| OBJECT NAME | GUID | STATUS | FILENAME | DESCRIPTION |
|---|
| Microsoft Explorer | {2546900C-451D-8645-8CBA-C735910FA104} | X BHO | wndcrt32.dll | Backdoor trojan, detected by Kaspersky antivirus and by CounterSpy as Trojan-Spy.Win32.Agent.ir |
| Class | {22B1EC47-1EAB-B7A8-630D-99F8D36BEB48} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {5683F3D3-3C69-9FD5-1198-9B61C523A6BB} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| SOSBHO Class | {004334EB-68A9-4A29-9C12-1B225260C14B} | X BHO | wnsd.dll, msoes.dll | Rogue.CZ.b adware |
| Class | {EDD1A398-C8F7-CF1A-2911-C9840D86CEC4} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {3E948DE2-4EA9-DB4D-D6CA-C5AB6D316BD5} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {BC875B7F-F1B9-A5C3-79CC-74EFBDC1B14B} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Microsoft Office Helper | {814194F1-4148-3871-4118-2417A488A878} | X BHO | wycctd32.dll | Variant of the Trojan-Spy.Win32.Agent.ir trojan |
| Class | {D60220AD-9C47-483B-E94C-13E6492A5C39} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| (no name) | {08FE5F77-19CB-4062-8E47-8EF8D9D0DC64} | X BHO | winbrume.dll | Search hijacker, redirecting to hotwebfinder.com - variant of the Dropper.GF trojan |
| Class | {9291DF23-029D-DC8D-B7E6-64BEFF3F25AF} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {CC208792-19B6-6EE1-3FF4-64629ED9B7E4} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {94FBCA21-3E7A-0B62-0589-3697BABFD630} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {CDD5BE34-0317-A174-CC72-8449DAA0CF02} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| XBTB08143 | {4A34B4F8-19E5-46d9-B2C9-DA6DB8C8A65C} | O BHO | WEB1000.DLL | Web1000 toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. |
| Arb Cruncher Toolbar | {099C2990-E592-49EC-B772-83CFD8BE6E74} | L TB | WebBarIE.dll | Arb Cruncher Toolbar |
| Class | {29139193-52D7-7EFC-F253-8C73A2C8A5D7} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {B9CAA1B0-2559-36A9-A0E2-B290709F0283} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {BD7CF1F4-6B41-646A-9D8F-5C2FA16992DE} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {8D1BAA26-F985-1788-3C2F-DBED986F74EE} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {EC68BA8D-6877-5903-0784-E7D735F34793} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| (no name) | {6167F471-EF2B-41DD-A5E5-C26ACDB5C096} | X BHO | WinSys8k.Sys, WinSys8v.Sys | Password stealer of Chinese origin detected as TSPY_QQGAME.GS |
| {8DA5457F-A8AA-4CCF-A842-70E6FD274094} | X BHO | WToolsT.dll | HuntBar_WebSearch adware variant |
| Class | {7CFF81A7-7FD3-D61B-619B-401F536792AF} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Extensão do Navegador | {********-****-****-****-************} | X BHO | wgapr32.dll | Password stealer of Brazilian origin, detected by AntiVir as PHISH/FraudTool.MalWarrior.C |
| Class | {4D4514A7-E398-DF47-3F79-B4D79BEDD49F} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {4EDAA6C9-E44C-0633-B08A-A3C68F567654} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| LpkHlpr Class | {00C104F7-0F5C-470C-ABCF-A5B2E70752F1} | X BHO | wtlhlp.dll, apphlp.dll, acczixp.dll, wpphlp.dll | Parasite of Chinese origin hailing from baidu.com - a BaiduBar adware component |
| XBTB01994 | {5CDD839E-255C-415D-9927-3AF98318D15B} | X BHO | wizard.dll | SearchWizard, a stealth installed Softomate Toolbar variant, detected by Kaspersky antivirus as AdWare.Win32.Softomate.ah |
| Class | {6A990596-36D6-C95A-0093-CB6EE8037406} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| WebSite | {F102FC89-1835-47C9-90C2-EEB60C25AB48} | X EB | WebSite.dll | Parasite of Korean origin detected as Adware.Website |
| Class | {008235DF-6200-E376-279F-7B87938F2373} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {E29FD263-8F4B-4991-8255-7C16E147AD4F} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {46034628-821C-05B4-C227-B5A0FC40FCAF} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {4F8F140F-AC5D-B2A8-88F2-102063F77E8B} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {913DFA36-9040-F4DA-2372-454F96C8DF8B} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {8535DE15-B339-6FE0-AC10-3E709432EF1D} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Macromedia Extension | {5A4C343C-BC5C-D7BB-C7B9-A47C8B74605E} | X BHO | wicstd32.dll | Variant of the Trojan-Spy.Win32.Agent.ir trojan |
| Class | {237063F1-5883-6276-61BD-0B26D2C16F98} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {B24C88EC-60FC-99C0-BA5F-3F3DA397E615} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {0B6F15E4-D9AD-DD9D-0AB8-5E7F014A9B8A} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| TrendProtect | {F83BE649-1CC3-48EE-B2E2-0826CEF3822A} | L TB | wrs.dll | TrendProtect - A trendmicro Security Toolbar. |
| Class | {B29B4EE7-C0E8-5AD3-6EC1-9F9C231539B9} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {CDDABFD3-90AF-3505-3DF4-F8DF446C5C4F} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| MS Explorer | {9E5E95F4-DF9F-31EB-D1AF-8F9F87F8D98E} | X BHO | wmhcst32.dll | Variant of the Trojan-Spy.Win32.Agent.ir trojan |
| Class | {6D6F824E-4876-24B2-D11B-49F9A8DF9F1B} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {8794ED77-EB91-D293-4349-10E13AF28460} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {1168F448-F54F-3E5B-04D1-4E47DD314008} | X BHO | win**.dll (* = random char) | CoolWebSearch/HomeSearch adware component |
| (no name) | {00000000-2565-4c5b-A455-A74C8A2247AB} | X BHO | wmcbaaca.dll | LZIO.com adware |
| XBTB06579 | {FF614A7A-C035-4467-AC2E-BD30BFAD0F17} | X BHO | wowokay.dll | WowOkay_MP3_Bar - a Softomate Toolbar variant |
| Video | {0F596190-DEC2-4D19-AB43-50B54243923F} | X BHO | windivx.dll | Downloader trojan, member of the FakeAlert aka SmitFraud malware family - produces IEDefender popups - also see here |
| Class | {F04EDD6C-366D-3C07-C7E4-27F0DB2B70C5} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Bugnosis | {3A6514CD-A457-11D4-8AF3-000102686B79} | L BHO EB | Webbug.dll | Bugnosis |
| XBTB09580 Class | {BBBE1C1A-89F7-4AF6-ABD1-F8FBCFA47408} | L BHO | wordreferenceEnFr.dll, WORDRE~1.DLL | WordReference toolbar |
| Class | {75F3F166-0DCD-26C3-33A3-208C8A544DCE} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |