Please help remove CiD ads

By shahare ยท 7 replies
May 25, 2008
  1. Hi

    I`ve got this ad pop-up window that opens every now and then with
    the headline CiD.
    I`ve looked at previous threads and I`m posting logs except the AVG as
    it is no longer avaiable.

    Hope you can help me

    Attached Files:

  2. Blind Dragon

    Blind Dragon TS Evangelist Posts: 3,908

    Please Download NoLop by Skate_Punk_21 to your desktop from the link below...
    Link 1
    • First close any other programs you have running as this will require a reboot
    • Double click NoLop.exe to run it
    • Now click the button labelled "Search and Destroy"
      <<your computer will now be scanned for infected files>>
    • When scanning is finished you will be prompted to reboot only if infected, Click OK
    • Now click the "REBOOT" Button.
    • A Message should popup from NoLop. If not, double click the program again and it will finish Please Post the contents of C:\NoLop.log along with a fresh HijackThis log
    --If you receive an error, "mscomctl.ocx or one of its dependencies are not correctly registered," please download mscomctl.ocx to your system32 folder then rerun the program.
  3. shahare

    shahare TS Rookie Topic Starter

    It apears that while i was entering the thread

    it was fixed.
    it must have been the last attempt with combofix.

    thanks for all your help :D
  4. zipperman

    zipperman TS Rookie Posts: 1,179   +7

    According to kimsland,"have your system specs available"
    I have a post poll regarding including your OS.
    You have not done this in your post or components.
    Do one or the other.I don't usually read HiJack logs but i see it there,
    But add your system specs option like i have.
    Please Vote.
  5. kimsland

    kimsland Ex-TechSpotter Posts: 14,523

    Thanks zipperman for the mention

    But two issues
    1. You really should supply links (to your post and the members profile)
    2. This thread states it's solved (just above your post!)

    I suspect this post and yours will likely be removed for being non-relevant at all.
  6. Blind Dragon

    Blind Dragon TS Evangelist Posts: 3,908

    Your still infected according to your last log

    LOP Infection
    O4 - HKCU\..\Run: [FRAG DEFAULT] E:\DOCUME~1\shahare\APPLIC~1\MEDIAB~1\bird slow five.exe
  7. shahare

    shahare TS Rookie Topic Starter

    I already noticed it and removed it

    I had a feeling it is suspicious
  8. Blind Dragon

    Blind Dragon TS Evangelist Posts: 3,908

    Superantispyware and MBAM should both remove it if scanned from safe mode.

    Make sure you update it while in regular mode

    Then boot to safe mode by tapping f8 before windows loads

    run full scan with Antispyware program

    attach the log here along with a new Hijackthis log. We may have to clean up the left overs manually
Topic Status:
Not open for further replies.

Similar Topics

Add your comment to this article

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...