Discussion of Online Advertising, CPA, SEO, Affiliate and Next Generation Marketing
  • NAVIGATION
  • TOPICS
  • THE REVENEWS BLOGGERS
  • QUICK CONTACT
ReveNews Online Revenue News & Opinions Since 1998

Yahoo Instant Messenger Virus

January 31st, 2006 by David Lewis

It looks like Yahoo Instant Messenger was hit with a virus. A few friends sent me a link via YIM. It was for http://www.geocities.com/my_new_look_2006/. Of course, they didn’t really send it.

We know that means it’s a virus but we don’t know what type of virus. Was it a virus where someone hacked YIM or was it a virus in Yahoo’s Marketing department where someone wanted to promote Yahoo! Photos?

49 Comments

Sherwin said:

It isn’t a virus. It’s actually a phishing attempt but via YM. When you click on the link it actually goes to a geocities page that looks like Yahoo Photos. If you login, it will send your username/password to someone else.

Jenna said:

Well when i went to this site, it didn’t even ask me for my passowrd. It was just some pictures of some skinny chicks in bikini’s. I’ve virus scanned and spybot scanned, and nothing has shown up. Any chance I’m infected with anything?

Annadote said:

I loged into Yahoo messenger and got an online message from someone I had not heard from in years and it sent me to a link which I clicked on , and I didnt think anything of it until I saw a pop up that said I had been signed off this computer b/c I had signed in somewhere else. Then several of my friends, asked me about it. Evidently they got the same message from me that I had gotten from someone else, and I was told it was a virus. Is this a virus? I ran Nortons and nothing showed up. What can I do to stop it from hitting on everyone in my address book? How do I stop it?

Mark said:

My Yahoo Instant Messenger has been signing me out for a few days not, saying I was logged in on another device, or computer. I wonder if it is a hack, piggybacking on YIM, because I have Norton Internet Security and Personal Firewall installed, and they have shown nothing. I was chatting with a scammer from Nigeria, told them off, and they said they were going to get their friend from India to hack my Yahoo password. I wonder if it actually happened?

This has been happening to several of the people in the Yahoo group I am in, http://groups.yahoo.com/group/romancescams, which fights back at the criminal scam element, mostly Nigerian.

Bjorn said:

I had the same thing happen to me. My virus scan and firewall and spyware detection found nothing. Yet I get signed out of yahoo saying someone else igned in on another computer. And my friends are asking what that site is about.
How can I stop this? And what else is this thing doing. Is it phishing for info on my computer?
Help would be greatly appreciated

Ryan said:

recently, while I’ve been chatting on YIM, I get automatically logged out with no dialogue box explaining why

rima said:

i have been affected by the same thing and now i cant access my mail.It says that my password is invalid.Please help!!!

janeen said:

I opened up a similiar infection..Came from a friend of mine. But, now I gather it was made to look like it came from her and didn’t..Now I cannot access my yahoo account or email.. Can someone please help

Randy Bias said:

Are any of you using the Meebo IM service?

Rajkumar said:

Hi,
I had the same problem and now my yahoo account is with someone else. They got my password and has changed it also. I’m really not sure what would be thier motive, but definetly a problem. For those who have actually clicked on the link and given your username and password, I would advice you to better change the password immediately. Or you could loose your account. I lost my yahoo id which I have been using fot the last 8 years with all my contact details etc.,. There is no way in yahoo to delete the account without signing in. To set up the account again and get a new password Yahoo asks some questions, basically your personal information and the secret question and answer that they ask during the registration. If you have all of these, I assume that your account could be recovered. Unfortunately for me, I’m not able to provide the secret answer and Yahoo is not helping me in this regard. I would better suggest people to change their password rather than to face the problems like this.

Regards,
Rajkumar K.

Thirumal Reddy said:

hello people!im glad to see some discussion going on about this common problem which all of us seem to have come across lately. Infact, i didnt even suspect that it could be some sort of bug until i came across the similar offline a few days later.The first time i came across it, as soon as i relaised that the said geocities link took me to my own yahoo fotos i called up the id of my friend whom i received the link from n asked him why did he send something so stupid n he told me he never sent anything like that in the first place.thatz when i found something was Phishy…i dont think personally i was affect by it till now as im able to log in n out of my messenger n mailbox normally but i feel it is rather safe to change our passwords beforehand as Raj has suggested in the last post than regret later like him.Thank u n sorry for you at the same time pal coz i understand how it must be to lose all the info n address as i have all my contacts saved on yahoo too…bubyee

Philip said:

If this happens to you, please report the url and the id you received it from to Yahoo! customer care.

Janet said:

I never received a url but when I try to use Yahoo! IM, it logs me out and says “you are already logged in on another computer or device”. It almost looks as if it logs me in twice on my computer when I open it up. Does anyone know if this can be fixed??

