<?xml version="1.0" encoding="Windows-1252"?>

<rdf:RDF 
xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" 
xmlns:dc="http://purl.org/dc/elements/1.1/" 
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" 
xmlns:admin="http://webns.net/mvcb/" 
xmlns:cc="http://web.resource.org/cc/" 
xmlns="http://purl.org/rss/1.0/">

<channel rdf:about="BHOList">
<title>Recent 10 BHO/CLSID/Toolbar Lists</title>
<link>http://www.castlecops.com/CLSID.html</link>
<description>CastleCops - TonyKlein's BHO Collection</description>
<dc:language>en-us</dc:language>
<dc:creator>Paul Laudanski (mailto:paul@computercops.biz)</dc:creator>
<dc:rights>Copyright &#169; 2002-2005 CastleCops&amp;reg;</dc:rights>
<dc:date>2008-07-24T01:39:40-05:00</dc:date>
<sy:updatePeriod>daily</sy:updatePeriod>
<sy:updateFrequency>24</sy:updateFrequency>
<sy:updateBase>2003-01-01T12:00-05:00</sy:updateBase>
<admin:generatorAgent rdf:resource="http://www.castlecops.com/" />

<item>
<guid>\{88E2C28F-80C8-49BA-94A3-A5D4930B4A23 }</guid>
<status>X BHO TB</status>
<filename>fdkowvbp.dll</filename>
<description>Parasite causing false spyware warnings and connecting to fake &quot;security sites&quot; - member of the FakeAlert, http://research.sunbelt-software.com/threatdisplay.aspx?threatid=43521 aka SmitFraud, http://research.sunbelt-software.com/threatdisplay.aspx?threatid=44645 malware family </description>
<infourl>http://www.castlecops.com/clsid-55105.html</infourl>
<link>http://www.castlecops.com/clsid-55105.html</link>
</item>
<item>
<guid>\{EF4940D2-F131-4412-BB03-4E40FCE06EC7 }</guid>
<status>X BHO TB</status>
<filename>fdkowvbp.dll</filename>
<description>Parasite causing false spyware warnings and connecting to fake &quot;security sites&quot; - member of the FakeAlert, http://research.sunbelt-software.com/threatdisplay.aspx?threatid=43521 aka SmitFraud, http://research.sunbelt-software.com/threatdisplay.aspx?threatid=44645 malware family </description>
<infourl>http://www.castlecops.com/clsid-55104.html</infourl>
<link>http://www.castlecops.com/clsid-55104.html</link>
</item>
<item>
<guid>\{199C2DDE-26C2-4FC7-A847-A28D57CB5A9B}</guid>
<status>X BHO TB</status>
<filename>fdkowvbp.dll</filename>
<description>Parasite causing false spyware warnings and connecting to fake &quot;security sites&quot; - member of the FakeAlert, http://research.sunbelt-software.com/threatdisplay.aspx?threatid=43521 aka SmitFraud, http://research.sunbelt-software.com/threatdisplay.aspx?threatid=44645 malware family </description>
<infourl>http://www.castlecops.com/clsid-55103.html</infourl>
<link>http://www.castlecops.com/clsid-55103.html</link>
</item>
<item>
<guid>\{FE0F4B4F-A5A0-4529-BC78-1B04220F45E6}</guid>
<status>X BHO TB</status>
<filename>nfavxwdbpgs.dll</filename>
<description>Adware downloader causing false spyware warnings and connecting to rogue &quot;security sites&quot;, a member of the Trojan-Downloader.Zlob.Media-Codec, http://research.sunbelt-software.com/threatdisplay.aspx?threatid=44478 aka NewMediaCodec, http://research.sunbelt-software.com/threatdisplay.aspx?threatid=149335 malware family
</description>
<infourl>http://www.castlecops.com/clsid-55102.html</infourl>
<link>http://www.castlecops.com/clsid-55102.html</link>
</item>
<item>
<guid>\{0D2C5F57-FA50-4B51-885E-EB4A31D734C3}</guid>
<status>X BHO TB</status>
<filename>nfavxwdbqxv.dll</filename>
