Liste de BHOs (Browser Helper Objects)

Liste de BHOs

   
En savoir plus :  Retourner à la page précédente   Imprimer cette page   

FAQ Microsoft Windows
 
 
Nota :
  1. Que sont les BHOs ?

  2. Anti-BHOs

  3. Nous avions commencé notre propre liste de BHOs à l'époque où cela n'existait pas encore sur l'Internet. La dernière mise à jour de cette liste date du 08 mai 2003. C'est la liste ci-dessous.

  4. La liste de BHOs actuelle la plus complète se trouve sur Castlecops.

  5. Une autre liste de BHOs, tous hostiles.









Nom Description X=Parasite
WebHancer's "Customer Companion"
WHIEHLPR.DLL {C900B400-CDFE-11D3-976A-00E02913A9E0}
Part of WebHancer's "Customer Companion", which according to the vendor "unobtrusively measures DNS lookup, TCP connect and web-page download performance, which includes the following types of measurements: DNS Lookup Time, Response Time, Network Round Trip Time, Load Time, connexion Delay, Access Speed."

Links: http://cexx.org/webhancer.htm (Counterexploitation).

http://www.webhancer.com/site/products/privacy/ (WebHancer's privacy policy).

http://www.zdnet.com/products/stories/reviews/0,4161,2670780,00.html (une histoire dans laquelle PC Magazine utilisa ce BHO lors d'un test de vitesse de connexion.

http://www.webhancer.com/site/support/install.asp (Instructions de désinstallation par WebHancer).

http://fff.fathom.org/ubb/Forum6/HTML/000394.html (un témoignage d'utilisateur - contient des grossièretés de langage).

 
Dragon Naturally Speaking
WEB_IE.DLL {2843DAC1-05EF-11D2-95BA-0060083493D6}
A priori ce Bho est anodin. Il est installé par Dragon Naturally Speaking, un logiciel de dictée vocale.

 
Vx2/e
Voir NetPal
Company=Mindset Interactive
Product=FavoriteMan
Threat=Adware/Spyware/BHO
CompanyURL=http://www.mindseti.com/
CompanyProductURL=
CompanyPrivacyURL=http://www.mindseti.com/privacy.html

 
Vx2/d
Voir NetPal
Company=Mindset Interactive
Product=TPS108
Threat=Adware/Spyware/BHO
CompanyURL=http://www.mindseti.com/
CompanyProductURL=
CompanyPrivacyURL=http://www.mindseti.com/privacy.html

 
Vx2/c
Voir NetPal
Company=Mindset Interactive
Product=RespondMiter/Sputnik
Threat=Adware/Spyware/BHO
CompanyURL=http://www.mindseti.com/
CompanyProductURL=
CompanyPrivacyURL=http://www.mindseti.com/privacy.html

 
Vx2/a
Voir NetPal

 
PricePopper
Voir NetPal

 
Search-Explorer toolbar
Company=Search-Explorer
Product=Search-Explorer toolbar
Threat=BHO
CompanyURL=http://www.search-explorer.com/
CompanyProductURL=http://www.search-explorer.com/
CompanyPrivacyURL=http://www.search-explorer.com/page.jsp?page=privacy
Functionality=A toolbar with search functions and quick links.
Privacy=We use information that we collect to make your Search-Explorer.Com visit more productive and tailored to your individual preferences. We require certain specific information when you contact us or send us a request, and we store that information in secure databases. We share information, both personally identifiable and aggregate data, with companies who provide content to portions of our site and communicate with you on behalf of Search-Explorer.Com.
Description=Uses tracking cookies, and sharing PII. Another source of information: http://and.doxdesk.com/parasite/SearchExplorer.html

 
StarDownloader
SDIEInt.dll {FFFFFEF0-5B30-21D4-945D-000000000000}
Une dll de StarDownloader, tout-à-fait légitime. Ne pas supprimer.

 
SpyBot Search and Destroy
SDHelper {53707962-6F74-2D53-2644-206D7942484F}
SDHelper.dll est une dll de l'utilitaire de sécurité SpyBot Search and Destroy et est tout-à-fait légitime. Ne pas supprimer.

 
NZDD
Voir RealDownload

 
NetZip Download Demon
Voir RealDownload

 
RealDownload
NZDD.DLL {{EBCDDA60-2A68-11D3-8A43-0060083CFB9C}
Part of the RealDownload product, formerly called "NetZip Download Demon" (hence the NZDD name). Does not appear to be "adware" or "spyware", but rather a legitimate BHO, that seems to integrate into your browser to support unzipping of downloads. According to Praveen R. at Real, "NZDD.dll is a system file which is used by RealDownload in downloading files from browser directly by clicking on the link."

