| OBJECT NAME | GUID | STATUS | FILENAME | DESCRIPTION |
|---|
| {F8CC9B08-C14F-4A5C-B73B-518AFECC067A} | L TB | rekruter_2_43.dll, REKRUT~*.DLL | Rekruter-Toolbar |
| Rightdown Software SearchBar | {D6F180CB-E683-41a3-8CD2-C53DBAA0530D} | X TB | rssb.dll | "Rightdown Software SearchBar"- bundled with certain RightDown games |
| RGWIE Class | {D4D5806E-EA2C-45b2-972D-8BE237697B87} | X BHO | RGWIE.dll | Unidentified parasite - should you have any information about this application, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks! |
| Risale-i Nur'da arama motoru | {BFB5F154-9212-46F3-B547-AC6106030A54} | O TB | risaleara toolbar Projesi.dll | Risaleara.com Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Remove unless you both trust it and expressly meant to install it. |
| Dictionar &Roman Englez | {3F5A62E2-51F2-11D3-A075-CC7364CAE42B} | L TB | RoEnIE.dll | Romanian-English dictionary plugin provided by diseara.ro |
| Barre d'Outils Radio Nejma | {CE41CDFF-BB50-4672-9BE3-5A1BE5990D2B} | O TB | RadioNejma.dll | Barre_d'Outils_Radio_Nejma - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Some of the toolbars are fine to have, so every case is different. Your choice. |
| rohantb | {B1427DAE-F43D-4D79-B7D4-9D37D77F59B8} | O TB | rohan.dll | "Rohan Toolbar" - an unidentified Softomate Toolbar - should you have any information about this application, such as its homepage, its exact purpose and whether you did or did not install it wittingly, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks! |
| &RelatedWeb | {6B1A3DA0-FDC7-4d5f-B827-2BAC083EF75D} | X TB | RelatedWeb.dll | RelatedWeb Tool, Chinese Toolbar by myweb.cn - hailing from sobar.163.com, sohu.com, sina.com - a BaiduBar adware component |
| The retnsrp | {AAA535B5-251D-4B8F-A8D0-0D3A29C7309E} | X TB | retnsrp.dll | Parasite connecting to rogue "security sites", member of the FakeAlert aka SmitFraud malware family |
| Redzee Toolbar | {34F459B8-1D37-4FF2-9EFA-192D8E3ABA6F} | O TB | redzee.dll | Redzee.com Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. |
| H | {8AF036B0-E4F1-4fa0-98D3-7F0887C51940} | X BHO | rtreywem.dll | Variant of the Infostealer.Banker.D trojan |
| Hook Class | {DBA0F35F-BCD6-4602-863A-96893E4DE018} | X BHO | repl.dll, repl1.dll | Downloader, detected by Kaspersky antivirus as Trojan.Win32.Agent.agx |
| rmd | {DE5F80FD-8A16-4E53-A670-25EDD1152274} | X BHO | rmd.dll | Parasite causing false spyware warnings and connecting to fake "security sites", notably pctotaldefender.com |
| XBTBPos00 Class | {658560A9-E2AF-4BB4-BE64-56C8DAC3EFBE} | O BHO | rankquest*.*.dll, RANKQU~*.DLL | RankQuest_SEO_Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Installer detected by Kaspersky antivirus as AdWare.Win32.Mostofate.ad and by Bitdefender as Adware.Softomate.AE
|
| &Reverso Translator | {995B2B9A-FCC5-4BE8-B98F-E9CD53C514FE} | L TB | REVERS~1.DLL, ReversoTranslator.dll | Reverso Translator |
| [full path to file] | {25AD49A2-94F3-42BD-F434-2604812C897D} | X BHO | random filenames (example: mkkgf65h.dll) | Parasite, detected by Kaspersky antivirus as Trojan-Downloader.Win32.Small.ddx |
