID / BHO List / Toolbar Master List

Currently 54019 entries and growing...

This is the Master BHO and Toolbar list copyrighted by Tony Klein and CastleCops. For expert assistance, please post here. The information is collected across the Internet by the CastleCops Team. Usage: please leave feedback requesting permission if you are interested in using this data beyond the approved channels.

BHOList - ToolbarList

KEY:
  • "X" - Certified spyware/foistware, or other malware
  • "L" - Legitimate items
  • "O" - Open to debate
  • "?" - Unknown Status
  • "BHO" - Browser Helper Object
  • "TB" - Toolbar
  • "SH" - R3 URL SearchHook
  • "EB" - IE Explorer Bar

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z

    Random sampling...
    OBJECT NAMEGUIDSTATUSFILENAMEDESCRIPTION
    Class{E0AEB7AC-A620-791D-2529-5ADF8D029A5E}X BHO WIN**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    H{E10BA102-6EB1-4bb4-AACF-5CC6D1110E21}X BHO weq24m.dllVariant of the Infostealer.Banker.D trojan
    Class{62B528F1-C07D-B10C-F50A-0AF9FF61D0BF}X BHO WIN**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{F2627B78-07E2-3E7C-7A72-89CC518E8CAE}X BHO WIN**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{028697AB-AAC0-E8A1-A394-10CF6F8477FE}X BHO WIN**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    ListX Class{AAA70FD3-2A4D-11D3-B897-00104B0749C0}? BHO WMOLstX.dllUnidentified browser plugin, file located in a "Program Files\Windream" folder - should you have any information about this application, such as its homepage or the site where it was downloaded or installed, its exact purpose and whether you did or did not install it wittingly, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks!
    Class{72E235C2-802F-1CA0-B24E-5FC67932116C}X BHO WIN**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    {66F67511-2665-4C34-9E20-FAC2C0954EF2}X BHO whattt.dll Whazit adware variant
    Class{117941E9-9B27-77EF-DB55-8CBAA2F96C40}X BHO WIN**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{934F676A-D4FB-68F8-BF73-44127B30E2D7}X BHO WIN**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{3AEAD8F8-7409-2055-D03F-1E630CC0A5B8}X BHO WIN**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{920AD1D2-5235-FD60-EB1A-42DB37705C6B}X BHO WIN**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{0CF3B610-277F-D80D-2D60-E2E75E58BD58}X BHO WIN**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    XBTB02205 Class{380D01CA-D5F0-4481-A733-B983CA3CDFBB}X BHO waynet.dll Adware-SearchIt.dr - a Softomate Toolbar variant
    WEB.nl Toolbar{C44158E1-6121-4442-ABE6-FD53D6534CCB}O TB SH web.nl.dll, WEBNL~1.DLL Web.nl_Toolbar - a Softomate Toolbar variant, modifies the default Windows search hook - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this.
    Class{8D4B3E40-2116-40E1-F3AF-F9E5E5BA8CC5}X BHO WIN**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{FEE6A68B-3F21-E687-5ADC-9A41AF02CE4F}X BHO WIN**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{4D84A68D-2093-98F0-D350-292ABF94B29E}X BHO WIN**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    ToolHelper{BBBE1C1A-89F7-4AF6-ABD1-F8FBCFA47408}O BHO webdetb.dll WEB.DE_Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this.
    (´ÎüÃûÃ){30837A05-1D4D-4C74-A334-D42B27F1E2D4}X BHO win87wm.dllUnidentified parasite - should you have any information about this application, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks!
    Class{59306F6D-32E3-66B4-A964-FA4556181BB5}X BHO WIN**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    {52FE5233-367C-4EFB-BDD7-0BE4D212C107}X TB winb2s3*.dll (* = digit) iLookup/Begin2Search adware variant
    Class{DF759AF7-B857-F801-07D7-2880E7156CC1}X BHO WIN**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{AB6F81AC-6C76-BCBF-C021-1BA9321DF5F0}X BHO WIN**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    QXK Olive{FD0B419C-54A2-4FA8-80FA-A3F883F474B1}X BHO wbxdpgfenlk.dllAdware downloader causing false spyware warnings and connecting to rogue "security sites", a member of the Trojan-Downloader.Zlob.Media-Codec aka NewMediaCodec malware family