Links: Real - Real's website.

 
Norton AntiVirus (NAV)
NavShExt.dll {BDF3E430-B101-42AD-A544-FADC6B084872}
Une dll de Norton Antivirus, tout-à-fait légitime. Ne pas supprimer.

 
Lop.com
Une des pires saloperies qui s'installe sournoisement sur nos machines. Est en partie un Bho. Installe un Bho hostile dont le nom et la clé de registre sont générés aléatoirement ce qui fait des billions de combinaisons dont il est impossible de faire la liste (ne peut donc pas être éradiqué par des outils utilisant des signatures basés sur l'enveloppe (le contenant) mais uniquement sur le contenu).

 
IE Plugin
Company=IMI
Product=IE Plugin
Threat=Spyware/BHO
CompanyURL=http://www.imiserver.com/
CompanyProductURL=http://www.ieplugin.com/intro.html
CompanyPrivacyURL=http://www.imiserver.com/terms.html
Functionality=A typical IE toolbar offering search and advertising
Privacy=12. UPDATES. You grant IMI permission to add/remove features and/or functions to the existing software and/or service, or to install new applications, at any time, in its sole discretion with or without your knowledge and/or interaction. You also grant IMI permission to make any changes to the software and/or service provided at any time.
Description=See Terms Of Use. IMI may change the software at any time and upload it to your computer without your knowledge. It also breaches your security by sending the whole URL to their server whenever it contains one of their keywords.

 
Guard-IE
PNIE.dll {D2F719F3-106A-402B-9996-3A5B12ACA564}
Cet utilitaire anti-popup, anti script etc... est sain. Il installe un Bho tout-à-fait sûr qu'il convient de conserver.

 
Download Accelerator Plus ads
Company=SpeedBit Ltd.
Product=Download Accelerator Plus
Threat=Adware/Spyware/BHO/Unstable
CompanyURL=http://www.speedbit.com/
CompanyProductURL=http://www.speedbit.com/
CompanyPrivacyURL=http://www.speedbit.com/legal/daplicense.asp
Functionality=A download manager that has very useful features like splitted downloads.
Privacy=[...] SpeedBit may gather contact information and other personally identifiable information (such as username, e-mail address, country and zip-code), and demographic information (like their age, occupation or gender). SpeedBit, it's partners, affiliates or other third parties may use any information submitted or collected from you.
Description=See the privacy policy: anyone may use any collected information. To do that, DAP (at least older versions) tries to open a connection even if no downloads are queued. And the Internet Explorer toolbar was unstable on the Windows 98 SE system I tested it on.%0D%0AOne more thing: I couldn't find a link on their webpage that is pointing to the privacy statement URL above. Right now, you will only see it if you install DAP.

 
Aureate Media
AMCIS.DLL {EBBFE27C-BDF0-11D2-BBE5-00609419F467}
Supports advertising-enabled software, and is a product of Radiate (formerly Aureate Media Corporation).

Links: http://home.t-online.de/home/TschiTschi/spyware_hints.htm is a discussion of alleged privacy violations by this DLL and others.

http://www.radiate.com/privacy/falserumors.html is Radiate's response to allegations of privacy violations.

http://www.zdnet.com/eweek/stories/general/0,11011,2478459,00.html is an editorial by Bill Machrone, vice president of technology for Ziff-Davis.

 
Radiate
Voir Aureate Media

 
Acrobat Reader
ACROIEHELPER.OCX {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}

Installé par Adobe Acrobat 5.0 (et Adobe Acrobat Reader). Serait un Bho tout-à-fait légitime. As of June 2, 2001, Adobe has ignored two requests to comment on this BHO. If you have any information on this BHO, please email us at BHODemon@DefinitiveSolutions.com. It is inadvisable to disable this BHO (see the Links below) without completely uninstalling Adobe Acrobat.

Links: this newsgroup thread alleges that disabling this BHO causes Explorer to report "Explorer has caused a runtime error...." and then shutdown.

Pour en savoir plus : Cet article de Microsoft (en anglais)

 
7FaSSt
Company=EMERgency Twenty Four, Inc.
Product=7FaSSt Search
Threat=Browser Hijacker/BHO
CompanyURL=http://www.7search.com/
CompanyProductURL=http://7search.com/fasstsearch.htm
CompanyPrivacyURL=
Functionality=Search add-on for IE
Privacy=From the License Agreement:%0D%0A"You are in full agreement that to gather the information necessary to provide our Information service requires our Software to gather URL and duration information of all web sites visits by the person using your computer while browsing the Internet. This information is then transferred to our database in order to provide you and other users with our 7FaSSt Search (tm) trafic reports. You are in full agreement to the transfer of any and all information necessary to provide the 7FaSSt Search(tm) services to others."
Description=Storing the tracked data in a database is bad enough, but what is meant by the last sentence? Transfer of all data to make the search engine services available to /others/?.%0D%0AAfter installation, the user is asked to enter user name and email address as if that would be necessary for use.

