CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

spacer spacer

The CLSID / BHO List / Toolbar Master List

Currently 53091 entries and growing...

This is the Master BHO and Toolbar list copyrighted by Tony Klein and CastleCops. For expert assistance, please post here. The information is collected across the Internet by the CastleCops Team. Usage: please leave feedback requesting permission if you are interested in using this data beyond the approved channels.

BHOList - ToolbarList

KEY:
  • "X" - Certified spyware/foistware, or other malware
  • "L" - Legitimate items
  • "O" - Open to debate
  • "?" - Unknown Status
  • "BHO" - Browser Helper Object
  • "TB" - Toolbar
  • "SH" - R3 URL SearchHook
  • "EB" - IE Explorer Bar

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z

    Random sampling...
    OBJECT NAMEGUIDSTATUSFILENAMEDESCRIPTION
    Hook Class{DBA0F35F-BCD6-4602-863A-96893E4DE018}X BHO repl.dll, repl1.dllDownloader, detected by Kaspersky antivirus as Trojan.Win32.Agent.agx
    HtmlEvent{E9919FD6-2DA2-4D5C-871D-89B548D882B8}? BHO RedPepper.dllUnidentified browser plugin of Chinese origin - should you have any information about this application, such as its exact purpose and whether you did or did not install it wittingly, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks!
    XBTBPos00{CDCB861F-7CDD-4768-87D0-4D2FCFF3D53A}O BHO RADIO-~*.DLLUnidentified Softomate Toolbar - should you have any information about this application, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks!
    The retnsrp{573E45AC-F20E-4DAF-AF6C-0775714BA0C1}X TB retnsrp.dllParasite connecting to rogue "security sites", member of the FakeAlert aka SmitFraud malware family
    rtsplgob{0939FF27-A717-4F67-96B5-555F9510F17F}X TB rtsplgob.dllParasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    RadioToolbar{F275EF20-1E52-47B8-98D3-0537A2EB8223}O TB radiotoolbar.dll, RADIOT~*.DLL RadioToolbar - a Dutch Softomate variant, detected by ESET's Nod32 antivirus as Adware.EZTracks. Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this.
    [full path to file]{27AD49A2-94F3-42bD-F434-2604812C897C}X BHO random filenames (example: htr4ikg.dll)Parasite, detected by Kaspersky antivirus as Trojan-Downloader.Win32.Small.ddx
    Network Essentials{0421701D-CF13-4E70-ADF0-45A953E7CB8B}X BHO RH.dll, NE.dll SmartPops adware
    (no name){D7515C61-A66C-4319-A0E0-D416CB8059E3}X BHO Relive.dllParasite of Chinese origin, detected by Kaspersky antivirus as Trojan-Downloader.Win32.Agent.bmo - dropped by the W32.Drom worm
    Redzee Toolbar{34F459B8-1D37-4FF2-9EFA-192D8E3ABA6F}O TB redzee.dll Redzee.com Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this.
    CRCCBHO Object {97110207-DE87-43C7-B844-0276FB63141E}L BHO RCC.dll Kwoopon
    [full path to file]{C5AC49A2-94F3-42BD-F434-2604812C897D}X BHO random filenames (example: fkg94fdg.dll)Parasite, detected by Kaspersky antivirus as Trojan-Downloader.Win32.Small.ddx
    ReconnectBHO{F523CC61-C818-4A44-8F78-61FE7BD7D64D}L BHO ReconnectBho.dll Reconnect shopping tool
    Editor plugin{2C91577A-5253-492c-89A6-DA08849A3298}X BHO reccon.dllVariant of the Infostealer.Banker.D trojan
    XBTP01975{B5D5C620-4AA9-42b7-ADA4-13BA26BD128F}O BHO realestate.com.au.dll, REALES~1.DLL Realestate.com.au_Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Your choice.
    (no name){0C7354A0-AC86-400B-AC06-27B6D46214E0}X BHO reginix86c.dllDownloader, a variant of the Win32.Kolweb aka Durvil trojan
    (no name){A1626E66-B26B-C628-A1DF-BDACCFA26EE1}X BHO Relive.dll PWS-OnlineGames/66A1DE20 password stealer trojan - also see here
    &Browser_Radio{0F08F55E-A4D7-4D3A-8264-8F85008100C2}O TB radiojockeyorg.dllRadioJockey.NET Browsertools
    rtsplgob{BDC832B3-37F6-4C6A-8B06-E1123700413F}X TB rtsplgob.dllParasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    AIRS Revo{57D350AF-4B85-11DC-8554-001C2386B43F}L TB revo4.dllAirs SourcePoint software
    The Radio Toolbar{BFB5F154-9212-46F3-B547-AC6106030A54}X TB radio-toolbar.dll, RADIO-~*.DLL The_Radio_Toolbar - a Softomate Toolbar variant detected by Kaspersky antivirus as Adware.Win32.Mostofate.ab
    The retnsrp{D528386A-A286-4697-9C9C-47856CCD7F67}X TB retnsrp.dllParasite connecting to rogue "security sites", member of the FakeAlert aka SmitFraud malware family
    realestate.com.au lite Toolbar{D8958E48-205B-4D96-9D30-74EEBF12C6EB}O TB realestate_lite2.dll, REALES~*.DLL Realestate.com.au_Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Remove unless you both trust it and expressly meant to install it.
    RuPass module{954A0637-9147-4b5e-964E-9F20E58FC29D}X BHO RuPass.dllParasite of Russian origin, detected by Kaspersky antivirus as AdWare.Win32.RuPorn.d - see here
    rtc, rter Class{0610C4E6-A0D0-45d8-B6CB-3CCD74296EBB}X BHO rtc.dllUnidentified hijacker - should you have any information about this file, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks!
    BrowserConnector Object{0D84AC30-5186-4CD9-8FD8-4A1382D5F0F3}O BHO rlep2p32.dll, drvel.dll, ctrat.dll, authzi.dll, instd3dx.dll, tuiole.dll, sqlcesem30.dll, ixssoy.dll, [random filename] Sentry parental control software
    Windows DNS Helper {11B1FC48-0FD0-4BC7-8C10-FF4705D0025F}X BHO random filename (examples: 45u107nv.dll, truq5e4x.dll)Parasite, detected by AntiVir as TR/BHO.DNSHelper
    [full path to file]{B5AF0562-94F3-42BD-F434-2604812C297D}X BHO random filenames (example: Bvdsf4g.dll , S7dsf4g.dll)Parasite, detected by Kaspersky antivirus as Trojan-Downloader.Win32.Small.ddx
    rtsplgob{77E3B584-A383-4130-89FD-CD54BAA2C608}X TB rtsplgob.dllParasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    XBTP09202 {147E8138-5C4C-4df4-9153-13005CD2E69E}O BHO rankquest*.*.dll, RANKQU~*.DLL RankQuest_SEO_Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Installer detected by Kaspersky antivirus as AdWare.Win32.Mostofate.ad and by Bitdefender as Adware.Softomate.AE
    ohb{999A06FF-10EF-4A29-8640-69E99882C26B}X BHO rtneg.dll, rtneg*.dll, ns***.dll (* = random char/digit)Begin2Search adware variant
    [full path to file]{B5AC49A2-94F2-42BD-F434-2604812C897D}X BHO random filenames (example: Lfj95jg.dll)Parasite, detected by Kaspersky antivirus as Trojan-Downloader.Win32.Small.ddx
    {D537A3D0-8C07-4D62-953F-162207F5090D}X BHO regsvrac32.dllAdware.Margoc
    The ddxbox{18D19587-63A8-4D24-B79D-267E8A3AB0BF}X TB retnsrp.dllParasite connecting to rogue "security sites", member of the FakeAlert aka SmitFraud malware family
    TBSB08552{A0C8452E-63CB-4790-A314-5095FE1F1387}O BHO ratdubai.com_-_free_internet_anonymous_proxying_service..dll, RATDUB~1.DLL RatDubai.com_Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Installer detected by Kaspersky antivirus as AdWare.Win32.MegaKiss.b and by Bitdefender as Adware.Softomate.P
    TBSB09400{1EF8C52D-928D-44C8-856D-8D0189973911}X BHO radio-toolbar.dll, RADIO-~*.DLL The_Radio_Toolbar - a Softomate Toolbar variant detected by Kaspersky antivirus as Adware.Win32.Mostofate.ab
    RSS Feeds Toolbar{4A5BE5EE-CFAD-11D9-8FAD-0007E9AA247E}L TB RSS.dllRSS Feeds Toolbar
    rtsplgob{8E1F6C9A-86C0-4811-B45A-278E754B457F}X TB rtsplgob.dllParasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    rohantb{B1427DAE-F43D-4D79-B7D4-9D37D77F59B8}O TB rohan.dll"Rohan Toolbar" - an unidentified Softomate Toolbar - should you have any information about this application, such as its homepage, its exact purpose and whether you did or did not install it wittingly, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks!
    Reliance Toolbar{B7D3E479-CC68-42B5-A338-938ECE35F419}O TB reliance.dll Reliance_Communications Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Your choice.
    H{68EBD240-34BC-4503-8432-D2AB5168F4EB}X BHO ramsfeld1.dllVariant of the Infostealer.Banker.D trojan
    TBSB00939{52E17EE0-7BF3-43B4-954C-DCEEF4A4C724}O BHO rtl.dll Dorar.net_Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Your choice.
    RichSoft Internet Explorer Helper{0E2F5DD8-5B0D-438F-A618-B0403F62636A}X BHO reshtm.dllInstalled by the Dachri trojan
    rijxakin.dll{15FD6584-698F-BCD2-602C-698745210351}X BHO rijxakin.dllPassword stealer of Chinese origin detected by Trend Micro as TSPY_ONLINEG.FOK
    Recados Para Orkut{BFB5F154-9212-46F3-B547-AC6106030A54}O TB recados.dll Recados_Para_Orkut - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Your choice
    RankQuest SEO Toolbar{6AE02E1C-8859-4F57-9097-5A55A56A4CAF}O TB rankquest*.*.dll, RANKQU~*.DLL RankQuest_SEO_Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Installer detected by Kaspersky antivirus as AdWare.Win32.Mostofate.ad and by Bitdefender as Adware.Softomate.AE
    Rediff Toolbar{12F02779-6D88-4958-8AD3-83C12D86ADC7}O TB SH redifftoolbar.dll, REDIFF~1.DLL Rediff.com Toolbar - see here - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Some of the toolbars are fine to have, so every case is different. Your choice.
    rtsplgob{E067413D-BC5E-4D4D-864D-A8932A9AC761}X TB rtsplgob.dllParasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    (no name){C64E4E3D-AAA0-4081-B6A7-22A40AFBFD35}X BHO rs.objUnidentified parasite of Chinese origin - should you have any information about this application, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks!
    Robot Genius{1FD7EA94-0650-4CF5-ACFF-CDB36A6E924F}L BHO RgWinId.dllRobot Genius Spyberus
    ReturnM{33C3DE49-CB44-4BE5-83EF-FD0AC5E4FD61}X BHO returnmband.dll, RETURN~1.DLLParasite of Korean origin hailing from remoney.co.kr and detected as Remoney or Returnmoney adware
    rtsplgob{573E5206-B092-4111-B5E0-A8580F026F03}X TB rtsplgob.dllParasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    Dictionar &Roman Englez{3F5A62E2-51F2-11D3-A075-CC7364CAE42B}L TB RoEnIE.dllRomanian-English dictionary plugin provided by diseara.ro
    rightonadz browser enhancer{74B42F25-4107-404D-A892-F9A31C106D06}X BHO rgtndz.dll AdRotator/IconAds related, a TrafficSector adware variant serving ads from rightonadz.biz
    Client Library{A319A311-EB29-49BD-8643-CA2409780DA0}X BHO rsvp32.dllUnidentified parasite - should you have any information about this file, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks!

    spacer spacer