| OBJECT NAME | GUID | STATUS | FILENAME | DESCRIPTION |
|---|
| Yvakt Class | {BA3DDC15-3EF1-4DC7-B9B6-ED0403F9422A} | X BHO | OUGHYA~1.DLL | QuickLinks/LinkMaker adware variant - also detected as Adware.Suggestor |
| URLSearch Class | {965A592F-8EFA-4250-8630-7960230792F1} | X SH | omdsn.dll | PowerStrip adware component |
| ozfydbyt.dll | {4A069845-2036-6084-9054-6087502480A4} | X BHO | ozfydbyt.dll | Password stealer of Chinese origin detected by Trend Micro as TSPY_ONLINEG.FOK
|
| AbnDebSink Class | {CFD1FB3B-963E-4774-921C-5043C437E3AE} | X BHO | orca11.dll | Variant of the TROJ_AGENT.XTN trojan |
| Oyunhileleri.com Toolbar | {8D2CD624-3650-4B4C-AF69-68B29FE445C2} | O TB | oyunhileleri.com.dll, OYUNHI~1.DLL | Oyunhileleri.com Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Remove unless you both trust it and expressly meant to install it. |
| NewFolder Class | {5F974BAE-7885-11D2-8CDB-205850C10000} | ? BHO | ObjFolder.dll | Unidentified browser plugin, file present in "System32\Fian" folder - should you have any information about this application, such as its exact purpose and whether you did or did not install it wittingly, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks! |
| OpenChina | {F7724DED-36CC-11D6-B88F-00C0261016CF} | ? TB | OPENCH~1.DLL, openchina.dll | Unidentified Toolbar - should you have any information about this application, such as its exact purpose and whether you did or did not install it wittingly, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks! |
| optcalApp Class | {B37AB40A-FB66-46AA-9AC1-8D21B51E7CFC} | X BHO | optcal.dll | Adware of Korean origin hailing from empas.com, detected by Kaspersky antivirus as Trojan.Win32.BHO.qu |
| oswxcttb.dll | {33512378-9874-5641-1025-985420368733} | X BHO | oswxcttb.dll | Password stealer of Chinese origin detected by Trend Micro as TSPY_ONLINEG.FOK |
| Translate Class | {49610FA4-04BB-46A5-9C66-B96A2406F656} | X SH | OnfindSearch.dll | OnfindSearch adware |
| Player | {F3DDAB38-C6E3-4EF8-A543-6E8625A61D93} | X BHO | orgnavi.dll | Downloader trojan causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family |
| DHTML View | {37A5FF76-9919-492C-98E3-EDA3502FC829} | X BHO | Oasis.dll | Oasisnet.com Hijacker/web downloader |
| OnShareToolbar 1.0 | {B1A0CB06-2A5F-4D80-AAA2-1B05D78314CC} | L TB | OnShareTB.dll, ONSHAR~1.DLL | OnShare Toolbar |
| (no name) | {D51C7E20-6800-4AE7-9702-64D9021BFEC1} | L BHO | OpiekunIE.dll | Opiekun internet filtering software |
| Owlforce | {37E1A9E5-00D4-4203-8E58-B91F383A3809} | X BHO | Owlforce.dll, Ofb1.dll, Ofm.dll | OwlForce, search tool bundled with Phone7 VoIP software |
| &OCNcƒ[‹ƒoƒ[ | {F1D4BD3E-92CB-4c2f-B34A-748495A48A1F} | O TB | ocnstick.dll | ocn.ne_Toolbar - also see here |
| ShowBar Class | {3EBB6ECC-75A9-40F7-8A12-0845F0D4B98B} | L BHO | OutlinerBar.dll | Outliner IE Toolbar |
| psnr | {F7C6FC64-80B1-47E2-9A5C-C67051BBDD70} | ? BHO | OCRQCJM4.dll | Unidentified browser plugin - should you have any information about this application, such as its exact purpose and whether you did or did not install it wittingly, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks! |
| (no name) | {********-****-****-****-************} | X BHO | odexl32d.dll | WebPrefix adware variant |
| {D2000F80-ABC6-11D3-9794-0090274D4CCA} | O TB | OSIEHLPR.DLL | Onscan |
| IE | {616D534C-3CA8-43AB-B439-618F850F1D2B} | X BHO | odunbegy.dll, iksaps.dll, apsagy.dll, other semi-random filenames made up from the following fragments: ap, od, ik, sa, do, unbe, gy, ps, xu | Parasite redirecting to fake security sites, member of the FakeAlert aka SmitFraud malware family - produces IEDefender , FilesSecure , MalwareBell , IE_Antivirus or similar popups - also see here
|
| {88C5C070-8C60-4F45-9345-3Ffb96334Cad} | L BHO | Openwaresiepatch.dll, IEWorkaround.dll | Openwares IE patch
|
| Opiekun | {3453E1A9-9D23-4B6B-9222-4A4B5E1002C9} | L TB | OpiekunIE.dll | Opiekun internet filtering software |
| Zmtm Class | {8BC199B4-330D-4009-AB9C-D55AC919DE8D} | X BHO | otpddpea5.dll, OTPDDP~1.DLL | QuickLinks/LinkMaker adware variant - also detected as Adware.Suggestor |
| player addon | {4EBAA7B0-740D-4CFA-9455-5C233BB354E1} | X BHO | oggview32.dll | Downloader trojan, member of the FakeAlert aka SmitFraud malware family - produces IEDefender popups - also see here |
| Reactivator | {6C31790D-1EDF-4b05-83DC-925B3A8E2318} | L BHO | Ortodoxism.dll | Ortodoxism Toolbar, powered by AsesoftNet |
| MSVPS System | {27A5292F-0C87-4E81-A34E-3131DBFCE994} | X BHO | oprevmqp.dll, oprevxlw.dll | Zlob downloader variant, a member of the SmitFraud malware family |
| (no name) | {28B68635-4AFB-1629-8DF2-6754127DB19D} | X SH | OinBHO.dll | ClickSpring.Oinadserver adware component, responsable for Outerinfo.com popups |
| SSV | {69F6C0AE-0C78-4999-B6D1-62932A265C5D} | X BHO | onenasek.dll, unopek.dll, ssvanasus.dll, onepad.dll, other semi-random filenames composed of the following fragments: one, ssva, uno, nas, p, k, ek, ad, us | Parasite redirecting to fake security sites, member of the FakeAlert aka SmitFraud malware family - produces IEDefender , FilesSecure , MalwareBell , IE_Antivirus or similar popups - also see here |
| (no name) | {28B6F144-3F8D-6D2C-8D89-13546601B19D} | X BHO | OinBHO.dll | ClickSpring.Oinadserver adware component, responsable for Outerinfo.com popups |
| ozby toolbar | {BFB5F154-9212-46F3-B547-AC6106030A54} | O TB | ozby.dll, hidden.dll | Ozby.com Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Installer detected by Kaspersky antivirus as AdWare.Win32.Mostofate.ap and by Bitdefender as Adware.Softomate.CZ |
| Player | {B5307BCB-64A5-4416-9BC2-5AF01DB90123} | X BHO | orgnavi.dll | Downloader trojan causing false spyware warnings and connecting to fake "security sites", member of the FakeAlert aka SmitFraud malware family |
| TBSB06983 | {2351B5B3-BDF2-4C71-9080-2772BFCCCE1C} | O BHO | oyna55.dll | Oyna55.com toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Remove unless you both trust it and expressly meant to install it. |
| OSM Manager Bar | {BFB5F154-9212-46F3-B547-AC6106030A54} | O TB | osmtoolbar.dll, OSMTOO~1.DLL | Online_Soccer_Manager Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. |
| oohxdbyt.dll | {5B1AEF69-DDAE-FDAD-DCAB-698F026ABDB5} | X BHO | oohxdbyt.dll | Password stealer of Chinese origin detected by Trend Micro as TSPY_ONLINEG.FOK |
| OhOhPopupBHO Class | {D276DDCD-E489-4EDE-9EB1-AE19FCEC4469} | X BHO | ohohpopup.dll | Parasite of Korean origin hailing from ieshow.co.kr - detected as Win-Adware/OhPopup |
| (no name) | {********-****-****-****-************} | X BHO | odbcji42.dll | WebPrefix adware variant |
| (no name) | {55C2F147-498D-1058-8DF9-10541D7BB1E0} | X SH | OinBHO.dll | ClickSpring.Oinadserver adware component, responsible for Outerinfo.com popups
|
| oyna55 oyun Toolbar | {25F97EB4-1C02-45BA-BA0C-E67AACE64D4A} | O TB | oyna55.dll | Oyna55.com toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Remove unless you both trust it and expressly meant to install it. |
| MSVPS System | {F675EED8-4A4B-4A11-801B-08297749B83D} | X BHO | oprevnpx.dll | Zlob downloader variant, a member of the SmitFraud malware family |
| player addon | {9DEC81A1-919F-41F0-A983-7F202E3EBBB3} | X BHO | oggview32.dll | Downloader trojan, member of the FakeAlert aka SmitFraud malware family - produces IEDefender or similar popups - also see here |
| SVC plugin | {64C94B46-1079-4C75-BE9B-380F6AE7624C} | X BHO | oddops.dll, apunbegy.dll, oddogy.dll, apsagy.dll, other semi-random filenames made up from the following fragments: ap, od, ik, na, do, unbe, gy, ps, xu | Parasite redirecting to fake security sites, member of the FakeAlert aka SmitFraud malware family - produces IEDefender , FilesSecure , MalwareBell , IE_Antivirus or similar popups - also see here
|
| OLWebProfile.Block | {2F7C3A7D-380A-4960-853C-C7980F6D816E} | L BHO | OlWebProfile.dll | MultiResource Client "Onelog" authentication plugin |
| (no name) | {********-****-****-****-************} | X BHO | openwin.dll (random Class ID) | CoolWebSearch parasite variant |
| TBSB09291 | {F7B09E8C-402E-45FB-A335-C042B5A3D7FF} | L BHO | oo_dashboard_v2.2.dll | OpinionLab software |
| oohxbbyt.dll | {3B1AEF69-DDAE-FDAD-DCAB-698F026ABDB3} | X BHO | oohxbbyt.dll | Password stealer of Chinese origin detected by Trend Micro as TSPY_ONLINEG.FOK |
| Player | {FC2458DB-B263-48C5-A106-0651B05DF38C} | X BHO | orgnavi.dll | Downloader trojan causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family |
| olado Toolbar von Ashampoo | {1CBF31FC-3C23-4BA6-AF16-2CEC501BD837} | O TB SH | olado.dll | Ashampoo/Olado Shopping toolbar |
| storiaguide | {8D0F678F-FFA1-44FE-8DA1-F2E5FE840D13} | X EB | ombar.dll | "Internet Explorer Guide" web search software of Korean origin hailing from Ieguide.kr, detected as "IEGuide" adware, also see here |
| OGG Viewer | {7AB85EC7-22E7-4B5D-89DA-A9EBD1AF3520} | X BHO | oggview.dll | Downloader trojan, member of the FakeAlert aka SmitFraud malware family - produces IEDefender popups - also see here |
| XBTP06129 | {5CF2592E-ADCA-4091-97B5-304564C14A64} | O BHO | opplysningen1881_ie.dll, OPPLYS~1.DLL | Opplysningen_1881 toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. |
| Windows OpenSearch | {793E0B8F-9387-4C53-8F0B-A903B72EDA63} | X TB | OpBand.dll | Parasite detected by Ahnlab antivirus as Win-Downloader/OpenSearch.155648 |
| Player | {84885FC9-44B0-4953-98F9-166E048B7052} | X BHO | orgnavi.dll | Downloader trojan causing false spyware warnings - member of the FakeAlert aka SmitFraud malware family |
| Orange | {4E7BD74F-2B8D-469E-A6FB-F862B587B57D} | L BHO TB | orange4.dll | Orange search toolbar |
| (no name) | {58B28244-4FFE-6324-8D88-1054167DB192} | X SH | OinBHO.dll | ClickSpring.Oinadserver adware component, responsable for Outerinfo.com popups |