<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: hijack this list` in Operating System - Microsoft</title>
    <link>https://community.hpe.com/t5/operating-system-microsoft/hijack-this-list/m-p/3342386#M5160</link>
    <description>Looks pretty clean now.  If everything is working as you want then you might want to go back into HijackThis and check everything then click on Add Checked to Ignore List.  That way if it happens again and you need to rerun hijackthis then you will only see the new stuff which has been added.&lt;BR /&gt;&lt;BR /&gt;Also a good time to make a restore point.&lt;BR /&gt;&lt;BR /&gt;Ron</description>
    <pubDate>Wed, 28 Jul 2004 15:15:34 GMT</pubDate>
    <dc:creator>Ron Kinner</dc:creator>
    <dc:date>2004-07-28T15:15:34Z</dc:date>
    <item>
      <title>hijack this list`</title>
      <link>https://community.hpe.com/t5/operating-system-microsoft/hijack-this-list/m-p/3342383#M5157</link>
      <description>hi i just did what you told that person to do, download all those things and so forth. So here's what i got after i did the hijacked thing:&lt;BR /&gt;Logfile of HijackThis v1.97.7&lt;BR /&gt;Scan saved at 6:56:39 PM, on 7/26/2004&lt;BR /&gt;Platform: Windows ME (Win9x 4.90.3000)&lt;BR /&gt;MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)&lt;BR /&gt;&lt;BR /&gt;Running processes:&lt;BR /&gt;C:\WINDOWS\SYSTEM\KERNEL32.DLL&lt;BR /&gt;C:\WINDOWS\SYSTEM\MSGSRV32.EXE&lt;BR /&gt;C:\WINDOWS\SYSTEM\mmtask.tsk&lt;BR /&gt;C:\WINDOWS\SYSTEM\MPREXE.EXE&lt;BR /&gt;C:\WINDOWS\SYSTEM\MSTASK.EXE&lt;BR /&gt;C:\WINDOWS\SYSTEM\ATI2EVXX.EXE&lt;BR /&gt;C:\WINDOWS\EXPLORER.EXE&lt;BR /&gt;C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE&lt;BR /&gt;C:\WINDOWS\TASKMON.EXE&lt;BR /&gt;C:\WINDOWS\SYSTEM\SYSTRAY.EXE&lt;BR /&gt;C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE&lt;BR /&gt;C:\WINDOWS\SYSTEM\WMIEXE.EXE&lt;BR /&gt;C:\WINDOWS\SYSTEM\DDHELP.EXE&lt;BR /&gt;C:\UNZIPPED\HIJACKTHIS[1]\HIJACKTHIS.EXE&lt;BR /&gt;&lt;BR /&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://192.168.1.1/index.htm" target="_blank"&gt;http://192.168.1.1/index.htm&lt;/A&gt;&lt;BR /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&amp;amp;clcid={SUB_CLSID}&amp;amp;pver={SUB_PVER}&amp;amp;ar=home" target="_blank"&gt;http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&amp;amp;clcid={SUB_CLSID}&amp;amp;pver={SUB_PVER}&amp;amp;ar=home&lt;/A&gt;&lt;BR /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://www.microsoft.com/isapi/redir.dll?prd=ie&amp;amp;ar=iesearch" target="_blank"&gt;http://www.microsoft.com/isapi/redir.dll?prd=ie&amp;amp;ar=iesearch&lt;/A&gt;&lt;BR /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;A href="http://www.microsoft.com/isapi/redir.dll?prd=ie&amp;amp;pver=6&amp;amp;ar=msnhome" target="_blank"&gt;http://www.microsoft.com/isapi/redir.dll?prd=ie&amp;amp;pver=6&amp;amp;ar=msnhome&lt;/A&gt;&lt;BR /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;A href="http://www.microsoft.com/isapi/redir.dll?prd=ie&amp;amp;ar=iesearch" target="_blank"&gt;http://www.microsoft.com/isapi/redir.dll?prd=ie&amp;amp;ar=iesearch&lt;/A&gt;&lt;BR /&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = &lt;A href="http://www.google.com/keyword/%s" target="_blank"&gt;http://www.google.com/keyword/%s&lt;/A&gt;&lt;BR /&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = &lt;A href="http://192.168.1.1/" target="_blank"&gt;http://192.168.1.1/&lt;/A&gt;&lt;BR /&gt;R3 - URLSearchHook: URLSearch Class - {965A592F-8EFA-4250-8630-7960230792F1} - C:\WINDOWS\SYSTEM\CDSM32.DLL&lt;BR /&gt;R3 - URLSearchHook: (no name) - {707E6F76-9FFB-4920-A976-EA101271BC25} - C:\PROGRAM FILES\TV MEDIA\TvmBho.dll (file missing)&lt;BR /&gt;O2 - BHO: (no name) - {5FA6752A-C4A0-4222-88C2-928AE5AB4966} - C:\WINDOWS\SYSTEM\SWIN32.DLL&lt;BR /&gt;O2 - BHO: (no name) - {A3FDD654-A057-4971-9844-4ED8E67DBBB8} - C:\PROGRAM FILES\SIDEFIND\SFBHO.DLL (file missing)&lt;BR /&gt;O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search &amp;amp; Destroy\SDHelper.dll&lt;BR /&gt;O3 - Toolbar: @msdxmLC.dll,-1@1033,&amp;amp;Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX&lt;BR /&gt;O3 - Toolbar: &amp;amp;Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll&lt;BR /&gt;O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun&lt;BR /&gt;O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe&lt;BR /&gt;O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s&lt;BR /&gt;O4 - HKLM\..\Run: [SystemTray] SysTray.Exe&lt;BR /&gt;O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe&lt;BR /&gt;O4 - HKLM\..\Run: [MSConfigReminder] C:\WINDOWS\SYSTEM\msconfig.exe /reminder&lt;BR /&gt;O4 - HKLM\..\Run: [bxxs5] RunDLL32.EXE C:\WINDOWS\BXXS5.DLL,DllRun&lt;BR /&gt;O4 - HKLM\..\Run: [Adstartup] C:\WINDOWS\SYSTEM\automove.exe&lt;BR /&gt;O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme&lt;BR /&gt;O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe&lt;BR /&gt;O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe&lt;BR /&gt;O4 - HKLM\..\RunServices: [ATIPOLL] ati2evxx.exe&lt;BR /&gt;O4 - HKLM\..\RunServices: [ATISmart] C:\WINDOWS\SYSTEM\ati2s9ag.exe&lt;BR /&gt;O4 - HKCU\..\Run: [Steam] "c:\valve\steam\steam.exe" -silent&lt;BR /&gt;O8 - Extra context menu item: &amp;amp;Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsearch.html&lt;BR /&gt;O8 - Extra context menu item: Cac&amp;amp;hed Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmcache.html&lt;BR /&gt;O8 - Extra context menu item: Si&amp;amp;milar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsimilar.html&lt;BR /&gt;O8 - Extra context menu item: Backward &amp;amp;Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmbacklinks.html&lt;BR /&gt;O8 - Extra context menu item: Translate into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmtrans.html&lt;BR /&gt;O9 - Extra button: AIM (HKLM)&lt;BR /&gt;O9 - Extra button: SideFind (HKLM)&lt;BR /&gt;O9 - Extra button: WeatherBug (HKCU)&lt;BR /&gt;O10 - Hijacked Internet access by WebHancer&lt;BR /&gt;O10 - Hijacked Internet access by WebHancer&lt;BR /&gt;O10 - Hijacked Internet access by WebHancer&lt;BR /&gt;O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - &lt;A href="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab" target="_blank"&gt;http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab&lt;/A&gt;&lt;BR /&gt;O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - &lt;A href="http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB" target="_blank"&gt;http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB&lt;/A&gt;&lt;BR /&gt;O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - &lt;A href="http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?38072.951875" target="_blank"&gt;http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?38072.951875&lt;/A&gt;&lt;BR /&gt;O16 - DPF: {68BCE50A-DC9B-4519-A118-6FDA19DB450D} (Info Class) - &lt;A href="http://www.blizzard.com/support/includes/cabs/si.cab" target="_blank"&gt;http://www.blizzard.com/support/includes/cabs/si.cab&lt;/A&gt;&lt;BR /&gt;O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - &lt;A href="http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab" target="_blank"&gt;http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab&lt;/A&gt;&lt;BR /&gt;O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - &lt;A href="http://www.apple.com/qtactivex/qtplugin.cab" target="_blank"&gt;http://www.apple.com/qtactivex/qtplugin.cab&lt;/A&gt;&lt;BR /&gt;O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - &lt;A href="http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab" target="_blank"&gt;http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab&lt;/A&gt;&lt;BR /&gt;O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - &lt;A href="http://chat.yahoo.com/cab/yacsui.cab" target="_blank"&gt;http://chat.yahoo.com/cab/yacsui.cab&lt;/A&gt;&lt;BR /&gt;O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - &lt;A href="http://chat.yahoo.com/cab/yvwrctl.cab" target="_blank"&gt;http://chat.yahoo.com/cab/yvwrctl.cab&lt;/A&gt;&lt;BR /&gt;O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - &lt;A href="http://zone.msn.com/bingame/zuma/default/popcaploader_v5.cab" target="_blank"&gt;http://zone.msn.com/bingame/zuma/default/popcaploader_v5.cab&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;please help, i always get some stupid ad popup on my computer and this download thing asking me to download a bxxs5. w/e</description>
      <pubDate>Tue, 27 Jul 2004 12:05:56 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-microsoft/hijack-this-list/m-p/3342383#M5157</guid>
      <dc:creator>Brandon Krisstopher San</dc:creator>
      <dc:date>2004-07-27T12:05:56Z</dc:date>
    </item>
    <item>
      <title>Re: hijack this list`</title>
      <link>https://community.hpe.com/t5/operating-system-microsoft/hijack-this-list/m-p/3342384#M5158</link>
      <description>Check the following and then hit Fix Checked.&lt;BR /&gt;&lt;BR /&gt;R3 - URLSearchHook: URLSearch Class - {965A592F-8EFA-4250-8630-7960230792F1} - C:\WINDOWS\SYSTEM\CDSM32.DLL&lt;BR /&gt;R3 - URLSearchHook: (no name) - {707E6F76-9FFB-4920-A976-EA101271BC25} - C:\PROGRAM FILES\TV MEDIA\TvmBho.dll (file missing)&lt;BR /&gt;O2 - BHO: (no name) - {5FA6752A-C4A0-4222-88C2-928AE5AB4966} - C:\WINDOWS\SYSTEM\SWIN32.DLL&lt;BR /&gt;O2 - BHO: (no name) - {A3FDD654-A057-4971-9844-4ED8E67DBBB8} - C:\PROGRAM FILES\SIDEFIND\SFBHO.DLL (file missing)&lt;BR /&gt;O4 - HKLM\..\Run: [bxxs5] RunDLL32.EXE C:\WINDOWS\BXXS5.DLL,DllRun&lt;BR /&gt;O4 - HKLM\..\Run: [Adstartup] C:\WINDOWS\SYSTEM\automove.exe&lt;BR /&gt;O9 - Extra button: SideFind (HKLM)&lt;BR /&gt;O10 - Hijacked Internet access by WebHancer&lt;BR /&gt;O10 - Hijacked Internet access by WebHancer&lt;BR /&gt;O10 - Hijacked Internet access by WebHancer&lt;BR /&gt;&lt;BR /&gt;You can get rid of this thing too unless you really like it.  &lt;BR /&gt;&lt;BR /&gt;O9 - Extra button: WeatherBug (HKCU)&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Don't forget to run HijackThis again after rebooting and repost so I can check that we got it all.&lt;BR /&gt;&lt;BR /&gt;Ron</description>
      <pubDate>Tue, 27 Jul 2004 13:06:44 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-microsoft/hijack-this-list/m-p/3342384#M5158</guid>
      <dc:creator>Ron Kinner</dc:creator>
      <dc:date>2004-07-27T13:06:44Z</dc:date>
    </item>
    <item>
      <title>Re: hijack this list`</title>
      <link>https://community.hpe.com/t5/operating-system-microsoft/hijack-this-list/m-p/3342385#M5159</link>
      <description>i did that and now restarted so heres what i got:&lt;BR /&gt;Logfile of HijackThis v1.97.7&lt;BR /&gt;Scan saved at 5:12:44 PM, on 7/27/2004&lt;BR /&gt;Platform: Windows ME (Win9x 4.90.3000)&lt;BR /&gt;MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)&lt;BR /&gt;&lt;BR /&gt;Running processes:&lt;BR /&gt;C:\WINDOWS\SYSTEM\KERNEL32.DLL&lt;BR /&gt;C:\WINDOWS\SYSTEM\MSGSRV32.EXE&lt;BR /&gt;C:\WINDOWS\SYSTEM\mmtask.tsk&lt;BR /&gt;C:\WINDOWS\SYSTEM\MPREXE.EXE&lt;BR /&gt;C:\WINDOWS\SYSTEM\MSTASK.EXE&lt;BR /&gt;C:\WINDOWS\SYSTEM\ATI2EVXX.EXE&lt;BR /&gt;C:\WINDOWS\EXPLORER.EXE&lt;BR /&gt;C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE&lt;BR /&gt;C:\WINDOWS\TASKMON.EXE&lt;BR /&gt;C:\WINDOWS\SYSTEM\SYSTRAY.EXE&lt;BR /&gt;C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE&lt;BR /&gt;C:\VALVE\STEAM\STEAM.EXE&lt;BR /&gt;C:\WINDOWS\SYSTEM\WMIEXE.EXE&lt;BR /&gt;C:\WINDOWS\SYSTEM\DDHELP.EXE&lt;BR /&gt;C:\UNZIPPED\HIJACKTHIS[1]\HIJACKTHIS.EXE&lt;BR /&gt;C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE&lt;BR /&gt;&lt;BR /&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://192.168.1.1/index.htm" target="_blank"&gt;http://192.168.1.1/index.htm&lt;/A&gt;&lt;BR /&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&amp;amp;clcid={SUB_CLSID}&amp;amp;pver={SUB_PVER}&amp;amp;ar=home" target="_blank"&gt;http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&amp;amp;clcid={SUB_CLSID}&amp;amp;pver={SUB_PVER}&amp;amp;ar=home&lt;/A&gt;&lt;BR /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://www.microsoft.com/isapi/redir.dll?prd=ie&amp;amp;ar=iesearch" target="_blank"&gt;http://www.microsoft.com/isapi/redir.dll?prd=ie&amp;amp;ar=iesearch&lt;/A&gt;&lt;BR /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;A href="http://www.microsoft.com/isapi/redir.dll?prd=ie&amp;amp;pver=6&amp;amp;ar=msnhome" target="_blank"&gt;http://www.microsoft.com/isapi/redir.dll?prd=ie&amp;amp;pver=6&amp;amp;ar=msnhome&lt;/A&gt;&lt;BR /&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;A href="http://www.microsoft.com/isapi/redir.dll?prd=ie&amp;amp;ar=iesearch" target="_blank"&gt;http://www.microsoft.com/isapi/redir.dll?prd=ie&amp;amp;ar=iesearch&lt;/A&gt;&lt;BR /&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = &lt;A href="http://www.google.com/keyword/%s" target="_blank"&gt;http://www.google.com/keyword/%s&lt;/A&gt;&lt;BR /&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = &lt;A href="http://192.168.1.1/" target="_blank"&gt;http://192.168.1.1/&lt;/A&gt;&lt;BR /&gt;O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search &amp;amp; Destroy\SDHelper.dll&lt;BR /&gt;O3 - Toolbar: @msdxmLC.dll,-1@1033,&amp;amp;Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX&lt;BR /&gt;O3 - Toolbar: &amp;amp;Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll&lt;BR /&gt;O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun&lt;BR /&gt;O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe&lt;BR /&gt;O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s&lt;BR /&gt;O4 - HKLM\..\Run: [SystemTray] SysTray.Exe&lt;BR /&gt;O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe&lt;BR /&gt;O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme&lt;BR /&gt;O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe&lt;BR /&gt;O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe&lt;BR /&gt;O4 - HKLM\..\RunServices: [ATIPOLL] ati2evxx.exe&lt;BR /&gt;O4 - HKLM\..\RunServices: [ATISmart] C:\WINDOWS\SYSTEM\ati2s9ag.exe&lt;BR /&gt;O4 - HKCU\..\Run: [Steam] "c:\valve\steam\steam.exe" -silent&lt;BR /&gt;O8 - Extra context menu item: &amp;amp;Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsearch.html&lt;BR /&gt;O8 - Extra context menu item: Cac&amp;amp;hed Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmcache.html&lt;BR /&gt;O8 - Extra context menu item: Si&amp;amp;milar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsimilar.html&lt;BR /&gt;O8 - Extra context menu item: Backward &amp;amp;Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmbacklinks.html&lt;BR /&gt;O8 - Extra context menu item: Translate into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmtrans.html&lt;BR /&gt;O9 - Extra button: AIM (HKLM)&lt;BR /&gt;O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - &lt;A href="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab" target="_blank"&gt;http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab&lt;/A&gt;&lt;BR /&gt;O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - &lt;A href="http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB" target="_blank"&gt;http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB&lt;/A&gt;&lt;BR /&gt;O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - &lt;A href="http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?38072.951875" target="_blank"&gt;http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?38072.951875&lt;/A&gt;&lt;BR /&gt;O16 - DPF: {68BCE50A-DC9B-4519-A118-6FDA19DB450D} (Info Class) - &lt;A href="http://www.blizzard.com/support/includes/cabs/si.cab" target="_blank"&gt;http://www.blizzard.com/support/includes/cabs/si.cab&lt;/A&gt;&lt;BR /&gt;O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - &lt;A href="http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab" target="_blank"&gt;http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab&lt;/A&gt;&lt;BR /&gt;O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - &lt;A href="http://www.apple.com/qtactivex/qtplugin.cab" target="_blank"&gt;http://www.apple.com/qtactivex/qtplugin.cab&lt;/A&gt;&lt;BR /&gt;O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - &lt;A href="http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab" target="_blank"&gt;http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab&lt;/A&gt;&lt;BR /&gt;O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - &lt;A href="http://chat.yahoo.com/cab/yacsui.cab" target="_blank"&gt;http://chat.yahoo.com/cab/yacsui.cab&lt;/A&gt;&lt;BR /&gt;O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - &lt;A href="http://chat.yahoo.com/cab/yvwrctl.cab" target="_blank"&gt;http://chat.yahoo.com/cab/yvwrctl.cab&lt;/A&gt;&lt;BR /&gt;O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - &lt;A href="http://zone.msn.com/bingame/zuma/default/popcaploader_v5.cab" target="_blank"&gt;http://zone.msn.com/bingame/zuma/default/popcaploader_v5.cab&lt;/A&gt;&lt;BR /&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://192.168.1.1/index.htm" target="_blank"&gt;http://192.168.1.1/index.htm&lt;/A&gt;&lt;BR /&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = &lt;A href="http://192.168.1.1/" target="_blank"&gt;http://192.168.1.1/&lt;/A&gt;&lt;BR /&gt;O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search &amp;amp; Destroy\SDHelper.dll&lt;BR /&gt;O3 - Toolbar: @msdxmLC.dll,-1@1033,&amp;amp;Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX&lt;BR /&gt;O3 - Toolbar: &amp;amp;Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll&lt;BR /&gt;O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun&lt;BR /&gt;O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe&lt;BR /&gt;O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s&lt;BR /&gt;O4 - HKLM\..\Run: [SystemTray] SysTray.Exe&lt;BR /&gt;O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe&lt;BR /&gt;O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme&lt;BR /&gt;O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe&lt;BR /&gt;O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe&lt;BR /&gt;O4 - HKLM\..\RunServices: [ATIPOLL] ati2evxx.exe&lt;BR /&gt;O4 - HKLM\..\RunServices: [ATISmart] C:\WINDOWS\SYSTEM\ati2s9ag.exe&lt;BR /&gt;O4 - HKCU\..\Run: [Steam] "c:\valve\steam\steam.exe" -silent&lt;BR /&gt;O8 - Extra context menu item: &amp;amp;Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsearch.html&lt;BR /&gt;O8 - Extra context menu item: Cac&amp;amp;hed Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmcache.html&lt;BR /&gt;O8 - Extra context menu item: Si&amp;amp;milar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsimilar.html&lt;BR /&gt;O8 - Extra context menu item: Backward &amp;amp;Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmbacklinks.html&lt;BR /&gt;O8 - Extra context menu item: Translate into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmtrans.html&lt;BR /&gt;O9 - Extra button: AIM (HKLM)&lt;BR /&gt;O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - &lt;A href="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab" target="_blank"&gt;http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab&lt;/A&gt;&lt;BR /&gt;O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - &lt;A href="http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB" target="_blank"&gt;http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB&lt;/A&gt;&lt;BR /&gt;O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - &lt;A href="http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?38072.951875" target="_blank"&gt;http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?38072.951875&lt;/A&gt;&lt;BR /&gt;O16 - DPF: {68BCE50A-DC9B-4519-A118-6FDA19DB450D} (Info Class) - &lt;A href="http://www.blizzard.com/support/includes/cabs/si.cab" target="_blank"&gt;http://www.blizzard.com/support/includes/cabs/si.cab&lt;/A&gt;&lt;BR /&gt;O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - &lt;A href="http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab" target="_blank"&gt;http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab&lt;/A&gt;&lt;BR /&gt;O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - &lt;A href="http://www.apple.com/qtactivex/qtplugin.cab" target="_blank"&gt;http://www.apple.com/qtactivex/qtplugin.cab&lt;/A&gt;&lt;BR /&gt;O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - &lt;A href="http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab" target="_blank"&gt;http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab&lt;/A&gt;&lt;BR /&gt;O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - &lt;A href="http://chat.yahoo.com/cab/yacsui.cab" target="_blank"&gt;http://chat.yahoo.com/cab/yacsui.cab&lt;/A&gt;&lt;BR /&gt;O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - &lt;A href="http://chat.yahoo.com/cab/yvwrctl.cab" target="_blank"&gt;http://chat.yahoo.com/cab/yvwrctl.cab&lt;/A&gt;&lt;BR /&gt;O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - &lt;A href="http://zone.msn.com/bingame/zuma/default/popcaploader_v5.cab" target="_blank"&gt;http://zone.msn.com/bingame/zuma/default/popcaploader_v5.cab&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 27 Jul 2004 19:16:04 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-microsoft/hijack-this-list/m-p/3342385#M5159</guid>
      <dc:creator>Brandon Krisstopher San</dc:creator>
      <dc:date>2004-07-27T19:16:04Z</dc:date>
    </item>
    <item>
      <title>Re: hijack this list`</title>
      <link>https://community.hpe.com/t5/operating-system-microsoft/hijack-this-list/m-p/3342386#M5160</link>
      <description>Looks pretty clean now.  If everything is working as you want then you might want to go back into HijackThis and check everything then click on Add Checked to Ignore List.  That way if it happens again and you need to rerun hijackthis then you will only see the new stuff which has been added.&lt;BR /&gt;&lt;BR /&gt;Also a good time to make a restore point.&lt;BR /&gt;&lt;BR /&gt;Ron</description>
      <pubDate>Wed, 28 Jul 2004 15:15:34 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-microsoft/hijack-this-list/m-p/3342386#M5160</guid>
      <dc:creator>Ron Kinner</dc:creator>
      <dc:date>2004-07-28T15:15:34Z</dc:date>
    </item>
  </channel>
</rss>

