CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

spacer spacer

The CLSID / BHO List / Toolbar Master List

Currently 54019 entries and growing...

This is the Master BHO and Toolbar list copyrighted by Tony Klein and CastleCops. For expert assistance, please post here. The information is collected across the Internet by the CastleCops Team. Usage: please leave feedback requesting permission if you are interested in using this data beyond the approved channels.

BHOList - ToolbarList

KEY:
  • "X" - Certified spyware/foistware, or other malware
  • "L" - Legitimate items
  • "O" - Open to debate
  • "?" - Unknown Status
  • "BHO" - Browser Helper Object
  • "TB" - Toolbar
  • "SH" - R3 URL SearchHook
  • "EB" - IE Explorer Bar

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z

    Random sampling...
    OBJECT NAMEGUIDSTATUSFILENAMEDESCRIPTION
    DVA Storm{21D27745-1B1A-4A5B-BEFB-7381FAEB5227}X BHO lgmxvpatklf.dllAdware downloader causing false spyware warnings and connecting to rogue "security sites", a member of the Trojan-Downloader.Zlob.Media-Codec aka NewMediaCodec malware family
    (no name){337C54C9-80C1-4de2-93CD-AAA510834074}X BHO laf**.dll , laf***.dll (* = random char or digit)Trojan dropper, detected by ESET's Nod32 antivirus as Win32/Hoax.Renos.NAV - a member of the SmitFraud malware family
    {2005F7BA-6189-4607-BF8B-667679251CC0}L TB Linkmailer.dllLinkmailer toolbar
    LycosToolbar BHO{A81DB557-45EA-4446-B222-F8FC3C89F6FB}O BHO LycosTB2.dllLycos Toolbar
    LNISOFT{89CB620F-35C3-11D5-96CA-0050DA08476E}L TB LniIEGate.dll HaanGuide - Korean - English translation software
    SystemSave LegalAppend, CPub Object{C68AE9C0-0909-4DDC-B661-C1AFB9F54444}X BHO LegalAppend.dllParasite, detected by AntiVir antivirus as ADSPY/SystemSave
    Glwcick Class{BDF4E4DF-B6BB-4ECE-8CD9-1880DEC7B82F}X BHO lqe2z.dll QuickLinks/LinkMaker adware variant - also detected as Adware.Suggestor
    DVA Storm{52676F4A-D830-4513-BE81-3A0C28B32C2F}X BHO lgmxvpatkmb.dllAdware downloader causing false spyware warnings and connecting to rogue "security sites", a member of the Trojan-Downloader.Zlob.Media-Codec aka NewMediaCodec malware family
    LinkedIn Toolbar{BB670D0B-5C46-40C7-B38B-40DD26987723}L TB LinkedInIEToolbar.dllLinkedIn Toolbar
    Class{F995B41E-CBE3-A866-782E-8D6294DA3DEA}X BHO LinkOptimizer.dll Linkoptimizer trojan
    LIQUIObj Class{00000000-663F-49E8-BDF6-F26DB51C7DD5}X BHO liqui.dll ADBreak adware component
    MS Explorer{705D9401-8A21-8145-25A1-8F35813F4101}X BHO lsdctl32.dllVariant of the Trojan-Spy.Win32.Agent.ir trojan
    Local Spool Net support DLL{327C2850-C90E-4D37-AA9E-10AD9BACA46C}X BHO localsplnet.dllOpenWares "ContextuAd" aka MediaBack adware
    Insomnia Toolbar{26586983-56D0-44E2-B891-26452BDCF2E5}O TB l2i_-_insomnia.dllUnidentified Softomate Toolbar - should you have any information about this application, such as its homepage, its exact purpose and whether you did or did not install it wittingly, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks!
