CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

spacer spacer

O21 ShellServiceObjectDelayLoad

Currently 237 entries and growing...
Last updated on 2008-06-02 04:41:03 Eastern.


FBJ originally ran this list but closed it permanently. FBJ graciously permitted CastleCops to continue maintaining the list as of Jul 8, 2005. The full HTML list is here.

KEY:
  • "L" = Legitimate
  • "O" = Open to Debate
  • "X" = Malware/Bad
  • "?" - Unknown

  •   

    CLSIDStatusNamePath/FileDescription
    {F5DF91F9-15E9-416B-A7C3-7519B11ECBFC}L0aMCPClientMCPCore.dll Stardock
    {35CEC8A3-2BE6-11D2-8773-92E220524150}XAceExt%SYSDIR%\AceExt32.dll Troj/Agent-FYG
    {********-****-****-****-************}Xadmggxp%WINDIR%\admggxp.dll Smitfraud
    {********-****-****-****-************}Xadsoowf%WINDIR%\adsoowf.dll Smitfraud
    {********-****-****-****-************}Xagrlmvp%WINDIR%\agrlmvp.dll Smitfraud
    {********-****-****-****-************}XAlrtComponent AvpKbd AvpPrx AvpService AvpSrv AvpSys
    BootAlrt BootCD BootChk BootKbd BootSys CDMon CDSys
    ChdMon CheckCD
    %WINDIR%\Installer\{********-****-****-****-************}\[name].dllTrojan.Win32.Agent (browser hijacker)
    {210b4043-35ca-4aa0-8796-191f9663dfb3}Xaltmannsbergervpxnk.dllSmitfraud variant
    {********-****-****-****-************}Xaltvxvm%WINDIR%\altvxvm.dll MyGeek/CPVFeed
    {********-****-****-****-************}Xalxvdvm%WINDIR%\alxvdvm.dll Smitfraud
    {4fc003c3-87a0-489c-85cd-878246eb2d18}Xamaranthaceousoebxpba.dll Smitfraud_variant
    {b28b396b-b9e8-44f5-aa04-ed4f383d79ad}Xanatolianyosdjh.dll SmitFraud/SpySheffif
    {CF21AC11-38FB-0279-2E68-00BC16A2CB77}XAnti-Leech ALIEzsqsow32.dllAntiLeech Plugin Plugin&threatid=15044
    {********-****-****-****-************}Xantivirusfirewallav.dllWin32/IRCBot.worm
    {d7bdd42a-7e69-4bb8-aac3-d76ff65a3aa3}Xarchentericimpgsje.dll SmitFraud/SpySheffif
    {5f938c17-fbc7-4a3c-8526-85e5b1a1f762}Xastralolnohdw.dll SmitFraud/SpySheffif
    {2be26361-58a2-4836-be57-b838f02fec3f}Xastrogeologyqxfgcg.dll SmitFraud/SpySheffif
    {********-****-****-****-************}Xaswmklt%WINDIR%\aswmklt.dll Smitfraud_MyGeek/CPVFeed_variant
    {{BCBCD383-3E06-11D3-91A9-00C04F68105C}}LAUHookC:\WINDOWS\SYSTEM\AUHOOK.DLLWindows ME Microsoft AutoUpdate
    {951a98d0-dad6-4a77-8280-a494279a884b}Xbeepervwfps.dll SmitFraud/SpySheffif
    {af4fd984-a939-4c32-82b2-8bae7abe9aec}Xbenumbmentdbqlrij.dll SmitFraud/SpySheffif
    {874443fe-aa33-4ebf-a6ac-73208787e62d}Xbestreakviruxz.dll Troj/Zlob-QK
    {********-****-****-****-************}Xbgrlsmn%WINDIR%\bgrlsmn.dll Smitfraud
    {********-****-****-****-************}Xbindmod%WINDIR%\bindmod.dll SmitFraud
    {f2efa195-4785-4db1-9316-b48c64bb71da}Xblippersxqpauzx.dll SmitFraud/SpySheffif
    {********-****-****-****-************}Xbmlvqkn%WINDIR%\bmlvqkn.dll Smitfraud
    {********-****-****-****-************}Xbokpkov%WINDIR%\bokpkov.dll MyGeek/CPVFeed
    {11853d5f-f894-4cc7-bbc3-fc7a9dcfd896}Xbonspellsokkmtv.dll SmitFraud/SpySheffif
    {01b55afa-f451-474b-9e91-c35b24d02641}Xboobqrzsyr.dll SmitFraud/SpySheffif
    {********-****-****-****-************}XBootSetup CheckRunOnce RamCD RomComponent RunOnceAlrt
    RunOnceRom SrvVolume
    %WINDIR%\Resources\[name].dll SmitFraud
    {0bad5052-665d-40d4-a9bd-a2891eaafb42}Xboucicaultfmrmhc.dll Smitfraud_variant
    {5c4f2cbc-f32d-4a03-9812-86f39379811b}Xbreadthesoksrqqu.dll Smitfraud
    {06fe8138-6c67-484f-ab1f-42abddd2cbb6}Xbreakneckqnusjji.dll SmitFraud/SpySheffif
    {9CE9F186-D208-4B02-959C-97FEC71C4867}OBrotiurl%SYSDIR%\seliw3d.dllSpector Pro monitoring software
    {b59f3ba4-98da-4b5f-8a2d-7b56fb11140b}Xbuprestidaecthkpcv.dll SmitFraud/SpySheffif
    {C145CF11-124F-3562-44AC-E685D962C63C}XBurnWin%SYSDIR%\apiuser32.dllTrojan-PSW.Win32.Delf.aoz
    {e51e3ade-ddc4-45d9-9a21-36cf20ea9306}Xbuysipztub.dll SmitFraud/SpySheffif
    {********-****-****-****-************}Xbvtqfvx%WINDIR%\bvtqfvx.dll Smitfraud
    {********-****-****-****-************}Xbxsbang%WINDIR%\bxsbang.dll Smitfraud
    {168cf174-6dab-461c-a761-a7adfa5a5719}Xcampywuwbxp.dll SmitFraud/SpySheffif
    {8d8c2387-7f80-4022-9be6-43630a969558}Xcarbinylgwquvw.dll Smitfraud
    {9a4b860b-b18e-4afe-9b26-2a19268eb6be}Xcecropiaownyhr.dll SmitFraud/SpySheffif
    {********-****-****-****-************}XCheckComponent CheckRam checkrunonce CheckService
    CheckSys ChkAlrt chkcomponent ChkMon ComponentCD
    ComponentMon DriveCD
    %WINDIR%\Installer\{********-****-****-****-************}\[name].dllTrojan.Win32.Agent (browser hijacker)
    {29b1075d-6c05-4cda-83aa-24d3777753c9}XCheckDrv%WINDIR%\Installer\{29b1075d-6c05-4cda-83aa-24d3777753c9}\CheckDrv.dll SmitFraud
    {ee2975b6-e8d5-405e-8448-8fe9590f6cfb}Xcholecystmzoeut.dll SmitFraud/SpySheffif
    {93ac7c30-3878-4eaa-9420-7977285df5b1}Xcinnamomumpmnqguh.dll SmitFraud/SpySheffif
    {0d9eb558-0666-479e-868a-21b1d1a53bd1}Xclamoringveklo.dllSmitfraud variant
    {4d993022-0899-4599-b4b6-0f887d0802e6}Xconsideratenessoqabf.dll Smitfraud/SpysSherrif
    {dfa61db1-388e-4c87-8d56-540fa229bcb4}Xcontrabandistsdpfwu.dll SmitFraud/SpySheffif
    {e758745e-b8aa-47ac-a652-6307ff5f3ebf}Xcounterclaim%SYSDIR%\vpccw.dll Troj/FakeVir-AE
    {f8d02387-789a-4c0f-a1d8-8a93f33ee4df}Xcoursingsyephk.dll SmitFraud/SpySheffif
    {ff170564-36c8-43f7-9100-559e166405cf}Xcusserscfltygd.dll Smitfraud_variant
    {2C1CD3D7-86AC-4068-93BC-A02304BB8C34}XDCOM Servermsdcom32.dll, dcom_*.dll (* = digit) Troj/Agent-FG
    {2C1CD3D7-86AC-4068-93BC-A02304BB2234}XDCOM Server 2234[random named].dllTR/Agent.PK.12 - Trojan
    {2C1CD3D7-86AC-4068-93BC-A02304BB2236}XDCOM Server 2236%SYSDIR%\2236_28.dll Troj/Agent-CIJ
    {2C1CD3D7-86AC-4068-93BC-A02304BB2238}XDCOM Server 2238explorer.exe, dxvw****.exe (**** = 4 letters) Troj/SpamThru-K
