CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

spacer spacer

The CLSID / BHO List / Toolbar Master List

Currently 54019 entries and growing...

This is the Master BHO and Toolbar list copyrighted by Tony Klein and CastleCops. For expert assistance, please post here. The information is collected across the Internet by the CastleCops Team. Usage: please leave feedback requesting permission if you are interested in using this data beyond the approved channels.

BHOList - ToolbarList

KEY:
  • "X" - Certified spyware/foistware, or other malware
  • "L" - Legitimate items
  • "O" - Open to debate
  • "?" - Unknown Status
  • "BHO" - Browser Helper Object
  • "TB" - Toolbar
  • "SH" - R3 URL SearchHook
  • "EB" - IE Explorer Bar

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z

    Random sampling...
    OBJECT NAMEGUIDSTATUSFILENAMEDESCRIPTION
    Yahoo Bar{A697BC46-BC93-4833-93F5-1E365011E88A}X BHO ODBINT.dll, clearsDemo.dll TROJ_CLICKER.ET trojan
    oswxattb.dll{13512378-9874-5641-1025-985420368731}X BHO oswxattb.dllPassword stealer of Chinese origin detected by Trend Micro as TSPY_ONLINEG.FOK
    mIRC Addon{20222418-0727-4AD7-9B49-828A739CF858}X BHO opa.dll, msram.dllAdware downloader, a member of the Trojan-Downloader.Zlob.Media-Codec aka NewMediaCodec malware family
    Onfolio Helper{ba727652-f90e-4d82-9ce4-98766dffc375}L BHO onfoliox.dllOnFolio
    okcashbackmall.com{1DDE8A86-89D8-4B55-A936-65C40B6A8DD0}X BHO okcashbackmall.dll, OKCASH~1.DLLParasite of Korean origin hailing from okcashbackmall.com and identified as Adware.OKcashBackMall
    oswxdttb.dll{43512378-9874-5641-1025-985420368734}X BHO oswxdttb.dllPassword stealer of Chinese origin detected by Trend Micro as TSPY_ONLINEG.FOK
    O-Card Utility{B88D6F42-A1AC-11D3-8424-00105A9B8D85}L BHO oichlpr.dllOrbiscom O-card Software
    chob Class{363E6889-1F64-497D-992B-2AF83B591118}X BHO ori.dllParasite of Korean origin detected as SideLinker adware
    Player{FC2458DB-B263-48C5-A106-0651B05DF38C}X BHO orgnavi.dllDownloader trojan causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    (no name){0019C3E2-DD48-4A6D-AB2D-8D32436313D9}X BHO oo4.dll, bsx5.dll BookedSpace adware variant
    Voice Soft {C313CF73-125F-3562-44FC-E755D912C63C}X BHO ole32.dllVariant of the Troj/BHO-CS trojan - file located in the "%WinDir%\Media" folder
    Orange{4E7BD74F-2B8D-469E-A3FB-F862B587B57D}L BHO TB orange1.dllOrange toolbar - see here or here
    (no name){********-****-****-****-************}X BHO ole232.dllWin32.Stud aka WebPrefix adware variant
    VPN-OEM Extension{11D003B5-B3B5-4BCC-A974-71148786E968}O BHO olescn16.dll, nvrcr16.dll, msuieng.dll, msexchdr.dll SpectorSoft computer monitoring software
    onsidebar system{D664CBB4-AC74-4599-B456-0D774457B520}X EBonsidebar.dllParasite of Korean origin hailing from onsidebar.com and detected as Adware.OnsideBar
    ooVoo Toolbar{A057A204-BACC-4D26-8087-36EE87E26986}O BHO TB OOVOOT~1.DLL, oovooToolbar.dll oovoo_Toolbar - a VMN_Toolbar variant by Visicom Media
    XBTB08033{AAAE1C1A-89F7-4AF6-ABD1-F8FBCFA47408}O BHO osmtoolbar.dll, OSMTOO~1.DLL Online_Soccer_Manager Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this.