    Waynet, b7z.dll{CAE916D2-880A-4198-BB83-9E9DBD9615DC}X TB waynet.dll, b7z.dll Adware-SearchIt.dr - a Softomate Toolbar variant.
    Editor plugin{ADBC0CB9-CCC5-495f-B578-4B9BB82B03DF}X BHO woodtype.dll, callps.dllVariant of the Infostealer.Banker.D trojan
    Class{4CB6F767-41BB-3180-B80F-3C091DD0FA1A}X BHO WIN**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Microsoft Office Helper{814194F1-4148-3871-4118-2417A488A878}X BHO wycctd32.dllVariant of the Trojan-Spy.Win32.Agent.ir trojan
    Class{BC964760-630B-7F96-DD49-A4589C07A991}X BHO WIN**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Internet Explorer Web Content Filter{1B77D30A-81C9-497A-8647-142F7511B1FB}? BHO WebAuthPlugin.dllUnidentified browser plugin - should you have any information about this application, such as its homepage or the site where it was downloaded or installed, its exact purpose and whether you did or did not install it wittingly, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks!
    Class{B825595B-2058-BCA4-1A37-31A9B58CD033}X BHO WIN**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{4E44DB1D-63E6-5ADA-8425-0CCE4EB8858F}X BHO WIN**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    {1BDD55B8-3985-4E59-B906-5E0AD56D6710}X BHO WH*_*******.dll, (* =random char)Browserplugin.com malware
    Class{D4FD3E7F-134B-3265-8C6A-C70ABD1A2E09}X BHO WIN**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    COM+ Service{3C49DDAC-3DA4-4743-AF6C-5974FEAF875C}X BHO winload.dllPassword stealer trojan, detected as Troj/BHO-CN
    Class{39003147-0564-FC80-401D-657710C0FEE1}X BHO WIN**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    XBTB09580 Class{BBBE1C1A-89F7-4AF6-ABD1-F8FBCFA47408}L BHO wordreferenceEnFr.dll, WORDRE~1.DLL WordReference toolbar
    Class{980DD9F9-2942-B1AC-EFBB-8485C26538D6}X BHO WIN**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{15AC61A5-E699-0150-B1AE-88BB5ADD5624}X BHO WIN**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    BHObj Class{8F4E5661-F99E-4B3E-8D85-0EA71C0748E4}X BHO Wsem***.dll , (* = digit) DyFuCa/Internet_Optimizer adware variant
    Class{22B1EC47-1EAB-B7A8-630D-99F8D36BEB48}X BHO WIN**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    (no name){29FA981B-341B-4726-8332-582732ED2DF3}X BHO wmp11exe.dllUnidentified parasite of Chinese origin - should you have any information about this application, such as for example the site where it was downloaded or installed, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks!
    Class{652D4929-5C76-94A9-0C3D-31460592C199}X BHO WIN**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Finder, Web Quick{872ED12E-C4C2-42BB-833A-9B237F275CB3}X BHO WebQuick.dll Troj/BHO-D spyware trojan
    Class{BCE7D6C6-91F7-121B-8DD6-E434352088D3}X BHO WIN**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{B6016FA4-6BEE-BC17-E07E-FBE10FBB1708}X BHO WIN**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{912319D7-D36D-DED4-B6ED-977C23402843}X BHO WIN**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{4E150563-A8F7-D1F4-1A3B-0B7AC88D30FC}X BHO WIN**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    (no name){11F0EE13-5947-2942-F631-09BEB2706006}X BHO wirvufc.dllVariant of the DisableKey.A aka Busky downloader trojan
    Class{EE0622B9-E1DD-2901-FB4F-F5C1BFA6825D}X BHO WIN**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Windows Media Player{C7E9503C-DA29-4183-8FA9-978C32852C20}X BHO wmpdxm.dllDownloader trojan, member of the FakeAlert aka SmitFraud malware family - produces IEDefender or similar popups - also see here - NOTE: this file is located in the Windows or Winnt directory, and must NOT be confused with the legitimate Windows Media Player file of the same name, always located in %SysDir%!
    Class{FFABD30C-C2C9-7B56-2B56-9C121E648476}X BHO WIN**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{47EA1720-78C9-292F-1E61-12875D376490}X BHO WIN**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{38AF1BB4-5940-C5E2-435F-08770DE172AB}X BHO WIN**.DLL (* = random char) CoolWebSearch/HomeSearch adware component

    spacer spacer