CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

spacer spacer

The CLSID / BHO List / Toolbar Master List

Currently 54019 entries and growing...

This is the Master BHO and Toolbar list copyrighted by Tony Klein and CastleCops. For expert assistance, please post here. The information is collected across the Internet by the CastleCops Team. Usage: please leave feedback requesting permission if you are interested in using this data beyond the approved channels.

BHOList - ToolbarList

KEY:
  • "X" - Certified spyware/foistware, or other malware
  • "L" - Legitimate items
  • "O" - Open to debate
  • "?" - Unknown Status
  • "BHO" - Browser Helper Object
  • "TB" - Toolbar
  • "SH" - R3 URL SearchHook
  • "EB" - IE Explorer Bar

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z

    Random sampling...
    OBJECT NAMEGUIDSTATUSFILENAMEDESCRIPTION
    qvdntlmw{0250B459-0F71-48F6-9784-CB7F2C338A0A}X TB qvdntlmw.dllParasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    H{70C872E5-69F5-456f-B809-484106881B7B}X BHO q24m.dll, re_.dllVariant of the Infostealer.Banker.D trojan
    BndBlock5 BHO Class{82EA1A55-9CBC-404b-9D0C-E8BFB7EAAE9B}X BHO QdrDrive10.dll"Hyperlinks Rotator" aka ISMonitor adware hailing from zredirector.com - installs a "Internet Speed Monitor" sidebar - file detected by Kaspersky antivirus as AdWare.Win32.Agent.ay
    DVA First{559A0463-48BF-433C-AC59-289E222FB77A}X BHO qvlbodmnfxv.dllAdware downloader causing false spyware warnings and connecting to rogue "security sites", a member of the Trojan-Downloader.Zlob.Media-Codec aka NewMediaCodec malware family
    {CF021F40-3E14-23A5-CBA2-717177650486}X BHO QWE0486.dllMakeMeSearch aka Tubby/Arau adware variant
    qndsfmao{267E332F-1684-4B6F-813E-186EEEE7F247}X TB qndsfmao.dllParasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    QQCycloneHelper Class{00000000-12B5-4305-82F9-43058F20E8D2}X BHO QQIEHelper01.dll, QQIEHelper02.dll TencentAddressBar adware - bundled with the Tencent_QQ instant messaging client
    qndsfmao{FCCD9F7B-5BF3-4DC4-B131-CE069F8A62AB}X TB qndsfmao.dllParasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    QQCycloneHelper{4E8A5277-C04E-4FE3-BF78-8A7CCD6EF333}X BHO QQIEHelper01.dll, QQIEHelper02.dll TencentAddressBar adware - bundled with the Tencent_QQ instant messaging client
    qtvglped {90972666-0EC6-40EC-8405-EE06D866CCD8}X TB qtvglped.dllParasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    qndsfmao{2D707802-C57D-42DC-84BA-ADEAAECEF77B}X TB qndsfmao.dllParasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    MSVPS System{C87D64B5-DF92-4703-90CB-B465B6982941}X BHO qnxplugin.dll MyGeek/Cpvfeed.com adware variant, detected by Kaspersky antivirus as AdWare.Win32.Agent.bn - logs search engine queries to a %Windir%\search_res.txt file. Also see here
    QQCycloneHelper Class{00C104F6-0F5C-470C-ABCF-A5B2E70752F1}X BHO QQIEHelper01.dll, QQIEHelper02.dllTencentAddressBar, TencentAddressBar adware - bundled with the Tencent_QQ instant messaging client
    QAPHlprObj Class{297CAF50-E4F7-11D1-A380-00600896ECCC}L BHO QAPHLPR.DLLSegue
    qvdntlmw {8BD58549-BB16-480E-8530-3F957AE09B51}X TB qvdntlmw.dllParasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    IEHlprObj Class{AA9742E6-AB51-48a8-831C-C1EB757C3E61}X BHO qyliehelper.dllAdware detected as Adware.Win32.Qyule
    QuickGrid Toolbar{7F1395EB-AEC2-4F0B-8B43-8F77D1C4D50C}O TB quickgrid.dll, QUICKG~1.DLLQuickGrid Toolbar, see here - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Remove unless you both trust it and expressly meant to install it.
    qndsfmao{3BB35E2E-9AE6-4FDE-A691-9E5BDBD93044}X TB qndsfmao.dllParasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    DVA First{235F29EF-99F0-47D9-B21D-6A18A1AC3777}X BHO qvlbodmnwrk.dllAdware downloader causing false spyware warnings and connecting to rogue "security sites", a member of the Trojan-Downloader.Zlob.Media-Codec aka NewMediaCodec malware family
    Qantas Toolbar{252E8A9B-56BD-4FC4-B5C2-2A2A1F0975B0}L TB qtoolbar.dllQantas toolbar
    QQCycloneHelper{00000000-12AF-4305-82F9-43058F20E8D2}X BHO QQIEHelper01.dll, QQIEHelper02.dll TencentAddressBar adware - bundled with the Tencent_QQ instant messaging client
    Cls {CF021F40-3E14-23A5-CBA2-717177658274}X BHO qwe8274.dllMakeMeSearch aka Tubby/Arau adware variant - also see here
    Quepasa 2.0{4E7BD74F-2B8D-469E-A0FF-EC6DA490AF2C}O TB quepasa2.dll Quepasa_Toolbar - also see here
    BndVeano4 BHO Class {8E4881AC-49E2-4761-9542-7E40C73CFB96}X BHO QdrDrive9.dll "Hyperlinks Rotator" aka ISMonitor adware hailing from zredirector.com - installs a "Internet Speed Monitor" sidebar - file detected by Kaspersky antivirus as a variant of AdWare.Win32.AdBand - also see here
    àÇéÓÖÀ, Qyule toolbar{9F3D9E36-66A4-48D2-AE43-5A13FECF4DB7}X TB qylurl.dll, lingyu.dll Qyule adware variant - also see here
    QQCycloneHelper Class{00000000-12C8-4305-82F9-43058F20E8D2}X BHO QQIEHelper01.dll, QQIEHelper02.dll TencentAddressBar adware - bundled with the Tencent_QQ instant messaging client
    qvdntlmw{6D77BB31-31C7-4900-9385-85CF45035131}X TB qvdntlmw.dllParasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    Internet Speed Monitor{1FE2EBE5-42FF-4586-A144-CA420C84FF6A}X EBQdrDrive9.dll"Hyperlinks Rotator" aka ISMonitor adware hailing from zredirector.com - installs a "Internet Speed Monitor" sidebar - detected by Kaspersky antivirus as AdWare.Win32.AdBand.a
    DVA Storm{EA3D41AC-9334-48AD-B582-19F2ADEB5C6A}X BHO qnmargolqgp.dllAdware downloader causing false spyware warnings and connecting to rogue "security sites", a member of the Trojan-Downloader.Zlob.Media-Codec aka NewMediaCodec malware family
    Cls{CF021F40-3E14-23A5-CBA2-717177656032}X BHO qwe6032.dllMakeMeSearch aka Tubby/Arau adware variant
    QQCycloneHelper Class{24F0654F-65E3-4D1C-8CFE-839C296B5530}X BHO QQIEHelper01.dll, QQIEHelper02.dll TencentAddressBar adware - bundled with the Tencent_QQ instant messaging client
    (no name){28A0F341-2711-82C5-F8DF-032A36D42E96}X BHO qgfalzg.dllVariant of the DisableKey.A aka Busky downloader trojan
    QQCycloneHelper{00000000-0000-0000-0000-E58E57C9C847}X BHO QQIEHelper01.dll, QQIEHelper02.dll TencentAddressBar adware - bundled with the Tencent_QQ instant messaging client
    DVA Gate {D1DE7404-BFDF-430B-AB48-3EBF39F05C9F}X BHO qnmargolwdn.dllAdware downloader causing false spyware warnings and connecting to rogue "security sites", a member of the Trojan-Downloader.Zlob.Media-Codec aka NewMediaCodec malware family
    QQCycloneHelper Class{01443AD3-0FD1-40FD-9C87-E93D1494C233}X BHO QQIEHelper01.dll, QQIEHelper02.dll TencentAddressBar adware - bundled with the Tencent_QQ instant messaging client
    Internet Speed Monitor{180175C0-913E-451c-9419-2D5500368D43}X EBQdrDrive20.dll"Hyperlinks Rotator" aka ISMonitor adware - installs a "Internet Speed Monitor" sidebar - detected by Kaspersky antivirus as AdWare.Win32.AdBand.a
    StFlex IE Helper{8334A30C-49E5-489a-B63D-5B927C1EF46E}X BHO QdrDrive15.dll"Hyperlinks Rotator" aka ISMonitor adware hailing from zredirector.com - installs a "Internet Speed Monitor" sidebar - detected by Kaspersky antivirus as AdWare.Win32.AdBand.a
    qvdntlmw{581D3CD5-E6DD-48AA-A993-5FD9F73F7831}X TB qvdntlmw.dllParasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    QQCycloneHelper Class{00000000-12C7-4305-82F9-43058F20E8D2}X BHO QQIEHelper01.dll, QQIEHelper02.dll TencentAddressBar adware - bundled with the Tencent_QQ instant messaging client
    DVA Storm{EFA665C4-6D72-4B8B-8286-045E879FCAE8}X BHO qnmargolktr.dllAdware downloader causing false spyware warnings and connecting to rogue "security sites", a member of the Trojan-Downloader.Zlob.Media-Codec aka NewMediaCodec malware family
    {337D0C1D-4053-4FAB-AF2B-45C2F7B0FAA7}X TB Quicklaunchie.dll, Broweraidtoolbar.dll, bptlb.dll BrowserAid adware variant
    QQCycloneHelper{00000000-1285-4305-82F9-43058F20E8D2}X BHO QQIEHelper01.dll, QQIEHelper02.dll TencentAddressBar adware - bundled with the Tencent_QQ instant messaging client
    QQCycloneHelper{089FD14C-132B-48FC-8861-0048AE113215}X BHO QQIEHelper01.dll, QQIEHelper02.dll TencentAddressBar adware - bundled with the Tencent_QQ instant messaging client
    QQCycloneHelper Class{7605CC7B-00FD-4A5F-BAFD-828342DE6279}X BHO QQIEHelper01.dll, QQIEHelper02.dll TencentAddressBar adware - bundled with the Tencent_QQ instant messaging client
    QQCycloneHelper Class{54EBD539-9BC1-480B-966A-843A333CA162}X BHO QQIEHelper01.dll, QQIEHelper02.dll TencentAddressBar adware - bundled with the Tencent_QQ instant messaging client
    DVA First{D23BF150-4C7B-4632-A723-DC604C2A47FB}O BHO qvlbodmnbew.dllAdware downloader causing false spyware warnings and connecting to rogue "security sites", a member of the Trojan-Downloader.Zlob.Media-Codec aka NewMediaCodec malware family
    QQCycloneHelper{0005A87C-D626-4B3A-84F9-1D9571695F55}X BHO QQIEHelper01.dll, QQIEHelper02.dll TencentAddressBar adware - bundled with the Tencent_QQ instant messaging client
    QQCycloneHelper Class{6D53EC83-6AAE-4787-AEEE-F4628F01010C}X BHO QQIEHelper01.dll, QQIEHelper02.dll TencentAddressBar adware - bundled with the Tencent_QQ instant messaging client
    H{488DB4F4-9B4A-49ef-A25D-9F84BDB07B27}X BHO q24m.dllVariant of the Infostealer.Banker.D trojan
    DVA Storm{0CE19AE8-6932-4B0F-82D3-FC5073160293}X BHO qnmargolwog.dllAdware downloader causing false spyware warnings and connecting to rogue "security sites", a member of the Trojan-Downloader.Zlob.Media-Codec aka NewMediaCodec malware family
    Qbox Player{50CB1324-0E85-4124-B88A-FB38E7E6803A}O TB qboxtb.dllPart of Qbox_Media_Player software
    qndsfmao{264BFEF2-1935-497C-9FD4-6EEF1FAA2764}X TB qndsfmao.dllParasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    BndAero6 IE Helper{82E5E2FF-9260-4d88-B0C6-7CC358C5D418}X BHO QdrDrive11.dll"Hyperlinks Rotator" aka ISMonitor adware hailing from zredirector.com - installs a "Internet Speed Monitor" sidebar - detected by Kaspersky antivirus as AdWare.Win32.AdBand.a
    QQCycloneHelper{18093455-9012-4568-9076-908765467181}X BHO QQIEHelper01.dll, QQIEHelper02.dll TencentAddressBar adware - bundled with the Tencent_QQ instant messaging client
    QQCycloneHelper{00000000-12AD-4305-82F9-43058F20E8D2}X BHO QQIEHelper**.dll TencentAddressBar adware - bundled with the Tencent_QQ instant messaging client

    spacer spacer