O2-Browser Helper Objects browser (BHO).

This module search all Browser Helper Objects (BHO) installed. A BHO is an application that adds some features to the Web browser.

Features

– Search on the CLSID of the Base of registry key subkeys
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects]

– The line is commented with the owner's name and the name of the file. (.Google Inc. – GoogleToolbarNotifier.)
– In the absence of startup and file, and so owner and description of the file, There are display of the mention 'an orphan key '.. The orphaned keys usually come a poorly done software uninstaller or a partial disinfection.

Overview ZHPDiag

—\\ Browser Helper Objects in browser (O2)
O2 – BHO: Google Toolbar notify BHO – {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} . (.Google Inc. – GoogleToolbarNotifier.) — C:\Program FilesGoogleGoogleToolbarNotifier5.4.4525.1752swg.dll
O2 – BHO: Google Toolbar Helper – {AA58ED58-01DD-4d91-8333-CF10577473F7} . (.Pas de propriétaire – Pas de description.) — C:\Program FilesGoogleGoogle ToolbarGoogleToolbar.dll
O2 – BHO: (name no.) – {00000000-17A6-11D0-99CB-00C04FD64497} An orphan key

Equivalence HijackThis

O2 – BHO: Google Toolbar notify BHO – {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} – C:\Program FilesGoogleGoogleToolbarNotifier5.4.4525.1752swg.dll
O2 – BHO: Google Toolbar Helper – {AA58ED58-01DD-4d91-8333-CF10577473F7} – C:\Program FilesGoogleGoogle ToolbarGoogleToolbar.dll

Equivalence OTL

O2 – BHO: (JQSIEStartDetectorImpl Class) – {E7E6F031-17CE-4C07-BC86-EABFE594F69C} – C:\Program FilesJavajre6libdeployjqsiejqs_plugin.dll (Sun Microsystems, Inc.);

Example of infection

O2 – BHO: MyWebSearch Search Assistant BHO – {00A6FAF1-072E-44cf-8957-5838F569A31D} . (.Pas de propriétaire – Pas de description.) — C:\Program FilesMyWebSearchbar1.binMWSSRCAS. DLL => Infection BT (MyWebSearch.Spy)

– Iinfection with usurpation of owner name :
O2 – BHO: (name no.) – {27598B57-2F92-42F0-A5FE-CF22BAFFC149} . (.Microsoft Corporation – User Idle Monitor.) — c:\windowssystem32ghfuhwu.dll => Infection BT

Action ZHPFix (General case)

O2 – BHO: (name no.) – {CLSIDKey} – {FileName}

{Key} : Registry key [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects]
{Startup} : Default value of the key [HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{CLSIDKey}]
{CLSIDKey} : The key CLSID subkey {Key}
{FileName} : The default value of the key data [HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{CLSIDKey}\InProcServer32]

1) The tool deletes the key [HKLMSOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper ObjectsCLSIDKEY}]
2) The Remove toolme the key [HKLMSOFTWAREClassesCLSID{CLSIDKey}]
3) The tool deletes the key [HKEY_CLASSES_ROOTCLSID{CLSIDKey}]
4) The tool removes the file {FileName}

Action ZHPFix (Case of an orphan key)

O2 – BHO: {Startup} – {CLSIDKey} An orphan key

{Key} : Registry key [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects]
{Startup} : Default value of the key [HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{CLSIDKey}]
{CLSIDKey} : The key CLSID subkey {Key}
{FileName} : The default value of the key data [HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{CLSIDKey}\InProcServer32]

1) The tool deletes the key [HKLMSOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper ObjectsCLSIDKey}]
2) The tool deletes the key [HKLMSOFTWAREClassesCLSID{CLSIDKey}]
3) The tool deletes the key [HKEY_CLASSES_ROOTCLSID{CLSIDKey}]

Report ZHPFix (General case)

O2 – BHO: MyWebSearch Search Assistant BHO – {00A6FAF1-072E-44cf-8957-5838F569A31D} . (…) — C:\Program FilesMyWebSearchbar1.binMWSSRCAS. DLL

Report of ZHPFix v1.12.3133 by Nicolas Coolman, Update of the 02/08/2010

= Key(s) the registry =.
O2 – BHO: MyWebSearch Search Assistant BHO – {00A6FAF1-072E-44cf-8957-5838F569A31D} . (…) — C:\Program FilesMyWebSearchbar1.binMWSSRCAS. DLL => Key deleted successfully
[HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{00A6FAF1-072E-44cf-8957-5838F569A31D}] => Key deleted successfully
[HKCRCLSID{00A6FAF1-072E-44cf-8957-5838F569A31D}] => Key deleted successfully

= File(s) ==========
C:\Program FilesMyWebSearchbar1.binMWSSRCAS. DLL => Deleted and quarantined

= Summary =.
3 : Key(s) the registry
1 : File(s)

Report ZHPFix (Case of an orphan key)

O2 – BHO: (name no.) – {00000000-17A6-11D0-99CB-00C04FD64497} An orphan key

Report of ZHPFix v1.12.3155 by Nicolas Coolman, Update of the 20/09/2010

= Key(s) the registry =.
O2 – BHO: (name no.) – {00000000-17A6-11D0-99CB-00C04FD64497} An orphan key => Key deleted successfully
[HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{00000000-17A6-11D0-99CB-00C04FD64497}] => Key deleted successfully
[HKCRCLSID{00000000-17A6-11D0-99CB-00C04FD64497}] => Key deleted successfully

= Summary =.
3 : Key(s) the registry

Links

* Browser Helper Objects