| OBJECT NAME | GUID | STATUS | FILENAME | DESCRIPTION |
|---|
| Starwood Toolbar | {CAC335E0-9FFB-4a59-A3F5-03B7713E937B} | L BHO TB | starwood.dll | Starwood Toolbar |
| {4FC00340-F75E-4EB5-880C-651A8A76965F} | L TB | SpokeToolBand.dll | Spoke Client software |
| Class | {6EE432C7-C0DC-9466-C802-2A708A166BCB} | X BHO | SYS**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {FEC8F3C3-A995-69E4-772B-B4D822AC38E8} | X BHO | SYS**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {10C089B7-77FD-C65D-35F0-BFA1479FFB41} | X BHO | SYS**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| ç»íÄó¶³Ä¬½ | {A8E64858-0D1D-4E0C-9C53-6F8C9EB1E893} | X TB | sakuracash.dll, SAKURA~1.DLL | Parasite of Korean origin hailing from sakuracash.co.kr and detected as Adware.Sakuracash |
| BA Toolbar | {952EC978-4920-4F18-8237-91D69B54C580} | X TB | sidebar.dll | BrowserAngel/SearchLocate toolbar - also see here |
| Class | {0092CB9E-A898-102E-13F0-85FC8AF2AD31} | X BHO | SYS**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {7621039D-911B-1A3D-343B-0F72B58EF21C} | X BHO | SYS**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {83EB6065-85E2-7595-DFD5-A093986B0410} | X BHO | SDK**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {54850D9F-AEBA-9087-428F-9ABB367027A1} | X BHO | SYS**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Skabble | {52979D61-D695-40CB-A346-C27CAE95CE42} | ? BHO | SCP4IE.dll | Unidentified browser plugin, file present in a Skabble\plugins - should you have any information about this application, such as its exact purpose and whether you did or did not install it wittingly, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks! |
| Sauce_Reader | {58F47E1A-D272-43BA-9BFE-162BC7F732E3} | L TB | SAUCER~1.DLL, SAUCER~2.DLL | Sauce_Reader - RSS feed reader |
| Class | {F0E44A95-C75A-FBD2-EDFA-0D6EDD539C09} | X BHO | SYS**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| IEHlprObj Class | {CE7C3CF0-4B15-11D1-ABED-709549C10000} | X BHO | sool0.dll, sool1.dll, ulso0.dll | Password stealer trojan, detected as Spyware.Vaklik.Do |
| Class | {3152E410-3368-7E44-2FCD-F5704D0FF9BE} | X BHO | SDK**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| GNX Bingo | {46E48593-8967-498C-8ED6-1064BAA584C2} | X BHO | svpekgonnof.dll | Adware downloader causing false spyware warnings and connecting to rogue "security sites", a member of the Trojan-Downloader.Zlob.Media-Codec aka NewMediaCodec malware family |
| Class | {127D9B94-C5DF-086E-9619-9881B830AE0C} | X BHO | SYS**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {A0DC9260-9177-5BA6-6C2A-92CC2CEBB91F} | X BHO | SYS**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {24C57E96-1520-C344-184A-B7C38F985690} | X BHO | SDK**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {3DCC181A-7DEF-24B0-6C35-70B9122CAEAB} | X BHO | SYS**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {0EFD4CCD-6801-830D-30AC-AB7C39B55B23} | X BHO | SYS**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {7FF512FD-EDD0-63AD-962B-A707A8CA4759} | X BHO | SYS**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {350C4851-32FB-4B62-4293-D6EB5125C66A} | X BHO | SYS**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| CBHO Object | {02681612-869A-4a07-9D7D-984F42217890} | L BHO | SRBHO.dll | StealthRay |
| XBTB01208 | {1AFE5D5A-4EC5-439d-AB7B-2A1D59669F86} | L BHO | scoresandodds.com.dll, SCORES~*.DLL | ScoresAndOdds.com Toolbar |
| My bookmarks Memotoo.com | {3BE658AE-55FE-4973-9593-051BBE4F2F77} | L EB | shdocvw.dll (MS file!) | Memotoo.com |
| Codec pack | {C44Ad542-3B2E-ab42-32ba-a11651A36980} | X BHO | sys_vd4.dat | Downloader and hijacker connecting to rogue sites (2--google.com, hipointltd.com, kandidatov.net and others) - identified by F-Secure antivirus as Trojan.Win32.Small.tz |
| SVIEBHO Class | {B3C54716-9D0A-4666-A81A-6072A6325A5A} | L BHO | svie.dll | SelectView ad filter |
| Search | {669695BC-A811-4A9D-8CDF-BA8C795F261C} | X TB | search.dll, cfg32s.dll | BookedSpace adware variant |
| Class | {479F8FB5-5D03-CE7E-6322-3BE0849F0645} | X BHO | SDK**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {ADF83008-D033-75CF-F558-8F5FD25A0CAC} | X BHO | SYS**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {C8BD785F-EB60-D323-EF30-B49C0D77C3C9} | X BHO | SYS**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {FF455AC6-FB2E-6A66-8E0D-2CA0A8C97D68} | X BHO | SYS**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {07DC8A2E-2890-3A08-D5A4-3F38743174E0} | X BHO | SYS**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {17FC710D-C0F3-9F8F-B630-C6A396F77B7E} | X BHO | SYS**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| sqvgnrpx | {FEE28DB7-CAA1-45D7-85BC-C9D7E8009E07} | X TB | sqvgnrpx.dll | Parasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
|
| Class | {8C70E5C4-7966-C457-B59B-A255A3E7EFBC} | X BHO | SYS**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {A1830146-396F-4059-5F0F-46BCBAD4B2DB} | X BHO | SYS**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {3A3C9967-8EA1-CE8A-DDF7-C35F20372D9D} | X BHO | SDK**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {6A8EF6F5-D235-2292-C21E-9791E67AA0F0} | X BHO | SYS**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Savila Class | {1FE45FFD-98A4-4090-BF24-F9D39BB90B4E} | ? BHO | savi.dll | Unidentified browser plugin,file located in "Program Files\SAVOYS~1" folder - should you have any information about this application, such as its exact purpose and whether you did or did not install it wittingly, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks! |
| XBTP04475 Class | {858EE471-F0C6-44c7-B593-9CA06DE9D804} | O BHO | sensis-toolbar.dll, sensis~1.dll | Sensis.com.au_Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Installer detected by Kaspersky antivirus as not-a-virus:AdWare.Win32.Softomate.ah and by Bitdefender as Adware.Softomate.AW |
| {907CA0E5-CE84-11D6-9508-02608CDD2846} | X BHO | SearchSquire33.dll, SEARCH~*.DLL | SearchSquire adware variant |
| Class | {01B9FA3E-898A-D32F-F1C9-F035F16758A4} | X BHO | SYS**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {7A97DD77-2070-7617-3461-0E4D0FF7624D} | X BHO | SDK**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {E4563C08-7705-A479-B77D-1C96DDF54534} | X BHO | SYS**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| (no name) | {f19c7206-f486-4753-8140-581f07677509} | X BHO | Starware.dll, Starware***.dll (* = digit) | Comet_Systems/StarWare adware |
| Class | {6785FFA5-2EE6-F258-DCBD-E29FEA7FDF52} | X BHO | SDK**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {8BCC2A80-7D9A-C66D-A965-C67926C9AD33} | X BHO | SDK**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {28258802-DCF4-0A65-50CC-A5E290AB5388} | X BHO | SYS**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| FavoriteMan Class | {EBBD88E5-C372-469D-B4C5-1FE00352AB9B} | X BHO | ss32.dll, mmview_101.dll | FavoriteMan adware variant |
| SurfingAdvisor | {08111E97-AB7D-B099-1D3F-F88F47E13432} | X BHO | SurfingAdvisor-1.dll, SurfingAdvisor-2.dll, SurfingAdvisor-3.dll | PlayMP3Z.biz adware variant |
| Spb Wallet | {2913D3DD-9363-4C21-B205-C19A584A0674} | L TB | SpbWalletToolbar.dll | Spb Wallet |
| Class | {388E9D4A-1396-83AE-0095-3D8F5CCFD035} | X BHO | SYS**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |