C:\Documents and Settings\All Users\Application Data\MPK\1 (Refog.Keylogger) -> Quarantined and deleted successfully. Post the contents of the log in your replyPlease download ComboFix from Here or Here to your Desktop.**Note: In the event you already have Combofix, this is a new version that Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data:, -> Quarantined and deleted successfully. http://softsystechnologies.com/hijackthis-log/hijackthis-log-please-help-with-browser-redirecting.html

Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.ShopperReports) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{20ea9658-6bc3-4599-a87d-6371fe9295fc} (Adware.ShopperReports) -> Quarantined and deleted successfully. It is free. C:\Documents and Settings\All Users\Application Data\MPK\CPDM (Refog.Keylogger) -> Quarantined and deleted successfully. com/images/iwon/games/playfirst/ddfotg. - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.

HKEY_CLASSES_ROOT\CLSID\{c9ccbb35-d123-4a31-affc-9b2933132116} (Adware.ShopperReports) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\MPK\MPKView.exe (Refog.Keylogger) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\MPK\Help\English\programs.htm (Refog.Keylogger) -> Quarantined and deleted successfully. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

The installation of the Recovery Console in the computer will be our only defense against this threat. BLEEPINGCOMPUTER NEEDS YOUR HELP! net - C:\Windows\system32\libusbd-nt.exeO23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exeO23 - Service: MediaMall Server - MediaMall Technologies, Inc. - C:\Program Files (x86)\MediaMall\MediaMallServer.exeO23 - Service: @comres.dll,-2797 (MSDTC) -

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.ShopperReports) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{a7cddcdc-beeb-4685-a062-978f5e07ceee} (Adware.ShopperReports) -> Quarantined and deleted successfully. Attached Files kaspersky.txt 14.32KB 206 downloads ComboFix.txt 16.24KB 68 downloads 0 #6 Rorschach112 Posted 06 November 2009 - 12:01 PM Rorschach112 Ralphie Retired Staff 47,710 posts hiPlease download OTM Save it Thread Tools Search this Thread Display Modes #1 13-06-09, 22:00 Kalinji11 Newbie Join Date: Jun 2009 Posts: 3 Hijack this log - Google hyperlink redirect Hi please can Some Rookit infection may damage your boot sector.

C:\WINDOWS\system32\MPK\Help\English\alarms.htm (Refog.Keylogger) -> Quarantined and deleted successfully. C:\WINDOWS\system32\MPK\Images\vista_hide.bmp (Refog.Keylogger) -> Quarantined and deleted successfully. Please post the "C:\Combo-Fix.txt" for further review.**Note: Do not mouseclick combo-fix's window while it's running.

C:\WINDOWS\system32\MPK\German.lng (Refog.Keylogger) -> Quarantined and deleted successfully. Download Combofix from any of the links below, and save it to your desktop.

That may cause it to stall===Third party programs if not up to date can be an open door for an infection.Please run this security check for my review.Download Security Check by