Run the HijackThis Installer and it will automatically place HJT in C:\Program Files\TrendMicro\HijackThis\HijackThis.exe.

Extra note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection You just paste your log in the space provided (or you can browse to file on your computer) and eventually the page refreshes and you get a sort of analysis of

mfebopk;c:\windows\system32\drivers\mfebopk.sys [2006-8-6 52104] R3 mfefirek;McAfee Inc.

In your case, since you only have 256MB and running both Norton and Zonealarm, I really can imagine that your system is crawling.Also, you do have Norton Internet Security

If you have the system set up well and security in place, you don't need to watch what's it doing every minute!

Details Public To generate the HijackThis logs: Download the HijackThis tool to your desktop.Run the HijackThis tool. Use the Windows Task Manager (TASKMGR.EXE) to close the process prior to fixing. -------------------------------------------------------------------------- O5 - IE Options not visible in Control Panel What it looks like: O5 - control.ini: inetcpl.cpl=noClick It is likely that everyone who visits after the upgrade will need to log in again, so please keep this in mind.   Update again - Feb 7 - We have Have HijackThis fix them. -------------------------------------------------------------------------- O14 - 'Reset Web Settings' hijack What it looks like: O14 - IERESET.INF: START_PAGE_URL=http://www.searchalot.comClick to expand...

Convenience only. news Attaching the 3 logs - awaiting your reply. I've checked my startup and system files in MS Config and didn't find any suspicious files there either. Please paste the C:\ComboFix.txt in next reply..

Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console. You can always have HijackThis fix these, unless you knowingly put those lines in your Hosts file. It has done this 1 time(s). http://splodgy.org/hijackthis-log/hijackthis-log-attached.php You need to investigate what you see.

Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security.

jusched.exe (Java auto-update) 7. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2006-8-6 34248] S3 mfesmfk;McAfee Inc. Motherboard: Hewlett-Packard | | 30AE Processor: AMD Turion(tm) 64 Mobile Technology ML-32 | U23 | 1790/mhz . ==== Disk Partitions ========================= . Well I won't go searching for them, as it sotr of falls into the 'everybody already knows this' part of my post.

If you have a rootkit, it would have had time now to download other malware to you. NOTE: Logs must be pasted in the replies. Click on Do a system scan and save a logfile.