CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

spacer spacer

O21 ShellServiceObjectDelayLoad

Currently 240 entries and growing...
Last updated on 2008-07-27 10:02:23 Eastern.


FBJ originally ran this list but closed it permanently. FBJ graciously permitted CastleCops to continue maintaining the list as of Jul 8, 2005. The full HTML list is here.

KEY:
  • "L" = Legitimate
  • "O" = Open to Debate
  • "X" = Malware/Bad
  • "?" - Unknown

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z



    CLSIDStatusNamePath/FileDescription
    {5368DCFC-4F5C-4f5b-B134-E67294FC78E9}XSysTray.Exlv[random].dllUnidentified malware (probable cozdoor variant)
    {73F8D5FF-6F5C-4f5b-B964-E6F214F6F852}XSysTray.Exmr[random].dllBackdoor.Krepper.b
    {1768ECFC-4F5C-4f5b-B134-D67294FC78E9}XSysTray.Exsh[random].dll Troj/Cozdoor-D
    {2368D1FC-2F5C-4f1b-B124-E67214FC78E2}XSysTray.Exsn[random].dllBackdoor.Small.ig
    {7368D5FC-6F5C-4f5b-B964-E67214F67852}XSysTray.Exys[random].dll TR/Drop.Small.afo.2
    {97421D0D-E07F-40DF-8F07-99597B9585AD}XThunderAdvise%WINDIR%\Downloaded Program Files\ThunderAdvise.dllOnline Games Trojan variant
    {********-****-****-****-************}XUnknownUnknown UnknownVolume VolumeAlrt VolumeChk
    VolumeDrive VolumeRam VolumeService VolumeSrv
    %WINDIR%\Installer\{********-****-****-****-************}\[name].dllTrojan.Win32.Agent (browser hijacker)
    {523455E4-ABCD-ABCD-1114-D709ADD3DDAB}XUpperHost%SYSDIR%\UpperHost.dllGoldun variant
    {EB9BDABE-1BD2-445B-9A13-BA9C7D2E3CA9}OURLREWINnetknl.dllSpector Keylogger
    {********-****-****-****-************}Xvadokmxt%WINDIR%\vadokmxt.dll Smitfraud
    {********-****-****-****-************}Xversionlibinets.dll W32/Dabber-D
    {********-****-****-****-************}XVersion1libweb.dll Win32/Checkout.M
    {********-****-****-****-************}XVersion1%SYSDIR%\syspoints.dll W32/IRCBot-XN
    {********-****-****-****-************}XVersion1 syspoint.dllIRCBot variant
    {********-****-****-****-************}XVolumeUnknown WinAvp WinDrv WinRom WinService WinSrv
    WinSetup
    %WINDIR%\Installer\{********-****-****-****-************}\[name].dllTrojan.Win32.Agent (browser hijacker)
    {********-****-****-****-************}Xvpnconfigvpnconfig.dll Win32.Adware.Agent
    {********-****-****-****-************}Xvpssup%WINDIR%\vpssup.dll MyGeek/CPVFeed
    {********-****-****-****-************}Xwdpoefan%WINDIR%\wdpoefan.dll Smitfraud
    {7CFBACFF-EE01-1231-ABDD-416592E5D639}XWeb Event Logger[8 random characters].dll Troj/Padodor-R
    {7CFBACFF-EE01-1231-ABDD-416592E5D639}XWeb Event Logger[random].dll Troj/Qukart-W
    {79FEACFF-FFCE-815E-A900-316290B5B738}XWeb Event Logger[8 random characters].dll Troj/Padodor-K
    {E6FB5E20-DE35-11CF-9C87-00AA005127ED}LWebCheck%SYSDIR%\webcheck.dllWebsite Monitor
    {FE2DB5FF-5ECF-11D2-B28F-0080C8383C7B}XWebExtLocation[random].dllunknown malware
    {66186F05-BBBB-4a39-864F-72D84615C679}XWebProxy%SYSDIR%\sockins32.dll W32/Dwnldr-HCP
    {66186F05-BBBB-4a39-864F-72D84615C679}XWebProxysockots64.dllTrojan.Clicker (Nuwar variant)
    {4C611512-2C1D-44b2-A044-872AD2AD5A61}Xwebworkwebwork.dll BaiduBar
    {1d64c57d-091f-4aa8-8bb6-06543a8bc431}XWinCD%WINDIR%\Installer\{1d64c57d-091f-4aa8-8bb6-06543a8bc431}\WinCD.dll SmitFraud
    {009541A0-3B00-1F1C-00F3-040224009C02}XWinCTLProgram Files\Common Files\winctl.dll Troj/Small-EJG
    {none}Xwinupzod32.exe W32/Dozic-A
    {********-****-****-****-************}Xwmpconfwmpconf.dllTrojan.SystemPoser
    {********-****-****-****-************}Xwmpdev%WINDIR%\wmpdev.dll Smitfraud
    {********-****-****-****-************}Xwmpenvwmpenv.dllTrojan.SystemPoser
    {********-****-****-****-************}Xwmphost%WINDIR%\wmphost.dll Smitfraud
    {********-****-****-****-************}Xwmplayer%WINDIR%\wmplayer.dll Smitfraud
    {********-****-****-****-************}Xwmsound%WINDIR%\wmsound.dll Smitfraud
    {AAA288BA-9A4C-45B0-95D7-94D524869DB5}LWPDShServiceObjWPDShServiceObj.dllWindows Portable Device Shell Service Object
    {********-****-****-****-************}Xxcvwer%WINDIR%\xcvwer.dll Smitfraud
    {0C887F38-5178-43DA-B9F0-B856141FCDA4}XXmLdrLocationmserrtrc.dll, nvrcr32.dll, olescn32.dll, msuueng.dll Spyware.Eblaster
    {********-****-****-****-************}Xxvideo%WINDIR%\xvideo.dll Smitfraud
    {********-****-****-****-************}Xzip%WINDIR%\Installer\{********-****-****-****-************}\zip.dllTrojan.Win32.Agent (browser hijacker)

    Engine Version 2.0 by CastleCops

    spacer spacer