kodiakzach
Topic Starter
Wanted to chime in and say that I've had the @ad.yieldmanager.com tracking cookie since October 2008. It is the subject of this current thread here:
http://forums.whatthetech.com/ad_yieldmanager_t100493.html
Long story short is this extremely well hidden low level adware/spyware has been undetectable to pretty much everything thrown at it. I first noticed it when having problems like the user in the above thread documented. I noticed that this malware was actually injecting ads (banner, flash, talking, etc…) into any web sites I visited using IE. Other than that, you wouldn't even know you were infected. Upon further inspection of the URL source of the ads, they all appeared to be being served from ad.yieldmanager.com.
I documented what I thought (at the time) to be the fix(es) here:
http://outdoorsbest.zeroforum.com/thread?id=800415
That was when I noticed the IE COOKIE that won't go away regardless of what I do. A couple programs like HJT detect it, but are unable to clean it. Manual deletion of the cooking, CW Shredder, etc… all result in it's re-appearance. Perhaps where I differ from the user in the thread above is that the banner ads are no longer injected and served from ad.yieldmanager.com. They are back to normal. It's just the fact that the cookie remains on my system…. that's what is bugging me because it tells me somehow, somewhere my system is still infected by this malware. I'm curious if it's possibly installed with one of the few programs I use on this machine that I didn't read the EULA for. I don't have any P2P sharing software of any kind. This machine is used for very few tasks with minimal software of any kind installed. I'm just wondering if one of the programs I use like XFIRE might be the source of this program?
Regardless, I'm willing to work with you guys to try and find out the source of this overly persistent malware/adware. I've uploaded my HJT, Malwarebytes, and ComboFix logs.
http://forums.whatthetech.com/ad_yieldmanager_t100493.html
Long story short is this extremely well hidden low level adware/spyware has been undetectable to pretty much everything thrown at it. I first noticed it when having problems like the user in the above thread documented. I noticed that this malware was actually injecting ads (banner, flash, talking, etc…) into any web sites I visited using IE. Other than that, you wouldn't even know you were infected. Upon further inspection of the URL source of the ads, they all appeared to be being served from ad.yieldmanager.com.
I documented what I thought (at the time) to be the fix(es) here:
http://outdoorsbest.zeroforum.com/thread?id=800415
That was when I noticed the IE COOKIE that won't go away regardless of what I do. A couple programs like HJT detect it, but are unable to clean it. Manual deletion of the cooking, CW Shredder, etc… all result in it's re-appearance. Perhaps where I differ from the user in the thread above is that the banner ads are no longer injected and served from ad.yieldmanager.com. They are back to normal. It's just the fact that the cookie remains on my system…. that's what is bugging me because it tells me somehow, somewhere my system is still infected by this malware. I'm curious if it's possibly installed with one of the few programs I use on this machine that I didn't read the EULA for. I don't have any P2P sharing software of any kind. This machine is used for very few tasks with minimal software of any kind installed. I'm just wondering if one of the programs I use like XFIRE might be the source of this program?
Regardless, I'm willing to work with you guys to try and find out the source of this overly persistent malware/adware. I've uploaded my HJT, Malwarebytes, and ComboFix logs.