| OBJECT NAME | GUID | STATUS | FILENAME | DESCRIPTION |
|---|
| {5BBFC00A-312C-4777-A5DF-DDA65C67120C} | L TB | Ubp.dll | Antipop-up UOL toolbar |
| Unsd Class | {0CA6C3EA-2054-4011-BC9F-8BBC017A169C} | X BHO | uns.dll | SBSoft/EZFinder.com hijacker |
| ???? | {8A03D6E7-7FDA-4CE9-95D0-988790911BF0} | L BHO | uact1.dll, uact2.dll | Browser plugin of Chinese origin, installed by ChinaNet or Vnet broadband ISP software |
| {9EAC0102-5E61-2312-BC2D-000000000000} | X BHO | unknown | MakeMeSearch aka Tubby/Arau adware variant |
| CMsgCenter Class, Usmsho | {6014EABC-B61A-4F07-A32B-440EAE835DF9} | L BHO | usmsho.dll | InfoArmor User Security Manager |
| XBTB00429 | {C1B54465-EA94-4185-9B02-39926A895447} | X BHO | untitled.dll | CramToolbar adware |
| Bazooka | {7891DA15-428E-11D7-BCC1-00A024831A8C} | X TB | USERSS~1.DLL | BazookaBar |
| UrlSearch | {35C77681-939D-11D4-AE10-008048C2AB95} | L SH | urlplus.dll | UrlPlus.net Toolbar - fast access to major search engines via browser address line and context menu |
| KmePchec Class | {D903D9F0-4E8E-2008-E836-6823572F20F2} | X BHO | ujjmcieu.dll | QuickLinks/LinkMaker adware variant - also detected as Adware.Suggestor |
| UriList Class | {00A4658F-104F-49F5-B123-8172789AF3C3} | X BHO | urihelper1.dll | Unidentified parasite - should you have any information about this application, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks!
|
| (no name) | {6F8ADBE2-8C92-4362-B0E6-7321AA49EE46} | X BHO TB EB | Ultrabar.dll | Blowsearch adware |
| Windows Shell | {********-****-****-****-************} | X BHO | usbmon32.dll (random Class ID) | Unidentified parasite - should you have any information about this application, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks! |
| Upromise IE Toolbar | {06E58E5E-F8CB-4049-991E-A41C03BD419E} | L TB | upromisetoolbar.dll, UPROMI~1.DLL | Upromise Toolbar |
| EDLApp Class | {BAA2F47D-9CF7-4015-8A29-89C46824A448} | X BHO | upcontrol.dll | Parasite of Korean origin detected as Win32.Spyware.Edl - also see here |
| ABCNews.com Toolbar | {C1D79200-7718-4656-A7B2-F23046E264E7} | O TB | ultrabar.dll, insptbar.dll | ABCNews.com Toolbar |
| (no name) | {278B661A-14A8-D8B0-6AF4-03088B866149} | X BHO | unaoakg.dll | Variant of the DisableKey.A aka Busky downloader trojan - also see here
|
| Kweaj Class | {DFE7D27E-C021-4C72-80F3-254B776E0992} | X BHO | ubbv.dll | QuickLinks/LinkMaker adware variant - also detected as Adware.Suggestor |
| ToolHelper | {EDC0F17F-F4B7-47e4-B73E-887FAEB376FA} | L BHO | upromisetoolbar.dll, UPROMI~1.DLL | Upromise Toolbar |
| update Class | {6223B57C-2428-46CD-96E4-2F810CF7550E} | ? BHO | updates.dll | Unidentified browser plugin - should you have any information about this application, such as its exact purpose and whether you did or did not install it wittingly, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks! |
| (no name) | {FCADDC14-BD46-408A-9842-CDBE1C6D37EB} | X BHO | updater.dll | "Banker" aka password stealer trojan, detected by Kaspersky antivirus as Trojan-Spy.Win32.Banbra.abg |
| {53CBEE82-D747-11d3-9ED0-005004189684} | X TB | Ucmie.dll | UCMore adware variant |
| IECatch Class | {0315AA2C-10C7-4504-A1C4-F552ABA8A095} | L BHO | URLCatch.dll | GetGo |
| eZanga Toolbar | {B789A28C-D063-4826-A31A-9268D503852E} | O TB | ultrabar.dll | eZanga Toolbar |
| UpSpiral Toolbar | {4E7BD74F-2B8D-469E-DEFF-ED65A486AA28} | X BHO TB | upspiral.dll | UpSpiralBar adware |
| inproc Class | {980A2B2F-7113-4302-9BFE-4A80337D1339} | X BHO | uus.dll | Downloader of Korean origin - should you have a copy of the file, do email us attaching the file to your email for analysis. Thanks! |
| XBTP01713 | {87A2A7C5-EFEF-4200-9575-A4AE9325F9DE} | X BHO | untitled.dll | FreeProd/Toolbar888 parasite, a MaxSearch/MaxiFiles adware variant |
| {8702D9E1-890B-4BF2-A233-FA44E582B2DE} | X BHO | unknown | Related to MainEntryPoint, DialerActiveX , and other types of adult content dialers |
| FiltURL Class | {5038FED1-CEFE-11D2-9E74-00A0C945A948} | O SH | URLSearchHook.dll, URLSEA~1.DLL | Net Express ( Netex ) Search Toolbar |
| Cram Toolbar | {20929603-21DB-477C-BA6F-0B8E70B3C8A0} | X TB SH | untitled.dll | Cram_Toolbar adware |
| UCmore XP - The Search Accelerator | {44BE0690-5429-47f0-85BB-3FFD8020233E} | X TB | Ucmtsaie.dll | UCMore adware variant |
| UCmore toolbar | {ED8DB0FD-D8F4-4b2c-BB5B-9EF040FE104D} | X BHO | Ucmie.dll | UCMore adware variant |
| XBTB04775 | {F1868CCC-EEFC-47eb-9967-22B23CFDFF71} | X BHO | untitled.dll | Unidentified Softomate Toolbar |
| Unoh Local Search Toolbar | {E89BC295-54F7-4DCD-B1C5-7119C8FCF1C4} | L TB | usearch.dll | Unoh Local Search Toolbar |
| TOOLBAR.BZ | {BFB5F154-9212-46F3-B547-AC6106030A54} | X TB | untitled.dll | Softomate Toolbar variant hailing from Toolbar.bz, a site hosting malware |
| userpart | {2DB2B5E2-818D-43A8-BBAA-CBC975050AE0} | O TB | userpart.dll | Userpart_Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Installer detected by Kaspersky antivirus as AdWare.Win32.Mostofate.x and by Bitdefender as Adware.Softomate.X |
| Affiliate Beta | {C49DD894-C6DE-4910-8C41-BA20F852D8BC} | O TB | untitled.dll | Affiliate_Beta_Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. |
| XBTP07549 | {6E9CAC95-D71B-4de9-979E-1C6C30583733} | L BHO | untitled.dll | Temporary Inbox |
| Cram Toolbar | {01E69986-A054-4C52-ABE8-EF63DF1C5211} | X TB SH | untitled.dll, untitled1.dll | CramToolbar adware |
| {4BCF322B-9621-4e90-9678-F1424EB7584E} | X BHO | Udpmod.dll, udpmod-1.dll | Adware.Sa |
| XBTB05041 | {0570397E-DB72-4e18-9597-4348671D3BDB} | O BHO | userpart.dll | UserPart_Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Installer detected by Kaspersky antivirus as AdWare.Win32.Mostofate.x and by Bitdefender as Adware.Softomate.X |
| (no name) | {********-****-****-****-************} | X SH | uio.dll | WareOut malware component, using a random Class ID |
| XBTB04775 | {129DD540-E5E4-4601-825A-43ED660159E0} | X BHO | untitled.dll | Unidentified Softomate Toolbar |
| TBSB09410 | {BAED151D-ED99-4E87-B199-BFA5AA5D8F06} | O BHO | upenntoolbarIE.dll | Penn_Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this. Your choice.
|
| ?????????????2.0 | {75D82598-4A3C-419e-99D2-3EB56D09CFD0} | ? TB | utilbar.dll | UtilToolBar by Shanghai Leysin Technology Co, Ltd. - should you have any information about this application, such as its exact purpose and whether you did or did not install it wittingly, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks!
|
| URSEARCH Toolbar | {92F02779-6D88-4958-8AD3-83C12D86ADC7} | X TB | ursearch.dll | UrSearch.com toolbar |
| (no name) | {********-****-****-****-************} | X SH | utsgmon.dll | WareOut malware component, using a random Class ID |
| Dogpile UK Toolbar | {03646F67-527E-4d2a-8073-092EE87A3DD5} | O TB | ultrabar.dll | Dogpile UK Toolbar |
| Universal Searchbar | {5F7AB1DB-A899-46c1-8345-B72B4567EE86} | X TB | utility.dll | UniversalTB adware |
| Barra Univision | {4E7BD74F-2B8D-469E-96B6-B337BB9CA934} | L BHO TB | UNIVIS~1.DLL | Univision.com search toolbar |
| URLHooker2 Class | {93935F7F-9C88-42F8-8445-95251D27FABC} | L BHO | URLHooker.dll, URLHOO~1.DLL | Flash Video Downloader |
| SSVHelper | {96488BA0-1A53-4583-8AC8-DB77560E8876} | X BHO | unopek.dll, ssvanasus.dll, onepad.dll, other semi-random filenames composed of the following fragments: one, ssva, uno, nas, p, k, ek, ad, us | Parasite redirecting to fake security sites, member of the FakeAlert aka SmitFraud malware family - produces IEDefender , FilesSecure , MalwareBell , IE_Antivirus or similar popups - also see here |
| {A097840A-61F8-4B89-8693-F68F641CC838} | X BHO | urlcli*******.dll , ms****.dl(* = random digit) | ClientMan adware variant |
| XBTB00429 | {3FDE0CB5-619F-4227-8961-F2D7ED15B88E} | X BHO | untitled.dll, UNTITL~1.DLL | CramToolbar adware variant |
| Social Bar | {E3B2DF84-EAFE-4669-8260-B46AA2D43D38} | L BHO TB | ustb.dll | SocialBar - IE toolbar that keeps you connected to your Facebook life while browsing the web. |
| [random] | {CEA9C7D2-748A-45f2-A404-56A46695D8E8} | X BHO | user32.dll | SearchingAll adware variant (the file is located in the system32\drivers folder, and must not be confused with the legitimate Microsoft file of the same name!) |