CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

spacer spacer

The CLSID / BHO List / Toolbar Master List

Currently 54019 entries and growing...

This is the Master BHO and Toolbar list copyrighted by Tony Klein and CastleCops. For expert assistance, please post here. The information is collected across the Internet by the CastleCops Team. Usage: please leave feedback requesting permission if you are interested in using this data beyond the approved channels.

BHOList - ToolbarList

KEY:
  • "X" - Certified spyware/foistware, or other malware
  • "L" - Legitimate items
  • "O" - Open to debate
  • "?" - Unknown Status
  • "BHO" - Browser Helper Object
  • "TB" - Toolbar
  • "SH" - R3 URL SearchHook
  • "EB" - IE Explorer Bar

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z

    Random sampling...
    OBJECT NAMEGUIDSTATUSFILENAMEDESCRIPTION
    Microsoft Explorer{2546900C-451D-8645-8CBA-C735910FA104}X BHO wndcrt32.dllBackdoor trojan, detected by Kaspersky antivirus and by CounterSpy as Trojan-Spy.Win32.Agent.ir
    Class{22B1EC47-1EAB-B7A8-630D-99F8D36BEB48}X BHO WIN**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{5683F3D3-3C69-9FD5-1198-9B61C523A6BB}X BHO WIN**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    SOSBHO Class{004334EB-68A9-4A29-9C12-1B225260C14B}X BHO wnsd.dll, msoes.dll Rogue.CZ.b adware
    Class{EDD1A398-C8F7-CF1A-2911-C9840D86CEC4}X BHO WIN**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{3E948DE2-4EA9-DB4D-D6CA-C5AB6D316BD5}X BHO WIN**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{BC875B7F-F1B9-A5C3-79CC-74EFBDC1B14B}X BHO WIN**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Microsoft Office Helper{814194F1-4148-3871-4118-2417A488A878}X BHO wycctd32.dllVariant of the Trojan-Spy.Win32.Agent.ir trojan
    Class{D60220AD-9C47-483B-E94C-13E6492A5C39}X BHO WIN**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    (no name){08FE5F77-19CB-4062-8E47-8EF8D9D0DC64}X BHO winbrume.dllSearch hijacker, redirecting to hotwebfinder.com - variant of the Dropper.GF trojan
    Class{9291DF23-029D-DC8D-B7E6-64BEFF3F25AF}X BHO WIN**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{CC208792-19B6-6EE1-3FF4-64629ED9B7E4}X BHO WIN**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{94FBCA21-3E7A-0B62-0589-3697BABFD630}X BHO WIN**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{CDD5BE34-0317-A174-CC72-8449DAA0CF02}X BHO WIN**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    XBTB08143{4A34B4F8-19E5-46d9-B2C9-DA6DB8C8A65C}O BHO WEB1000.DLL Web1000 toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this.
    Arb Cruncher Toolbar{099C2990-E592-49EC-B772-83CFD8BE6E74}L TB WebBarIE.dllArb Cruncher Toolbar
    Class{29139193-52D7-7EFC-F253-8C73A2C8A5D7}X BHO WIN**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{B9CAA1B0-2559-36A9-A0E2-B290709F0283}X BHO WIN**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{BD7CF1F4-6B41-646A-9D8F-5C2FA16992DE}X BHO WIN**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{8D1BAA26-F985-1788-3C2F-DBED986F74EE}X BHO WIN**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{EC68BA8D-6877-5903-0784-E7D735F34793}X BHO WIN**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    (no name){6167F471-EF2B-41DD-A5E5-C26ACDB5C096}X BHO WinSys8k.Sys, WinSys8v.SysPassword stealer of Chinese origin detected as TSPY_QQGAME.GS
    {8DA5457F-A8AA-4CCF-A842-70E6FD274094}X BHO WToolsT.dll HuntBar_WebSearch adware variant
    Class{7CFF81A7-7FD3-D61B-619B-401F536792AF}X BHO WIN**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Extensão do Navegador{********-****-****-****-************}X BHO wgapr32.dllPassword stealer of Brazilian origin, detected by AntiVir as PHISH/FraudTool.MalWarrior.C
    Class{4D4514A7-E398-DF47-3F79-B4D79BEDD49F}X BHO WIN**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{4EDAA6C9-E44C-0633-B08A-A3C68F567654}X BHO WIN**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    LpkHlpr Class{00C104F7-0F5C-470C-ABCF-A5B2E70752F1}X BHO wtlhlp.dll, apphlp.dll, acczixp.dll, wpphlp.dllParasite of Chinese origin hailing from baidu.com - a BaiduBar adware component
    XBTB01994{5CDD839E-255C-415D-9927-3AF98318D15B}X BHO wizard.dllSearchWizard, a stealth installed Softomate Toolbar variant, detected by Kaspersky antivirus as AdWare.Win32.Softomate.ah
    Class{6A990596-36D6-C95A-0093-CB6EE8037406}X BHO WIN**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    WebSite {F102FC89-1835-47C9-90C2-EEB60C25AB48}X EBWebSite.dllParasite of Korean origin detected as Adware.Website
    Class{008235DF-6200-E376-279F-7B87938F2373}X BHO WIN**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{E29FD263-8F4B-4991-8255-7C16E147AD4F}X BHO WIN**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{46034628-821C-05B4-C227-B5A0FC40FCAF}X BHO WIN**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{4F8F140F-AC5D-B2A8-88F2-102063F77E8B}X BHO WIN**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{913DFA36-9040-F4DA-2372-454F96C8DF8B}X BHO WIN**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{8535DE15-B339-6FE0-AC10-3E709432EF1D}X BHO WIN**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Macromedia Extension{5A4C343C-BC5C-D7BB-C7B9-A47C8B74605E}X BHO wicstd32.dllVariant of the Trojan-Spy.Win32.Agent.ir trojan
    Class{237063F1-5883-6276-61BD-0B26D2C16F98}X BHO WIN**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{B24C88EC-60FC-99C0-BA5F-3F3DA397E615}X BHO WIN**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{0B6F15E4-D9AD-DD9D-0AB8-5E7F014A9B8A}X BHO WIN**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    TrendProtect{F83BE649-1CC3-48EE-B2E2-0826CEF3822A}L TB wrs.dll TrendProtect - A trendmicro Security Toolbar.
    Class{B29B4EE7-C0E8-5AD3-6EC1-9F9C231539B9}X BHO WIN**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{CDDABFD3-90AF-3505-3DF4-F8DF446C5C4F}X BHO WIN**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    MS Explorer{9E5E95F4-DF9F-31EB-D1AF-8F9F87F8D98E}X BHO wmhcst32.dllVariant of the Trojan-Spy.Win32.Agent.ir trojan
    Class{6D6F824E-4876-24B2-D11B-49F9A8DF9F1B}X BHO WIN**.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{8794ED77-EB91-D293-4349-10E13AF28460}X BHO WIN**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Class{1168F448-F54F-3E5B-04D1-4E47DD314008}X BHO win**.dll (* = random char) CoolWebSearch/HomeSearch adware component
    (no name){00000000-2565-4c5b-A455-A74C8A2247AB}X BHO wmcbaaca.dllLZIO.com adware
    XBTB06579{FF614A7A-C035-4467-AC2E-BD30BFAD0F17}X BHO wowokay.dll WowOkay_MP3_Bar - a Softomate Toolbar variant
    Video{0F596190-DEC2-4D19-AB43-50B54243923F}X BHO windivx.dllDownloader trojan, member of the FakeAlert aka SmitFraud malware family - produces IEDefender popups - also see here
    Class{F04EDD6C-366D-3C07-C7E4-27F0DB2B70C5}X BHO WIN**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component
    Bugnosis{3A6514CD-A457-11D4-8AF3-000102686B79}L BHO EBWebbug.dllBugnosis
    XBTB09580 Class{BBBE1C1A-89F7-4AF6-ABD1-F8FBCFA47408}L BHO wordreferenceEnFr.dll, WORDRE~1.DLL WordReference toolbar
    Class{75F3F166-0DCD-26C3-33A3-208C8A544DCE}X BHO WIN**32.DLL (* = random char) CoolWebSearch/HomeSearch adware component

    spacer spacer