CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

spacer spacer

O21 ShellServiceObjectDelayLoad

Currently 237 entries and growing...
Last updated on 2008-06-02 04:41:03 Eastern.


FBJ originally ran this list but closed it permanently. FBJ graciously permitted CastleCops to continue maintaining the list as of Jul 8, 2005. The full HTML list is here.

KEY:
  • "L" = Legitimate
  • "O" = Open to Debate
  • "X" = Malware/Bad
  • "?" - Unknown

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z



    CLSIDStatusNamePath/FileDescription
    {********-****-****-****-************}Xsapnet%WINDIR%\sapnet.dll Smitfraud
    {********-****-****-****-************}XServicePrx ServiceRam ServiceRom ServiceSys SetupAlrt
    SetupMon SetupService SrvAlrt SrvCheck
    %WINDIR%\Installer\{********-****-****-****-************}\[name].dllTrojan.Win32.Agent (browser hijacker)
    {8FB2D6CA-E258-48CF-9DAB-EEFB735E225C}XshellserviceShellService.dll Spyware.Ultraview
    {********-****-****-****-************}Xsounddrv%WINDIR%\sounddrv.dll Smitfraud
    {********-****-****-****-************}XSrvComponent SrvSetup SrvUnknown SysDrive SysService
    SysSys UnknownKbd UnknownCD UnknownDrive UnknownKernel
    %WINDIR%\Installer\{********-****-****-****-************}\[name].dllTrojan.Win32.Agent (browser hijacker)
    {********-****-****-****-************}XSvcSyssvcsys.dll Infostealer.Bancos
    {6CBCB0E8-BAAD-4450-AF88-CE02C567AC36}XSvrpnpgeteng.dll Spyware.Eblaster
    {********-****-****-****-************}Xsyscore%WINDIR%\syscore.dll Smitfraud
    {23456789-0000-0020-0900-00AAFF6D2EA4}XSysctl Desktop Handlerntosv.dll Troj/Agent-CL
    {********-****-****-****-************}Xsysdx%WINDIR%\sysdx.dll Smitfraud
    {********-****-****-****-************}Xsyshelps%SYSDIR%\syshelps.dll, wmhs32.dll Troj/IRCBot-WL
    {********-****-****-****-************}Xsyshelpssystesrt32.dll W32/IRCBot-XF
    {********-****-****-****-************}Xsyshostssyshosts.dllhttp://www.sophos.com/security/analyses/w32ircbotwb.html
    {D7FFD784-5276-42D1-887B-00267870A4C7}XSysRunsvshost.dll Troj/Small-CPO
    {********-****-****-****-************}XSystemvr_sys.dll Troj/LdPinch
    {********-****-****-****-************}Xsystem32sysprinters.dll W32/IRCBot-WV
    {54645654-2225-4455-44A1-9F4543D34545}XSystemCheck2vbsys2.dll Troj/AdClick
    {********-****-****-****-************}Xsystemiesystemie.dll Troj/Sisie-D
    {********-****-****-****-************}Xsystempsystemp.dll Troj/Narod-D
    {35CEC8A3-2BE6-11D2-8773-92E220524153}LSysTray%SYSDIR%\stobject.dllSysTray Shell Service Object Library
    {6368D1FC-6F5C-4f1b-B164-E67214F678E9}XSysTray.Exbr[random].dll Troj/Slogger-I
    {5368D5FC-6F6C-4f5b-B564-E67214F67552}XSysTray.Exbt[random].dll Troj/Slogger-K
    {1722ECFF-4356-4f5b-B534-E67294FE75E9}XSysTray.Excn[random].dllWorm.Prox.c
    {1722ECFF-4356-4f5b-B534-E67294FE75E9}XSysTray.Excn2[random].dll Troj/Cozdoor-C
    {636821FC-6F5C-2f1b-B164-E67214F678E2}XSysTray.Exgl[random].dllTrojan-Proxy.Win32.Small variant
    {2963ECFC-4E5C-2f3b-B334-D67434FC72E0}XSysTray.Exiv[random].dll Troj/Slogger-F
    {5368DCFC-4F5C-4f5b-B134-E67294FC78E9}XSysTray.Exlv[random].dllUnidentified malware (probable cozdoor variant)
    {73F8D5FF-6F5C-4f5b-B964-E6F214F6F852}XSysTray.Exmr[random].dllBackdoor.Krepper.b
    {1768ECFC-4F5C-4f5b-B134-D67294FC78E9}XSysTray.Exsh[random].dll Troj/Cozdoor-D
    {2368D1FC-2F5C-4f1b-B124-E67214FC78E2}XSysTray.Exsn[random].dllBackdoor.Small.ig
    {7368D5FC-6F5C-4f5b-B964-E67214F67852}XSysTray.Exys[random].dll TR/Drop.Small.afo.2

    Engine Version 2.0 by CastleCops

    spacer spacer