x
ADBreak
Company=AdBreak.com
Product=
Threat=BHO
CompanyURL=http://www.adbreak.com/
CompanyProductURL=http://www.adbreak.com/about.php
CompanyPrivacyURL=http://www.adbreak.com/support.php?action=privacy
Functionality=
Privacy=Privacy URL doesn't say anything about the software itself.
Description=

x
Alexa Toolbar
Company=Alexa Internet
Product=Alexa Toolbar
Threat=Spyware/BHO/Unstable
CompanyURL=http://info.alexa.com/
CompanyProductURL=http://download.alexa.com/alexa6/quicktour.html
CompanyPrivacyURL=http://www.alexa.com/company/privacy.html
Functionality=Internet Explorer toolbar providing additional information and related links about visited websites.
Privacy=ALEXA COLLECTS AND STORES INFORMATION ABOUT THE WEB PAGES YOU VIEW, THE DATA YOU ENTER IN ONLINE FORMS AND SEARCH FIELDS WHILE USING THE ALEXA SOFTWARE, AND, WITH VERSIONS 5.0 AND HIGHER OF THE BROWSER COMPANION SOFTWARE, THE PRODUCTS YOU PURCHASE ONLINE. ALTHOUGH ALEXA DOES NOT ATTEMPT TO ANALYZE WEB USAGE DATA TO DETERMINE THE IDENTITY OF ANY ALEXA USER, SOME INFORMATION COLLECTED BY THE SOFTWARE IS PERSONALLY IDENTIFIABLE. ALEXA AGGREGATES AND ANALYZES THE INFORMATION IT COLLECTS TO IMPROVE ITS SERVICE AND TO PREPARE REPORTS ABOUT AGGREGATE WEB USAGE AND SHOPPING HABITS.%0D%0A[...]%0D%0AWe employ other companies and individuals to perform functions on our behalf, such as technical support services. To perform those functions, it may be necessary for them to obtain access to Alexa's databases and servers, which may contain personally identifying information about users. They may not use such access or information for any purpose other than that for which they are retained.
Description=The privacy statement says it all. They are storing quite a lot information, including personal data like accounts (if account data is used in URL). They give other companies access to their databases; those may only use the data to what it was retained for. The statements says what the data was retained for, but doesn't give exlusions what it isn't retained for.

x
Aornum

x
Bargain Buddy
Company=
Product=
Threat=Adware/BHO
CompanyURL=http://www.mybargainbuddy.com/
CompanyProductURL=
CompanyPrivacyURL=
Functionality=
Privacy=
Description=Page can't be loaded, so no privacy details available

x
BazookaBar

x
Bulla
Company=Bulla Software Publishing
Product=Bulla Internet Explorer Browser Plugin
Threat=Tracking BHO
CompanyURL=http://www.bulla.com/
CompanyProductURL=http://www.bulla.com/
CompanyPrivacyURL=
Functionality=Announces to pay for clicking banners
Privacy=No Privacy Policy available online.
Description=According to http://and.doxdesk.com/parasite/Bulla.html all URLs are transmitted combined with a GUID. Installation works using an ActiveX component that has no trusted certificate. License Agreement in INF-Tool Demo (the installer) contains blank fields for authors name, email etc... The Bulla BHO redirects the browser startpage. May be a false positive if only the IEPlugin system file and browser helper object are found.
x
Burnaby Module

x
CommonName

x
Cytron

x
DailyWinner

x
DailyWinner Prize Bar

x
Deltaclick

x
Divago Surfairy

x
EZSearch / EZCybersearch bar
Company=ezCyberSearch.com
Product=EzCyberSearch
Threat=Hijacker & BHO
CompanyURL=http://www.ezcybersearch.com/
CompanyProductURL=
CompanyPrivacyURL=http://64.159.94.251/privacy.html
Functionality=Search bar
Privacy=With whom your information may be shared: As a general rule, will not disclose any of your personally identifiable information except when we have your permission or under special circumstances, such as when we believe in good faith that the law requires it or under the circumstances described below. Please see the Terms of Service or Use Agreements for each of our products and services for more detailed information about how your personal information may be shared.
Description=But the Terms of Service or Use Agreements state nothing about further uses.

x
Exact Search Bar

x
FriendGreetings E-Card

x
Go'Zilla
GOIEHLP.DLL {CD4C3CF0-4B15-11D1-ABED-709549C10000}
Ostensibly a part of the Go!Zilla product. No information is currently available.

