###############################################################################
#
#  NOADDURL $LST(ClassIDs)
#  Block the Class IDs of malicious programs
#
#  For use with Specific ClassID Remover.
#
#  sidki 2002-07-12
#  updated 2002-08-22 TEggHead
#  updated 2002-12-28 SgtPepper
#  updated 2003-10-20 JD5000
#  updated 2007-05-26 sidki
#
###############################################################################


## |||||||||||||||||||||||||||||||||| Dialers |||||||||||||||||||||||||||||||||


# http://www.ca.com/us/securityadvisor/pest/pest.aspx?id=453074942
# -----------------------------------------------------------------------------
D1B80EBF-1A26-4FEC-B0B9-DCB934C6507E $SET(9=Dialer.AccessMembre)

# http://www.pestpatrol.com/spywarecenter/pest.aspx?id=453074946
# -----------------------------------------------------------------------------
AD7FAFB0-16D6-40C3-AF27-585D6E6453FD $SET(9=Dialer.ComLoad)

# http://www.symantec.com/region/jp/sarcj/data/d/dialer.marcado.html
# -----------------------------------------------------------------------------
03FBB191-FB50-4154-91D7-587D5E3C3C9A $SET(9=Dialer.Marcado)

# http://www.castlecops.com/atxlist-1364.html
# -----------------------------------------------------------------------------
E8EDB60C-951E-4130-93DC-FAF1AD25F8E7 $SET(9=Dialer.MoneyTree)


A45F39DC-3608-4237-8F0E-139F1BC49464 $SET(9=Dialer.01)
C771B05E-E725-4516-97A5-4CE5EB163CFB $SET(9=Dialer.02)
DB893839-10F0-4AF9-92FA-B23528F530AF $SET(9=Dialer.29)
37D29DDC-4754-B54D-BB04-5D865235BF21 $SET(9=Dialer.30)
FFFF0003-0001-101A-A3C9-08002B2F49FB $SET(9=Dialer.31)
F7FD91D1-45E6-4349-B698-F976062DAC26 $SET(9=Dialer.32)
951324C5-B08E-45A7-B95A-C5E49F9F828C $SET(9=Dialer.33)
16E166F9-35E8-4CA5-B50D-5CEFABF45B09 $SET(9=Dialer.34)
9F5BB9E1-31AE-4A13-8734-15CED0F60A3D $SET(9=Dialer.35)
A304787C-B552-CDA6-5A3C-E109F104B767 $SET(9=Dialer.36)
BAFBCDFE-1004-2008-60BA-100242130552 $SET(9=Dialer.37)
FFCEABDA-C04E-7F4A-E9B6-DFA72B2F49FB $SET(9=Dialer.39)
869518C3-FBA5-4D75-8A14-7047437E9498 $SET(9=Dialer.40)
B4E0F9CB-BC06-4A33-BBB3-F75F16B6FF5E $SET(9=Dialer.41)
90D610E8-F6D0-4AD4-93CE-178A46F8C412 $SET(9=Dialer.42)
7CAA184C-91E7-4E84-8681-32F2A0D68DF1 $SET(9=Dialer.43)
3AEA6239-7D97-4B70-A342-A824B55E5A5B $SET(9=Dialer.44)
E7BA45C9-D2F0-4BD0-B7BA-C29C16A46DE6 $SET(9=Dialer.45)
C32EE4CB-E99F-4147-BFAE-67FF3B6F8076 $SET(9=Dialer.46)
C1C3CC42-F029-49A2-91C2-C043DFAE3C96 $SET(9=Dialer.47)
FFFFEEEE-DDDD-CCCC-BBBB-AAAA99998888 $SET(9=Dialer.48)
7DD95801-9882-11CF-9FA9-00AA006C42C4 $SET(9=Dialer.49)
98765432-9876-9876-9876-987654321987 $SET(9=Dialer.50)
91433D86-9F27-402C-B5E3-DEBDD122C339 $SET(9=Dialer.51)
86EEF11E-FF16-48CE-B1A2-474B663041A9 $SET(9=Dialer.52)


## ||||||||||||||||||||||||||||| Adware / Spyware |||||||||||||||||||||||||||||


# www.symantec.com/security_response/writeup.jsp?docid=2004-061516-5303-99
# -----------------------------------------------------------------------------
B10031B2-F184-4803-9A88-D239C0641D70 $SET(9=Adware.180Search)

# http://sarc.com/avcenter/venc/data/adware.adblock.html
# -----------------------------------------------------------------------------
93829908-07C2-44A2-95DB-F78F201A9B48 $SET(9=Adware.AdBlock)

