List Information

Started by: Tony Klein

Maintained by: TonyKlein, miekiemoes
CLSID List

The CLSID list catalogues a number of different Windows / Internet Explorer components:

Browser Helper Objects (BHOs), Toolbars (TBs), SearchHooks (SHs), Explorer Bars (EBs)

Status Key:
X = Malware, spyware, adware, or other potentially unwanted items
L = Legitimate items
O = Open to debate
? = Currently unknown status
Search Results
(displaying 17 results)

CLSID Name Filename Description Status
{B3A05538-8F91-49C1-8EE3-6EB142B41E2A}HelloWorldBHO, Microsoft HelpMicrosoft.System.Help.dll, Microsoft.System.Help.Object.dll, Microsoft.System.Help.Library.dllKeyword hijacker redirecting to find.fm and bestsamara.org, detected by Kaspersky antivirus as Trojan.Win32.BHO.esX BHO
{11111111-1111-1111-1111-110611561119}6d9e5b4b83b642dda6872290d49
2b0fa0065619, System Support
System Support-bho.dll, System Support-bho64.dllCrossrider cross-browser plugin, often bundled with third party software or part of an adware bundle - detected as Adware.CrossRider and by Malwarebytes Anti-Malware as "PUP.Optional.CrossRider" or "PUP.Optional.SystemSupport.A" - also see hereX BHO
{11111111-1111-1111-1111-110211701196}CrossriderApp0027096, Services x86Services x86.dll, Services x86-bho.dllCrossrider cross-browser plugin, detected as Adware.GamePlayLabs or Adware.CrossRider and by Malwarebytes Anti-Malware as PUP.215Apps, PUP.CrossFire or PUP.CrossRiderX BHO
{67A06BB1-027B-4E94-8C3D-2DCD5E808A28}IHiu ClassServices.dll, AYBHOAD.dllParasite of Chinese origin, a variant of the Win-Clicker/Puper.73728 trojan - also detected as Trojan.HIUX BHO
{BE1962AB-3E8F-422a-934D-12E1AD39AF4C}XBTB00664intermedia-services.com.dll, INTERM~*.DLLFlatland.net Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this.O BHO
{2EE23D9D-622E-4E74-A8A0-26141A81A905}Flatland Toolbarintermedia-services.com.dll, INTERM~*.DLLFlatland.net Toolbar - a Softomate Toolbar variant - Softomate customizes toolbars to customers needs. The dll files for their toolbars contain some spyware/adware functionality, although not all of the toolbars use this.O TB
{18CB1A7B-94CD-4582-8022-ADA16851E44B}[random name] moduleCableRouting.dll, BurstWriting.dll, ColorUtility.dll, AbsoluteTransfer.dll, CenterLock.dll, LabelCommand.dll, LogicFunctions.dll, services.dllWinSpywareProtect adware, also see hereX BHO
{D03419A3-BF44-4b21-81B9-C59046E87C4A}XBTP04665System.dllSoftomate Toolbar variant, detected by Kaspersky antivirus as AdWare.Win32.Softomate.xX BHO
{A8C9556C-FDF9-4e07-887F-6DA5E4BD233E}XBTP04665 ClassSystem.dllSoftomate Toolbar variant, detected by Kaspersky antivirus as AdWare.Win32.Softomate.xX BHO
{B7D3E479-CC68-42B5-A338-938ECE35F419}SystemSystem.dllSoftomate Toolbar variant, detected by Kaspersky antivirus as AdWare.Win32.Softomate.xX TB, SH
{A692062A-11A1-261B-BE36-B971F01F35FC}(no name)system.dllParasite of Chinese origin, detected by Kaspersky antivirus as Trojan-Downloader.Win32.Delf.basX BHO
{FFFFFFFF-74CC-4B7C-B5F1-45913F368388}(no name)SystemInspect.dll, SYSTEM~*.DLLPPRich adware of Chinese origin - also see hereX BHO
{11111111-1111-1111-1111-110011471161}CrossriderApp0004761facebook lily system.dllCrossrider cross-browser plugin - installed by TrojanDownloader:Win32/Deyjalil.A aka "LilyJade"- also see here and hereX BHO
{B6F1A4CB-DADD-4D0C-BDFC-E945647302C1}(no name)systems.dll, system.dll, wmplayer.dll, autoexec.dll, autoexcs.dllDownloader and browser hijacker, detected by Kaspersky antivirus as Adware.Win32.BHO.ar and by Sophos as Troj/BHO-EP - also see hereX BHO
{5BF30720-20EA-4B01-8C6A-21D3B0428FD0}Microsoft HTTP Proxy Mail Simple MAPIwinhlp32.dll, msgsocm.dll, system.dll, twunk_32.dll, SET29.dll, other filenamesPassword stealer aka "Banker" trojan of Brazilian origin, see this ThreatExpert Report. Detected by Kaspersky antivirus as Trojan-Banker.Win32.BHO.acr. also see hereX BHO
{2018eb71-06b5-4438-abf4-e40df31e0be5}CouponFollow.BHOmscoree.dll (Windows system file!) [codebase: Program Files\CouponFollow, LLC\Coupons at Checkout\CouponFollowAddon.dll]Coupons at Checkout - "The Automatic Coupon Savings Tool"L BHO
{36DBC179-A19F-48F2-B16A-6A3E19B42A87}(no name)systeminfo.dll, rundll32.dll, esentutl.dll, tskill.dll, odbcad32.dll, winver.dll, rasdial.dll, setup.dll, spoolsv.dll, finger.dll, charmap.dll, runonce.dll, scardsvr.dll, winspool.dll, any filename taken at random from the System or System32 folderPassword stealer trojan, detected by Symantec as Infostealer.Bzup.BX BHO


Powered by SystemLookup Engine. © 2008-2018 BrightFort. All Rights Reserved. | Privacy Policy | Terms of Use