    {2C1CD3D7-86AC-4068-93BC-A02304B25319}XDCOM Server 25319%SYSDIR%\*******.dll (**** = random letters) Troj/Agent-FZF
    {F33812FB-F35C-4674-90F6-FD757C419C51}XDDEbirdihuy32.dll TROJ_AGENT.BCB
    {303F44D5-5FEA-4509-ABDE-5E00C3F2125A}XDDE Modulehun32.dllTrojanProxy.Win32.Small
    {********-****-****-****-************}Xddkret%WINDIR%\ddkret.dll Smitfraud
    {5A6F2F95-3191-433B-8533-EB0B596A7BAC}XDelayRun********.dll (*********= 8 digit hexadecimal number)Asian Adware which could be DesktopMedia related
    {716002db-288c-4bf0-80cd-a467e78d8b55}Xdepreciabledxovx.dll Smitfraud
    {01d8d081-0f76-4ab5-b5e4-9b23a709670e}Xdetachmentssacskza.dll SmitFraud/SpySheffif
    {e6adaaf0-79b2-4cf1-a660-50a0b33991a1}Xdidymiumsvblhanf.dll Smitfraud/AntiVermins
    {8329660f-e248-4872-98cc-fb9c4fec7ba8}Xdidynamia%SYSDIR%\xkrdk.dll Smitfraud
    {4fbbdfd6-2ca9-4bba-93e4-aadf75321bca}Xdiscriminablekuhmk.dll SmitFraud/SpySheffif
    {C111980D-B372-44b4-8095-1B6060E8C647}XDL5%WINDIR%\AppPatch\deamon.dll W32.Almanahe.A
    {********-****-****-****-************}XDriveDrv DrivePrx DriveRom DriveWin DrvAvp DrvCheck
    DrvMon DrvPrx DrvSys DrvVolume KbdCD KbdMon KbdPrx
    %WINDIR%\Installer\{********-****-****-****-************}\[name].dllTrojan.Win32.Agent (browser hijacker)
    {********-****-****-****-************}Xdrvsvp%WINDIR%\drvsvp.dll Smitfraud
    {********-****-****-****-************}XE404Helpere404d.dll MalwareCrush
    {1559e6c1-7e5e-4461-9457-6a2dea85eb9f}Xeelertitiau.dll SmitFraud/SpySheffif
    {2016a466-91a2-43c6-97d8-2fd380f065ef}Xeitherorhigehsg.dll Troj/FakeAle-AM
    {588599f4-de26-4c28-ba14-f4eb17e33481}Xemptinsxxfgmy.dll SmitFraud/SpySheffif
    {6D972050-A934-44D7-AC67-7C9E0B264220}LEnhancedDialogenhdlginit.dllEnhancedDialog by Stardock
    {********-****-****-****-************}Xeplrr9eplrr9.dll Troj/StartPa-DJ
    {********-****-****-****-************}Xeplrr9mspdnx.dllCoolWebSearch parasite variant
    {70305bc2-b289-4209-a344-be21f22bc930}Xequestrezphnok.dll SmitFraud/SpySheffif
    {ECD3491F-ED1D-4775-B567-789E55CDC6C7}OErroxzipdlgadcan.dll Spector_keylogger
    {8670ee50-01f9-47da-ac1e-cf8549e9e521}Xeupepticaxlet.dll Smitfraud
    {2acf3add-34a1-4f2f-99cf-cc69785d1e90}Xexemplarscwgppb.dll Smitfraud/AntiVermins
    {1a01a98c-4f25-42e1-971a-185cf63569b2}Xexpatriatestpedvf.dll SmitFraud/SpySheffif
    {********-****-****-****-************}Xexpro%WINDIR%\expro.dll MyGeek/CPVFeed
    {5839511e-ec1b-4f91-ace3-fb88e52f5239}Xfairydomjevtxpg.dllSmitfraud variant
    {ab340860-fd81-4a65-b345-82eb77a66b5e}Xfeatherweedjbtazy.dll Smitfraud_variant
    {27321538-5739-4aa1-b84c-7d18e4383f1f}Xferrateenrrtcany.dll Smitfraud_variant
    {9d635a36-6b3c-4146-8625-f3aaf507bbf8}Xflammeivcehaeb.dll SmitFraud/SpySheffif
    {********-****-****-****-************}Xfldrsysfldrsys.dll Troj/Agent-QY
    {89e4aaba-3b21-49b3-b922-8ca35193c68e}Xfurnariidaezlara.dllSmitfraud variant
    {f31aee4a-1530-4fef-8537-79c6973bff9a}Xgaonictazth.dll SmitFraud/SpySheffif
    {40dcff6e-af8d-4183-8ebe-a82270ac449e}Xgimmicksdcvwaah.dll Smitfraud_variant
    {9cc1c589-4b22-4dae-8e12-4c3b5fa12b3f}Xgloomilymlraakb.dll SmitFraud/SpySheffif
    {e944d14a-03aa-43e3-9d0e-4f50c4d1b005}Xgorgonianeowygj.dll SmitFraud/SpySheffif
    {********-****-****-****-************}Xgormet%WINDIR%\gormet.dll Smitfraud
    {fe288882-f661-4522-88f3-20cfb7866fa4}Xgutturalnesscvnzie.dll SmitFraud/SpySheffif
    {3c767c6b-602d-4b9b-829d-a3dc5b2d89dd}Xhaematobiahjpprpu.dll SmitFraud/SpySheffif
    {6076d2b1-634c-4685-843b-f826045ea5dc}Xhemadynamometersyycum.dll SmitFraud/SpySheffif
    {18c3fa26-192e-4c17-9c0f-76dc9b56c0c2}Xheteropodousficqv.dll SmitFraud/SpySheffif
    {59080fb1-a43e-4059-a155-18b1eac7352c}Xhinniblefhmfes.dll SmitFraud/SpySheffif
    {fa19bd7e-50bc-4203-80ac-c4edc81ca9a3}Xhirtellousnbbrhbd.dll Smitfraud
    {********-****-****-****-************}Xhjoqor%WINDIR%\hjoqor.dll Smitfraud
    {7be183d2-a42d-4915-bf60-ec86fbf002cf}Xhorologiumhttge.dll SmitFraud/SpySheffif
    {********-****-****-****-************}Xhostctrl%WINDIR%\hostctrl.dll SmitFraud
    {********-****-****-****-************}Xhstsys%WINDIR%\hstsys.dll Smitfraud
    {7b1eeccd-0a6d-4ad5-8ac1-4af5722b3885}Xhubbsivwlummc.dllSmitfraud variant
    {********-****-****-****-************}Xhupsrv%WINDIR%\hupsrv.dll SmitFraud
    {b166be07-30a4-4d38-b781-44528a630706}Xhydrodictyongqagksr.dll SmitFraud/SpySheffif
    {1799460C-0BC8-4865-B9DF-4A36CD703FF0}LIconPackager Repairiprepair.dllStardock\Object Desktop\ ThemeManager
    {********-****-****-****-************}Xiebrowseriebrowser.dll Smitfraud
    {********-****-****-****-************}Xiecontextiecontext.dll Smitfraud
    {********-****-****-****-************}Xiedebugiedebug.dll Smitfraud
    {********-****-****-****-************}XIEFilter%SYSDIR%\IEFilter.dll Troj/SrchSpy-A
    {********-****-****-****-************}Xiesupportiesupport.dll Smitfraud
    {bb720bab-2f75-456b-a850-04d77b20f6b8}Ximpasserosdzop.dll SmitFraud/SpySheffif
    {03413bf7-e34c-445b-bfc0-a2b127255871}Xincestuouslyurroxtl.dllSmitfraud variant
    {11F1576E-3AB4-439A-A5C9-4D77B4087863}XInternet Agent[random].dll Troj/PPdoor-J
    {F28A40D7-AD0E-034A-C651-5F0ED76232E6}XInternet Explorer%System%\[RANDOM NAME].dll Backdoor.Berbew.T
    {********-****-****-****-************}Xjetctrl%WINDIR%\jetctrl.dll Smitfraud
    {c6e9c531-af10-4639-bcd8-21e3520441a1}XKbdBoot%WINDIR%\Installer\{c6e9c531-af10-4639-bcd8-21e3520441a1}\KbdBoot.dll SmitFraud
    {A3023D18-B93F-4892-B89B-56FB36382B8F}Xkbdctrl%WINDIR%\kbdctrl.dll SmitFraud
    {********-****-****-****-************}XKbdRom KbdSrv KernelAlrt KernelBoot KernelComponent
    KernelDrv KernelMon KernelPrx KernelSrv KernelSys
    KernelUnknown
    %WINDIR%\Installer\{********-****-****-****-************}\[name].dllTrojan.Win32.Agent (browser hijacker)
    {000000A0-0000-0000-0000-000000000011}XKeysaver%System%\Keysaver.dll Trojan-Dropper.Win32.Small
    {********-****-****-****-************}Xkopmet%WINDIR%\kopmet.dll Smitfraud
    {71EC5123-28DF-324A-D76B-32549AB4C338}XLDpswSend%SYSDIR%\[random named].dllTrojan-Downloader.Win32.Agent
    {********-****-****-****-************}Xleorop%WINDIR%\leorop.dll Smitfraud
    {********-****-****-****-************}XLiveUpdatec:\program files\symantec\(liveupdate\)[random].dllUnidentified malware
    {C222CF73-124F-3562-44AC-E685D962C63C}XMailExport%WINDIR%\Media\sendmail.dll Trojan.Win32.BHO.gb
    {523455E4-ABCD-ABCD-1114-D709ADD3DDAB}XMemManMemMan.dll Troj/Goldun-EH
    {79FEACFF-FFCE-815E-A900-316290B5B738}XMicrosoft DirectXb[random].dll Troj/Padodor-L
    {********-****-****-****-************}Xmjdw32_mjd.dllIRCBot-Mygallery
    {********-****-****-****-************}Xmodemsnotice.dll Win32.Backdoor.IRCBot
    {********-****-****-****-************}XMonAlrt MonBoot MonRam monvolume prxboot RamChk
    RamRunOnce RamSys RamUnknown RomCheck
    %WINDIR%\Installer\{********-****-****-****-************}\[name].dllTrojan.Win32.Agent (browser hijacker)
    {********-****-****-****-************}XMonWin%WINDIR%\Installer\{********-****-****-****-************}\MonWin.dllTrojan.Win32.Agent
    {********-****-****-****-************}Xmsddemsdde.dll Smitfraud
    {********-****-****-****-************}Xmsddxmsddx.dll Smitfraud
    {********-****-****-****-************}Xmsmdev%WINDIR%\msmdev.dll Smitfraud
    {********-****-****-****-************}Xmsmduo%WINDIR%\msmduo.dll Smitfraud
    {********-****-****-****-************}Xmsmduo2%WINDIR%\msmduo2.dll Smitfraud
    {********-****-****-****-************}Xmsmhost%WINDIR%\msmhost.dll Smitfraud
    {280A7B65-8F00-438F-3E5A-1F039433FE60}XMSN Messengerdssdll32.dllTrojan horse Downloader.Agent
    {35CEC8A3-2BE6-11D2-8773-92E220524250}XMsnShell32%SYSDIR\MsnShell32.dllBackdoor.Win32.Agent.gkf (Zlob variant)
    {********-****-****-****-************}Xmsolemsole.dll Smitfraud
    {8EBB4EC4-DD60-E1B1-E00E-DA54CCE9218D}Xmspc32.dllmspc32.dll W32/Feebs-J
    {********-****-****-****-************}Xmsqnx%windir%\msqnx.dll Smitfraud
    {********-****-****-****-************}Xmssql%WINDIR%\mssql.dll Smitfraud
    {6F9DD472-2CC4-459A-A620-70D75E53E35E}XMStaskp2sys.dllTrojan-PSW.Win32.LdPinch variant
    {********-****-****-****-************}Xmsvb%WINDIR%\msvb.dll Smitfraud
    {0D13BB81-D4DB-B06F-0AAF-613A52E287C3}Xms[random characters]32.dllms[random characters]32.dll W32/Feebs-BA
    {********-****-****-****-************}Xmtkle******32.dll Win32.Blewfit.A
    {5D1C9A4F-438B-4C5C-BE66-FAAA08D4BF49}Xneobus%WINDIR%\neobus.dll SmitFraud
    {********-****-****-****-************}Xnopctrl%WINDIR%\nopctrl.dll Smitfraud
    {********-****-****-****-************}Xnopzet%WINDIR%\nopzet.dll Smitfraud
    {********-****-****-****-************}XNTDBGTOOL*******.dll (* =random letter) Troj/PPdoor-C
    {********-****-****-****-************}Xocgrep%WINDIR%\ocgrep.dll Smitfraud
    {70BC2408-9E0E-47A4-8B46-BDA634995AA9}Xodb_setodbcmr32.dll Troj/Spy-UL
    {0656A137-B161-CADD-9777-E37A75727E78}XOLE Modulethun32.dll Backdoor.Fivsec
    {********-****-****-****-************}XOLE Objectbarseek.dllTrojan-Proxy.Win32.Small
    {C777CF73-124F-3562-44AC-E685D962C63C}XOleExport%WINDIR%\Media\CertMgr.dllTrojan.Win32.BHO.gb
    {********-****-****-****-************}Xossmartossmart.dll AdWare.Win32.Agent
    {********-****-****-****-************}Xpmkretpmkret.dll Smitfraud
    {********-****-****-****-************}XPreBootCheck%WINDIR%\Resources\[random name].dll Smitfraud
    {********-****-****-****-************}Xprintersnotiffy.dll, msn.dll, libcintles3.dll W32/Kik-A
    {********-****-****-****-************}Xprinterslibwinets.dll Troj/IRCBot-XD
    {********-****-****-****-************}Xprinterslibmsns.dll W32/IRCBot-XG
    {********-****-****-****-************}Xprinterslibweb.dll W32/Dabber-D
    {448BAC42-AABD-42C5-A550-826BF4AF4BB3}Xprodigy1prodigys323.dll Mimbot.A
    {********-****-****-****-************}Xprodigy1newsystem25.dll Mimbot.A
    {ee12547f-4a79-494f-be6d-14fc2f037713}XPrxDrive%WINDIR%\Installer\{ee12547f-4a79-494f-be6d-14fc2f037713}\PrxDrive.dll SmitFraud
    {********-****-****-****-************}Xrdihost%SYSDIR%\rdihost.dll W32/IRCBot-VR
    {5344BB88-3DE1-409F-8307-C85923A1F4DD}Xrdshostrdfhost.dll W32/IrcWorm-A
    {FAD81399-F9B1-95E0-B45E-956A216893A0}XRealJukebox 1.0SpeechEngines.dllTrojan-Downloader.Win32.Murlo.a
    {********-****-****-****-************}Xrmvgor%WINDIR%\rmvgor.dll Smitfraud
    {ff24a0f4-b93e-4b4b-9bfb-e398e98db703}XRomAvpRomAvp.dll Smitfraud
    {********-****-****-****-************}XRomMon RomPrx RomSrv RomUnknown RunOnceAlrt
    RunOnceSetup RunOnceVolume ServiceCD ServiceComponent
    %WINDIR%\Installer\{********-****-****-****-************}\[name].dllTrojan.Win32.Agent (browser hijacker)
    {********-****-****-****-************}Xsapnet%WINDIR%\sapnet.dll Smitfraud
    {********-****-****-****-************}XServicePrx ServiceRam ServiceRom ServiceSys SetupAlrt
    SetupMon SetupService SrvAlrt SrvCheck
    %WINDIR%\Installer\{********-****-****-****-************}\[name].dllTrojan.Win32.Agent (browser hijacker)
    {8FB2D6CA-E258-48CF-9DAB-EEFB735E225C}XshellserviceShellService.dll Spyware.Ultraview
    {********-****-****-****-************}Xsounddrv%WINDIR%\sounddrv.dll Smitfraud
    {********-****-****-****-************}XSrvComponent SrvSetup SrvUnknown SysDrive SysService
    SysSys UnknownKbd UnknownCD UnknownDrive UnknownKernel