x
Grupo Financiero Banorte software

x
IGN Keywords

x
ILookup/Chgrgs

x
ILookup/Ineb

x
IPInsight

x
InetSpeak / Iexplorr
Company=Jaypee Systems
Product=INetSpeak
Threat=Adware/BHO
CompanyURL=http://www.music-magnet.com/
CompanyProductURL=
CompanyPrivacyURL=
Functionality=Advertisement installed through MusicMagnet
Privacy=
Description=No privacy policy or any mentioning of the BHO found on website.

x
Kontiki

x
LetsSearch IE Toolbar Lookup

x
MSN SmartTags

x
MediaLoads Enhanced

x
My Way Speedbar

x
My Yodlee Assistant

x
MyBar

x
MySearch

x
NetPal / PricePopper
[VX2/a] [VX2/c] [VX2/d] [VX2/e]
Company=Mindset Interactive
Product=NetPal/PricePopper
Threat=Adware/Spyware/BHO
CompanyURL=http://www.mindseti.com/
CompanyProductURL=
CompanyPrivacyURL=http://www.mindseti.com/privacy.html
Functionality=
Privacy=The software collects and transmits to Mindset servers the URLs of the Web pages visited on your browser. URLs are the addresses of the web pages that your browser visits (http://www.Mindseti.com, for example). The Mindset software collects and maintains information on both current and historical browsing. Mindset will use this information to build a summary of your interests so that Mindset can help its partners make relevant and personalized offers to you.%0D%0AMindset and its affiliates' software also collects some information from online forms that you fill out. This information is sent to us in order to save you the time and trouble of submitting such information to us yourself. We use this information to allow our partners to reach you with only those personalized and targeted offers and advertisements that may be relevant to your interests.
Description=How friendly those people at Mindset are. They are collecting information about you and transmit it back to themselves, so you don't need to bother to do it yourself!

x
Netster Smart Browse Toolbar

x
Network Essentials
Company=SmartPops.com
Product=Network Essentials
Threat=Spyware/BHO
CompanyURL=http://www.smartpops.com/
CompanyProductURL=http://www.smartpops.com/terms.html
CompanyPrivacyURL=http://www.smartpops.com/privacy.html
Functionality=Targetted advertisement
Privacy=Access and Interference: You agree that you will not use any robot, spider, other automatic or manual device or process to interfere or attempt to interfere with the proper working of Supplied Licensed Materials.
Description=According to http://and.doxdesk.com/parasite/NetworkEssentials.html it sends visited URLs to its controlling servers. There is a privacy statement for the website, and a link to the terms that should contain 'SmartPops.com downloadable Application Privacy Statement' (& License Agreement), but I couldn't find any privacy information in that second one. Only that you may not interfere with its proper working.

x
New.Net

x
NewDotNet

x
NewtonKnows search bar

x
Odigo

x
OpinionBar Paid-to-Surf

x
ProBot Activity Monitor

x
Qcbar/AdultLinks

x
QuickFlicks Streaming Player

x
Secure4U Firewall

x
SideStep

x
SpotOn Browser plugin

x
StumbleUpon

x
Surfmonkey

x
Transponder

x
Trek8 software

x
UCmore toolbar
Company=Effective-i, Inc.
Product=UCmore toolbar
Threat=BHO
CompanyURL=http://www.ucmore.com/
CompanyProductURL=http://www.ucmore.com/
CompanyPrivacyURL=http://www.ucmore.com/co_privacy.asp
Functionality=Search accelerator & manager
Privacy=Providing personnally identifiable information, such as your e-mail address, will allow us to notify you of updates to our services and concerning products and/or services that we determine you would be interested in.
Description=Accord to http://and.doxdesk.com/parasite/UCmore.html every URL is transmitted with a unique ID.

x
UrlBlaze

x
Videogate VG Companion

x
Vividence Connector

x
W32.Aspam.Trojan.B

x
Win32/Aspam.Trojan

x
WurldMedia/bpboh
Génère des clés et des noms de fichiers aléatoires.

x
XnsMin

x
Xrenoder

x
eBoom Search Bar

x
i-lookup search bar

x
iWon Co-Pilot

x


Nouvelle adresse du site Assiste.com depuis le 22 octobre 2012 : http://assiste.com Nouvelle adresse du site Assiste.com depuis le 22 octobre 2012 : http://assiste.com

Nouvelle adresse du site Assiste.com depuis le 22 octobre 2012 : http://assiste.com






Historique des révisions de ce document :

La dernière mise à jour de cette liste date du 08 mai 2003 - La liste actuelle est sur Castlecops
 
   
Rédigé en écoutant :
Music