CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

spacer spacer

The CLSID / BHO List / Toolbar Master List

Currently 54019 entries and growing...

This is the Master BHO and Toolbar list copyrighted by Tony Klein and CastleCops. For expert assistance, please post here. The information is collected across the Internet by the CastleCops Team. Usage: please leave feedback requesting permission if you are interested in using this data beyond the approved channels.

BHOList - ToolbarList

KEY:
  • "X" - Certified spyware/foistware, or other malware
  • "L" - Legitimate items
  • "O" - Open to debate
  • "?" - Unknown Status
  • "BHO" - Browser Helper Object
  • "TB" - Toolbar
  • "SH" - R3 URL SearchHook
  • "EB" - IE Explorer Bar

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z

    Random sampling...
    OBJECT NAMEGUIDSTATUSFILENAMEDESCRIPTION
    eBay Toolbar Helper{22D8E815-4A5E-4DFB-845E-AAB64207F5BD}L BHO eBayTB.dlleBay_Toolbar
    Exalead Toolbar{8F6D9079-D956-4D31-B7CC-CE6FA3044EE5}O TB ExaleadToolbar.dllExalead Toolbar
    ViewFolderSize Bar{66FBBF2F-A36F-434F-AAB9-590C0BE6EC53}L TB ExplorerBar.dll, vfs_bar.dllMoveax ViewFolderSize
    The egodktf{C83F2709-EB72-4FB8-ADC9-320BF14F3D45}X TB egodktf.dllParasite causing false spyware warnings and connecting to rogue "security sites" - member of the FakeAlert aka SmitFraud malware family
    The ensfolr{A037112F-183D-4E98-8CEA-1A0D93BA9F48}X TB ensfolr.dllParasite causing false spyware warnings and connecting to rogue "security sites", a member of the Trojan-Downloader.Zlob.Media-Codec malware family
    EPSON Web-To-Page{EE5D279F-081B-4404-994D-C6B60AAEBA6D}L TB EPSON Web-To-Page.dllEPSON Web-To-Page software
    ExtractorPlugin Class{E49C2526-26BF-499f-912F-B97B44814087}L BHO Extractor.dllAcmeta Fragmento
    ekvgsnw {292547EC-9C38-4398-B336-6219B91A1634}X TB ekvgsnw.dllParasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    Englishtown Toolbar{B7D3E479-CC68-42B5-A338-938ECE35F419}O TB ETownToolbar.dll Englishtown Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Some of the toolbars are fine to have, so every case is different. Your choice.
    knead a massage{FEDCB000-9ED3-4087-ABE3-9D9AC5EFE684}O TB etp.dll knead_a_massage toolbar - powered by Ask Jeeves Inc - see this_note
    The enqvwkp{FFB13247-794A-4E4F-8B97-937F906013D1}X TB enqvwkp.dllParasite causing false spyware warnings and connecting to rogue "security sites" - member of the FakeAlert aka SmitFraud malware family
    &EyeTideBar{987D027C-F0EF-40fa-9A1A-C45007F1F36F}O TB ETBar.dllEyeTide Viewer
    {CCE83E45-30B2-4BAE-B1F5-25D128D27A43}X TB Ezsearch.dll EZCyberSearch/EZSearch adware variant
    Europe Explorer{FBD22D62-A803-11d3-8F03-00105A9965CA}O EBe2bar.dllEuropeExplorer EasyClick pay-per-view software - also see here
    The emlkdvo {114B82D9-FBBF-4CED-8DDC-B42DCF85E18E}X TB emlkdvo.dllParasite connecting to rogue "security sites", member of the FakeAlert aka SmitFraud malware family
    ekvgsnw {E3DCF32C-D76E-494F-92FF-3CF77E5D3A2A}X TB ekvgsnw.dllParasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    XBTP03410{0976B5E5-5014-4e79-81A8-A11178B7F9A0}L BHO engine.dll CCTV toolbar
    XBTP03704 {1D6C60F6-F97C-4d48-B442-ED2441AA2A66}O BHO Ecompserv.dll, ECOMPS~1.DLLUnidentified Softomate Toolbar - should you have any information about this application, such as its homepage, its exact purpose and whether you did or did not install it wittingly, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks!
    The emlkdvo{9E1833D1-423D-4485-950E-0A417C2C15CA}X TB emlkdvo.dllParasite connecting to rogue "security sites", member of the FakeAlert aka SmitFraud malware family
    EkkoClientObj Class{3D5EB85C-D084-4449-BDEC-DB6EF6DAC21A}L BHO EC200031.dll, EC104088.dll, EC******.dllCodekko software
    ekvgsnw {7EB9F20D-11C7-4D4C-828A-A29F010BD259}X TB ekvgsnw.dllParasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    The egodktf{0720868F-9F83-48AB-B1C2-284674202F72}X TB egodktf.dllParasite causing false spyware warnings and connecting to rogue "security sites" - member of the FakeAlert aka SmitFraud malware family
    XBTB06814{E1C545DC-FB30-4df2-9EB6-DFBA2CC7D6D4}X BHO eztracks-toolbar.dll, EZTRAC~1.DLL EZ-Tracks adware variant
    The epxonwo{BFAA078B-58E2-4E6C-BD54-BA2A5C6DA153}X TB epxonwo.dllParasite causing false spyware warnings and connecting to rogue "security sites" - member of the FakeAlert aka SmitFraud malware family
    The enqvwkp{12A25CE9-0A93-4074-9516-A5B1A83141C9}X TB enqvwkp.dllParasite connecting to rogue "security sites", member of the FakeAlert aka SmitFraud malware family
    Ezcashmall Class{58881F3E-3B3B-4A7F-9413-B65E59B17060}X BHO ecashsave.dllParasite of Korean origin detected as Win32.Spyware.ecashsave
    etcetera BHO{1112954A-58B9-4677-8358-82287EF05414}L BHO etcetera.dll Etcetera
    emotigt{AA8B47FF-72C3-45C3-A7F1-8E86D1C65E67}X TB emotigt.dllParasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    CHelper Class{99A7C4DD-B2E6-4CA0-BB6E-737A61364155}L BHO e2003i.dll, e11.dll Eurotran translation software
    SMS-Bieten, Erinnerungsassistent{63983FD2-298E-40B0-A246-D32FD0C9CACD}L BHO eaiext.dllmediaBEAM eBay add-on
    ekvgsnw {474928DE-BC0F-4637-ADC1-C6DD2D1161D7}X TB ekvgsnw.dllParasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    ekxdvft {B3A57C90-D66D-42D7-AAC2-CBB2841008BD}X TB ekxdvft.dllParasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    EarthLink ScamBlocker V3{15F4D456-5BAA-4076-8486-EECB38CD3E57}L BHO EScamBlk.dll, ElnkScamBlocker.dll, ScamGrd.dllEarthLink ScamBlocker
    {001F2570-5DF5-11d3-B991-00A0C9BB0874}O BHO Ebayband.dllEbay Toolbar
    Search Explorer Toolbar{23DDAE8C-6A79-4d62-80AA-E95D89CB9811}X TB explbar.dll ExplBar adware
    emotigt {ACCD25A4-DF3F-47EC-9630-EB3A3142EEDD}X TB emotigt.dllParasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    UIECuve Class{610BCC4F-6076-4FEC-B7C1-D4B36D50D8CC}X BHO eyec.dllParasite of Korean origin hailing from eyecuve.co.kr and detected as Adware.Eyecuve - Installer detected by Kaspersky antivirus as Trojan-Downloader.Win32.Agent.gsg
    edfqvrw {BB1966D0-076C-49FD-A0DE-E142EAE25C57}X TB edfqvrw.dllParasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    etlrlws {55F54AD1-35AC-4206-A8D8-5E1BF61C7652}X TB etlrlws.dllParasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    XBTP06823 {5597E093-A959-420E-8555-14B2F3315397}O BHO ewossnewsbar.dll, EWOSSN~1.DLL eWoss_Newsbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Installer detected by Kaspersky antivirus as AdWare.Win32.Softomate.v
    emotrlq {7B1E78A2-2FC8-4947-A9D1-5177D10B38E6}X TB emotrlq.dllParasite causing false spyware warnings and connecting to rogue "security sites", a member of the Trojan-Downloader.Zlob.Media-Codec malware family
    {4E7BD74F-2B8D-469E-C0FB-FA62BD92B438}L TB engineer.dllEngineering.com Toolbar
    (no name){********-****-****-****-************}X SH EXE32EXE.dll WareOut malware component, using a random Class ID
    ShowBarObj Class{43AE45CB-DDA7-454B-9650-93A4C090BDB8}O BHO ETBar.dllEyeTide Viewer
    etlrlws{AD701758-30F6-4425-8F8A-C9E0CC16F59C}X TB etlrlws.dllParasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    Allakhazam EQ2 Toolbar{85D54D8C-452E-423E-A754-D32481741AB5}O TB eq2band.dll EQ2_Allakhazam_Toolbar - also see here
    (no name){BC261919-6129-4576-A38F-B5E91D5BC29D}X BHO ezuseraddr.dllParasite of Korean origin detected as Win-Adware/BHO.Ezusraddr
    enlfxgw {BB99C038-EEE6-44F9-9F70-821824438961}X TB enlfxgw.dllParasite causing false spyware warnings and connecting to rogue "security sites", member of the FakeAlert aka SmitFraud malware family
    formsPlayer Licensing{6E398F38-B49F-4EAF-80DE-AD5345F4DB42}L TB ExplorerBand.dllForms Player Soft-Bar
    enlfxgw{EAF43BEC-A979-470B-8EC0-9225C11CB213}X TB enlfxgw.dllParasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    The elfwgps{74415C3D-DB1D-40BF-9F91-1D1A31027A31}X TB elfwgps.dllParasite causing false spyware warnings and connecting to rogue "security sites" - member of the FakeAlert aka SmitFraud malware family
    etlrlws{CE98234D-64C9-42BE-80B9-5D9EC9E1E0A4}X TB etlrlws.dllParasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    etlrlws {475F2B10-9370-4B0D-9D5F-E52015328D22}X TB etlrlws.dllParasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    (no name){C7809CCE-71B1-4EAB-90FE-A0C09231B675}X BHO ExplorerAgent.dllTurck Software MultiBrowser Bar - the publisher's homepage now contains a javascript exploit
    (no name){704A5FF4-883C-CB14-1919-03A9CD93AEB9}X BHO eisrwym.dll Busky_AM downloader trojan

    spacer spacer