Hello
Could you restart Hijack This and put a checkmark next to the following entries:
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://homepage.com%00@www.e-finder.cc/hp/ (obfuscated)
O2 - BHO: (no name) - {834261E1-DD97-4177-853B-C907E5D5BD6E} - C:\DPE.DLL
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKCU\..\Run: [RealJukeboxSystray] "C:\PROGRAM FILES\REAL\REALJUKEBOX\tsystray.exe"
O4 - HKCU\..\Run: [XiD] "C:\PROGRAM FILES\INTERNET EXPLORER\mmx.exe"
O13 - DefaultPrefix:
O13 - WWW Prefix:
O14 - IERESET.INF:
Click Fix Checked
You've also been infected with Trojan.Analogx. To remove, it go to C:\Program Files\Internet Explorer and delete mmx.exe.
Post a new log to the forum