| rtsplgob | {56D53A84-40DD-4FF2-9847-0E6EB884CE48} | X TB | rtsplgob.dll | Parasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
|
| RTL_Yellow_V1.5.1 | {B555D77A-5CA3-461D-8D72-349AE15C5FDF} | O TB | rtl.dll | RTL_Yellow_Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Your choice. |
| MS Explorer | {705E9481-27B1-7C41-28BD-8E93811F4081} | X BHO | rswctl32.dll | Variant of the Trojan-Spy.Win32.Agent.ir trojan |
| XBTP09202 | {147E8138-5C4C-4df4-9153-13005CD2E69E} | O BHO | rankquest*.*.dll, RANKQU~*.DLL | RankQuest_SEO_Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Installer detected by Kaspersky antivirus as AdWare.Win32.Mostofate.ad and by Bitdefender as Adware.Softomate.AE
|
| XBTB09612 | {654DCF3A-00ED-422e-BDA2-D7FA69261CE9} | X BHO | RR-TOO~1.DLL, EZT-TO~1.DLL | Recipe Rewards Toolbar - a Traffix_inc EZTracks/aavalue.com foistware variant |
| RG_Toolbar | {C5D431C0-9D73-43FF-8424-A9EE96B3727D} | O TB | rg.dll | Ricercagiuridica.com toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. |
| realestate.com.au lite Toolbar | {D8958E48-205B-4D96-9D30-74EEBF12C6EB} | O TB | realestate_lite2.dll, REALES~*.DLL | Realestate.com.au_Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Remove unless you both trust it and expressly meant to install it. |
| (no name) | {B45FC20D-6906-4E72-AA59-392CC61FDAA9} | X BHO | reginix86b.dll | Downloader, a variant of the Win32.Kolweb aka Durvil trojan |
| XBTP03004 | {19058002-11E0-486a-9EC7-2827CA0AB3B2} | O BHO | ramicro_toolbar.dll, RAMICR~1.DLL | RA-Recherche_Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Some of the toolbars are fine to have, so every case is different. Your choice. |
| Windows DNS Helper | {11B1FC48-0FD0-4BC7-8C10-FF4705D0025F} | X BHO | random filename (examples: 45u107nv.dll, truq5e4x.dll) | Parasite, detected by AntiVir as TR/BHO.DNSHelper
|
| (no name) | {********-****-****-****-************} | X SH | RtlFindVal.dll | WareOut malware component |
| CRCCBHO Object | {97110207-DE87-43C7-B844-0276FB63141E} | L BHO | RCC.dll | Kwoopon |
| ReadToMe | {1FFFE263-3C8E-4DD8-9BAA-36998D29561E} | L TB | ReadToMePlugin.dll | ReadToMe browser plugin |
| {80672997-D58C-4190-9843-C6C61AF8FE97} | X BHO | rundll16.dll | BrowserAid adware variant |
| RestrictFolderBHO Class | {4A90840E-87EC-41C2-B926-2687F57C0F1E} | L BHO | RCEShell.dll | RightClick-Encrypt |
| ü°Ã·µ¸©Åéµ(&R) | {548E3580-6FED-43EC-A918-82D580817BCF} | ? BHO | RELATE~1.DLL | Unidentified browser plugin - should you have any information about this application, such as its exact purpose and whether you did or did not install it wittingly, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks! |
| rtsplgob | {CB25FC2F-305D-4538-9462-18A2CA4130D5} | X TB | rtsplgob.dll | Parasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
|
| rtsplgob | {8EA4273D-8CC9-49D9-BEC4-5134C34E3CA0} | X TB | rtsplgob.dll | Parasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
|
| ToolHelper | {AAAE1C1A-89F7-4AF6-ABD1-F8FBCFA47408} | L BHO | rekruter_2_43.dll, REKRUT~*.DLL | Rekruter-Toolbar |
| H | {21F6EE00-FEC3-4a0e-BA2E-F919CF11D87E} | X BHO | rsssewe_.dll, rtywem.dll | Variant of the Infostealer.Banker.D trojan |
| Browser Class | {D8C32D92-3120-4D44-B295-5D4461C6AF95} | X BHO | rasapi.DLL | Malware of Chinese origin - detected by Avast antvirus as Win32:Agent-FZQ |
| rtsplgob | {4DE15B3F-84EE-4F6F-BA12-B0AB8229C2F1} | X TB | rtsplgob.dll | Parasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
|
| TBSB03262 | {06B3672D-1FD0-4BAE-89D0-E8D5A476AA87} | O BHO | rednano_ie.dll | Rednano_Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Your choice. |
| Flash Module | {C87FA4A3-2474-4a3f-B413-67D515905024} | X BHO | rasmoesa.dll, akun54.dll | Password stealer, a variant of Win32.Trojan-Spy.Banker.EGJ - also see here |
| (no name) | {E37D4210-1D22-437A-96B6-977EC202869E} | X BHO | redir.dll | SpyGuarder - rogue "security software" using false positives as goad to purchase. |
| XBTP05494 | {37138967-CD8A-4b6e-8254-5EED6A50BB69} | O BHO | redzee.dll | Redzee.com Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. |
| Hook Class | {6E3D2E1D-7B23-41c8-8A6C-13012A889F99} | X BHO | rasda2.dll, ra21s1.dll | Password stealer trojan, detected as TROJ_AGENT.AGV |
| (no name) | {D3626E66-B13B-C628-ACDF-BDABCFA265E1} | X BHO | Relive.dll | Password stealer trojan, detected as Troj/OnLineG-F |
| Real Estate Toolbox | {26A1CBE4-13EC-424B-854C-CCDA191FBA26} | O TB | realestatetoolbox.dll | Real Estate Toolbox Toolbar by CRWork.com - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Installer detected by Kaspersky antivirus as AdWare.Win32.Mostofate.ap |
| rtsplgob | {4840F5B3-C8E8-4900-BEBF-667735B7C7DB} | X TB | rtsplgob.dll | Parasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
|
| & Band | {3F5A62E2-51F2-11D3-A075-CC7364CAE42F} | X TB | reword3.dll | Parasite of Korean origin hailing from pcup.co.kr and detected as Win32.Toolbar.Pcup |
| XBTBPos00 Class | {BBBE1C1A-89F7-4AF6-ABD1-F8FBCFA47408} | O BHO | redifftoolbar.dll, REDIFF~1.DLL | Rediff.com Toolbar - see here - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Remove unless you both trust it and expressly meant to install it. |
| {D48F2E28-68E2-4920-9848-D6E6C7AB3EB7} | X BHO | Redirector.dll | Xupiter/Sqwire adware |
| (no name) | {6477E005-5456-1621-8899-ca3230262a11} | X BHO | ras_z.rc1 | Trojan Dropper, detected as TrojanDropper:Win32/Jevafus.A |
| symndis | {166DF856-08F0-4D1C-991D-7CE3DB5C26F5} | X BHO | rasacd.dll | Parasite of Chinese origin hailing from sd.ncast.cn and detected as nCast adware |
| &RoboForm | {724D43A0-0D85-11D4-9908-00400523E39A} | L TB | RoboForm.dll | RoboForm |
| XBTP01975 | {B5D5C620-4AA9-42b7-ADA4-13BA26BD128F} | O BHO | realestate.com.au.dll, REALES~1.DLL | Realestate.com.au_Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Your choice. |
| realestate.com.au Toolbar | {D8958E48-205B-4D96-9D30-74EEBF12C6EB} | O TB | realestate.com.au.dll, REALES~1.DLL | Realestate.com.au_Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Your choice. |
| rtc, rter Class | {0610C4E6-A0D0-45d8-B6CB-3CCD74296EBB} | X BHO | rtc.dll | Unidentified hijacker - should you have any information about this file, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks!
|