ad.yieldmanager.com/st%3Fad_type - help!

Discussion in 'Malware Help (A Specialist Will Reply)' started by Akinah, Nov 8, 2008.

  1. Akinah

    Akinah Private E-2

    Hi, thanks for your help.
    The only time this happens is when I go to www.comcast.net to check my email. They run ads on the right side - each time the ad starts to load, it jumps to a dell/goodle page that says this page can't be found: ad.yieldmanager.com/st%3Fad_type. It doesn't happen when the ads are from comcast itself. It started about 3 days ago - I didn't do anything different that I can remember. I've followed all your preliminary steps and am attaching the four logs - 3 in this post and 1 to follow.
    Thank you for any help - this is driving me crazy!!
     

    Attached Files:

  2. Akinah

    Akinah Private E-2

    fourth log attached

    here is the last log.
    Thanks!
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi

    Just to let you know we are currently reviewing your logs and will get back to you with some instructions as soon as we possibly can.

    Thanks for your patience
    Kes13!
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi

    I am not seeing any signs of malware in your logs but we can do a couple things before I leave you with the final steps...

    1) If you do not use Windows Messenger Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    2) Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Wendy Leigh\Local Settings\Temp

    3) Run Ccleaner!


    4) Please tell me whether you uninstalled McAfee Security Suite....I see it in your logs but not in your "Add and Remove program" list.

    Thanks
    Kes13! :)
     
  5. Akinah

    Akinah Private E-2

    Hi,
    1. I had already downloaded and run the windows messenger disabler.
    2. I deleted the files as you suggested - there were only 6 in one of the folders.
    3. I ran CCleaner.
    4. No, I have not uninstalled McAfee - I merely disabled it. Was I supposed to uninstall it?

    I've looked through some other responses to this issue and it seems in their logs there is something about "ask" that has to be removed. Did I not have anything like that? as it's still happening :-(

    Thanks for your help.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member


    Things like this are quite common today. There are standard work arounds you can try such as ( opt outs when possible ), popup blockers, and adding URLs to your host file and also adding them to your Restricted Zone. But these are not considered malware and no amount of scanning is going to find anything to remove related to them. If you do not know how to add a site to your hosts file please go to the software forum to learn how to do this.

    It is just an advertisement site and you will see cookies from it too. It is not malware. Many advertisements use popups. Popup type windows are not necessarily bad just because a popup blocker blocks them.

    Try using Firefox as a browser instead of Internet Explorer, download the add on for Firefox called AdBlockerPlus..I can highly recommend it!

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:



    Thanks
    Kestrel13!
     
    Last edited: Nov 10, 2008
  7. Akinah

    Akinah Private E-2

    Thank you for your help! I switched to Firefox with AdBlocker and am one happy camper!!
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome! Safe surfing :wave

    Kes
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds