| OBJECT NAME | GUID | STATUS | FILENAME | DESCRIPTION |
|---|
| Orange | {4E7BD74F-2B8D-469E-A0FB-F862B587B57D} | L BHO TB | orange2.dll | Orange toolbar - see here or here |
| OffSurf Proxy | {A6790AA5-1213-4BCF-A46D-0FDAC4EA90EB} | L TB | OffSurf.dll | OffSurf - Firewall Bypass and Site Unblocker |
| (no name) | {********-****-****-****-************} | X BHO | odexl32d.dll | WebPrefix adware variant |
| XBTB08158 | {12C94DE4-5CE2-4a2d-A493-2C8D5B00AB18} | O BHO | onlinearabic_toolbar_turkce.dll, ONLINE~1.DLL | Www.onlinearabic.net_Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. |
| MSVPS System, HTGTUP System | {6C7A1C43-D86E-49D4-A66E-8EF0DCFCBB71} | X BHO | oprevmqp.dll | Zlob downloader variant, a member of the SmitFraud malware family |
| psnr | {F7C6FC64-80B1-47E2-9A5C-C67051BBDD70} | X BHO | OCRQCJM4.dll, 8INX7NES.dll | Downloader and browser hijacker, a variant of Troj/Mdrop-AHY |
| ozfydbyt.dll | {4A069845-2036-6084-9054-6087502480A4} | X BHO | ozfydbyt.dll | Password stealer of Chinese origin detected by Trend Micro as TSPY_ONLINEG.FOK
|
| Player | {BA2020CE-AF34-4B1A-82D4-507C7F002079} | X BHO | orgnavi.dll | Downloader trojan causing false spyware warnings and connecting to fake "security sites", member of the FakeAlert aka SmitFraud malware family |
| XBTP06129 | {5CF2592E-ADCA-4091-97B5-304564C14A64} | O BHO | opplysningen1881_ie.dll, OPPLYS~1.DLL | Opplysningen_1881 toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. |
| Oyunhileleri.com Toolbar | {8D2CD624-3650-4B4C-AF69-68B29FE445C2} | O TB | oyunhileleri.com.dll, OYUNHI~1.DLL | Oyunhileleri.com Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Remove unless you both trust it and expressly meant to install it. |
| oswxdttb.dll | {43512378-9874-5641-1025-985420368734} | X BHO | oswxdttb.dll | Password stealer of Chinese origin detected by Trend Micro as TSPY_ONLINEG.FOK |
| (no name) | {28B68635-4AFB-1629-8DF2-6754127DB19D} | X SH | OinBHO.dll | ClickSpring.Oinadserver adware component, responsable for Outerinfo.com popups |
| FavoriteMan Class | {139D88E5-C372-469D-B4C5-1FE00852AB9B} | X BHO | ofrg.dll, favorite.dll | FavoriteMan adware variant |
| OKTE BHO | {DE18BCD3-DA99-4927-B87B-653D62AB9A95} | ? BHO | OKTIET~1.DLL, oktieToolbar.dll | OkteSchHook/Oktie.Toolbar software from axdisk.cn - Unidentified browser plugin - should you have any information about this application, such as its exact purpose and whether you did or did not install it wittingly, do email us. Thanks! |
| Outliner IE Toolbar | {681A6C0B-A772-4F63-BBB9-5B434DE1F9B2} | L TB | OutlinerBar.dll | Outliner IE Toolbar |
| ieefanhelper Object | {F20C798F-04D0-44de-A59B-B34588DE9A94} | L BHO | olhieplg.dll | OnLetterhead |
| onlinepixel24 Toolbar | {81CFC095-AC7A-4B6C-9EBF-9B353A7A7EE2} | X TB | onlinepixel24.dll, ONLINE~1.DLL | Onlinepixel24 Toolbar, reportedly stealth installed! A Softomate Toolbar variant |
| OpenSite.CBrowserHelper | {30A56549-9D5B-4D34-AFA7-440A7F0538A9} | X BHO | Opnste.dll | Adware.OpenSite |
| oohxebyt.dll | {6B1AEF69-DDAE-FDAD-DCAB-698F026ABDB6} | X BHO | oohxebyt.dll | Password stealer trojan of Chinese origin detected as Trojan-PWS.OnlineGames.ADRD
|
| NLogSink Class | {B3F79291-2D04-4c82-8F23-E126F239EACA} | X BHO | orca0.dll, roca0.dll, moon0.dll | Variant of the TROJ_AGENT.XTN trojan |
| (no name) | {********-****-****-****-************} | X BHO | olf2disp.dll | WebPrefix adware variant |
| XBTP00560 | {F0F1FCAA-CFBC-4f8a-8A21-FFC9AF03F16B} | X BHO | onlinepixel24.dll, ONLINE~1.DLL | Onlinepixel24 Toolbar, reportedly stealth installed! A Softomate Toolbar variant |
| OnLetterhead Toolbar | {C66BE3BA-0A75-4db1-A988-ACE7087CA121} | L TB | olhieplg.dll | OnLetterhead |
| Orange | {4E7BD74F-2B8D-469E-A1FB-F862B587B57D} | L BHO TB | orange3.dll, orange31.dll | Orange toolbar - see here or here |
| MSVPS System | {2D42D689-4B94-4734-92C2-606FC5F4C15D} | X BHO | oprevtdp.dll | Zlob downloader variant, a member of the SmitFraud malware family |
| &Okapiland | {6b532243-2d02-48b3-95d7-cac66acbebc3} | L TB | okapibar.dll | IE_Okapiland_Search Toolbar - also see here |
| Player | {E5AF0624-F539-47D9-BA37-D8B339E858F4} | X BHO | orgnavi.dll | Downloader trojan causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family |
| Internet Explorer OneGuide | {61995404-D92F-4A03-9F98-BCCB368E3DAA} | X BHO | oneguide.dll | "Internet Explorer OneGuide" web search software of Korean origin hailing from Oneguide.co.kr - detected as Win32.Spyware.OneGuide |
| VPN-OEM Extension | {11D003B5-B3B5-4BCC-A974-71148786E968} | O BHO | olescn16.dll, nvrcr16.dll, msuieng.dll, msexchdr.dll | SpectorSoft computer monitoring software |
| Player | {22347AEE-A37A-45D3-8804-FDC7F9289CE1} | X BHO | orgnavi.dll | Downloader trojan causing false spyware warnings and connecting to fake "security sites", member of the FakeAlert aka SmitFraud malware family |
| ShowBar Class | {3EBB6ECC-75A9-40F7-8A12-0845F0D4B98B} | L BHO | OutlinerBar.dll | Outliner IE Toolbar |
| Player | {B5307BCB-64A5-4416-9BC2-5AF01DB90123} | X BHO | orgnavi.dll | Downloader trojan causing false spyware warnings and connecting to fake "security sites", member of the FakeAlert aka SmitFraud malware family |
| optcalApp Class | {B37AB40A-FB66-46AA-9AC1-8D21B51E7CFC} | X BHO | optcal.dll | Adware of Korean origin hailing from empas.com, detected by Kaspersky antivirus as Trojan.Win32.BHO.qu |
| OGG Viewer | {82FE0677-75EC-49BF-83E9-A815F68F6212} | X BHO | oggview.dll | Downloader trojan, member of the FakeAlert aka SmitFraud malware family - produces IEDefender popups - also see here |
| OnMuz2BHO | {012246F2-A06C-4039-8C4E-24A14D702D8B} | X BHO | ombho.dll | "Internet Explorer Guide" web search software of Korean origin hailing from Ieguide.kr, detected as "IEGuide" adware, also see here |
| osk | {830D4A9B-19CE-44E5-8A53-0C81B91A902C} | X BHO | osk.dll | Password stealer, detected by Kaspersky antivirus as Trojan.Win32.Agent.ecf |
| (no name) | {55C2F147-498D-1058-8DF9-10541D7BB1E0} | X SH | OinBHO.dll | ClickSpring.Oinadserver adware component, responsible for Outerinfo.com popups
|
| MSVPS System | {1658DABA-FC4C-46C6-BC48-246CFEA0C436} | X BHO | oprevgkx.dll | Zlob downloader variant, a member of the SmitFraud malware family |
| OK ?? | {73182355-ED2B-4064-A45F-49227EA0EE74} | X BHO TB | OkToolbar.dll | Parasite of Korean origin identified as OkToolbar adware |
| TBSB01662 | {C85390F6-8A64-496C-9405-BFB673744B82} | O BHO | oyna55.dll | Oyna55.com Toolbar - - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Your choice.
|
| Authorworks Main | {88651B85-70A6-42D7-96F5-08C9922D67BB} | L TB | ObjectsToolbar.dll | NetMediaOne AuthorWorks Editor |
| olado Toolbar von Ashampoo | {1CBF31FC-3C23-4BA6-AF16-2CEC501BD837} | O TB SH | olado.dll | Ashampoo/Olado Shopping toolbar |
| SSV | {69F6C0AE-0C78-4999-B6D1-62932A265C5D} | X BHO | onenasek.dll, unopek.dll, ssvanasus.dll, onepad.dll, other semi-random filenames composed of the following fragments: one, ssva, uno, nas, p, k, ek, ad, us | Parasite redirecting to fake security sites, member of the FakeAlert aka SmitFraud malware family - produces IEDefender , FilesSecure , MalwareBell , IE_Antivirus or similar popups - also see here |
| (no name) | {********-****-****-****-************} | X BHO | ole232.dll | Win32.Stud aka WebPrefix adware variant |
| okcashbackmall bar | {EEEF3CF7-4A59-4157-B6C8-E80C25ACBE5F} | X EB | okcashbackmallsb.dll | Parasite of Korean origin detected as Adware.Okcashbackmall |
| OfficePDFplus Toolbar | {E198984B-9CC9-4f5f-9E97-32E69CE42A9C} | L TB | OPPBar.dll | OfficePDFplus |
| MEobjectSDT | {D4D5C535-BA95-4327-870D-A33826FDD17A} | X BHO | obwbkya.dll, gogobm.dll, sdxbeia.dll, shwasobj.dll, smgykeb.dll | SDAgent aka SmartDove adware |
| okcashback system | {C3C7C84F-2E47-47E7-A596-6919C30662FE} | X BHO | okcashbackmallr.dll, OKCASH~1.DLL | Parasite of Korean origin hailing from okcashbackmall.com and identified as Adware.OKcashBackMall |
| OpenChina | {F7724DED-36CC-11D6-B88F-00C0261016CF} | ? TB | OPENCH~1.DLL, openchina.dll | Unidentified Toolbar - should you have any information about this application, such as its exact purpose and whether you did or did not install it wittingly, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks! |
| Yvakt Class | {BA3DDC15-3EF1-4DC7-B9B6-ED0403F9422A} | X BHO | OUGHYA~1.DLL | QuickLinks/LinkMaker adware variant - also detected as Adware.Suggestor |
| TBSB06358 | {977BBB7A-DD26-4E47-A4C3-3242272C98FE} | O BHO | ormedunyasi.dll | Orme_Dunyasi Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Your choice. |
| SVC plugin | {64C94B46-1079-4C75-BE9B-380F6AE7624C} | X BHO | oddops.dll, apunbegy.dll, oddogy.dll, apsagy.dll, other semi-random filenames made up from the following fragments: ap, od, ik, na, do, unbe, gy, ps, xu | Parasite redirecting to fake security sites, member of the FakeAlert aka SmitFraud malware family - produces IEDefender , FilesSecure , MalwareBell , IE_Antivirus or similar popups - also see here
|
| player addon | {6A219F2A-3ECA-4258-9A8A-FD7312EB7391} | X BHO | oggview32.dll | Downloader trojan, member of the FakeAlert aka SmitFraud malware family - produces IEDefender or similar popups - also see here |
| OGG Viewer | {90F39E5A-1C6C-4597-8B59-9AED38E88387} | X BHO | oggview.dll | Downloader trojan, member of the FakeAlert aka SmitFraud malware family - produces IEDefender popups - also see here |
| CPopupControl Object | {4B764F4A-BC63-4CE4-AF5E-B24F76DA5B22} | L BHO | oqoieplugin.dll | Browser Plugin for OQO_docking_station |