CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

spacer spacer

The CLSID / BHO List / Toolbar Master List

Currently 54019 entries and growing...

This is the Master BHO and Toolbar list copyrighted by Tony Klein and CastleCops. For expert assistance, please post here. The information is collected across the Internet by the CastleCops Team. Usage: please leave feedback requesting permission if you are interested in using this data beyond the approved channels.

BHOList - ToolbarList

KEY:
  • "X" - Certified spyware/foistware, or other malware
  • "L" - Legitimate items
  • "O" - Open to debate
  • "?" - Unknown Status
  • "BHO" - Browser Helper Object
  • "TB" - Toolbar
  • "SH" - R3 URL SearchHook
  • "EB" - IE Explorer Bar

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z

    Random sampling...
    OBJECT NAMEGUIDSTATUSFILENAMEDESCRIPTION
    {F8CC9B08-C14F-4A5C-B73B-518AFECC067A}L TB rekruter_2_43.dll, REKRUT~*.DLLRekruter-Toolbar
    Rightdown Software SearchBar{D6F180CB-E683-41a3-8CD2-C53DBAA0530D}X TB rssb.dll"Rightdown Software SearchBar"- bundled with certain RightDown games
    RGWIE Class{D4D5806E-EA2C-45b2-972D-8BE237697B87}X BHO RGWIE.dllUnidentified parasite - should you have any information about this application, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks!
    Risale-i Nur'da arama motoru {BFB5F154-9212-46F3-B547-AC6106030A54}O TB risaleara toolbar Projesi.dll Risaleara.com Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Remove unless you both trust it and expressly meant to install it.
    Dictionar &Roman Englez{3F5A62E2-51F2-11D3-A075-CC7364CAE42B}L TB RoEnIE.dllRomanian-English dictionary plugin provided by diseara.ro
    Barre d'Outils Radio Nejma{CE41CDFF-BB50-4672-9BE3-5A1BE5990D2B}O TB RadioNejma.dll Barre_d'Outils_Radio_Nejma - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Some of the toolbars are fine to have, so every case is different. Your choice.
    rohantb{B1427DAE-F43D-4D79-B7D4-9D37D77F59B8}O TB rohan.dll"Rohan Toolbar" - an unidentified Softomate Toolbar - should you have any information about this application, such as its homepage, its exact purpose and whether you did or did not install it wittingly, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks!
    &RelatedWeb{6B1A3DA0-FDC7-4d5f-B827-2BAC083EF75D}X TB RelatedWeb.dllRelatedWeb Tool, Chinese Toolbar by myweb.cn - hailing from sobar.163.com, sohu.com, sina.com - a BaiduBar adware component
    The retnsrp{AAA535B5-251D-4B8F-A8D0-0D3A29C7309E}X TB retnsrp.dllParasite connecting to rogue "security sites", member of the FakeAlert aka SmitFraud malware family
    Redzee Toolbar{34F459B8-1D37-4FF2-9EFA-192D8E3ABA6F}O TB redzee.dll Redzee.com Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this.
    H{8AF036B0-E4F1-4fa0-98D3-7F0887C51940}X BHO rtreywem.dllVariant of the Infostealer.Banker.D trojan
    Hook Class{DBA0F35F-BCD6-4602-863A-96893E4DE018}X BHO repl.dll, repl1.dllDownloader, detected by Kaspersky antivirus as Trojan.Win32.Agent.agx
    rmd{DE5F80FD-8A16-4E53-A670-25EDD1152274}X BHO rmd.dllParasite causing false spyware warnings and connecting to fake "security sites", notably pctotaldefender.com
    XBTBPos00 Class{658560A9-E2AF-4BB4-BE64-56C8DAC3EFBE}O BHO rankquest*.*.dll, RANKQU~*.DLL RankQuest_SEO_Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Installer detected by Kaspersky antivirus as AdWare.Win32.Mostofate.ad and by Bitdefender as Adware.Softomate.AE
    &Reverso Translator{995B2B9A-FCC5-4BE8-B98F-E9CD53C514FE}L TB REVERS~1.DLL, ReversoTranslator.dllReverso Translator
    [full path to file]{25AD49A2-94F3-42BD-F434-2604812C897D}X BHO random filenames (example: mkkgf65h.dll)Parasite, detected by Kaspersky antivirus as Trojan-Downloader.Win32.Small.ddx
    rtsplgob{56D53A84-40DD-4FF2-9847-0E6EB884CE48}X TB rtsplgob.dllParasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    RTL_Yellow_V1.5.1{B555D77A-5CA3-461D-8D72-349AE15C5FDF}O TB rtl.dll RTL_Yellow_Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Your choice.
    MS Explorer{705E9481-27B1-7C41-28BD-8E93811F4081}X BHO rswctl32.dllVariant of the Trojan-Spy.Win32.Agent.ir trojan
    XBTP09202 {147E8138-5C4C-4df4-9153-13005CD2E69E}O BHO rankquest*.*.dll, RANKQU~*.DLL RankQuest_SEO_Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Installer detected by Kaspersky antivirus as AdWare.Win32.Mostofate.ad and by Bitdefender as Adware.Softomate.AE
    XBTB09612{654DCF3A-00ED-422e-BDA2-D7FA69261CE9}X BHO RR-TOO~1.DLL, EZT-TO~1.DLLRecipe Rewards Toolbar - a Traffix_inc EZTracks/aavalue.com foistware variant
    RG_Toolbar{C5D431C0-9D73-43FF-8424-A9EE96B3727D}O TB rg.dll Ricercagiuridica.com toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this.
    realestate.com.au lite Toolbar{D8958E48-205B-4D96-9D30-74EEBF12C6EB}O TB realestate_lite2.dll, REALES~*.DLL Realestate.com.au_Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Remove unless you both trust it and expressly meant to install it.
    (no name){B45FC20D-6906-4E72-AA59-392CC61FDAA9}X BHO reginix86b.dllDownloader, a variant of the Win32.Kolweb aka Durvil trojan
    XBTP03004{19058002-11E0-486a-9EC7-2827CA0AB3B2}O BHO ramicro_toolbar.dll, RAMICR~1.DLL RA-Recherche_Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Some of the toolbars are fine to have, so every case is different. Your choice.
    Windows DNS Helper {11B1FC48-0FD0-4BC7-8C10-FF4705D0025F}X BHO random filename (examples: 45u107nv.dll, truq5e4x.dll)Parasite, detected by AntiVir as TR/BHO.DNSHelper
    (no name){********-****-****-****-************}X SH RtlFindVal.dll WareOut malware component
    CRCCBHO Object {97110207-DE87-43C7-B844-0276FB63141E}L BHO RCC.dll Kwoopon
    ReadToMe{1FFFE263-3C8E-4DD8-9BAA-36998D29561E}L TB ReadToMePlugin.dll ReadToMe browser plugin
    {80672997-D58C-4190-9843-C6C61AF8FE97}X BHO rundll16.dll BrowserAid adware variant
    RestrictFolderBHO Class{4A90840E-87EC-41C2-B926-2687F57C0F1E}L BHO RCEShell.dllRightClick-Encrypt
    ü°Ã·µ¸©Åéµ(&R){548E3580-6FED-43EC-A918-82D580817BCF}? BHO RELATE~1.DLLUnidentified browser plugin - should you have any information about this application, such as its exact purpose and whether you did or did not install it wittingly, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks!
    rtsplgob{CB25FC2F-305D-4538-9462-18A2CA4130D5}X TB rtsplgob.dllParasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    rtsplgob{8EA4273D-8CC9-49D9-BEC4-5134C34E3CA0}X TB rtsplgob.dllParasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    ToolHelper{AAAE1C1A-89F7-4AF6-ABD1-F8FBCFA47408}L BHO rekruter_2_43.dll, REKRUT~*.DLLRekruter-Toolbar
    H{21F6EE00-FEC3-4a0e-BA2E-F919CF11D87E}X BHO rsssewe_.dll, rtywem.dllVariant of the Infostealer.Banker.D trojan
    Browser Class{D8C32D92-3120-4D44-B295-5D4461C6AF95}X BHO rasapi.DLLMalware of Chinese origin - detected by Avast antvirus as Win32:Agent-FZQ
    rtsplgob{4DE15B3F-84EE-4F6F-BA12-B0AB8229C2F1}X TB rtsplgob.dllParasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    TBSB03262{06B3672D-1FD0-4BAE-89D0-E8D5A476AA87}O BHO rednano_ie.dll Rednano_Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Your choice.
    Flash Module{C87FA4A3-2474-4a3f-B413-67D515905024}X BHO rasmoesa.dll, akun54.dllPassword stealer, a variant of Win32.Trojan-Spy.Banker.EGJ - also see here
    (no name){E37D4210-1D22-437A-96B6-977EC202869E}X BHO redir.dll SpyGuarder - rogue "security software" using false positives as goad to purchase.
    XBTP05494{37138967-CD8A-4b6e-8254-5EED6A50BB69}O BHO redzee.dll Redzee.com Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this.
    Hook Class{6E3D2E1D-7B23-41c8-8A6C-13012A889F99}X BHO rasda2.dll, ra21s1.dllPassword stealer trojan, detected as TROJ_AGENT.AGV
    (no name){D3626E66-B13B-C628-ACDF-BDABCFA265E1}X BHO Relive.dllPassword stealer trojan, detected as Troj/OnLineG-F
    Real Estate Toolbox{26A1CBE4-13EC-424B-854C-CCDA191FBA26}O TB realestatetoolbox.dllReal Estate Toolbox Toolbar by CRWork.com - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Installer detected by Kaspersky antivirus as AdWare.Win32.Mostofate.ap
    rtsplgob {4840F5B3-C8E8-4900-BEBF-667735B7C7DB}X TB rtsplgob.dllParasite causing false spyware warnings and connecting to fake "security sites" - member of the FakeAlert aka SmitFraud malware family
    & Band{3F5A62E2-51F2-11D3-A075-CC7364CAE42F}X TB reword3.dllParasite of Korean origin hailing from pcup.co.kr and detected as Win32.Toolbar.Pcup
    XBTBPos00 Class{BBBE1C1A-89F7-4AF6-ABD1-F8FBCFA47408}O BHO redifftoolbar.dll, REDIFF~1.DLL Rediff.com Toolbar - see here - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Remove unless you both trust it and expressly meant to install it.
    {D48F2E28-68E2-4920-9848-D6E6C7AB3EB7}X BHO Redirector.dll Xupiter/Sqwire adware
    (no name){6477E005-5456-1621-8899-ca3230262a11}X BHO ras_z.rc1Trojan Dropper, detected as TrojanDropper:Win32/Jevafus.A
    symndis{166DF856-08F0-4D1C-991D-7CE3DB5C26F5}X BHO rasacd.dllParasite of Chinese origin hailing from sd.ncast.cn and detected as nCast adware
    &RoboForm{724D43A0-0D85-11D4-9908-00400523E39A}L TB RoboForm.dllRoboForm
    XBTP01975{B5D5C620-4AA9-42b7-ADA4-13BA26BD128F}O BHO realestate.com.au.dll, REALES~1.DLL Realestate.com.au_Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Your choice.
    realestate.com.au Toolbar{D8958E48-205B-4D96-9D30-74EEBF12C6EB}O TB realestate.com.au.dll, REALES~1.DLL Realestate.com.au_Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Your choice.
    rtc, rter Class{0610C4E6-A0D0-45d8-B6CB-3CCD74296EBB}X BHO rtc.dllUnidentified hijacker - should you have any information about this file, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks!

    spacer spacer