| OBJECT NAME | GUID | STATUS | FILENAME | DESCRIPTION |
|---|
| DVA Storm | {21D27745-1B1A-4A5B-BEFB-7381FAEB5227} | X BHO | lgmxvpatklf.dll | Adware downloader causing false spyware warnings and connecting to rogue "security sites", a member of the Trojan-Downloader.Zlob.Media-Codec aka NewMediaCodec malware family |
| (no name) | {337C54C9-80C1-4de2-93CD-AAA510834074} | X BHO | laf**.dll , laf***.dll (* = random char or digit) | Trojan dropper, detected by ESET's Nod32 antivirus as Win32/Hoax.Renos.NAV - a member of the SmitFraud malware family |
| {2005F7BA-6189-4607-BF8B-667679251CC0} | L TB | Linkmailer.dll | Linkmailer toolbar |
| LycosToolbar BHO | {A81DB557-45EA-4446-B222-F8FC3C89F6FB} | O BHO | LycosTB2.dll | Lycos Toolbar |
| LNISOFT | {89CB620F-35C3-11D5-96CA-0050DA08476E} | L TB | LniIEGate.dll | HaanGuide - Korean - English translation software |
| SystemSave LegalAppend, CPub Object | {C68AE9C0-0909-4DDC-B661-C1AFB9F54444} | X BHO | LegalAppend.dll | Parasite, detected by AntiVir antivirus as ADSPY/SystemSave |
| Glwcick Class | {BDF4E4DF-B6BB-4ECE-8CD9-1880DEC7B82F} | X BHO | lqe2z.dll | QuickLinks/LinkMaker adware variant - also detected as Adware.Suggestor |
| DVA Storm | {52676F4A-D830-4513-BE81-3A0C28B32C2F} | X BHO | lgmxvpatkmb.dll | Adware downloader causing false spyware warnings and connecting to rogue "security sites", a member of the Trojan-Downloader.Zlob.Media-Codec aka NewMediaCodec malware family |
| LinkedIn Toolbar | {BB670D0B-5C46-40C7-B38B-40DD26987723} | L TB | LinkedInIEToolbar.dll | LinkedIn Toolbar |
| Class | {F995B41E-CBE3-A866-782E-8D6294DA3DEA} | X BHO | LinkOptimizer.dll | Linkoptimizer trojan |
| LIQUIObj Class | {00000000-663F-49E8-BDF6-F26DB51C7DD5} | X BHO | liqui.dll | ADBreak adware component |
| MS Explorer | {705D9401-8A21-8145-25A1-8F35813F4101} | X BHO | lsdctl32.dll | Variant of the Trojan-Spy.Win32.Agent.ir trojan |
| Local Spool Net support DLL | {327C2850-C90E-4D37-AA9E-10AD9BACA46C} | X BHO | localsplnet.dll | OpenWares "ContextuAd" aka MediaBack adware |
| Insomnia Toolbar | {26586983-56D0-44E2-B891-26452BDCF2E5} | O TB | l2i_-_insomnia.dll | Unidentified Softomate Toolbar - should you have any information about this application, such as its homepage, its exact purpose and whether you did or did not install it wittingly, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks! |
| Log.Full | {B7B0089A-FAF6-43FB-A33D-657E416AE259} | X BHO | log.dll | FastFind.org SubSearch parasite, a variant of Adware.Fastfind.B |
| CRSSSubscriber Object | {18A5CAE8-FAF6-49A9-B3D8-2954437D9BBC} | L BHO | LektoraCOM.dll | Lektora |
| {223405EC-01F9-48a2-BDBB-D519913E2765} | X TB | li01f948.dll | LZIO.com adware |
| {C55D30C7-3B86-4D70-98D3-CAA716DF0D83} | L TB | LektoraCOM.dll | Lektora |
| IEBtnHlprObj Class | {B84311B6-ABFF-4d41-93C8-A407FF42D307} | X BHO | lingyuhelper.dll | Related to Qyule.com "Blue Entertainment" foistware - also see here |
| XBTB05195 | {C92D3160-B8D4-11d9-AED1-004033A00168} | X BHO | lyrics.dll | Lyrics_Toolbar - a Softomate Toolbar variant detected by Kaspersky antivirus as AdWare.Win32.SearchIt.o - also see here |
| DVA Storm | {61AC0015-9872-4BE8-BC80-33BA4A7BB632} | X BHO | lgmxvpatqfx.dll | Adware downloader causing false spyware warnings and connecting to rogue "security sites", a member of the Trojan-Downloader.Zlob.Media-Codec aka NewMediaCodec malware family |
| ViewSource Class | {E7CFDCBD-BE61-4CB2-8EDF-E3C6B1A690F3} | X BHO | linkage.dll | Linkage adware |
| Libero Toolbar | {D3403F23-7D39-435F-A8CB-45016C29E48E} | L TB | Liberoband.dll | Libero Toolbar |
| LokiBHO Class | {ED314C2D-CB10-4C7D-B1A7-EC89C797DD06} | L BHO | LokiPlugin.dll | Skyhook Wireless Loki |
| Love Free Games Toolbar | {8DFD5077-FB25-4397-8D9F-ACFB8CC7E34B} | X TB | lfg-toolbar.dll, LFG-TO~1.DLL | LoveFreeGames adware |
| LgHp BHO | {9D0A0666-30AD-4338-948D-D9620B953B6F} | L BHO | LhcomiE.dll | ZqWare LoginHelper |
| l_intlProc Class | {1B961B1C-1A96-4971-A3B2-A10B455E470E} | X BHO | l_intl.dll | Browser plugin of Korean origin hailing from anycleaner.co.kr, and detected as Win32.Spyware.Anycleaner |
| The leosrv | {A3B1F7ED-8EDA-410F-8CB9-F6AFD8301B7C} | X TB | leosrv.dll | Parasite connecting to rogue "security sites", member of the FakeAlert aka SmitFraud malware family |
| l_intlProc Class | {1B961B1C-1A96-4971-A3B2-A10B455E471E} | X BHO | l_intl.dll | Browser plugin of Korean origin hailing from anycleaner.co.kr, and detected as Win32.Spyware.Anycleaner |
| The leosrv | {8B6860DE-2CFA-4713-B42F-DC06D008DC54} | X TB | leosrv.dll | Parasite connecting to rogue "security sites", member of the FakeAlert aka SmitFraud malware family |
| Local Spool Net support DLL | {EF99BD50-CDFB-11E2-892F-1090271D4F78} | X BHO | localsplnet.dll | OpenWares "ContextuAd" aka MediaBack adware |
| WebSpeechBHO Class | {83A30C59-3A50-49E6-9DAF-4923C4EA3C23} | L BHO | LgxIEBar.dll | WebSpeech |
| LLIEHlprObj Class | {F757FBBF-10E5-4DDA-BBEA-2357E54BEA2B} | L BHO | LLBHO3.dll | LiveLink Explorer |
| Local Spool Net support DLL | {4E7BD750-2C8E-469B-C1E2-F063C081BF33} | X BHO | localsplnet.dll | OpenWares "ContextuAd" aka MediaBack adware |
| MiniFlashGetBHO, FlashGetMini | {C74E94A7-B7BD-4891-9328-455395BCC7AD} | L BHO | libMiniBHO.dll | FlashGet Mini |
| lassaplo.dll | {2B69874A-C58C-458D-69F0-698F874E41B2} | X BHO | lassaplo.dll | Password stealer of Chinese origin detected by Trend Micro as TSPY_ONLINEG.FOK |
| (no name) | {12FE2DFD-9644-42F1-AB2E-730552F028D6} | X BHO | lanbio.dll | "ComSpy", a keystroke logger that records both sides of IM's and P2P downloads, then emails the results out - detected by Kaspersky antivirus as Backdoor.Win32.Ulrbot.f |
