| OBJECT NAME | GUID | STATUS | FILENAME | DESCRIPTION |
|---|
| pvnsmfor | {59EC7E90-81DE-40EC-B1EB-93E3CA3AD395} | X TB | pvnsmfor.dll | Parasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family |
| XBTP04197 | {335230F7-C28F-41dc-B851-0605B06DF44B} | O BHO | phatbar2.dll | Phatbar_Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Some of the toolbars are fine to have, so every case is different. Your choice. |
| PowerSearch | {4E7BD74F-2B8D-469E-D1F0-E56FA787AD2D} | X TB | pwrscznc.dll | KeenValue PowerSearch adware variant, also see here |
| &Paessler Site Inspector 4 Toolbar | {EC3A37EF-F4CF-447A-B0FD-206073E2DAE9} | L TB | psitoolbar.dll , PSITOO~1.DLL | Paessler Site Inspector |
| pjjxddwd.dll | {44FAE856-AD58-20CB-A025-CD4895FA6E44} | X BHO | pjjxddwd.dll | Password stealer of Chinese origin detected by Trend Micro as TSPY_ONLINEG.FOK
|
| XBTB09393 Class | {1006E3B9-F7C8-4cb6-AFDB-EEE844FE1259} | O BHO | pagesconso_toolbar.dll, PAGESC~1.DLL | PagesConso.com toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Your choice. |
| Video decompressor | {0B686DCA-F3F7-4829-8EB4-B453EEEA7B05} | X BHO | pandsf.dll | Downloader trojan causing false spyware warnings - member of the FakeAlert aka SmitFraud malware family |
| SysShield IE Popup Blocker | {9A23B8A4-C6C9-4A68-8FA6-5F905DC8FF80} | L BHO | PKExt.dll | AbsoluteShield IE Popup blocker |
| PSH.PSHelper | {1A0884BA-B25E-4E7A-8F87-453172DBBFD0} | L BHO | PSH.dll | Password Saver |
| Praize toolbar | {C6335B00-E8D9-423e-A691-48D17CBB6C5A} | X TB | Praizetoolbar.dll | PraizeToolbar adware |
| PhishGuard.Helper | {8B50176C-DD6E-4C14-A603-727A859337CD} | L BHO | PhishGuardHelper.dll | PhishGuard |
| Pars IE Module Initializer | {D3B7BD81-3E02-4cd8-8E52-1CDB835BE087} | L BHO | parsiexp.dll | Lingvistica "Pars" translation software |
| HTML Source Editor | {EB3968F4-72F5-4f8c-B4EA-8C99CEE27DBA} | L BHO | PrefetchBHO.dll | AirH by Sourcenext |
| Pluck Helper | {7385D9F8-418B-4e6a-938F-F7596857CB54} | L TB | PluckExplorerBar.dll | Pluck Toolbar |
| PicLens plug-in for Internet Explorer | {EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA} | L BHO | PicLens.dll | CoolIris PicLens |
| pwn plugin | {4AAC4708-FE47-4B80-92EF-47406444DDD2} | X BHO | pwnbho.dll | Downloader trojan, member of the FakeAlert aka SmitFraud malware family - produces IEDefender popups - also see here |
| &PC-WELT | {42DFCA97-ED3F-4984-99BB-9C6E67B737A8} | L TB | pcwBand2.dll | PCWBand2 - Software provided by PC-WELT - also see here |
| Op pro, nop Class | {537E69E9-ACE1-43e3-8659-06811DFE0BCC} | X BHO | per.dll, sys.dll, sys32.dll | OpenSearch adware |
| PPGouCatcher | {00000000-0000-0000-0000-E58E57C9C848} | L BHO | PPGouIEDown2.dll, PPGOUI~1.DLL, PPGOUI~2.DLL, PPGOUI~*.DLL | PPGou p2p client and download accelerator |
| ToolBar Class | {B111AF88-E1AA-48D9-8FF9-159B057FDCD6} | X TB | pluscashbag.dll | Parasite of Korean origin, detected as PlusCashbag or PlusCB adware |
| Video On-line | {7E4C5F57-FF13-4006-A5F6-BE97D9CD6261} | X BHO | PowerVideo.dll | Downloader trojan, member of the FakeAlert aka SmitFraud malware family - produces IEDefender popups - also see here |
| {790C1F44-C559-434B-BE18-13C042555D8E} | L TB | PhoneShell.dll | Telefoongids |
| PNLoader.IEHelperClass | {748A5D0A-68D3-11D4-A67E-00E098823A80} | L BHO | pnloader.dll | PopNot |
| PolicyMaker Browser Helper | {0A9CDB52-EBDF-4210-9C6A-B90C2FD410AB} | L BHO | pmbho.dll | PolicyMaker Application Security 2.0 by BeyondTrust_Privilege_Manager |
| Platrium | {B12ACA14-C7FB-44FE-883B-6121FD02BAD3} | X BHO | Platrium.dll | Platrium - Collection of programs (games toolbar, sidesearch add-on, & weather program) that is supported by desktop pop-up advertising |
| XBTP07646 | {9A5152BA-6D72-4293-BB53-CBE60BCD8593} | X BHO | pics-factory.dll, PICS-F~1.DLL | PicsFactory adware |
| FFDP Toolbar | {4E7BD74F-2B8D-469E-B9DB-CC39F0D3F960} | O BHO TB | prodegetoolbar***.dll, PRODEG~*.DLL | FFDP Toolbar - a Prodege_Toolbar by Visicom Media |
| PolyMeta kereső | {F0C7C904-A309-42a0-9FCA-40B9A85D1025} | O TB | PolyMetaSearchBar_Hun.dll | PolyMeta SearchSmart |
| IEHlprObj Class | {23C2B10E-9ACE-11D5-B0A7-00E0296405CB} | ? BHO | PKPRHTML.dll | Unidentified browser plugin - should you have any information about this application, such as its exact purpose and whether you did or did not install it wittingly, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks! |
| PluswordBHO | {A7407398-8E5D-4CE9-BFAC-5C22637426F0} | X BHO | plusword.dll | Parasite of Korean origin, detected as Win32.Spyware.plusword |
| (no name) | {********-****-****-****-************} | X BHO | perfos32.dll | WebPrefix adware variant |
| Plugin | {5F8BAA39-4F80-4df5-BA18-6477CDAAC53E} | X BHO | paranorm.dll, sokoban.dll | Parasite, detected as Adware.BHO.MSMic - also see here |
| PeoplePal Toolbar | {A8FB8EB3-183B-4598-924D-86F0E5E37085} | X BHO TB | PPCToolbar.dll, PPCToolbar_*.*.*.**.dll (* = digit) | People_PC/PAL toolbar |
| (no name) | {C7CF1142-0785-4B12-A280-B64681E4D45E} | X BHO | prflbmsgp32.dll | Variant of the Win32.Delf downloader trojan |
| CIEIntegrator Object | {5C3F6257-3E00-45C2-88D5-CB0F3A17BF0E} | X BHO | pblock.dll | WinSpyControl - rogue "security software" using false positives as a goad to purchase |
| PowerSearch | {4E7BD74F-2B8D-469E-D4FF-ED78A787AD2D} | X BHO TB | pwrstraf.dll | KeenValue PowerSearch adware variant, also see here |
| &Proxy Toolbar | {21521694-BD6F-11DB-8C39-117D55D89593} | L TB | ProxyToolbar.dll | Proxy_Toolbar - also see here |
| Phishing Inspector | {63D687A8-0913-49DE-9EAF-9ABF2D384BD6} | L BHO | PhishingInspector.dll | Phishing Inspector |
| Kanye West Toolbar | {4E7BD74F-2B8D-469E-BDD9-CC39F0D3F960} | O BHO TB | prodegetoolbar***.dll, PRODEG~*.DLL | Kanye_West Toolbar - a Prodege_Toolbar by Visicom Media |
| RocketMyWeb | {3FE0A87E-5672-4582-9DD7-01D5B2B89D24} | L BHO | PTBar.dll | Rocket Mobile & Security Center |
| e404 helper | {F10587E9-0E47-4CBE-84AE-7DD20B8684BB} | X BHO | prolooker.dll, TURBOS~1.DLL, powerwebfind.dll, mastersearchsite.dll | Parasite, a member of the Trojan-Downloader.Zlob.Media-Codec aka NewMediaCodec malware family - detected as Trackware.ProSearch |
| PT Corporate Bar | {5F1ABCDB-A875-46c1-8345-B72A4567E486} | ? BHO TB | PTCorpBar.dll | Unidentified Toolbar, file present in %Windir% folder - should you have any information about this application, such as its exact purpose and whether you did or did not install it wittingly, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks! |
| PLAsim plugin | {F60777DA-D6A6-40F6-B665-6F361C1017B6} | X BHO | poswin.dll | Downloader trojan, member of the FakeAlert aka SmitFraud malware family - produces IEDefender popups - also see here |
| PornTubeViewer.exe | {85493D9B-A4A2-478C-B36F-B729202DF748} | X TB | porntubeviewer.dll | PornTubeViewer - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. |
| BHO | {F41E9234-774D-407d-B8C8-7E6C16FE108B} | X BHO | plugin.dll | Topbrowsing.com adware, see here |
| AdsCleaner Links Bar | {A8415B7A-F661-4D31-92D7-4398E50483DF} | L TB | Pakiegui.dll | AdsCleaner |
| PPGou BHO | {00000000-0000-0000-0000-C4CA9A05F1E2} | L BHO | ppgiecom*.dll, PPGIEC~*.DLL, PPG2IE~1.DLL | PPGou p2p client and download accelerator |
| JavaScript Author | {4DC66C8F-1B6B-44D6-A9C2-7938DE41ADA3} | X BHO | pidgen.ocx | Unidentified parasite - should you have any information about this application, such as for example the site where it was downloaded or installed, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks! |
| PBlockHelper Class | {4115122B-85FF-4DD3-9515-F075BEDE5EB5} | L BHO | PBHelper.dll | SlipStream_Web_Accelerator - file located in the "Program Files\SlipStream Web Accelerator" folder |
| PopSmasherNoTlbrObj Class | {0025739A-5875-4e33-8056-C03BABE37F9C} | L BHO | PS.dll | AT&T Worldnet Service toolbar |
| Pando Search Assistant BHO | {06663B51-0D73-4f9f-BCC5-4AA941470AFD} | O BHO SH | P4SRCHAS.DLL | Pando P2P software - adware supported |
| (no name) | {********-****-****-****-************} | X BHO | ProSiteFinder.dll (random Class ID) | 180Solutions ProSiteFinder adware - also see this_note |
| AMUST 1-Login IE Helper | {FFF1A4CB-472E-404a-9898-0B73B6B2E421} | L BHO | PMIEObjects.dll | AMUST_1-Login - A password manager |
| Swag Bucks Toolbar | {4E7BD74F-2B8D-469E-BDD2-CC39F0D3F960} | O BHO TB | prodegetoolbar***.dll, PRODEG~*.DLL | Swag_Bucks Toolbar - a Prodege_Toolbar by Visicom Media |
| pvnsmfor | {C17C95A8-9A32-4250-8F46-D7DFBB4B4947} | X TB | pvnsmfor.dll | Parasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family |