    %WINDIR%\Installer\{********-****-****-****-************}\[name].dllTrojan.Win32.Agent (browser hijacker)
    {********-****-****-****-************}XSvcSyssvcsys.dll Infostealer.Bancos
    {6CBCB0E8-BAAD-4450-AF88-CE02C567AC36}XSvrpnpgeteng.dll Spyware.Eblaster
    {********-****-****-****-************}Xsyscore%WINDIR%\syscore.dll Smitfraud
    {23456789-0000-0020-0900-00AAFF6D2EA4}XSysctl Desktop Handlerntosv.dll Troj/Agent-CL
    {********-****-****-****-************}Xsysdx%WINDIR%\sysdx.dll Smitfraud
    {********-****-****-****-************}Xsyshelps%SYSDIR%\syshelps.dll, wmhs32.dll Troj/IRCBot-WL
    {********-****-****-****-************}Xsyshelpssystesrt32.dll W32/IRCBot-XF
    {********-****-****-****-************}Xsyshostssyshosts.dllhttp://www.sophos.com/security/analyses/w32ircbotwb.html
    {D7FFD784-5276-42D1-887B-00267870A4C7}XSysRunsvshost.dll Troj/Small-CPO
    {********-****-****-****-************}XSystemvr_sys.dll Troj/LdPinch
    {********-****-****-****-************}Xsystem32sysprinters.dll W32/IRCBot-WV
    {54645654-2225-4455-44A1-9F4543D34545}XSystemCheck2vbsys2.dll Troj/AdClick
    {********-****-****-****-************}Xsystemiesystemie.dll Troj/Sisie-D
    {********-****-****-****-************}Xsystempsystemp.dll Troj/Narod-D
    {35CEC8A3-2BE6-11D2-8773-92E220524153}LSysTray%SYSDIR%\stobject.dllSysTray Shell Service Object Library
    {6368D1FC-6F5C-4f1b-B164-E67214F678E9}XSysTray.Exbr[random].dll Troj/Slogger-I
    {5368D5FC-6F6C-4f5b-B564-E67214F67552}XSysTray.Exbt[random].dll Troj/Slogger-K
    {1722ECFF-4356-4f5b-B534-E67294FE75E9}XSysTray.Excn[random].dllWorm.Prox.c
    {1722ECFF-4356-4f5b-B534-E67294FE75E9}XSysTray.Excn2[random].dll Troj/Cozdoor-C
    {636821FC-6F5C-2f1b-B164-E67214F678E2}XSysTray.Exgl[random].dllTrojan-Proxy.Win32.Small variant
    {2963ECFC-4E5C-2f3b-B334-D67434FC72E0}XSysTray.Exiv[random].dll Troj/Slogger-F
    {5368DCFC-4F5C-4f5b-B134-E67294FC78E9}XSysTray.Exlv[random].dllUnidentified malware (probable cozdoor variant)
    {73F8D5FF-6F5C-4f5b-B964-E6F214F6F852}XSysTray.Exmr[random].dllBackdoor.Krepper.b
    {1768ECFC-4F5C-4f5b-B134-D67294FC78E9}XSysTray.Exsh[random].dll Troj/Cozdoor-D
    {2368D1FC-2F5C-4f1b-B124-E67214FC78E2}XSysTray.Exsn[random].dllBackdoor.Small.ig
    {7368D5FC-6F5C-4f5b-B964-E67214F67852}XSysTray.Exys[random].dll TR/Drop.Small.afo.2
    {********-****-****-****-************}XUnknownUnknown UnknownVolume VolumeAlrt VolumeChk
    VolumeDrive VolumeRam VolumeService VolumeSrv
    %WINDIR%\Installer\{********-****-****-****-************}\[name].dllTrojan.Win32.Agent (browser hijacker)
    {523455E4-ABCD-ABCD-1114-D709ADD3DDAB}XUpperHost%SYSDIR%\UpperHost.dllGoldun variant
    {EB9BDABE-1BD2-445B-9A13-BA9C7D2E3CA9}OURLREWINnetknl.dllSpector Keylogger
    {********-****-****-****-************}Xvadokmxt%WINDIR%\vadokmxt.dll Smitfraud
    {********-****-****-****-************}Xversionlibinets.dll W32/Dabber-D
    {********-****-****-****-************}XVersion1libweb.dll Win32/Checkout.M
    {********-****-****-****-************}XVersion1%SYSDIR%\syspoints.dll W32/IRCBot-XN
    {********-****-****-****-************}XVersion1 syspoint.dllIRCBot variant
    {********-****-****-****-************}XVolumeUnknown WinAvp WinDrv WinRom WinService WinSrv
    WinSetup
    %WINDIR%\Installer\{********-****-****-****-************}\[name].dllTrojan.Win32.Agent (browser hijacker)
    {********-****-****-****-************}Xvpnconfigvpnconfig.dll Win32.Adware.Agent
    {********-****-****-****-************}Xvpssup%WINDIR%\vpssup.dll MyGeek/CPVFeed
    {********-****-****-****-************}Xwdpoefan%WINDIR%\wdpoefan.dll Smitfraud
    {7CFBACFF-EE01-1231-ABDD-416592E5D639}XWeb Event Logger[8 random characters].dll Troj/Padodor-R
    {7CFBACFF-EE01-1231-ABDD-416592E5D639}XWeb Event Logger[random].dll Troj/Qukart-W
    {79FEACFF-FFCE-815E-A900-316290B5B738}XWeb Event Logger[8 random characters].dll Troj/Padodor-K
    {E6FB5E20-DE35-11CF-9C87-00AA005127ED}LWebCheck%SYSDIR%\webcheck.dllWebsite Monitor
    {FE2DB5FF-5ECF-11D2-B28F-0080C8383C7B}XWebExtLocation[random].dllunknown malware
    {66186F05-BBBB-4a39-864F-72D84615C679}XWebProxy%SYSDIR%\sockins32.dll W32/Dwnldr-HCP
    {66186F05-BBBB-4a39-864F-72D84615C679}XWebProxysockots64.dllTrojan.Clicker (Nuwar variant)
    {4C611512-2C1D-44b2-A044-872AD2AD5A61}Xwebworkwebwork.dll BaiduBar
    {1d64c57d-091f-4aa8-8bb6-06543a8bc431}XWinCD%WINDIR%\Installer\{1d64c57d-091f-4aa8-8bb6-06543a8bc431}\WinCD.dll SmitFraud
    {009541A0-3B00-1F1C-00F3-040224009C02}XWinCTLProgram Files\Common Files\winctl.dll Troj/Small-EJG
    {none}Xwinupzod32.exe W32/Dozic-A
    {********-****-****-****-************}Xwmpconfwmpconf.dllTrojan.SystemPoser
    {********-****-****-****-************}Xwmpdev%WINDIR%\wmpdev.dll Smitfraud
    {********-****-****-****-************}Xwmpenvwmpenv.dllTrojan.SystemPoser
    {********-****-****-****-************}Xwmphost%WINDIR%\wmphost.dll Smitfraud
    {********-****-****-****-************}Xwmplayer%WINDIR%\wmplayer.dll Smitfraud
    {********-****-****-****-************}Xwmsound%WINDIR%\wmsound.dll Smitfraud
    {AAA288BA-9A4C-45B0-95D7-94D524869DB5}LWPDShServiceObjWPDShServiceObj.dllWindows Portable Device Shell Service Object
    {********-****-****-****-************}Xxcvwer%WINDIR%\xcvwer.dll Smitfraud
    {0C887F38-5178-43DA-B9F0-B856141FCDA4}XXmLdrLocationmserrtrc.dll, nvrcr32.dll, olescn32.dll, msuueng.dll Spyware.Eblaster
    {********-****-****-****-************}Xxvideo%WINDIR%\xvideo.dll Smitfraud
    {********-****-****-****-************}Xzip%WINDIR%\Installer\{********-****-****-****-************}\zip.dllTrojan.Win32.Agent (browser hijacker)

    Engine Version 2.0 by CastleCops

    spacer spacer