ad.yieldmanager removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by roving, Oct 25, 2008.

  1. roving

    roving Private E-2

    I have just finished following and doing Chaslang's Vista cleanup instructions and none of the programs have found ad.yieldmanager at this point. I have attached the logs from Mbam, ComboFix, MGtools and Procdll.txt (not sure of the source of it). SAS found nothing and left no log that I could find. I am new at this and hope my posting is correct. I'll send another post with the MG tools log. Many thanks for your assistance. Roving
    View attachment ComboFixlog.txt

    View attachment mbam-log-2008-10-25 (09-45-42).txt

    View attachment procdll.txt
     
  2. roving

    roving Private E-2

    The sysinfo.txt file from MGtools is 731KB, so is too large to attach.
    Roving
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    We did not ask you to attach the individual logs in the MGtools folder. We asked you to attach the C:\MGlogs.zip file. Please attach it.

    User SUPERAntiSpyware log will be in the below folder. Please attach it as requested. We need to be sure that you are using the correct version of the program.
    C:\Users\Dick\AppData\Roaming\SUPERAntiSpyware\SUPERAntiSpyware\Logs

    What browser are you using when you are getting popups from ad.yieldmanager?
     
    Last edited: Oct 26, 2008
  4. roving

    roving Private E-2

    I am using Avant Browser. The version of IE is 7. I don't get popups of ad.yieldmanager.com. It shows up when using the browser at websites, whether using only IE7 or Avant. Its appears in the bar at the bottom of the page when I am switching pages within a site. One xample:
    when I am viewing http://groups.yahoo.com/mazinfo/message/66114 and hit the back arrow to return to the main group or a previous message, etc. the message in that bar changes instantly to "xxxxxxx ad.yieldmanager.comxxxxx, the x's representing something that occurs so rapidly I can't read anymore of it other than recognizing the "ad.yieldmanager.com" words. It is at that point that usually the process slows or stops for several seconds and then starts working again, with the next page appearing. Things are getting diverted to/through ad.yieldmanager.com apparently.

    I really appreciate your help and interest. Roving
     

    Attached Files:

  5. roving

    roving Private E-2

    I was able to get screenshots that will show what is happening. One shows the yieldmanager info as well as a pic of the URL blocking of another ad site "yimg", which I hadn't been aware of. And another ad site BlueLithium also showed up and its screenshot is attached as well. A third pic shows the blocking of a yieldmanager URL. I was hoping that these might be of some help to you. I need to get rid of all of them and hopefully find a sure way to block them and others like them from invading me again. Thanks, Roving
     

    Attached Files:

  6. roving

    roving Private E-2

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not malware. It is just advertising techniques. There is no malware to remove. Things like this are quite common today. The standard work arounds are things like you did ( opt outs when possible ), popup blockers, and adding URLs to your host file and also adding them to your Restricted Zone. But these are not considered malware and no amount of scanning is going to find anything to remove related to them.

    You did not disable Spybot's Teatimer as requested in the READ & RUN ME. You need to do this to avoid conflicts with Windows Defender.

    Your logs are clean but you should uninstall your old version of Sun Java and update to the current version.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  8. roving

    roving Private E-2

    Thanks for the time and effort on my part. Yesterday I came to the same conclusion about the 'advertising', not malware, that you mention. I'll work on my Hosts file, etc. and see if I can't get it stopped. You folks do great things for us out here. Roving
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     
  10. roving

    roving Private E-2

    I put them into Hosts and haven't seen them since. Tnx again!
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Good job! ;)

    You're welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds