CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

spacer spacer

The CLSID / BHO List / Toolbar Master List

Currently 54019 entries and growing...

This is the Master BHO and Toolbar list copyrighted by Tony Klein and CastleCops. For expert assistance, please post here. The information is collected across the Internet by the CastleCops Team. Usage: please leave feedback requesting permission if you are interested in using this data beyond the approved channels.

BHOList - ToolbarList

KEY:
  • "X" - Certified spyware/foistware, or other malware
  • "L" - Legitimate items
  • "O" - Open to debate
  • "?" - Unknown Status
  • "BHO" - Browser Helper Object
  • "TB" - Toolbar
  • "SH" - R3 URL SearchHook
  • "EB" - IE Explorer Bar

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z

    Random sampling...
    OBJECT NAMEGUIDSTATUSFILENAMEDESCRIPTION
    BndBlock4 BHO Class{8F9E2BE3-766D-4831-BB0E-766D5B819995}X BHO QdrDrive9.dll"Hyperlinks Rotator" aka ISMonitor adware hailing from zredirector.com - installs a "Internet Speed Monitor" sidebar - file detected by Kaspersky antivirus as a variant of AdWare.Win32.AdBand
    QQCycloneHelper Class{0FA24E3D-422C-4D94-A125-104F32352C90}X BHO QQIEHelper01.dll, QQIEHelper02.dll TencentAddressBar adware - bundled with the Tencent_QQ instant messaging client
    qtvglped{1358BEF5-2BCF-469D-A33E-E967387862D6}X TB qtvglped.dllParasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    QQCycloneHelper Class{00000000-127B-4305-82F9-43058F20E8D2}X BHO QQIEHelper01.dll, QQIEHelper02.dll TencentAddressBar adware - bundled with the Tencent_QQ instant messaging client
    Internet Speed Monitor{180175C0-913E-451c-9419-2D5500368D43}X EBQdrDrive20.dll"Hyperlinks Rotator" aka ISMonitor adware - installs a "Internet Speed Monitor" sidebar - detected by Kaspersky antivirus as AdWare.Win32.AdBand.a
    qvdntlmw {F243E888-02D6-4E4F-A51B-0824109ACCB7}X TB qvdntlmw.dllParasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    DVA Storm{38A36BC9-15D0-4EA0-ABA2-CEE104719DFF}X BHO qnmargolbve.dllAdware downloader causing false spyware warnings and connecting to rogue "security sites", a member of the Trojan-Downloader.Zlob.Media-Codec aka NewMediaCodec malware family
    H{8EF45F60-7FD5-4724-90BB-BB72335007B3}X BHO q24m.dll, re_.dllVariant of the Infostealer.Banker.D trojan
    DVA Gate {D1DE7404-BFDF-430B-AB48-3EBF39F05C9F}X BHO qnmargolwdn.dllAdware downloader causing false spyware warnings and connecting to rogue "security sites", a member of the Trojan-Downloader.Zlob.Media-Codec aka NewMediaCodec malware family
    (no name){28A0F341-2711-82C5-F8DF-032A36D42E96}X BHO qgfalzg.dllVariant of the DisableKey.A aka Busky downloader trojan
    QQCycloneHelper Class{00000000-1297-4305-82F9-43058F20E8D2}X BHO QQIEHelper01.dll, QQIEHelper02.dll TencentAddressBar adware - bundled with the Tencent_QQ instant messaging client
    QQ???({FC1DF328-F720-4FD3-98A4-2595A7356D7F}? TB QQSST.dllUnidentified toolbar of Chinese origin - should you have any information about this application, such as its homepage, or the site where it was downloaded or installed, its exact purpose and whether you did or did not install it wittingly, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks!
    QQ6LinkToActWebBHO{E287205F-B1BD-4AFC-A134-8E3075300B89}? BHO QQ6LinksActWebBHO.dll Unidentified browser plugin - should you have any information about this application, such as its exact purpose and whether you did or did not install it wittingly, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks!
    QQCycloneHelper{00000000-1285-4305-82F9-43058F20E8D2}X BHO QQIEHelper01.dll, QQIEHelper02.dll TencentAddressBar adware - bundled with the Tencent_QQ instant messaging client
    QQCycloneHelper Class{C56CB6AF-0D96-11D6-8C65-B2868B609932}X BHO QQIEHelper01.dll, QQIEHelper02.dll TencentAddressBar adware - bundled with the Tencent_QQ instant messaging client
    (no name){7B55BB05-0B4D-44fd-81A6-B136188F5DEB}X BHO questmod.dll, questmod-1.dll SA adware
    qndsfmao{FC64D173-5A2F-4840-991D-CE64FAD8D132}X TB qndsfmao.dllParasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    Quick!{4E7BD74F-2B8D-469E-C0FF-FD67B79CAF2C}X BHO TB quickbar.dll New.Net QuickBar adware - also see this_note
    H{D4E2516F-A030-49a7-9500-3EDA3891793D}X BHO qwdsfref.dllVariant of the Infostealer.Banker.D trojan
    qvdntlmw{6D77BB31-31C7-4900-9385-85CF45035131}X TB qvdntlmw.dllParasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    QBoxtbStarter Class{679B72EA-B257-4FB6-B176-0F84604B6F11}O BHO qboxtb.dllPart of Qbox_Media_Player software
    XBTB08408{7413FDA3-644E-431a-B481-46F635FDE856}O BHO qwika-final.dll, QWIKA-~1.DLL Qwika.com toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this.
    qvdntlmw{581D3CD5-E6DD-48AA-A993-5FD9F73F7831}X TB qvdntlmw.dllParasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    QQCycloneHelper Class{75BED22B-339D-4827-BA51-ECD7B55A8792}X BHO QQIEHelper01.dll, QQIEHelper02.dll TencentAddressBar adware - bundled with the Tencent_QQ instant messaging client
    QQCycloneHelper Class{00000000-1162-4305-82F9-43058F20E8D2}X BHO QQIEHelper01.dll, QQIEHelper02.dll TencentAddressBar adware - bundled with the Tencent_QQ instant messaging client
    {965E6B07-6832-4738-BDBE-25F226BA2AB0}X TB Qabar.dll QCbar/AdultLinks adware variant
    {CF021F40-3E14-23A5-CBA2-717177654820}X BHO qwe4820.dllMakeMeSearch aka Tubby/Arau adware variant
    (no name){********-****-****-****-************}X SH qwe.dll WareOut malware component
    qndsfmao{9A3D91FB-FCF6-46A4-A0C2-B4865D8D05DC}X TB qndsfmao.dllParasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    QQCycloneHelper Class{38928D4F-8A48-44C2-945F-D2F23F771410}X BHO QQIEHelper01.dll, QQIEHelper02.dll TencentAddressBar adware - bundled with the Tencent_QQ instant messaging client
    QQCycloneHelper{00000000-12C5-4305-82F9-43058F20E8D2}X BHO QQIEHelper01.dll, QQIEHelper02.dll TencentAddressBar adware - bundled with the Tencent_QQ instant messaging client
    BeSideit IE Helper{83C35173-E029-42f1-9692-0341EE379A0D}X BHO QdrDrive16.dll"Hyperlinks Rotator" aka ISMonitor adware hailing from zredirector.com - installs a "Internet Speed Monitor" sidebar - detected by Kaspersky antivirus as AdWare.Win32.AdBand.a
    QQCycloneHelper Class{7E853D71-626A-48EC-A868-BA8D5E23E045}X BHO QQIEHelper01.dll, QQIEHelper02.dll TencentAddressBar adware - bundled with the Tencent_QQ instant messaging client
    DVA First{D23BF150-4C7B-4632-A723-DC604C2A47FB}O BHO qvlbodmnbew.dllAdware downloader causing false spyware warnings and connecting to rogue "security sites", a member of the Trojan-Downloader.Zlob.Media-Codec aka NewMediaCodec malware family
    QQCycloneHelper Class{77FEF28D-EB96-44FF-B511-3185DEA48697}X BHO QQIEHelper01.dll, QQIEHelper02.dll TencentAddressBar adware - bundled with the Tencent_QQ instant messaging client
    qndsfmao{FCCD9F7B-5BF3-4DC4-B131-CE069F8A62AB}X TB qndsfmao.dllParasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    QQCycloneHelper{00000000-12BD-4305-82F9-43058F20E8D2}X BHO QQIEHelper01.dll, QQIEHelper02.dll TencentAddressBar adware - bundled with the Tencent_QQ instant messaging client
    5940.cn??{6144F1E9-C6D4-4FF3-9008-AA43F3D287AC}X TB qq3818201Toolbar.dll, QQ3818~1.DLLParasite/homepage hijacker of Chinese orgin, hailing from 5940.cn
    QQCycloneHelper Class{06849E9E-C8D7-4D59-B87D-784B7D6BE0B3}X BHO QQIEHelper01.dll, QQIEHelper02.dll TencentAddressBar adware - bundled with the Tencent_QQ instant messaging client
    qndsfmao{267E332F-1684-4B6F-813E-186EEEE7F247}X TB qndsfmao.dllParasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    qiawpbjj.msdn_hlp{66E72884-4FD2-464F-A6B8-468F31C40E36}X BHO qiawpbjj.dllDownloader trojan, member of the FakeAlert aka SmitFraud malware family
    Quepasa 2.0{4E7BD74F-2B8D-469E-A0FF-EC6DA490AF2C}O TB quepasa2.dll Quepasa_Toolbar - also see here
    &QuickBar{0CD774FE-B25B-45AA-A16C-F6500E8A7B50}X TB Quickbar.dllParasite of Korean origin hailing from quickbar.co.kr, and detected as QuickBar adware
    qvdntlmw {8BD58549-BB16-480E-8530-3F957AE09B51}X TB qvdntlmw.dllParasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    H{BE639B7E-59E1-4e6f-9E1F-5F9D7DF29176}X BHO qwe123434.dllVariant of the Infostealer.Banker.D trojan
    BndFibu7 IE Helper{8041E642-8CFC-4720-BC9D-D2DB8904286F}X BHO QdrDrive12.dll"Hyperlinks Rotator" aka ISMonitor adware hailing from zredirector.com - installs a "Internet Speed Monitor" sidebar - detected by Kaspersky antivirus as AdWare.Win32.AdBand.a
    QQCycloneHelper Class{385AB8C5-FB22-4D17-8834-064E2BA0A6F0}X BHO QQIEHelper01.dll, QQIEHelper02.dll TencentAddressBar adware - bundled with the Tencent_QQ instant messaging client
    QQCycloneHelper{4E8A5277-C04E-4FE3-BF78-8A7CCD6EF333}X BHO QQIEHelper01.dll, QQIEHelper02.dll TencentAddressBar adware - bundled with the Tencent_QQ instant messaging client
    QSupport Class{7C3A71BA-2979-45AC-926C-9AC0098F9127}X BHO qserchcom.dllParasite, detected as Win-Adware/ToolBar.QSearch
    DVA Gate{66F72B26-DA47-4B7C-A2E1-5046043496B5}X BHO qnmargoldpq.dllAdware downloader causing false spyware warnings and connecting to rogue "security sites", a member of the Trojan-Downloader.Zlob.Media-Codec aka NewMediaCodec malware family
    QQCycloneHelper{00000000-12A5-4305-82F9-43058F20E8D2}X BHO QQIEHelper01.dll, QQIEHelper02.dll TencentAddressBar adware - bundled with the Tencent_QQ instant messaging client
    MSVPS System{D3936AE2-494C-4D80-A4A3-702B63C30104}X BHO qnxplugin.dll MyGeek/Cpvfeed.com adware variant, detected by Kaspersky antivirus as AdWare.Win32.Agent.bn - logs search engine queries to a %Windir%\search_res.txt file. Also see here
    QQCycloneHelper Class{00000000-12C9-4305-82F9-43058F20E8D1}X BHO QQIEHelper01.dll, QQIEHelper02.dll TencentAddressBar adware - bundled with the Tencent_QQ instant messaging client
    [full path to file]{7A7E6D97-B492-4884-9ABB-C31281DCC4F2}X BHO q********.dll (* = random digit)Adware downloader, detected as the DLOADER.AHD trojan
    QQCycloneHelper{089FD14C-132B-48FC-8861-0048AE113215}X BHO QQIEHelper01.dll, QQIEHelper02.dll TencentAddressBar adware - bundled with the Tencent_QQ instant messaging client

    spacer spacer