Melodie said:

ACK! Stupid me! I clicked on the link TWICE and entered my username and password before I realized something was not right!

What should I do?

Melodie said:

OK… I changed my yahoo password… but what damage may have already been done to my computer, and how can I tell? I’m having trouble with my Spybot Search and Destroy, and my Outlook programs… could it be cause by whatever this Yahoo thing is?

Del said:

Hi I have the problem too when i try to log into chat it logs me off yahoo saying I have been logged off because i have logged into a different device. I changed my password and have found it keeps changing back to a different amount of letters in the password so someone has put there own password in and i cant change it. I think my yahoo has been taken over. Think i will have to choose a different name. Any advice please.

dj said:

i m using analox proxy s/w for internet sharing,
when i am trying to log in from any machine in my lan it gives me following error:

you are signed out because you are signed in on a different computer or device

sometime i can log in, but while entering in chat room it gives me same problem & i get signed out of messenger,
plz help me,
contact me at dj82_2006@yahoo.com

thank you,

sufian said:

The problem just happened to me and after searching the solution for a while, i tried to change the connection preference to ‘No proxy’ (initilly Firewall with no proxy) and it works well. Happy trying guys!

anvar said:

guys, any body have a removal tool for this stuff,,
its spreding from my yahoo

bguillermo said:

So if you click on the link but you do not enter your account info, nothing bad happens right?

Loyid Varghese said:

Friends

i got a phishing url
http://www.geocities.com/dont_try_this_a
t_home_14/ which will take you to the yahoo flickr page and if u login using ur yahoo account your password is hacked. i lost my password and luckily recovered my password. i had a look at the phising page. it seems that the guy with email jackedurname@gmail.com is doing the trick and the information is posted to url “http://www2.fiberbit.net/form/ma
ilto.cgi” (its somewhere in japan).

Kart said:

Hi,

I had the same problem. I received a URL that when clicked on led me to the Yahoo Flicker page and I entered the account details. Now my account is completely inaccessible even when I try to retrieve another password. Can you please tell me if there is any way to recover the password. One of my friends even told me that he received the link from my ID too and I know I didn’t send it to him. Please help.
Thanks

Linda said:

I haven’t been able to log on to my messenger most of the day. Within the past day or two, my messenger is not showing me when I have mail, or it’s showing I have mail when I don’t. What’s the problem?

Howard said:

I haven’t been able to log into messenger all day, either…..I’m in VA (if that makes any difference). I’ve even gone to a couple sites to try and link to a new download and getting dead pages there too. Anybody else having these type problems or any idea what’s going on? Thanks!

Loma said:

As of today I am unable to access Messenger or my email…help! In the past I have been able to reload my messenger with dll and winzip and I have simply used the refresh button access my yahoo email. I am refreshing my AVG virus protection……but what can I do to correct this problem?? Thank you for you input…..

Linda said:

Ok… I don’t know if anyone else is still having problems accessing their messenger, but mine is working today. I went to http://www.oldversion.com/program.php?n=yahoo and downloaded 7.0 messenger. I hated the beta one anyway and have had nothing but problems since I have had it.

Dave said:

I received the link to the geocities website. I didn’t suspect anything when i log in using my username and password. Now, i can’t access my yahoo email…:(
I have been using this account for about 10 years and i couldn’t remember the particulars i’ve entered. Thus, i’m unable to get a new password.

Can Yahoo or some one pls help.

Jeevitha said:

Hi i have been attacked by this virus too. It was unfortunate as the link came as family pictures take a look at it here followed by a geocities URL.

Is there any way i can get back my password. Can i reset my password.

My atlternate email Id is deactivated and my secret user name and password also i have forgotton.

Any help is really appriciated.

regards
Jeevitha

Murthy said:

Hi Friends,

I am another victim of this virus.I have this account from last 10 years and whole information was gone.

I would be grateful if anybody advice me on how to fix it.

regards
Murthy

Mihir said:

Same problem. Lost my password. Tried contacting the Yahoo Customer Care. All I get is some automated reply. So much for being loyal. Damn them. :(

Lee said:

Discovered: April 23, 2005
Updated: June 26, 2005 04:24:19 PM PDT
Also Known As: Backdoor.Win32.SdBot.gen [Kaspersky Lab], W32/Sdbot.worm.gen.j [McAfee], W32/Sdbot-Fam [Sophos], WORM_SDBOT.GEN [Trend Micro]
Type: Worm
Infection Length: 33,739 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP

The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.

1. Disable System Restore (Windows Me/XP).
2. Update the virus definitions.
3. Run a full system scan and delete all the files detected as W32.Velkbot.A.
4. Delete any values added to the registry.

For specific details on each of these steps, read the following instructions.

1. To disable System Restore (Windows Me/XP)
If you are running Windows Me or Windows XP, we recommend that you temporarily turn off System Restore. Windows Me/XP uses this feature, which is enabled by default, to restore the files on your computer in case they become damaged. If a virus, worm, or Trojan infects a computer, System Restore may back up the virus, worm, or Trojan on the computer.

Windows prevents outside programs, including antivirus programs, from modifying System Restore. Therefore, antivirus programs or tools cannot remove threats in the System Restore folder. As a result, System Restore has the potential of restoring an infected file on your computer, even after you have cleaned the infected files from all the other locations.

Also, a virus scan may detect a threat in the System Restore folder even though you have removed the threat.

For instructions on how to turn off System Restore, read your Windows documentation, or one of the following articles:

* How to disable or enable Windows Me System Restore
* How to turn off or turn on Windows XP System Restore

Note: When you are completely finished with the removal procedure and are satisfied that the threat has been removed, reenable System Restore by following the instructions in the aforementioned documents.

For additional information, and an alternative to disabling Windows Me System Restore, see the Microsoft Knowledge Base article: Antivirus Tools Cannot Clean Infected Files in the _Restore Folder (Article ID: Q263455).

2. To update the virus definitions
Symantec Security Response fully tests all the virus definitions for quality assurance before they are posted to our servers. There are two ways to obtain the most recent virus definitions:

* Running LiveUpdate, which is the easiest way to obtain virus definitions: These virus definitions are posted to the LiveUpdate servers once each week (usually on Wednesdays), unless there is a major virus outbreak. To determine whether definitions for this threat are available by LiveUpdate, refer to the document: Virus Definitions (LiveUpdate).
* Downloading the definitions using the Intelligent Updater: The Intelligent Updater virus definitions are posted daily. You should download the definitions from the Symantec Security Response Web site and manually install them. To determine whether definitions for this threat are available by the Intelligent Updater, refer to the document: Virus Definitions (Intelligent Updater).

The latest Intelligent Updater virus definitions can be obtained here: Intelligent Updater virus definitions. For detailed instructions read the document: How to update virus definition files using the Intelligent Updater.

3. To scan for and delete the infected files

1. Start your Symantec antivirus program and make sure that it is configured to scan all the files.
* For Norton AntiVirus consumer products: Read the document: How to configure Norton AntiVirus to scan all files.
* For Symantec AntiVirus Enterprise products: Read the document: How to verify that a Symantec Corporate antivirus product is set to scan all files.
2. Run a full system scan.
3. If any files are detected as infected with W32.Velkbot.A, click Delete.

Note: If your Symantec antivirus product reports that it cannot delete an infected file, Windows may be using the file. To fix this, run the scan in Safe mode. For instructions, read the document: How to start the computer in Safe Mode. Once you have restarted in Safe mode, run the scan again.

After the files are deleted, restart the computer in Normal mode and proceed with section 4.

Warning messages may be displayed when the computer is restarted, as the threat has not been fully removed at this point. Please ignore these messages and just click OK. These messages will not appear when the computer is restarted after the removal instructions have been fully completed. The messages displayed may be similar to the following:

Title: [File path]
Message body: Windows cannot find [file name]. Make sure you typed the name correctly, and then try again. To search for a file, click the Start button, and then click Search.

4. To delete the value from the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified subkeys only. For instructions refer to the document: How to make a backup of the Windows registry.

Note: If the Registry Editor does not open, the worm has made changes to the registry that prevent it from running. To fix this, download and run the Tool to reset shell\open\command registry keys, which also fixes this problem.

1. Click Start > Run.
2. Type regedit
3. Click OK.

4. Navigate to the subkeys:

HKEY_LOCAL_MACHINE\Software\Microsoft\Ole
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\
RunServices

5. In the right pane, delete the value:

“Windows Messenger Messenger” = “winmsg.exe”
6. Navigate to the subkeys:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
7. In the right pane, delete the values:

“DisableRegistryTools” = “Invalid dword value”
“DisableTaskManager” = “Invalid dword value”

8. Exit the Registry Editor.

Writeup By: Kaoru Hayashi

Babulal said:

Same thing happened with me , but it was from my best friends id, so i opened it and, which opened yahoo 360 and asked my login, i entered my username and password, nothing was there… Last day i got a mail from yahoo in my alternate email that my yahoo password has been changed…

Now wat to do guys [:)]

robbie said:

Same thing happened with me , but it was from my best friends id, so i opened it and, which opened yahoo 360 and asked my login, i entered my username and password, nothing was there… Last day i got a mail from yahoo in my alternate email that my yahoo password has been changed.
Now the issue is that I dont remember the initial registration details without which I am not able get back into my account.
Any help on this is welcome

Josh said:

I feel very bad for everyone that this has happened to because it happened to me. I spent days talking to yahoo on the phone because they wouldnt help me outright. They referred me to yahoo security who will only work through email, not fone. It took me about 2 weeks just to remember all of the information that they asked for as i registered about 10 years ago. All in all from the back and forth emails they reset my password after about a month. good luck and send them all the info that you know and they will try it all, so guess if you have to. hope this helps.