| DVA Storm | {27F06E78-8650-4E11-934C-4CF91F971277} | X BHO | lgmxvpatrqm.dll | Adware downloader causing false spyware warnings and connecting to rogue "security sites", a member of the Trojan-Downloader.Zlob.Media-Codec aka NewMediaCodec malware family |
| Lphant Toolbar Helper | {DF47B953-69DF-42C6-B1C1-48D1FFEA725D} | X BHO | Lphant_Toolbar.dll | Lphant P2P filesharing - bundled with WhenUSave adware |
| (no name) | {********-****-****-****-************} | X SH | lpt.dll | WareOut malware component, using a random Class ID |
| Logos Toolbar | {C94158E1-6151-4442-ABE6-FD53D6534CCB} | O BHO TB | logos_ie.dll | Logos_Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. |
| Longdo Toolbar | {8BF27F8B-236F-4b81-AC69-8EB7690E5845} | L TB | longdo-98.dll | Longdo Toolbar - Thai dictionary search and compilation service |
| Her | {2A7102DE-1F71-4146-86FD-A722E8AB3489} | X BHO | lorinhib.dll, procins.dll | Keyword hijacker and trojan connecting to meoryprof.info and using seobiz.us as click referer |
| Skyhook Wireless Loki | {7F16E247-9F8E-4778-956E-AFEDF3D2FE0C} | L TB | LokiIe.dll | Skyhook Wireless Loki |
| DVA Storm | {F97B50CB-E441-427A-967E-0300347AD03E} | X BHO | lgmxvpatnpa.dll | Adware downloader causing false spyware warnings and connecting to rogue "security sites", a member of the Trojan-Downloader.Zlob.Media-Codec aka NewMediaCodec malware family |
| Nick | {A30B8EF5-82CA-4789-B77F-9C1C20DF53CB} | L TB | launchpadtoolbar.dll | Nick.com_Launchpad |
| bho2gr Class | {F1FF080D-12A3-439A-A2EF-4BA95A3148E8} | O BHO | LD_Catch.dll | Lightning Download |
| (no name) | {81270159-E8F9-4713-9646-03531E0EEF58} | X TB | LIE1D6FF.DLL, li16a4a6.dll | HTMLEdit hijacker |
| IEToolbarBHO Class | {1A1DAC8C-074D-440F-8707-7009A672D7D1} | L BHO | LinkedInIEToolbar.dll, LIToolbar.dll | LinkedIn Outlook Toolbar |
| Lyrics | {4B44E961-B842-11D9-AED1-004033A00168} | X TB | lyrics.dll | Lyrics_Toolbar - a Softomate Toolbar variant detected by Kaspersky antivirus as AdWare.Win32.SearchIt.o - also see here |
| {20A66F2F-31CE-11D5-8BF7-0090CC12D082} | O BHO | LightFrameIECOM.dll | For Lightframe monitors |
| (no name) | {8F2183B9-F4DB-4913-8F82-6F9CC42E4CF8} | X BHO | laf**.dll , laf***.dll (* = random char or digit) | Trojan dropper, detected by ESET's Nod32 antivirus as Win32/Hoax.Renos.NAV - a member of the SmitFraud malware family |
| (no name) | {047E9E19-6E5A-D335-60B0-03D3D0EC4A6F} | X BHO | lelctpm.dll, rmdrfje.dll | Trj/DisableKey aka Troj/Dloadr-ANM or Busky_H trojan |
| Lycos iQ Toolbar | {25F97EB4-1C02-45BA-BA0C-E67AACE64D4A} | O TB | LycosIQToolBar.dll, LYCOSI~*.DLL | Lycos_iQ_Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Remove unless you both trust it and expressly meant to install it. |
| Editor plugin | {9F4BC278-AA12-4716-A1EC-F1888B200F89} | X BHO | loadplg.dll | Variant of the Infostealer.Banker.D trojan |