<?xml version="1.0" encoding="Windows-1252"?>

<rdf:RDF 
xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" 
xmlns:dc="http://purl.org/dc/elements/1.1/" 
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" 
xmlns:admin="http://webns.net/mvcb/" 
xmlns:cc="http://web.resource.org/cc/" 
xmlns="http://purl.org/rss/1.0/">

<channel rdf:about="BHOList">
<title>Recent 10 BHO/CLSID/Toolbar Lists</title>
<link>http://www.castlecops.com/CLSID.html</link>
<description>CastleCops - TonyKlein's BHO Collection</description>
<dc:language>en-us</dc:language>
<dc:creator>Paul Laudanski (mailto:paul@computercops.biz)</dc:creator>
<dc:rights>Copyright &#169; 2002-2005 CastleCops&amp;reg;</dc:rights>
<dc:date>2008-08-28T13:38:57-05:00</dc:date>
<sy:updatePeriod>daily</sy:updatePeriod>
<sy:updateFrequency>24</sy:updateFrequency>
<sy:updateBase>2003-01-01T12:00-05:00</sy:updateBase>
<admin:generatorAgent rdf:resource="http://www.castlecops.com/" />

<item>
<guid>\{CC628875-53FE-4DE3-9CA8-E61652820398}</guid>
<status>X BHO TB</status>
<filename>[random filename]</filename>
<description>VirtuMonde/Vundo, http://www.symantec.com/security_response/writeup.jsp?docid=2004-112111-3912-99 adware component
</description>
<infourl>http://www.castlecops.com/clsid-55539.html</infourl>
<link>http://www.castlecops.com/clsid-55539.html</link>
</item>
<item>
<guid>\{EB6EC5D7-7D19-A8C7-D607-F0993BF94A9F}</guid>
<status>X BHO TB</status>
<filename>ExpertHelper-1.dll, ExpertHelper-2.dll, ExpertHelper-3.dll</filename>
<description>PlayMP3Z.biz, http://research.sunbelt-software.com/threatdisplay.aspx?threatid=153897 adware variant
</description>
<infourl>http://www.castlecops.com/clsid-55538.html</infourl>
<link>http://www.castlecops.com/clsid-55538.html</link>
</item>
<item>
<guid>\{EC42C204-B7C5-4e0e-BF8F-690D278018C1}</guid>
<status>X BHO TB</status>
<filename>****.dll (random char or digit)</filename>
<description>Parasite of Chinese origin, detected by Kaspersky, http://www.kaspersky.com/ antivirus as AdWare.Win32.WSearch.o
</description>
<infourl>http://www.castlecops.com/clsid-55537.html</infourl>
<link>http://www.castlecops.com/clsid-55537.html</link>
</item>
<item>
<guid>\{D26AAB3B-B0DD-456C-A7E5-4DA9565FD6EE}</guid>
<status>X BHO TB</status>
<filename>goldmng.dll, goldman.dll, gldmng.dll, gldman.dll gldmanager.dll, GLDMAN~1.DLL, GOLDMA~1.DLL</filename>
<description>Parasite redirecting to fake security sites, member of the FakeAlert, http://research.sunbelt-software.com/threatdisplay.aspx?threatid=43521 aka SmitFraud, http://research.sunbelt-software.com/threatdisplay.aspx?threatid=44645 malware family - produces IEDefender, http://www.symantec.com/security_response/writeup.jsp?docid=2007-111420-0754-99  , FilesSecure, http://www.symantec.com/security_response/writeup.jsp?docid=2007-122812-3859-99 , MalwareBell, http://www.symantec.com/business/security_response/writeup.jsp?docid=2008-041610-3304-99 ,  IE_Antivirus, http://www.symantec.com/business/security_response/writeup.jsp?docid=2008-042813-4856-99&amp;tabid=1 or similar popups - also see here, http://www.bleepingcomputer.com/forums/topic114240.html
</description>
<infourl>http://www.castlecops.com/clsid-55536.html</infourl>
<link>http://www.castlecops.com/clsid-55536.html</link>
</item>
<item>
<guid>\{04B2B073-361D-420E-B5A5-78C4B926E39A}</guid>
<status>X BHO TB</status>
<filename>bgrqfetx.dll</filename>
<description>Parasite causing false spyware warnings and connecting to fake &quot;security sites&quot; - member of the FakeAlert, http://research.sunbelt-software.com/threatdisplay.aspx?threatid=43521 aka SmitFraud, http://research.sunbelt-software.com/threatdisplay.aspx?threatid=44645 malware family
</description>
<infourl>http://www.castlecops.com/clsid-55535.html</infourl>
<link>http://www.castlecops.com/clsid-55535.html</link>
</item>
<item>
<guid>\{E0597566-BAA7-49B5-875B-5E203D363229}</guid>
<status>X BHO TB</status>
<filename>bgrqfetx.dll</filename>
<description>Parasite causing false spyware warnings and connecting to fake &quot;security sites&quot; - member of the FakeAlert, http://research.sunbelt-software.com/threatdisplay.aspx?threatid=43521 aka SmitFraud, http://research.sunbelt-software.com/threatdisplay.aspx?threatid=44645 malware family
</description>
<infourl>http://www.castlecops.com/clsid-55534.html</infourl>
<link>http://www.castlecops.com/clsid-55534.html</link>
</item>
<item>
<guid>\{36C52D2F-5D45-49DC-810E-2EAA0E1925A2}</guid>
<status>X BHO TB</status>
<filename>wnlmdakqpbv.dll</filename>
<description>Adware downloader causing false spyware warnings and connecting to rogue &quot;security sites&quot;, a member of the Trojan-Downloader.Zlob.Media-Codec, http://research.sunbelt-software.com/threatdisplay.aspx?threatid=44478 aka NewMediaCodec, http://research.sunbelt-software.com/threatdisplay.aspx?threatid=149335 malware family
</description>
<infourl>http://www.castlecops.com/clsid-55533.html</infourl>
<link>http://www.castlecops.com/clsid-55533.html</link>
</item>
<item>
<guid>\{4A10BF18-AE42-4D89-8D72-0742D83AA2C6}</guid>
<status>X BHO TB</status>
<filename>wnlmdakqqas.dll</filename>
<description>Adware downloader causing false spyware warnings and connecting to rogue &quot;security sites&quot;, a member of the Trojan-Downloader.Zlob.Media-Codec, http://research.sunbelt-software.com/threatdisplay.aspx?threatid=44478 aka NewMediaCodec, http://research.sunbelt-software.com/threatdisplay.aspx?threatid=149335 malware family </description>
<infourl>http://www.castlecops.com/clsid-55532.html</infourl>
<link>http://www.castlecops.com/clsid-55532.html</link>
</item>
<item>
<guid>\{583fcb3d-8b18-450c-8120-42f8d42d737c}</guid>
<status>O BHO TB</status>
<filename>tbDj_C.dll, tbDj_0.dll, tbDj_l1.dll</filename>
<description>Dj_Clup, http://djclup.ourtoolbar.com/ Toolbar - a Conduit/EffectiveBrand, http://www.conduit.com/Benefits/Default.aspx &quot;Free Community&quot; toolbar - modifies the default IE SearchHook. Some Conduit toolbars are reputed to have a certain adware/trackware functionality.</description>
<infourl>http://www.castlecops.com/clsid-55531.html</infourl>
<link>http://www.castlecops.com/clsid-55531.html</link>
</item>
<item>
<guid>\{db35fda8-77e3-4784-92c2-ee7345e91af4}</guid>
<status>O BHO TB</status>
<filename>tbxplo.dll, tbxpl0.dll, tbxpl1.dll</filename>
<description>xplorer2, http://xplorer2.ourtoolbar.com/ Toolbar - a Conduit/EffectiveBrand, http://www.conduit.com/Benefits/Default.aspx &quot;Free Community&quot; toolbar - modifies the default IE SearchHook. Some Conduit toolbars are reputed to have a certain adware/trackware functionality.</description>
<infourl>http://www.castlecops.com/clsid-55530.html</infourl>
<link>http://www.castlecops.com/clsid-55530.html</link>
</item>
</channel>

</rdf:RDF>