    Log.Full{B7B0089A-FAF6-43FB-A33D-657E416AE259}X BHO log.dllFastFind.org SubSearch parasite, a variant of Adware.Fastfind.B
    CRSSSubscriber Object{18A5CAE8-FAF6-49A9-B3D8-2954437D9BBC}L BHO LektoraCOM.dllLektora
    {223405EC-01F9-48a2-BDBB-D519913E2765}X TB li01f948.dllLZIO.com adware
    {C55D30C7-3B86-4D70-98D3-CAA716DF0D83}L TB LektoraCOM.dllLektora
    IEBtnHlprObj Class{B84311B6-ABFF-4d41-93C8-A407FF42D307}X BHO lingyuhelper.dllRelated to Qyule.com "Blue Entertainment" foistware - also see here
    XBTB05195 {C92D3160-B8D4-11d9-AED1-004033A00168}X BHO lyrics.dll Lyrics_Toolbar - a Softomate Toolbar variant detected by Kaspersky antivirus as AdWare.Win32.SearchIt.o - also see here
    DVA Storm{61AC0015-9872-4BE8-BC80-33BA4A7BB632}X BHO lgmxvpatqfx.dllAdware downloader causing false spyware warnings and connecting to rogue "security sites", a member of the Trojan-Downloader.Zlob.Media-Codec aka NewMediaCodec malware family
    ViewSource Class{E7CFDCBD-BE61-4CB2-8EDF-E3C6B1A690F3}X BHO linkage.dll Linkage adware
    Libero Toolbar{D3403F23-7D39-435F-A8CB-45016C29E48E}L TB Liberoband.dllLibero Toolbar
    LokiBHO Class{ED314C2D-CB10-4C7D-B1A7-EC89C797DD06}L BHO LokiPlugin.dllSkyhook Wireless Loki
    Love Free Games Toolbar{8DFD5077-FB25-4397-8D9F-ACFB8CC7E34B}X TB lfg-toolbar.dll, LFG-TO~1.DLL LoveFreeGames adware
    LgHp BHO{9D0A0666-30AD-4338-948D-D9620B953B6F}L BHO LhcomiE.dllZqWare LoginHelper
    l_intlProc Class{1B961B1C-1A96-4971-A3B2-A10B455E470E}X BHO l_intl.dllBrowser plugin of Korean origin hailing from anycleaner.co.kr, and detected as Win32.Spyware.Anycleaner
    The leosrv{A3B1F7ED-8EDA-410F-8CB9-F6AFD8301B7C}X TB leosrv.dllParasite connecting to rogue "security sites", member of the FakeAlert aka SmitFraud malware family
    l_intlProc Class{1B961B1C-1A96-4971-A3B2-A10B455E471E}X BHO l_intl.dllBrowser plugin of Korean origin hailing from anycleaner.co.kr, and detected as Win32.Spyware.Anycleaner
    The leosrv{8B6860DE-2CFA-4713-B42F-DC06D008DC54}X TB leosrv.dllParasite connecting to rogue "security sites", member of the FakeAlert aka SmitFraud malware family
    Local Spool Net support DLL{EF99BD50-CDFB-11E2-892F-1090271D4F78}X BHO localsplnet.dllOpenWares "ContextuAd" aka MediaBack adware
    WebSpeechBHO Class{83A30C59-3A50-49E6-9DAF-4923C4EA3C23}L BHO LgxIEBar.dllWebSpeech
    LLIEHlprObj Class{F757FBBF-10E5-4DDA-BBEA-2357E54BEA2B}L BHO LLBHO3.dllLiveLink Explorer
    Local Spool Net support DLL{4E7BD750-2C8E-469B-C1E2-F063C081BF33}X BHO localsplnet.dllOpenWares "ContextuAd" aka MediaBack adware
    MiniFlashGetBHO, FlashGetMini{C74E94A7-B7BD-4891-9328-455395BCC7AD}L BHO libMiniBHO.dll FlashGet Mini
    lassaplo.dll{2B69874A-C58C-458D-69F0-698F874E41B2}X BHO lassaplo.dllPassword stealer of Chinese origin detected by Trend Micro as TSPY_ONLINEG.FOK