<description>Adware downloader causing false spyware warnings and connecting to rogue &quot;security sites&quot;, a member of the Trojan-Downloader.Zlob.Media-Codec, http://research.sunbelt-software.com/threatdisplay.aspx?threatid=44478 aka NewMediaCodec, http://research.sunbelt-software.com/threatdisplay.aspx?threatid=149335 malware family
</description>
<infourl>http://www.castlecops.com/clsid-55101.html</infourl>
<link>http://www.castlecops.com/clsid-55101.html</link>
</item>
<item>
<guid>\{FBE58CC0-D14B-45FE-A717-57BB8247F652}</guid>
<status>X BHO TB</status>
<filename>bho2extn.dll, bho_e.dll, bhoext.dll, other semi-random filenames made up from the following fragments: bho, bho2, ie, ext, extn, _e</filename>
<description>Parasite redirecting to fake security sites, member of the FakeAlert, http://research.sunbelt-software.com/threatdisplay.aspx?threatid=43521 aka SmitFraud, http://research.sunbelt-software.com/threatdisplay.aspx?threatid=44645 malware family - produces IEDefender, http://www.symantec.com/security_response/writeup.jsp?docid=2007-111420-0754-99  , FilesSecure, http://www.symantec.com/security_response/writeup.jsp?docid=2007-122812-3859-99 , MalwareBell, http://www.symantec.com/business/security_response/writeup.jsp?docid=2008-041610-3304-99 ,  IE_Antivirus, http://www.symantec.com/business/security_response/writeup.jsp?docid=2008-042813-4856-99&amp;tabid=1 or similar popups - also see here, http://www.bleepingcomputer.com/forums/topic114240.html
</description>
<infourl>http://www.castlecops.com/clsid-55100.html</infourl>
<link>http://www.castlecops.com/clsid-55100.html</link>
</item>
<item>
<guid>\{8E581CE9-8C25-4E5B-9282-564B7DC06ED8}</guid>
<status>X BHO TB</status>
<filename>confmsp.ocx</filename>
<description>Unidentified parasite - should you have any information about this application, such as for example the site where it was downloaded or installed,   [xs4] - if you actually have a copy of the file,  please attach it to your email for analysis.  Thanks!
</description>
<infourl>http://www.castlecops.com/clsid-55099.html</infourl>
<link>http://www.castlecops.com/clsid-55099.html</link>
</item>
<item>
<guid>\{ED71602F-B2F6-470F-943F-0DA300E034D8}</guid>
<status>X BHO TB</status>
<filename>[random filename]</filename>
<description>ConHook, http://research.sunbelt-software.com/threatdisplay.aspx?threatid=45786 aka Chisyne, http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=48117 trojan variant - VirtuMonde/Vundo, http://www.symantec.com/security_response/writeup.jsp?docid=2004-112111-3912-99 adware downloader</description>
<infourl>http://www.castlecops.com/clsid-55098.html</infourl>
<link>http://www.castlecops.com/clsid-55098.html</link>
</item>
<item>
<guid>\{A057A204-BACC-4D26-C7D7-6BAD84E32FCB}</guid>
<status>O BHO TB</status>
<filename>buySAFEShoppingAdvisor.dll, BUYSAF~1.DLL</filename>
<description>buySAFE_Shopping_Advisor, http://www.buysafe.com/web/general/shoppingadvisordownload.aspx</description>
<infourl>http://www.castlecops.com/clsid-55097.html</infourl>
<link>http://www.castlecops.com/clsid-55097.html</link>
</item>
<item>
<guid>\{EAB15366-0E81-476D-83CC-1052FDF017C8}</guid>
<status>X BHO TB</status>
<filename>[random filename]</filename>
<description>ConHook, http://research.sunbelt-software.com/threatdisplay.aspx?threatid=45786 aka Chisyne, http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=48117 trojan variant - VirtuMonde/Vundo, http://www.symantec.com/security_response/writeup.jsp?docid=2004-112111-3912-99 adware downloader</description>
<infourl>http://www.castlecops.com/clsid-55096.html</infourl>
<link>http://www.castlecops.com/clsid-55096.html</link>
</item>
</channel>

</rdf:RDF>