    OsmBrowser Class{7CEFF536-1623-4029-BEA4-7D4933DD72B4}? BHO osmieu.dll Unidentified browser plugin, file located in a "Program Files\Alacris\Osmium\bin" folder - should you have any information about this application, such as its homepage or the site where it was downloaded or installed, its exact purpose and whether you did or did not install it wittingly, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks!
    OffSurf Proxy{A6790AA5-1213-4BCF-A46D-0FDAC4EA90EB}L BHO OffSurf.dllOffSurf Proxy
    OGG Viewer{82FE0677-75EC-49BF-83E9-A815F68F6212}X BHO oggview.dllDownloader trojan, member of the FakeAlert aka SmitFraud malware family - produces IEDefender popups - also see here
    (no name){5FC3F136-4F88-1659-8DF2-1554677BB191}X BHO OinBHO.dll ClickSpring.Oinadserver adware component, responsable for Outerinfo.com popups
    OSM Manager Bar{E828EC21-EAA9-44B3-8021-EE89101C6ACD}O TB osmtoolbar.dll, OSMTOO~1.DLL Online_Soccer_Manager Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this.
    OmniMedicalSearch Toolbar{8B2666D9-E1FA-4F38-B571-FC3181D9F0C8}L TB OMSTOO~1.DLL, OMSToolbar.dll OmniMedicalSearch Toolbar
    oohxcbyt.dll{4B1AEF69-DDAE-FDAD-DCAB-698F026ABDB4}X BHO oohxcbyt.dllPassword stealer of Chinese origin detected by Trend Micro as TSPY_ONLINEG.FOK
    {88C5C070-8C60-4F45-9345-3Ffb96334Cad}L BHO Openwaresiepatch.dll, IEWorkaround.dllOpenwares IE patch
    MSVPS System{D5375315-6567-4DCA-8344-C78AA4B89C11}X BHO oprevfqv.dll Zlob downloader variant, a member of the SmitFraud malware family
    optionsXpress Toolbar{63CC63C6-1AE1-491C-B96A-812A7950A1EC}L TB optionsXpressToolbar.dlloptionsXpress Toolbar
    GamesBarBHO Class{CB0D163C-E9F4-4236-9496-0597E24B23A5}X BHO oberontb.dll Oberon_Media gamesbar, a Zango/Hotbar adware variant
    Internet Explorer OneGuide{61995404-D92F-4A03-9F98-BCCB368E3DAA}X BHO oneguide.dll"Internet Explorer OneGuide" web search software of Korean origin hailing from Oneguide.co.kr - detected as Win32.Spyware.OneGuide
    IEyeOnIE Class{AEC6C206-8B4A-4203-A5E2-F16174D46422}? BHO OPACPL~1.DLL, OpacPlugIn.dllUnidentified browser plugin, file present in "Program Files\EMLib3" folder - should you have any information about this application, such as its exact purpose and whether you did or did not install it wittingly, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks!
    URLSearch Class{965A592F-8EFA-4250-8630-7960230792F1}X SH omdsn.dll PowerStrip adware component
    OGG Viewer{FBFE32FE-4ED6-4099-A087-8C238B714831}X BHO oggview.dllDownloader trojan, member of the FakeAlert aka SmitFraud malware family - produces IEDefender popups - also see here
    onsidebar.com{9440CEA7-AE85-4866-B114-C1C61B5454E8}X BHO onside.dllParasite of Korean origin hailing from onsidebar.com and detected as Adware.OnsideBar
    Ortodoxism Toolbar{977b1a99-0c65-45c6-909a-10eda8b7db8f}L TB Ortodoxism.dllOrtodoxism Toolbar, powered by AsesoftNet
    AbnDebSink Class{CFD1FB3B-963E-4774-921C-5043C437E3AE}X BHO orca11.dllVariant of the TROJ_AGENT.XTN trojan
    XBTB08158{12C94DE4-5CE2-4a2d-A493-2C8D5B00AB18}O BHO onlinearabic_toolbar_turkce.dll, ONLINE~1.DLL Www.onlinearabic.net_Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this.
    ozfycbyt.dll{3A069845-2036-6084-9054-6087502480A3}X BHO ozfycbyt.dllPassword stealer of Chinese origin detected by Trend Micro as TSPY_ONLINEG.FOK
    Player {E5AF0624-F539-47D9-BA37-D8B339E858F4}X BHO orgnavi.dllDownloader trojan causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    (no name){********-****-****-****-************}X BHO olf2disp.dll WebPrefix adware variant
    XBTBPos00{30351581-82FC-42FC-8041-5749A309557F}O BHO oyunhileleri.com.dll, OYUNHI~1.DLL Oyunhileleri.com Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Remove unless you both trust it and expressly meant to install it.
    ofb1{639CCF76-CACA-4a1e-BFA1-7DF0D5EC2FA1}X BHO Ofb1s.dll, Ofb1w.dllDownloader, detected by Bitdefender antivirus as Trojan.Clicker.OwlForce.A
    OnLetterhead Toolbar{C66BE3BA-0A75-4db1-A988-ACE7087CA121}L TB olhieplg.dllOnLetterhead
    (no name){********-****-****-****-************}X BHO openwin.dll (random Class ID) CoolWebSearch parasite variant
    OKTE{88CFEFCD-CA04-4D50-84D9-2A7083E63AE4}? TB OKTIET~1.DLL, oktieToolbar.dllOkteSchHook/Oktie.Toolbar software from axdisk.cn - Unidentified browser plugin - should you have any information about this application, such as its exact purpose and whether you did or did not install it wittingly, do email us. Thanks!
    OnMuz2BHO{012246F2-A06C-4039-8C4E-24A14D702D8B}X BHO ombho.dll"Internet Explorer Guide" web search software of Korean origin hailing from Ieguide.kr, detected as "IEGuide" adware, also see here
    (no name){5BC18644-41FD-1622-8DFD-1054637EB195}X SH OinBHO.dll ClickSpring.Oinadserver adware component, responsible for Outerinfo.com popups
    oohxebyt.dll{6B1AEF69-DDAE-FDAD-DCAB-698F026ABDB6}X BHO oohxebyt.dllPassword stealer trojan of Chinese origin detected as Trojan-PWS.OnlineGames.ADRD
    MSVPS System{27A5292F-0C87-4E81-A34E-3131DBFCE994}X BHO oprevmqp.dll, oprevxlw.dll Zlob downloader variant, a member of the SmitFraud malware family
    OTSI Class{85CC6BFF-5A5C-4A76-8FC8-DB0787DF1597}X BHO OTS.dllParasite of Korean origin detected as SBSToolBar spyware
    btorbit.com, Octh Class{000123B4-9B42-4900-B3F7-F4B073EFC214}L BHO orbitcth.dllOrbit Downloader
    OnShareToolbar 1.0{B1A0CB06-2A5F-4D80-AAA2-1B05D78314CC}L TB OnShareTB.dll, ONSHAR~1.DLLOnShare Toolbar
    opshbbty.dll{22596546-2036-9451-6058-658402589722}X BHO opshbbty.dllPassword stealer of Chinese origin detected by Trend Micro as TSPY_ONLINEG.FOK
    SVC plugin{7EA5E375-6136-496E-9616-E03B4F9EA1C0}X BHO oddoxu.dll, apsagy.dll, other semi-random filenames made up from the following fragments: ap, od, ik, na, do, unbe, gy, ps, xuParasite redirecting to fake security sites, member of the FakeAlert aka SmitFraud malware family - produces IEDefender , FilesSecure , MalwareBell , IE_Antivirus or similar popups - also see here
    (no name){2E9D4C81-9F27-4c14-B804-7B0F6BC88A4F}X BHO Outerinfo.dll ClickSpring "Oinadserver" adware
    okcashback system{C3C7C84F-2E47-47E7-A596-6919C30662FE}X BHO okcashbackmallr.dll, OKCASH~1.DLLParasite of Korean origin hailing from okcashbackmall.com and identified as Adware.OKcashBackMall

    spacer spacer