# www.symantec.com/security_response/writeup.jsp?docid=2003-080113-5610-99
# http://www.castlecops.com/atxlist-1131.html
# -----------------------------------------------------------------------------
51958169-D5E3-11D1-AA42-0000E842E40A $SET(9=Adware.BDE.1)
8721F16D-CBF8-4CE5-B924-18D64E12E77E $SET(9=Adware.BDE.2)

# http://vil.nai.com/vil/content/v_133287.htm
# -----------------------------------------------------------------------------
BC207F7D-3E63-4ACA-99B5-FB5F8428200C $SET(9=Adware.BDSearch)

# www.trendmicro.com/vinfo/grayware/ve_graywareDetails.asp?GNAME=ADW_CNSMIN.A
# -----------------------------------------------------------------------------
B83FC273-3522-4CC6-92EC-75CC86678DA4 $SET(9=Adware.CnsMin.A)

# www.symantec.com/security_response/writeup.jsp?docid=2004-091615-0103-99
# -----------------------------------------------------------------------------
1678F7E1-C422-11D0-AD7D-00400515CAAA $SET(9=Adware.CometCursor)

# www.trendmicro.com/vinfo/grayware/ve_graywareDetails.asp?GNAME=ADW_DIYBAR.A
# -----------------------------------------------------------------------------
28E0FA88-ABA8-4937-A247-3031F1A11165 $SET(9=Adware.DIYBar.A)

# http://www.castlecops.com/atxlist-1638.html
# -----------------------------------------------------------------------------
2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6 $SET(9=Adware.DriveCleaner)

# http://www.siteadvisor.com/sites/qqay.com/downloads/1785839/
# -----------------------------------------------------------------------------
A927C078-E82F-471B-83F5-3D1504F7D01B $SET(9=Adware.Estalive)

# http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453097557
# -----------------------------------------------------------------------------
01E69986-A054-4C52-ABE8-EF63DF1C5211 $SET(9=Adware.FindFM)

# www.trendmicro.com/vinfo/grayware/ve_graywareDetails.asp?GNAME=ADW_HOTBAR.F
# -----------------------------------------------------------------------------
B195B3B3-8A05-11D3-97A4-0004ACA6948E $SET(9=Adware.Hotbar.F)

# http://vil.nai.com/vil/content/v_134089.htm
# -----------------------------------------------------------------------------
56A7DC70-E102-4408-A34A-AE06FEF01586 $SET(9=Adware.IEBar)

# http://www.spywaredata.com/spyware/malware/istactivex.dll.php
# www.symantec.com/security_response/writeup.jsp?docid=2003-091913-2632-99
# -----------------------------------------------------------------------------
7C559105-9ECF-42b8-B3F7-832E75EDD959 $SET(9=Adware.ISTbar.1)
018B7EC3-EECA-11D3-8E71-0000E82C6C0D $SET(9=Adware.ISTbar.2)

# http://sarc.com/avcenter/venc/data/adware.mediaticket.html
# -----------------------------------------------------------------------------
9EB320CE-BE1D-4304-A081-4B4665414BEF $SET(9=Adware.MediaTickets)

# http://www.siteadvisor.com/sites/cracks.am/downloads/112235/
# -----------------------------------------------------------------------------
2473BF2D-CA0A-11DA-88DB-0050BF2938E1 $SET(9=Adware.NetPumper)

# http://www.castlecops.com/tk31186-SH_Class.html
# -----------------------------------------------------------------------------
23EF65E8-0D45-46A0-A994-B58CBEE373A9 $SET(9=Adware.Search4Top)

# www.trendmicro.com/vinfo/grayware/ve_graywareDetails.asp?GNAME=ADW_SIDESTEP.A
# -----------------------------------------------------------------------------
0837121A-6472-43BD-8A40-D9221FF1C4CE $SET(9=Adware.SideStep.A)

# http://www.econsultant.com/spyware-database/s/spedia-surf+.html
# -----------------------------------------------------------------------------
84B71424-B020-11D4-B198-000102C6D473 $SET(9=Adware.SpediaSurf+)

# http://vil.nai.com/vil/content/v_137581.htm
# -----------------------------------------------------------------------------
205FF73B-CA67-11D5-99DD-444553540000 $SET(9=Adware.SpywareStormer)

# http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453096392
# -----------------------------------------------------------------------------
D8C6179A-58C3-4662-800A-22DAE7DCB152 $SET(9=Adware.TryToFind)


## ||||||||||||||||||||||||||||| Trojans / Viruses ||||||||||||||||||||||||||||


# http://www.popupsentry.com/G/GBIEH.DLL-3537.html
# -----------------------------------------------------------------------------
E37CB5F0-51F5-4395-A808-5FA49E399F83 $SET(9=Trojan.BancoDoBrasil.1)
DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931 $SET(9=Trojan.BancoDoBrasil.2)

# http://koti.mbnet.fi/pattaya1/customblocking.txt
# -----------------------------------------------------------------------------
D014C699-B8E4-44CC-A15B-C0CD1FF48FF7 $SET(9=Trojan.BVActX)		&&\0

# http://www.castlecops.com/atxlist-1642.html
# -----------------------------------------------------------------------------
00000000-0000-0000-0000-100005000004 $SET(9=Trojan.Downloader.35.1)
00000005-0000-0000-0000-100005000004 $SET(9=Trojan.Downloader.35.2)

# http://www.bitdefender.com/VIRUS-166319-en--Trojan.Funweb.A.html
# -----------------------------------------------------------------------------
1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB $SET(9=Trojan.Funweb.A)

# http://v.chol.com/badcode_info_view.asp?list=/badcode_info_list.asp&seq=5550
# -----------------------------------------------------------------------------
E53458D2-5A83-4BD1-8DE2-EEEBE73BAB77 $SET(9=Trojan.SpySheriff)

# http://www.malwarelist.org/startup/scheda.asp?num=2397
# -----------------------------------------------------------------------------
9F54BF10-C88E-43FD-AA9E-16BF45747C72 $SET(9=Trojan.Win32.Dialer.GL)

# http://www.scanspyware.net/info/WinAntivirus.htm
# -----------------------------------------------------------------------------
B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A $SET(9=Trojan.WinAntivirus.1)
09F1ADAC-76D8-4D0F-99A5-5C907DADB988 $SET(9=Trojan.WinAntivirus.2)


9DE912ED-C9ED-4FDE-816A-27BC68972D59 $SET(9=Trojan.BeWired)		&&\0


## ||||||||||||||||||||||||||||||||| Exploits |||||||||||||||||||||||||||||||||


# http://www.securiteam.com/exploits/5FP080A5FM.html
# -----------------------------------------------------------------------------
0D43FE01-F093-11CF-8940-00A0C9054228 $SET(9=Exploit.FileSystem)		&&\0
F935DC26-1CF0-11D0-ADB9-00C04FD58A0B $SET(9=Exploit.WSH.Network)
F935DC22-1CF0-11D0-ADB9-00C04FD58A0B $SET(9=Exploit.WSH.Shell)

# http://www.securitytracker.com/alerts/2005/Aug/1014727.html
# -----------------------------------------------------------------------------
EC444CB6-3E7E-4865-B1C3-0DE72EF39B3F $SET(9=Exploit.DDS.LibraryShape)	&&\0

# http://www.greymagic.com/security/advisories/gm001-ie/
# -----------------------------------------------------------------------------
11111111-1111-1111-1111-111111111111 $SET(9=Exploit.DSO)

# http://www.securiteam.com/windowsntfocus/5FP010UGAA.html
# -----------------------------------------------------------------------------
03D9F3F2-B0E3-11D2-B081-006008039BF0 $SET(9=Exploit.Javaprxy)

# http://www.kb.cert.org/vuls/id/500753
# -----------------------------------------------------------------------------
D4FE6227-1288-11D0-9097-00AA004254A0 $SET(9=Exploit.Media.NMSA)		&&\0

# http://www.securiteam.com/windowsntfocus/6N00F1FHFE.html
# -----------------------------------------------------------------------------
88D969C5-F192-11D4-A65F-0040963251E5 $SET(9=Exploit.MS-XMLHTTP.4/6)

# http://www.kb.cert.org/vuls/id/234812
# -----------------------------------------------------------------------------
BD96C556-65A3-11D0-983A-00C04FC29E36 $SET(9=Exploit.RDS.DataSpace)

# http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=462
# -----------------------------------------------------------------------------
10072CEC-8CC1-11D1-986E-00A0C955B42E $SET(9=Exploit.VML/PeerDraw)


# http://archives.neohapsis.com/archives/fulldisclosure/2004-12/0312.html
# Controversial, hence blocked but not killed.
# -----------------------------------------------------------------------------
2D360201-FFF5-11d1-8D03-00A0C959BC0(A)\0 $SET(9=Exploit.DHTMLSafe)

# http://archives.neohapsis.com/archives/fulldisclosure/2005-01/0196.html
# Controversial, hence blocked but not killed.
# -----------------------------------------------------------------------------
ADB880A6-D8FF-11CF-9377-00AA003B7A1(1)\0 $SET(9=Exploit.HTMLHelpControl)