Mary Jimison said:

i have been told by my friends that the email the people have got is a virus. http://www.geocities.comcheck_out_my_latest_pics39

harry said:

[Note from David: From what I can tell, Mytemex is spyware. I would recommend NOT using this. If you have Mytermex on your computer, remove it immediately!]

Dear bro & sis

I have problem with YM! otomatic status message like this: you are virus infected . Use this tool to remove viruses from your PC : mytermex.com/?id=virus_shield

Any help on this is welcome

JO said:

Anyone tried to click on “forgot your ID or password” in yahoo mail? You may be able to reset it if you can give the right answers and info it asks.

The same thing happened to a friend of mine and she couldn’t opened her account. We were able fix it by getting a new password.

Hope it works for all of you.

BB said:

If you know exactly when you got the virus (you may find it in your browser history when you clicked on the link), then you can do a system restore to a time before you got it. That will rid your computer of it. If you did fill out your login and password, it would be a good idea to change your passwords.

Jimmy said:

Mine were stolen too lastnight. :-( I got up this morning and it said I was signed out on to another location and I could get in either of my accounts :-(

putergirl said:

for the past week or so I keep getting logged off of yahoo IM.. no message, no link.. just poof, logged off. Sometimes it logs itself back in, other times it doesn’t. Has anyone found a solution to this?

Thanks.

lenky said:

ok when ever i log into yahoo as soon as my list of friends appear i get a message that says “Yahoo! Messenger quit unexpectedly. So plug-ins have not been reopened. Double-click each plug-in’s title bar to reopen it. Then i can chat to my friends but when ever i want to put one of the smileys in my conversation or left click on the messenger buddy list it, all my yahoo im windows and the buddy list dissapears and i’m logged off. It does this everytime and i dont seem to know whats the problem. But when i switch to my other account on my laptop the yahoo messenger on that account doesnt do that. Has anyone else seen or heard of this problem? And do u know what it is?

Aftab said:

Hi,
I am a student and therefore was in my college comp. lab. And I access my yahoo msg. where i got some of the links saying as (My holiday pics, My vacation pics, Images on Iraq war etc…) which was as shown been sended by my friends but when i asked them about it they completely denied for that. And accidentally i clicked on 1 of such link.Then after that my labs pc just got infected. My homepage is also been set freeze and it shows some kind of Porn site homepage. Now my whole lab pc got infected bcoz i tried wit Yahoo msg. on every1 of them. I am completely in danger. so if any 1 got some kind of thng like this NEVER EVER click on it. And if any 1 have some solution please send me on my E-mail I.D.

Sudhakar said:

Hello Friends,

First of all i would like to tell you that, most of the people are right here about their doubts regarding phishing.

The spyware was detected on my computer by the NOD32 antivirus system so i wud recommend people to install that software. Also wud recommend the microsoft antispyware tool available from microsoft.com which also would solve the problem.
It has been stated that a virus called yhoo32.explr gets installed into your system when you click the link and hence it sends the link again from your id to others too.

Even though this solves the problem, there are a few cases in which the problem persists.

Get the latest updates for Spybot S&D too. They too have recieved information about an virus by that name so they might have found a solution for that.

And lastly, prevention is better than the cure so

Please do not click on any links on yahoo before confirming them with your friends, whom supposedly sent them, as there are many more viruses also being sent through yahoo messenger and other IM’s these days.

So if it works out please do tell me on sudhakar.vemuri@rediffmail.com.

If it does not, then also tell me, so that i can tell you of a better solution.

You can get NOD32 at flmsdown.net

Zech said:

(Replying to putergirl) You have to go to Internet Options - Security Tab - Custom Level - Enable first one on list

Dean said:

Here is the latest one that just hit me and now everyone in my friends list. I was not thinking and clicked on the link and then I entered my username and password. I changed my password in time though.

pss piss
http://www.geocities.com/watch_my_funny_pics1 : )

Ken said:

Just happened to me today. I was able to go back in and change my password, but I cannot tell who got it from my contacts list and who might have done the same thing I did.

Hamdan said:

hi friend :( when i open my yahoo id directly it sing out :( i dnt knw whats the prob but thats ma best and lucky id plzz help me friendz if u can plzzz :(

Linda said:

The past couple of days when I signed on my messenger would disappear. The little smiling icon would be lit up on the bottom bar, and as soon as I waved my pointer over it, it would disappear completely. I fixed this problem by deleting my yahoo messenger and reinstalling it. It works fine now!

Leave a comment

(required)
(required)

Search Through 10 Years of ReveNews Content: