Open
notepad and copy/paste the text in the quotebox below into it:
Code:
http://www.techsupportforum.com/security-center/hijackthis-log-help/258034-pops-ups-slowness-usual-suspects.html#post1528990
Collect::
C:\Program Files\xloader30029.exe
C:\Program Files\11523781.exe
C:\Program Files\11461562.exe
C:\Program Files\11399515.exe
C:\Program Files\11151437.exe
C:\Program Files\11089062.exe
C:\Program Files\11027437.exe
C:\Program Files\10037734.exe
C:\Program Files\9929968.exe
C:\Program Files\21104359.exe
C:\Program Files\20977859.exe
C:\Program Files\18792484.exe
C:\Program Files\19167531.exe
C:\Program Files\19105203.exe
C:\Program Files\19292515.exe
File::
C:\Program Files\11709078.exe
C:\Program Files\11647578.exe
C:\Program Files\11585468.exe
C:\Program Files\11337718.exe
C:\Program Files\11275921.exe
C:\Program Files\11213828.exe
C:\Program Files\10965500.exe
C:\Program Files\10903703.exe
C:\Program Files\10841828.exe
C:\Program Files\10779609.exe
C:\Program Files\10717625.exe
C:\Program Files\10655656.exe
C:\Program Files\10593906.exe
C:\Program Files\10532484.exe
C:\Program Files\10470218.exe
C:\Program Files\10408437.exe
C:\Program Files\10347187.exe
C:\Program Files\10285312.exe
C:\Program Files\10223453.exe
C:\Program Files\10161109.exe
C:\Program Files\10099031.exe
C:\Program Files\9864609.exe
C:\Program Files\9521234.exe
C:\Program Files\9508234.exe
C:\Program Files\21901437.exe
C:\Program Files\21919468.exe
C:\Program Files\21860625.exe
C:\Program Files\21796609.exe
C:\Program Files\21733734.exe
C:\Program Files\21671093.exe
C:\Program Files\21608953.exe
C:\Program Files\21546437.exe
C:\Program Files\21482875.exe
C:\Program Files\21418859.exe
C:\Program Files\21356031.exe
C:\Program Files\21293640.exe
C:\Program Files\21230765.exe
C:\Program Files\21167515.exe
C:\Program Files\20915421.exe
C:\Program Files\20852859.exe
C:\Program Files\20789625.exe
C:\Program Files\20726734.exe
C:\Program Files\20663640.exe
C:\Program Files\20600703.exe
C:\Program Files\20538234.exe
C:\Program Files\20476484.exe
C:\Program Files\20414390.exe
C:\Program Files\20351390.exe
C:\Program Files\20289656.exe
C:\Program Files\20227515.exe
C:\Program Files\20165546.exe
C:\Program Files\20102531.exe
C:\Program Files\20040687.exe
C:\Program Files\19978265.exe
C:\Program Files\19916984.exe
C:\Program Files\19854546.exe
C:\Program Files\19791953.exe
C:\Program Files\19729546.exe
C:\Program Files\19667375.exe
C:\Program Files\19604250.exe
C:\Program Files\19541796.exe
C:\Program Files\19479921.exe
C:\Program Files\19417234.exe
C:\Program Files\19355125.exe
C:\Program Files\19230031.exe
C:\Program Files\19042578.exe
C:\Program Files\18979281.exe
C:\Program Files\18916968.exe
C:\Program Files\18855218.exe
C:\Program Files\18730218.exe
C:\Program Files\18668031.exe
C:\DOCUME~1\CHRIST~1\LOCALS~1\Temp\fb36.tmp
C:\WINDOWS\Installer\{9c6cc8ca-c6cd-404c-a987-d0e5124aad8c}\AvpRunOnce.dll
C:\WINDOWS\Installer\{5e6fe06e-8ec3-472c-b364-227326a89f0d}\zip.dll
Save this as
CFScript
Referring to the picture above, drag CFScript into ComboFix.exe
Follow the prompts, and post the resulting log, C:\ComboFix.txt
Warning:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall
When CF finishes running, the ComboFix log will open along with a message box--do not be alarmed. With the above script, ComboFix will capture a file to submit for analysis. Please submit
"[4]-Submit_Date_Time.zip" by following the prompts.