ad.yieldmanager opens IE on its own!!!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by jsh1975, Aug 30, 2008.

  1. jsh1975

    jsh1975 Private E-2

    Ok....first let me say I have done the following
    * SUPERAntiSpyware
    * SpyBot - Search & Destroy
    * Malwarebytes Anti-Malware
    * combofix.exe
    * MGtools.exe

    After running these 5 programs I am still having issues with this malware. I am not sure where to go next. I just stepped away from my computer for 10 mins leaving mozilla open and when I returned there were 5 IE windows open with different ads in them. Any advice would be greatly appreciated.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You can thank Dell for this problem.

    Uninstall the below that they put on your PC.
    URL Assistant

    Then reboot. How are things looking now?
     
  3. jsh1975

    jsh1975 Private E-2

    I do not have a Dell nor do I have URL Assistant. I do however have a program Mirar that can't be removed. Has anyone heard of this before.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it is adware.


    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    Notes:

    1. If you run into problems trying to run theREAD & RUN ME or any of the scans in normal boot mode. You can running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    Even though you do not have a Dell or URL Assistant. The ad.yieldmanager items may be occurring for similar reasons.
     
  5. jsh1975

    jsh1975 Private E-2

    Already followed those steps. When I woke up this morning there were 25+ ie windows open with various ads. Nothing seems to be fixing the problem.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you dod not attach the 4 requested logs, it means you have not finished the instructions and we cannot help you. So please attach the logs as requested in the READ & RUN ME.
     
  7. jsh1975

    jsh1975 Private E-2

    Here is post 1of2 for the logs. If I have added the wrong logs let me know. A brief history.....I can think of two things that may have started my problem. About 2 weeks ago I had a Microsoft security box come up that asked about turning my firewall on something to that extent and I said yes to it. The other issue could be a result of filling out forms and surveys for Godfather credits in a facebook game called Mobwars. Besides these two incidents I can not think of anything else. Here is a breakdown of the problem I am having.....If my computer is on and with IE not running(I use mozilla) I will get upwards of 20 IE windows open up with random ads in them. Ad.yieldmanager will be at the bottom of the window as it opens...sometimes the window will remain open others it will close. I also have a program in my add/remove I came across when doing that step called Mirar. When I try to uninstall it nothing happens. Thanks in advance to the help. Part 2 of 2 will follow.
     

    Attached Files:

  8. jsh1975

    jsh1975 Private E-2

    2 of 2
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to attach the correct log from running MGtools. This is the C:\MGlogs.zip file.

    Also you need to disable Spybot's Teatimer as requested in the READ & RUN ME. Disable this now. See: How to disable Spybot's TeaTimer Afterwards reboot your PC.

    Also run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.


    You do not appear to have any antivirus protection install! Why not?
    Also you are relying on the inadequate Windows firewall for a firewall.
     
    Last edited: Sep 2, 2008
  10. jsh1975

    jsh1975 Private E-2

    Sorry about that.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What purpose does the below serve as it does not appear to be providing any real security?
    O4 - HKLM\..\Run: [ISW.exe] "C:\Program Files\AT&T\Internet Security Wizard\ISW.exe" /AUTORUN

    You need a real antivirus, antispyware, and firewall to be installed.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of Sun Java:
    Java(TM) 6 Update 5

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=presario&pf=laptop
    O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds