This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Ad.Yieldmanager.Com

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Wanted to chime in and say that I've had the @ad.yieldmanager.com tracking cookie since October 2008. It is the subject of this current thread here:

http://forums.whatthetech.com/ad_yieldmanager_t100493.html

Long story short is this extremely well hidden low level adware/spyware has been undetectable to pretty much everything thrown at it. I first noticed it when having problems like the user in the above thread documented. I noticed that this malware was actually injecting ads (banner, flash, talking, etc…) into any web sites I visited using IE. Other than that, you wouldn't even know you were infected. Upon further inspection of the URL source of the ads, they all appeared to be being served from ad.yieldmanager.com.

I documented what I thought (at the time) to be the fix(es) here:

http://outdoorsbest.zeroforum.com/thread?id=800415

That was when I noticed the IE COOKIE that won't go away regardless of what I do. A couple programs like HJT detect it, but are unable to clean it. Manual deletion of the cooking, CW Shredder, etc… all result in it's re-appearance. Perhaps where I differ from the user in the thread above is that the banner ads are no longer injected and served from ad.yieldmanager.com. They are back to normal. It's just the fact that the cookie remains on my system…. that's what is bugging me because it tells me somehow, somewhere my system is still infected by this malware. I'm curious if it's possibly installed with one of the few programs I use on this machine that I didn't read the EULA for. I don't have any P2P sharing software of any kind. This machine is used for very few tasks with minimal software of any kind installed. I'm just wondering if one of the programs I use like XFIRE might be the source of this program?

Regardless, I'm willing to work with you guys to try and find out the source of this overly persistent malware/adware. I've uploaded my HJT, Malwarebytes, and ComboFix logs.
Hi and :welcome:

Please do the following

Please download ATF Cleaner by Atribune.
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
    • If you use Firefox browser
    • Click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
It's normal after running ATF cleaner that the PC will be slower to boot the first time.


NEXT


Download RogueRemover by Rubber Ducky fromHERE
  • Double-click on rr-free-setup.exe to start the installation of RogueRemover
  • Click Next then click I agree and finally click Install
  • Untick Show Readme and click Finish
  • This will now launch RogueRemover
  • Close the help window
  • Click Check for updates
  • If there are any updates found click Download
  • Wait for any updates to finish downloading/installing, then click Close in the update window
  • Click on Scan
  • If nothing is found, then close RogueRemover
  • If RogueRemover did find something, it will present a list of detected items
  • Click Remove selected
  • Click YES at the prompt
  • Click Ok when it informs you it's saved a logfile
  • Wait for removal to complete & then close RogueRemover
  • Use notepad to open this file
    C:\Program Files\RogueRemover\RRLog******.txt

  • (Note: ****** is the "time" when you ran RogueRemover)

Please post those results in your next reply.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI