| OBJECT NAME | GUID | STATUS | FILENAME | DESCRIPTION |
|---|
| CoTGT_BHO Class | {C555CF63-747F-4831-94AC-E683D962C63C} | X BHO | wavaapi.dll | Parasite, bundled with DoylesRoom and/or other online poker software - should you have any further information about this application, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks! |
| Class | {426EADED-93FE-ED52-66F6-16F8DA085282} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {7E570CFF-0FA2-144A-CDD3-CADF704FD3DC} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {8D1BAA26-F985-1788-3C2F-DBED986F74EE} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {9077A962-ADEE-5591-6287-7FF61B9A9249} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {46D28766-906E-9E67-824D-DE45649B6032} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {F81802C0-6E82-2373-9AB6-16A464EFC959} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {C660661C-10FD-F21F-3A46-4EAAF0E43199} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {874CD1C6-F8F4-10B0-DC92-CB55C53C978A} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Mirar, Related Page | {9A9C9B69-F908-4AAB-8D0C-10EA8997F37E} | X BHO TB | WinNB**.dll (* = digit), version69ie7fix.dll, version55ie7fix.dll, version52ie7fix.dll, version**ie7fix.dll (* = digit) | NetNucleus/Mirar adware |
| Class | {F855FF71-EE65-86CD-DD54-7FF98165E3BF} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| (no name) | {F484C398-C71D-4482-8700-A9CCE5D2A0BE} | X BHO | win32hp.dll | Variant of the Troj/Dropper-GS trojan - pops ads and downloads an adult content dialer to your computer |
| Class | {A41D2ABC-7149-E38B-8039-8E941F9E4589} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| {E7AFFF2A-1B57-49C7-BF6B-E5123394C970} | X BHO | webinfo.dll | GonnaSearch adware |
| MS Explorer | {9A5C9584-DE98-310B-21A1-899F87184987} | X BHO | wmdcst32.dll | Variant of the Trojan-Spy.Win32.Agent.ir trojan, also detected as Troj/BHO-CD |
| Class | {9291DF23-029D-DC8D-B7E6-64BEFF3F25AF} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| winhost_app.winhost_appdll | {14EE7227-4ED0-4A70-BF80-8501A70E5403} | X BHO | winhost_app.dll | Browser hijacker popping inonto.com ads |
| Class | {5A3E7B4A-4BD4-D8F5-EE42-404E0AA25C6C} | X BHO | win**.dll (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {5F25A197-5C64-2844-84AC-BE08CBD78A39} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {47F1A18E-4D68-80F1-6BBB-16B984AC80ED} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {7C061B06-4572-3DED-BEE5-45419ADBBEFC} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {75591E87-1EA0-C1A4-3C7E-E20344EE7281} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {287368C4-44ED-86D5-A425-EFBB34F6C8C6} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {C902789B-AF19-4056-CC6A-4E38EC39868F} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {A98BEA99-7B4B-FA3E-03F1-10C3D1AE7212} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {CF2FCF52-41E5-9E51-846F-629C8711C67E} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {4040EFBB-6ECB-E57E-FA69-6B589DA7741C} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| QXK Olive | {FD0B419C-54A2-4FA8-80FA-A3F883F474B1} | X BHO | wbxdpgfenlk.dll | Adware downloader causing false spyware warnings and connecting to rogue "security sites", a member of the Trojan-Downloader.Zlob.Media-Codec aka NewMediaCodec malware family
|
| Class | {0D3C697A-11C9-2DA5-EC25-B1ADBC618039} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| wbspark | {BC42164F-2C53-1B42-1563-1A7624A24C11} | X BHO | wbspark.dll | Malware, detected by Kaspersky antivirus as Trojan-Dropper.Win32.Agent.azv
|
| Class | {AEA0AA17-241D-D1A4-6B03-544854F6A984} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {3DDACC72-6F8F-7927-166E-F828A44E47F1} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| SWL IE Plugin | {1E1B2879-88FA-11D3-8D96-D7ACAC95951A} | O BHO | Web.dll | StealthWebPage surveillance software |
| Class | {75F3F166-0DCD-26C3-33A3-208C8A544DCE} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {646C57CD-B620-5ABD-0600-A30E3EA96595} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| (no name) | {00000000-0000-41a3-98CF-00000000168B} | X BHO | wmcbaaca.dll, wm41a398.dll | LZIO.com adware |
| Class | {DB1F0CAD-DFCA-D4CB-CE35-6727626309D9} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {E6734850-621D-44A8-7518-2AA3C5935D68} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {A5123093-2B1E-B4CD-75E9-0E69B25100C1} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {98CC5E5F-7877-CB9D-3D33-989DA81B39DA} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {9625BB58-2718-B27A-AF0B-FA8C05740FD7} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| winapi32.MyBHO | {A313F723-15E1-42D7-9E62-A40F345CD1C6} | X BHO | winapi32.dll | CashDeLuxe adware component |
| Class | {79C93508-E653-3149-0C20-C0B4BFC88F32} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {EAF52E39-F0F9-7652-DA70-CAD2851543E8} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {C72B3431-7C0A-658B-575C-BCB6286A7705} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {19ADC647-766D-0AC1-0176-44846D7DA203} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Explorer | {7348D74C-731B-DECE-9F8A-A37D8214708E} | X BHO | wlcstp32.dll | Parasite of Russian origin connecting to ku-dzu.com - a variant of the Trojan-Spy.Win32.Agent.ir trojan |
| Class | {27AB907C-8C71-0316-AAB8-F84D9E8EEADC} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| ClientExp.ComClientExport | {E9D36F0A-A053-4A63-AF1A-781A9DA45572} | X BHO | winchat.dll | Unidentified parasite - should you have any information about this application, such as for example the site where it was downloaded or installed, do email us - if you actually have a copy of the file, please attach it to your email for analysis. Thanks! |
| Class | {CC39318E-E921-454F-0085-6E15E5DCDF77} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {8D072086-FE7E-C1B0-97E3-5B58C51A83E4} | X BHO | WIN**.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Web Search | {6A719349-BDF5-4268-9019-4ACA0C2562D2} | X BHO | websrc32.dll | Downloader trojan, member of the FakeAlert aka SmitFraud malware family - produces IEDefender popups - also see here |
| Class | {B6EE36B3-955D-C400-BD4A-895722D75AF0} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Class | {05F3F3D2-8BFA-C735-FCDF-D4BD8418D325} | X BHO | WIN**32.DLL (* = random char) | CoolWebSearch/HomeSearch adware component |
| Video | {38329D14-1302-4CA7-BEE4-C954516C43B3} | X BHO | windivx.dll | Downloader trojan, member of the FakeAlert aka SmitFraud malware family - produces IEDefender popups - also see here |