    (no name){12FE2DFD-9644-42F1-AB2E-730552F028D6}X BHO lanbio.dll"ComSpy", a keystroke logger that records both sides of IM's and P2P downloads, then emails the results out - detected by Kaspersky antivirus as Backdoor.Win32.Ulrbot.f
    DVA Storm{27F06E78-8650-4E11-934C-4CF91F971277}X BHO lgmxvpatrqm.dll Adware downloader causing false spyware warnings and connecting to rogue "security sites", a member of the Trojan-Downloader.Zlob.Media-Codec aka NewMediaCodec malware family
    Lphant Toolbar Helper{DF47B953-69DF-42C6-B1C1-48D1FFEA725D}X BHO Lphant_Toolbar.dll Lphant P2P filesharing - bundled with WhenUSave adware
    (no name){********-****-****-****-************}X SH lpt.dll WareOut malware component, using a random Class ID
    Logos Toolbar{C94158E1-6151-4442-ABE6-FD53D6534CCB}O BHO TB logos_ie.dll Logos_Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this.
    Longdo Toolbar{8BF27F8B-236F-4b81-AC69-8EB7690E5845}L TB longdo-98.dll Longdo Toolbar - Thai dictionary search and compilation service
    Her{2A7102DE-1F71-4146-86FD-A722E8AB3489}X BHO lorinhib.dll, procins.dllKeyword hijacker and trojan connecting to meoryprof.info and using seobiz.us as click referer
    Skyhook Wireless Loki{7F16E247-9F8E-4778-956E-AFEDF3D2FE0C}L TB LokiIe.dllSkyhook Wireless Loki
    DVA Storm{F97B50CB-E441-427A-967E-0300347AD03E}X BHO lgmxvpatnpa.dllAdware downloader causing false spyware warnings and connecting to rogue "security sites", a member of the Trojan-Downloader.Zlob.Media-Codec aka NewMediaCodec malware family
    Nick{A30B8EF5-82CA-4789-B77F-9C1C20DF53CB}L TB launchpadtoolbar.dll Nick.com_Launchpad
    bho2gr Class{F1FF080D-12A3-439A-A2EF-4BA95A3148E8}O BHO LD_Catch.dllLightning Download
    (no name){81270159-E8F9-4713-9646-03531E0EEF58}X TB LIE1D6FF.DLL, li16a4a6.dllHTMLEdit hijacker
    IEToolbarBHO Class{1A1DAC8C-074D-440F-8707-7009A672D7D1}L BHO LinkedInIEToolbar.dll, LIToolbar.dllLinkedIn Outlook Toolbar
    Lyrics {4B44E961-B842-11D9-AED1-004033A00168}X TB lyrics.dll Lyrics_Toolbar - a Softomate Toolbar variant detected by Kaspersky antivirus as AdWare.Win32.SearchIt.o - also see here
    {20A66F2F-31CE-11D5-8BF7-0090CC12D082}O BHO LightFrameIECOM.dllFor Lightframe monitors
    (no name){8F2183B9-F4DB-4913-8F82-6F9CC42E4CF8}X BHO laf**.dll , laf***.dll (* = random char or digit)Trojan dropper, detected by ESET's Nod32 antivirus as Win32/Hoax.Renos.NAV - a member of the SmitFraud malware family
    (no name){047E9E19-6E5A-D335-60B0-03D3D0EC4A6F}X BHO lelctpm.dll, rmdrfje.dllTrj/DisableKey aka Troj/Dloadr-ANM or Busky_H trojan
    Lycos iQ Toolbar{25F97EB4-1C02-45BA-BA0C-E67AACE64D4A}O TB LycosIQToolBar.dll, LYCOSI~*.DLL Lycos_iQ_Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Remove unless you both trust it and expressly meant to install it.
    Editor plugin{9F4BC278-AA12-4716-A1EC-F1888B200F89}X BHO loadplg.dllVariant of the Infostealer.Banker.D trojan

    spacer spacer