<?xml version="1.0" encoding="Windows-1252"?>

<rdf:RDF 
xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" 
xmlns:dc="http://purl.org/dc/elements/1.1/" 
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" 
xmlns:admin="http://webns.net/mvcb/" 
xmlns:cc="http://web.resource.org/cc/" 
xmlns="http://purl.org/rss/1.0/">

<channel rdf:about="BHOList">
<title>Recent 10 BHO/CLSID/Toolbar Lists</title>
<link>http://www.castlecops.com/CLSID.html</link>
<description>CastleCops - TonyKlein's BHO Collection</description>
<dc:language>en-us</dc:language>
<dc:creator>Paul Laudanski (mailto:paul@computercops.biz)</dc:creator>
<dc:rights>Copyright &#169; 2002-2005 CastleCops&amp;reg;</dc:rights>
<dc:date>2008-07-20T21:22:25-05:00</dc:date>
<sy:updatePeriod>daily</sy:updatePeriod>
<sy:updateFrequency>24</sy:updateFrequency>
<sy:updateBase>2003-01-01T12:00-05:00</sy:updateBase>
<admin:generatorAgent rdf:resource="http://www.castlecops.com/" />

<item>
<guid>\{188E4299-4959-4C54-A0B1-3E43B082BB59}</guid>
<status>X BHO TB</status>
<filename>qndsfmao.dll</filename>
<description>Parasite causing false spyware warnings and connecting to fake &quot;security sites&quot; - member of the FakeAlert, http://research.sunbelt-software.com/threatdisplay.aspx?threatid=43521 aka SmitFraud, http://research.sunbelt-software.com/threatdisplay.aspx?threatid=44645 malware family
</description>
<infourl>http://www.castlecops.com/clsid-55019.html</infourl>
<link>http://www.castlecops.com/clsid-55019.html</link>
</item>
<item>
<guid>\{6EA1DB25-2524-4DD6-B997-42E8F38C6E46}</guid>
<status>X BHO TB</status>
<filename>219725.dll</filename>
<description>Parasite,  a member of the Trojan-Downloader.Zlob.Media-Codec, http://research.sunbelt-software.com/threatdisplay.aspx?threatid=44478 aka NewMediaCodec, http://research.sunbelt-software.com/threatdisplay.aspx?threatid=149335 malware family - detected as Trackware.ProSearch, http://www.symantec.com/security_response/writeup.jsp?docid=2008-030615-2713-99
</description>
<infourl>http://www.castlecops.com/clsid-55018.html</infourl>
<link>http://www.castlecops.com/clsid-55018.html</link>
</item>
<item>
<guid>\{F8EA6827-1B82-494a-ACAC-A582A714DCA8}</guid>
<status>X BHO TB</status>
<filename>tBHO.dll</filename>
<description>Browser hijacker connecting to wickedscene.com and redirecting searches to seekandexplore.com - a variant of these, http://www.castlecops.com/modules.php?name=CLSID&amp;query=TinyBHO</description>
<infourl>http://www.castlecops.com/clsid-55017.html</infourl>
<link>http://www.castlecops.com/clsid-55017.html</link>
</item>
<item>
<guid>\{D5DDDA4B-BB20-4DE5-A8AC-CDB828FA5858}</guid>
<status>O BHO TB</status>
<filename>ieexp.dll</filename>
<description>Jingle Keyboard, http://www.yankeedownload.com/software/jingle-keyboard-jkqji.html</description>
<infourl>http://www.castlecops.com/clsid-55016.html</infourl>
<link>http://www.castlecops.com/clsid-55016.html</link>
</item>
<item>
<guid>\{22485458-DFE2-461D-92BB-6FBE7B53A1C3}</guid>
<status>X BHO TB</status>
<filename>sqvgnrpx.dll</filename>
<description>Parasite causing false spyware warnings and connecting to fake &quot;security sites&quot; - member of the FakeAlert, http://research.sunbelt-software.com/threatdisplay.aspx?threatid=43521 aka SmitFraud, http://research.sunbelt-software.com/threatdisplay.aspx?threatid=44645 malware family
</description>
<infourl>http://www.castlecops.com/clsid-55015.html</infourl>
<link>http://www.castlecops.com/clsid-55015.html</link>
</item>
<item>
<guid>\{106827D3-2E72-401A-B9E2-849A518128DA}</guid>
<status>X BHO TB</status>
<filename>wbxdpgfembe.dll</filename>
<description>Adware downloader causing false spyware warnings and connecting to rogue &quot;security sites&quot;, a member of the Trojan-Downloader.Zlob.Media-Codec, http://research.sunbelt-software.com/threatdisplay.aspx?threatid=44478 aka NewMediaCodec, http://research.sunbelt-software.com/threatdisplay.aspx?threatid=149335 malware family
</description>
<infourl>http://www.castlecops.com/clsid-55014.html</infourl>
<link>http://www.castlecops.com/clsid-55014.html</link>
</item>
<item>
<guid>\{529842C8-D114-4D26-9C99-ED1EFE297D9A}</guid>
<status>X BHO TB</status>
<filename>jtoolbars.dll, JTOOLB~2.DLL</filename>
<description>Parasite of Korean origin detected as CashBack or JToolbar adware - see here, http://kr.ahnlab.com/info/smart2u/virus_detail_16942.html
</description>
<infourl>http://www.castlecops.com/clsid-55013.html</infourl>
<link>http://www.castlecops.com/clsid-55013.html</link>
</item>
<item>
<guid>\{19EA4A41-C849-4756-A5B8-D25EC7AA87D1}</guid>
<status>X BHO TB</status>
<filename>jtoolbar.dll, JTOOLB~1.DLL</filename>
<description>Parasite of Korean origin detected as CashBack or JToolbar adware - see here, http://kr.ahnlab.com/info/smart2u/virus_detail_16942.html
</description>
<infourl>http://www.castlecops.com/clsid-55012.html</infourl>
<link>http://www.castlecops.com/clsid-55012.html</link>
</item>
<item>
<guid>\{098716A9-0310-4CBE-BD64-B790A9761158}</guid>
<status>X BHO TB</status>
<filename>RichVideoCodec.dll</filename>
<description>Adware downloader, member of the Trojan-Downloader.Zlob.Media-Codec, http://research.sunbelt-software.com/threatdisplay.aspx?threatid=44478 aka NewMediaCodec, http://research.sunbelt-software.com/threatdisplay.aspx?threatid=149335 malware family
</description>
<infourl>http://www.castlecops.com/clsid-55011.html</infourl>
<link>http://www.castlecops.com/clsid-55011.html</link>
</item>
<item>
<guid>\{E759620E-585D-4893-A44B-C84F892A3100}</guid>
<status>X BHO TB</status>
<filename>[random filename]</filename>
<description>ConHook, http://research.sunbelt-software.com/threatdisplay.aspx?threatid=45786 aka Chisyne, http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=48117 trojan variant - VirtuMonde/Vundo, http://www.symantec.com/security_response/writeup.jsp?docid=2004-112111-3912-99 adware downloader</description>
<infourl>http://www.castlecops.com/clsid-55010.html</infourl>
<link>http://www.castlecops.com/clsid-55010.html</link>
</item>
</channel>

</rdf:RDF>

