| OBJECT NAME | GUID | STATUS | FILENAME | DESCRIPTION |
|---|
| Class | {BE0B92E6-FE88-CE97-83A2-80F270CDA5CF} | X BHO | D3**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {58EDEE37-3961-A0F9-A428-713B6BA5B6BC} | X BHO | D3**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| detxeiua.dll | {50618412-C528-C784-C056-C164D1F7C505} | X BHO | detxeiua.dll | Password stealer trojan of Chinese origin, a variant of Infostealer.Gampass
|
| DeskbarBHO | {C6BC3414-BF19-4DFD-BAB5-70C5C395E9B4} | X BHO SH | deskbar.dll | DeskBar adware variant - also see here - NOTE: do not confuse with the legitimate DeskBar software, which does NOT install a BHO! |
| Class | {5DBD25EB-EA8A-07D7-E366-2146A2ECD99B} | X BHO | D3**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {4B32A432-7AED-32E2-A1C8-FB0690AC63E5} | X BHO | D3**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| RDL Rolex | {152C7E80-204C-4CE9-A7D6-289D558D4B57} | X BHO | drnpfdxknx.dll | Adware downloader causing false spyware warnings and connecting to rogue "security sites", a member of the Trojan-Downloader.Zlob.Media-Codec aka NewMediaCodec malware family |
| Class | {5D033C2B-BD84-D7B8-DACB-6FCC38044C66} | X BHO | D3**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| XBTB05596 | {981254B1-A193-4A2A-A1CC-839F0159C92B} | O BHO | directoriesfrIE.dll | Directories_Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. |
| Class | {65691213-DA99-32B2-8A8C-8E844757F263} | X BHO | D3**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {837083AF-B511-DCC4-05AB-DB06515B52E4} | X BHO | D3**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {90A013EF-29FC-F988-6018-F201E961F75E} | X BHO | D3**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {6CB920B6-4A64-6E07-07F3-02819E653897} | X BHO | D3**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {4BBEC0FD-DA38-B544-F1BF-7C2CC424B596} | X BHO | D3**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {2D4DA982-94D2-D05C-3D8D-91173119D9B6} | X BHO | D3**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| {2D556983-83D7-4630-9AA5-27C74CA27B79} | X BHO | Drbr.dll | i-Lookup adware variant |
| Class | {655E410A-DEC2-F00A-61F5-F4B2C0F1BA9B} | X BHO | D3**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {2EDD9108-F5D8-936A-8F9A-116CB847DCC0} | X BHO | D3**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {28A44E47-1962-F448-78C6-1A2589E5B9B5} | X BHO | D3**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| KillObj Class | {66C28884-4E5D-494B-80C9-CAA27528FD6D} | ? BHO | ddtkillw.ocx | Browser plugin from Sina.com.cn - possibly RSS reader or chat software related - should you have any further information about this application, do email us. Thanks!
|
| Class | {61C65389-9A99-E0F0-7E64-C35B49DA6455} | X BHO | d3**32.dll (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {AC7E3BCE-14CE-7C2A-E29B-412270AA8258} | X BHO | D3**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {9A8FA81A-5DB1-391E-A47A-E2064E5B330E} | X BHO | D3**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| DeskbarBHO | {FC518CE0-F6B0-45b0-B6D9-9E6293CEC105} | X BHO | deskbar.dll | DeskBar adware variant - also see here - NOTE: the file must NOT be confused with the legitimate DeskBar software, which does NOT install a BHO!
|
| Class | {AA0A9B7C-1E92-535C-0904-539590028603} | X BHO | D3**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {D4B37658-9FC7-CBCE-2648-EADA0B911772} | X BHO | D3**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Duk.cn | {188FC5D2-2577-4F4D-992D-8FEF34C7B43E} | L BHO | DukSpaceHelp.dll | Webdoker - Chinese Magazine downloader and reader |
| DoctorXP Toolbar | {EDA0A591-0696-477E-896B-A14491FB75B4} | O TB | DoctorXP_Toolbar.dll | DoctorXP Toolbar |
| Class | {0E367930-654D-7C53-BF90-51083EB7625C} | X BHO | D3**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| RDS.Dataspace | {875AC22C-372A-4BCF-9964-101074CCC393} | ? BHO | dhcsvc32.dll | Unidentified browser plugin - should you have any information about this application, such as its homepage or the site where it was downloaded or installed, its exact purpose and whether you did or did not install it wittingly, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks! |
| SXG Advisor | {7603FD22-36C0-4DE7-A28F-ADFA9CE3ACB8} | X BHO | dpvtporxno.dll | Adware downloader causing false spyware warnings, a member of the Trojan-Downloader.Zlob.Media-Codec aka NewMediaCodec malware family |
| Class | {A45618F3-F6BE-0909-6EB6-763DD408A2FD} | X BHO | D3**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| dpevflbg | {60174039-2A3E-490F-B5CA-3CFBB6703F35} | X TB | dpevflbg.dll | Parasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family |
| Class | {27E1325A-4288-1A73-79FB-785DCF6C8EAB} | X BHO | D3**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {93235C1A-4087-6BFB-2FBA-24A41BE46E88} | X BHO | D3**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {7F1738DF-16B2-2588-2CDC-480A65E50CC6} | X BHO | D3**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {F8303BFB-E09E-BCDD-FA8F-E8D3C07DA44E} | X BHO | D3**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| max Class | {BD49A3ED-9645-4F06-AC3B-09231CAD748C} | X BHO | dlsts.dll | Parasite of Korean origin detected as Adware.Upmachines |
| Class | {1D35FEE6-4A46-0EEF-09E4-41ED063F55D0} | X BHO | D3**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {9DB0FB34-86EE-9B55-7FA5-3F3C3C3744BF} | X BHO | D3**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {85201BB6-388D-DCC6-C89B-AA43E4FA80F7} | X BHO | D3**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| &Delphi-PRAXiS Suche | {8A4291C3-6C3A-4EFD-8885-F454DEC0721A} | L TB | DPDeskBand.dll | Delphi-PRAXiS DeskBar |
| Class | {B07D856C-91C1-5E64-38D1-C2FB088F1802} | X BHO | D3**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {ABA7F993-DA7E-7B57-A8D0-A14855CCD81E} | X BHO | D3**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {E3AEAC49-3143-318F-BE0C-F3ADBF1F53EA} | X BHO | D3**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {0E13927A-A542-8D30-D846-7E08B0344793} | X BHO | D3**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {22A99D53-6CB9-33A5-DED6-D04F5F0F1AE8} | X BHO | D3**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {630CE911-1C5F-5B88-32CC-C5938E8B0AC0} | X BHO | D3**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {FAA3A3EA-E842-9714-3713-2160648F21EE} | X BHO | D3**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {B8460335-3BB1-0C22-657E-91A1AF013E8D} | X BHO | D3**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {ABEFC8A2-1733-F386-48F3-B861F6CBA8BC} | X BHO | D3**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {11CA0DB0-AEB2-18AF-A270-52A6A4851766} | X BHO | D3**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {90920AC0-CE70-911A-27A7-D53EDA3B6DED} | X BHO | D3**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {28794D46-D75B-7CDB-21C3-65E69FD4B409} | X BHO | D3**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| PPVADownloader | {A986E409-30CC-4185-89BB-AB212C104524} | L BHO | DownloaderManager.dll | PPLive accelerator |