| OBJECT NAME | GUID | STATUS | FILENAME | DESCRIPTION |
|---|
| Class | {E0AEB7AC-A620-791D-2529-5ADF8D029A5E} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| H | {E10BA102-6EB1-4bb4-AACF-5CC6D1110E21} | X BHO | weq24m.dll | Variant of the Infostealer.Banker.D trojan |
| Class | {62B528F1-C07D-B10C-F50A-0AF9FF61D0BF} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {F2627B78-07E2-3E7C-7A72-89CC518E8CAE} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {028697AB-AAC0-E8A1-A394-10CF6F8477FE} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| ListX Class | {AAA70FD3-2A4D-11D3-B897-00104B0749C0} | ? BHO | WMOLstX.dll | Unidentified browser plugin, file located in a "Program Files\Windream" folder - should you have any information about this application, such as its homepage or the site where it was downloaded or installed, its exact purpose and whether you did or did not install it wittingly, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks! |
| Class | {72E235C2-802F-1CA0-B24E-5FC67932116C} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| {66F67511-2665-4C34-9E20-FAC2C0954EF2} | X BHO | whattt.dll | Whazit adware variant |
| Class | {117941E9-9B27-77EF-DB55-8CBAA2F96C40} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {934F676A-D4FB-68F8-BF73-44127B30E2D7} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {3AEAD8F8-7409-2055-D03F-1E630CC0A5B8} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {920AD1D2-5235-FD60-EB1A-42DB37705C6B} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {0CF3B610-277F-D80D-2D60-E2E75E58BD58} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| XBTB02205 Class | {380D01CA-D5F0-4481-A733-B983CA3CDFBB} | X BHO | waynet.dll | Adware-SearchIt.dr - a Softomate Toolbar variant |
| WEB.nl Toolbar | {C44158E1-6121-4442-ABE6-FD53D6534CCB} | O TB SH | web.nl.dll, WEBNL~1.DLL | Web.nl_Toolbar - a Softomate Toolbar variant, modifies the default Windows search hook - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. |
| Class | {8D4B3E40-2116-40E1-F3AF-F9E5E5BA8CC5} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {FEE6A68B-3F21-E687-5ADC-9A41AF02CE4F} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {4D84A68D-2093-98F0-D350-292ABF94B29E} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| ToolHelper | {BBBE1C1A-89F7-4AF6-ABD1-F8FBCFA47408} | O BHO | webdetb.dll | WEB.DE_Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. |
| (´ÎüÃûÃ) | {30837A05-1D4D-4C74-A334-D42B27F1E2D4} | X BHO | win87wm.dll | Unidentified parasite - should you have any information about this application, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks! |
| Class | {59306F6D-32E3-66B4-A964-FA4556181BB5} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| {52FE5233-367C-4EFB-BDD7-0BE4D212C107} | X TB | winb2s3*.dll (* = digit) | iLookup/Begin2Search adware variant |
| Class | {DF759AF7-B857-F801-07D7-2880E7156CC1} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {AB6F81AC-6C76-BCBF-C021-1BA9321DF5F0} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| QXK Olive | {FD0B419C-54A2-4FA8-80FA-A3F883F474B1} | X BHO | wbxdpgfenlk.dll | Adware downloader causing false spyware warnings and connecting to rogue "security sites", a member of the Trojan-Downloader.Zlob.Media-Codec aka NewMediaCodec malware family
|
| Waynet, b7z.dll | {CAE916D2-880A-4198-BB83-9E9DBD9615DC} | X TB | waynet.dll, b7z.dll | Adware-SearchIt.dr - a Softomate Toolbar variant. |
| Editor plugin | {ADBC0CB9-CCC5-495f-B578-4B9BB82B03DF} | X BHO | woodtype.dll, callps.dll | Variant of the Infostealer.Banker.D trojan |
| Class | {4CB6F767-41BB-3180-B80F-3C091DD0FA1A} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Microsoft Office Helper | {814194F1-4148-3871-4118-2417A488A878} | X BHO | wycctd32.dll | Variant of the Trojan-Spy.Win32.Agent.ir trojan |
| Class | {BC964760-630B-7F96-DD49-A4589C07A991} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Internet Explorer Web Content Filter | {1B77D30A-81C9-497A-8647-142F7511B1FB} | ? BHO | WebAuthPlugin.dll | Unidentified browser plugin - should you have any information about this application, such as its homepage or the site where it was downloaded or installed, its exact purpose and whether you did or did not install it wittingly, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks! |
| Class | {B825595B-2058-BCA4-1A37-31A9B58CD033} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {4E44DB1D-63E6-5ADA-8425-0CCE4EB8858F} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| {1BDD55B8-3985-4E59-B906-5E0AD56D6710} | X BHO | WH*_*******.dll, (* =random char) | Browserplugin.com malware
|
| Class | {D4FD3E7F-134B-3265-8C6A-C70ABD1A2E09} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| COM+ Service | {3C49DDAC-3DA4-4743-AF6C-5974FEAF875C} | X BHO | winload.dll | Password stealer trojan, detected as Troj/BHO-CN |
| Class | {39003147-0564-FC80-401D-657710C0FEE1} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| XBTB09580 Class | {BBBE1C1A-89F7-4AF6-ABD1-F8FBCFA47408} | L BHO | wordreferenceEnFr.dll, WORDRE~1.DLL | WordReference toolbar |
| Class | {980DD9F9-2942-B1AC-EFBB-8485C26538D6} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {15AC61A5-E699-0150-B1AE-88BB5ADD5624} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| BHObj Class | {8F4E5661-F99E-4B3E-8D85-0EA71C0748E4} | X BHO | Wsem***.dll , (* = digit) | DyFuCa/Internet_Optimizer adware variant |
| Class | {22B1EC47-1EAB-B7A8-630D-99F8D36BEB48} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| (no name) | {29FA981B-341B-4726-8332-582732ED2DF3} | X BHO | wmp11exe.dll | Unidentified parasite of Chinese origin - should you have any information about this application, such as for example the site where it was downloaded or installed, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks!
|
| Class | {652D4929-5C76-94A9-0C3D-31460592C199} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Finder, Web Quick | {872ED12E-C4C2-42BB-833A-9B237F275CB3} | X BHO | WebQuick.dll | Troj/BHO-D spyware trojan |
| Class | {BCE7D6C6-91F7-121B-8DD6-E434352088D3} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {B6016FA4-6BEE-BC17-E07E-FBE10FBB1708} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {912319D7-D36D-DED4-B6ED-977C23402843} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {4E150563-A8F7-D1F4-1A3B-0B7AC88D30FC} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| (no name) | {11F0EE13-5947-2942-F631-09BEB2706006} | X BHO | wirvufc.dll | Variant of the DisableKey.A aka Busky downloader trojan |
| Class | {EE0622B9-E1DD-2901-FB4F-F5C1BFA6825D} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Windows Media Player | {C7E9503C-DA29-4183-8FA9-978C32852C20} | X BHO | wmpdxm.dll | Downloader trojan, member of the FakeAlert aka SmitFraud malware family - produces IEDefender or similar popups - also see here - NOTE: this file is located in the Windows or Winnt directory, and must NOT be confused with the legitimate Windows Media Player file of the same name, always located in %SysDir%! |
| Class | {FFABD30C-C2C9-7B56-2B56-9C121E648476} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {47EA1720-78C9-292F-1E61-12875D376490} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {38AF1BB4-5940-C5E2-435F-08770DE172AB} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |