Please help remove CiD ads

Status
Not open for further replies.
Hi

I`ve got this ad pop-up window that opens every now and then with
the headline CiD.
I`ve looked at previous threads and I`m posting logs except the AVG as
it is no longer avaiable.

Hope you can help me
Shahar
 

Attachments

  • hijackthis.log
    11.1 KB · Views: 7
Please Download NoLop by Skate_Punk_21 to your desktop from the link below...
Link 1
  • First close any other programs you have running as this will require a reboot
  • Double click NoLop.exe to run it
  • Now click the button labelled "Search and Destroy"
    <<your computer will now be scanned for infected files>>
  • When scanning is finished you will be prompted to reboot only if infected, Click OK
  • Now click the "REBOOT" Button.
  • A Message should popup from NoLop. If not, double click the program again and it will finish Please Post the contents of C:\NoLop.log along with a fresh HijackThis log
--If you receive an error, "mscomctl.ocx or one of its dependencies are not correctly registered," please download mscomctl.ocx to your system32 folder then rerun the program.
 
It apears that while i was entering the thread

it was fixed.
it must have been the last attempt with combofix.

thanks for all your help :D
 
According to kimsland,"have your system specs available"
I have a post poll regarding including your OS.
You have not done this in your post or components.
Do one or the other.I don't usually read HiJack logs but i see it there,
But add your system specs option like i have.
Please Vote.
 
Thanks zipperman for the mention

But two issues
1. You really should supply links (to your post and the members profile)
2. This thread states it's solved (just above your post!)

I suspect this post and yours will likely be removed for being non-relevant at all.
 
shahare said:
it was fixed.
it must have been the last attempt with combofix.

thanks for all your help :D

Your still infected according to your last log

LOP Infection
O4 - HKCU\..\Run: [FRAG DEFAULT] E:\DOCUME~1\shahare\APPLIC~1\MEDIAB~1\bird slow five.exe
 
Superantispyware and MBAM should both remove it if scanned from safe mode.

Make sure you update it while in regular mode

Then boot to safe mode by tapping f8 before windows loads

run full scan with Antispyware program

attach the log here along with a new Hijackthis log. We may have to clean up the left overs manually
 
Status
Not open for further replies.
Back