TechSpot

Cid is poping up everywhere?

By ste.q
Feb 24, 2008
  1. can anyone help I read the thread for lindylou2 and it seemed to be very effective for her however when i tried the same i got know where???

    Any help would be really apreciated

    thanks

    Ste
     
  2. kritius

    kritius TS Guru Posts: 2,084

    Hi ste.q, and welcome to TechSpot,

    It would be good if you followed all the steps HERE and then posted the three requested logs (see how here).

    It would also be good if you added your system specs to your profile as this will also help whoever reads your logs.

    Good luck,

    Kritius
     
  3. ste.q

    ste.q TS Rookie Topic Starter

    thanks a lot I'll get right onto it now

    cheers !!! :)
     
  4. kritius

    kritius TS Guru Posts: 2,084

    You should post the THREE reaquested logs back in this post. (no sense creating another for what is the same problem.

    O4 - HKLM\..\Run: [Love default global mess] C:\Documents and Settings\All Users\Application Data\great coal love default\new name.exe

    O4 - HKCU\..\Run: [Chin deaf] C:\DOCUME~1\Steven\APPLIC~1\GLUESI~1\Internet Boob Wma.exe

    Do you know these?

    Also it doesnt appear to be picking up your anti virus or firewall, I didnt see any files in there apart from Authentium\AntiVirus\dvpapi.exe, is this what your running?

    Also I think that you should run through the rest of the 15 steps, not just a few of them.
     
  5. Blind Dragon

    Blind Dragon TS Evangelist Posts: 3,908

    kritius - those look like LOP infection. From his other post?
     
  6. kritius

    kritius TS Guru Posts: 2,084

    Yeah, I figured that because it was about the same problem momok would possibly just merge the threads so I may as well use the original one.
     
  7. ste.q

    ste.q TS Rookie Topic Starter

    Hi guys

    thanks for that I am still getting my head around using the site at the moment and can only continue with the progress between shifts at work, I think I might be in a little over my head hear however i will persiveer if that even how its spelt im sure its not but you know what I mean.
    I posted the threads before reading the other part and am now trying the rest of the steps and will then post th threads properly how dose that sound only one thing I wasnt too shure about was the procedure around the scasns at point 13 onwards in safe mode do all of these scans need to be in safe mode and will it matter that i had to come out of safe mode between scans to download avg antispyware? god I just hope that all this works what a lot of effort for an anoying problem. I do apriciate your help this site is great people are really helpfull i hope i didnt miss the smallprint concerning the billing procedure.!!! lol
     
  8. ste.q

    ste.q TS Rookie Topic Starter

    sory and in reply to the earlier message i dont recognise those logs but i wouldn't know where i was looking for them anyway. sorry.
     
  9. Blind Dragon

    Blind Dragon TS Evangelist Posts: 3,908

    Do you have messenger Plus installed?
     
  10. ste.q

    ste.q TS Rookie Topic Starter

    Hi

    If I have it installed I've never heard of it.
    I'm still getting those anoying cid pop ups, Ive got those logs here as well so i'll attatch them.

    I just clicked on manage attatchments and nothing happens I'm starting to feel really stupid.
     
  11. ste.q

    ste.q TS Rookie Topic Starter

  12. ste.q

    ste.q TS Rookie Topic Starter

    apparently the antirootkit scan found nothing
    Do I need to do this again?


    thanks
    Ste
     
  13. kritius

    kritius TS Guru Posts: 2,084

    You really dont want the antirootkit to find anything, if it did you would have rootkits and you really wouldnt want them.

    How did you attatch your logs?

    Did you use the paperclip icon at the top of the reply box? Have a look here for instructions.
     
  14. ste.q

    ste.q TS Rookie Topic Starter

    hi

    i used the paper clip is that ok can you not access my attachments or something?
     
  15. kritius

    kritius TS Guru Posts: 2,084

    They would normally look like this,

    Attached Files
    File Type: txt log.txt (13.0 KB, 0 views)
    File Type: log hijackthis.log (10.6 KB, 1 views)
    File Type: txt Report-Scan-20080227-093115.txt (508 Bytes, 0 views)

    whereas your are just like this

    1 log.txt

    1hijackthis.log

    Report-Scan-20080227-080505.txt

    Dont know, just seemed a bit different.
     
  16. ste.q

    ste.q TS Rookie Topic Starter

    do they not work or something?

    I'm not sure why they are different I saved them as and changed the name slightly so that i could identify them against the old ones. what do i do next coz Ive still got these pop ups coming hard and fast....... ?
     
  17. kritius

    kritius TS Guru Posts: 2,084

    Is your antivurus running ok? Also the firewall should be installed.

    I would then fix the two entries I mentioned earlier,

    O4 - HKLM\..\Run: [Love default global mess] C:\Documents and Settings\All Users\Application Data\great coal love default\new name.exe

    O4 - HKCU\..\Run: [Chin deaf] C:\DOCUME~1\Steven\APPLIC~1\GLUESI~1\Internet Boob Wma.exe

    Other than that i dont know, Im not an expert on this, think you may have to wait for Blind Dragon to get back to you, or Momok.
     
  18. ste.q

    ste.q TS Rookie Topic Starter

    ste.q

    i just found those two files on the hjt log ive fixed or removed them should this have gotten rid of cid coz he's stil here! if blind dragon or mimok are around could you please advise me where to go from here?

    thanks

    Ste
     
  19. kritius

    kritius TS Guru Posts: 2,084

    Are any of these in your add/remove programs list?

    Browser Enhance r
    Brows er Enhancer
    Ultimate Browse r Enhancer
    Ultimate Browser En hancer
    L.O P. Un insta11
    L O.P. Un instal1
    Live 0n line Portal
    Live.0nli ne Porta1

    Have a check through and see.

    Open the Application Data folder, on Windows 2000 and XP it is inside your user folder in ‘Documents and Settings’, but it’s hidden, so go to Tools->Folder Options->View and turn on ‘Show hidden files and folders’ to see it. There should normally only be files in there not extensions so if there is then post back with the names of them.


    You can also reset your homepage (from Internet Options->General) and search settings (Internet Options->Programs->Reset Web Settings), and delete the entries added to your Favorites menu. If you use Netscape/Mozilla you will need to reset the home page (Edit->Preferences->Navigator) and remove the Bookmarks too.

    Try that for now then repost with a new HJT log.
     
  20. Blind Dragon

    Blind Dragon TS Evangelist Posts: 3,908

    @kritius

    i have to be up for work in 4 hours so I can't be here long.

    The filename NEW NAME.EXE was first seen on Feb 24 2008 in The UNITED KINGDOM.

    The unsafe files using this name are associated with the malware group Adware.Lop.

    Alternate Names
    Window Search
    Window Searching
    Lop.com
    LOP SEARCH
    Browser Enhancer
    Ultimate Browser Enhancer


    @ste.q
    If you see any of the programs listed by myself or kritius please remove them from add/remove programs. If so uninstall then follow the on screen instructions -> It will ask if you want to uninstall -> YES then each of the sponsors asks if you want to uninstall ->YES

    and finally post this into Notepad
    Save it as jobs.bat on your desktop. Save it as type all types *.*.

    Doubleclick the file jobs.bat. A notepad file called files.txt will be created.

    attach files.txt here with a fresh Hijackthis log
     
  21. ste.q

    ste.q TS Rookie Topic Starter

    hi guys

    here are the logs and reports you wanted to see I looked for all those files you asked me to in the add remove list and did not find any of them I'm sure you know allready but cid help is in there and cannot be removed. when i press the remove button it just flickers and nothing happens.
    View attachment 29173

    View attachment 29174
     
  22. Blind Dragon

    Blind Dragon TS Evangelist Posts: 3,908

    Boot into Safe Mode
    • Restart your computer and start pressing the F8 key on your keyboard.
    • Select the Safe Mode option when the Windows Advanced Options menu appears, and then press ENTER.

    uninstall any of the following program(s) using Add/Remove Programs if they are present. To do this, go to Start > Settings > Control Panel and double-click on Add/Remove Programs. From within Add/Remove Programs highlight each one and select Remove.

    Netpumper
    BitRoll
    CiD Help
    CiD Manager
    Download Plugin for Internet Explorer
    Zone Media


    Reboot your computer into normal mode

    Run another scan with Hijackthis and attach a new log
     
  23. kritius

    kritius TS Guru Posts: 2,084

    Also what about your antivirus and firewall?

    EDIT\ Also can you list the names of the folders in the application data folder?
     
  24. ste.q

    ste.q TS Rookie Topic Starter

    hi guys

    Thanks, Cid help is there but as i said it will not leave add remove when I click the remove button. however I read somewhere that this is a programme that comes in another programme often downloaded so and can only be removed by removing the programme that it came down with so i removed a few things I did not recognise as essential and funny enough it dissapeared i cant remember what i removed now though coz i didnt expect it to work so i didnt take much notice. anyway ive not seen a pop up since and i'm happy as a pig in mud.

    hopefully this is now resolved if you know different please feel free to chuck a bucket on my bonfire.

    any way you guys have all been great and I will reccomend you to other people you really are good people.

    thanks again.

    ste
     
  25. ste.q

    ste.q TS Rookie Topic Starter

    actually there is another thing

    this may not be as difficult for you to help me with

    I've got nero and whenever I try to burn downloaded copys of my fav tv series like lost or prison break it is allways out of sinc with the voices looking on the net i believe it to be a common problem and else where i was advised to use the convertx to dvd software which i downloaded for free I've downloaded it twice now and find that when it dose a copy the copys are good but it freezes part the way through most of the time and my computer completely locks up and has to be shut down at the mains and back on again to free it up. nero dosen't even cause this is there a good free alternative I can get my hands on ????
     
Topic Status:
Not open for further replies.

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...