Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Yahoo Messenger worm turns on IE
VNUnet ^ | 21 May 2006 | Clement James

Posted on 05/21/2006 6:32:25 PM PDT by gondramB

Researchers have identified an "insidious" threat affecting Yahoo Messenger. A self-propagating worm, named yhoo32.explr, installs a piece of software called 'Safety Browser' and then hijacks the Internet Explorer homepage, leading users to a site that puts spyware on their PCs.

Because Safety Browser uses the IE icon to identify itself, users can easily mistake it for the legitimate Internet Explorer. This is the first recorded incidence of malware installing its own web browser on a PC without the user's permission, according to security firm FaceTime.

The self-propagating worm spreads the infection to all contacts in Yahoo! Messenger by sending a website link that loads a command file onto the user's PC and installs Safety Browser.

"This is one of oddest and more insidious pieces of malware we have encountered in years," said Tyler Wells, senior director of research at FaceTime Security Labs.

"This is the first instance of a complete web browser hijack without the user's awareness. Similar 'rogue' browsers, such as 'Yapbrowser,' have demonstrated the potential for serious damage by directing end-users to potentially illegal or illicit material. 'Rogue' browsers seem to be the hot new thing among hackers."


TOPICS:
KEYWORDS: ie; malware; spyware; threat; virus; windows; yahoo
Navigation: use the links below to view more comments.
first 1-2021-35 next last
>>"This is the first instance of a complete web browser hijack without the user's awareness. <<

A new type and level of threat - IMs are used more and more by non-techies.

1 posted on 05/21/2006 6:32:26 PM PDT by gondramB
[ Post Reply | Private Reply | View Replies]

To: gondramB

So what do you do if you use Yahoo Messenger? Never let it boot again? Is there some remedy?


2 posted on 05/21/2006 6:36:23 PM PDT by formercalifornian (One nation, under whatever popular fad comes to mind at the moment, indivisible...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: formercalifornian

>>So what do you do if you use Yahoo Messenger? Never let it boot again? Is there some remedy?<<

I'm looking into that - this is a discussion on the topic on slashdot - if nothing else there will surely be a fix from Yahoo.

http://it.slashdot.org/it/06/05/21/132211.shtml


3 posted on 05/21/2006 6:38:46 PM PDT by gondramB (He who angers you, in part, controls you. But he may not enjoy what the rest of you does about it.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: gondramB

If this sort of thing were classified as a capital offense that upon conviction, carried a mandatory death sentence without any optional sentencing possible by the judge, you would see a dramatic decrease in hacking and other sorts of computer tampering.


4 posted on 05/21/2006 6:39:03 PM PDT by mkjessup (The Shah doesn't look so bad now, eh? But nooo, Jimmah said the Ayatollah was a 'godly' man.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: gondramB

Save


5 posted on 05/21/2006 6:39:24 PM PDT by freeangel ( (free speech is only good until someone else doesn't like what you say))
[ Post Reply | Private Reply | To 1 | View Replies]

To: formercalifornian
>>So what do you do if you use Yahoo Messenger? Never let it boot again? Is there some remedy?<<

As a somewhat related issue, I would suggest using Firefox instead IE. It is safer and has many plugins to block ads, download entire sites, spellcheck and enlarge the text of any page.

http://www.mozilla.com/firefox/
6 posted on 05/21/2006 6:44:19 PM PDT by gondramB (He who angers you, in part, controls you. But he may not enjoy what the rest of you does about it.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: mkjessup
carried a mandatory death sentence without any optional sentencing possible

Come on. We don't have the b@lls to put down the gang-bangers, drug-peddlers, rapists and child molesters...

7 posted on 05/21/2006 6:47:18 PM PDT by AbeKrieger (A country without secure borders will not long be a country.)
[ Post Reply | Private Reply | To 4 | View Replies]

To: AbeKrieger
carried a mandatory death sentence without any optional sentencing possible
Come on. We don't have the b@lls to put down the gang-bangers, drug-peddlers, rapists and child molesters...


Hey, we gotta start somewhere.
8 posted on 05/21/2006 6:54:02 PM PDT by mkjessup (The Shah doesn't look so bad now, eh? But nooo, Jimmah said the Ayatollah was a 'godly' man.)
[ Post Reply | Private Reply | To 7 | View Replies]

To: gondramB

So if you don't use Yahoo Messenger you are OK?


9 posted on 05/21/2006 7:03:11 PM PDT by perfect stranger (I need new glasses.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: perfect stranger

>>So if you don't use Yahoo Messenger you are OK?<<

Yes. As I understand it this is a threat only to Yahoo messenger users.


10 posted on 05/21/2006 7:07:24 PM PDT by gondramB (He who angers you, in part, controls you. But he may not enjoy what the rest of you does about it.)
[ Post Reply | Private Reply | To 9 | View Replies]

To: gondramB

Thanks.


11 posted on 05/21/2006 7:11:10 PM PDT by perfect stranger (I need new glasses.)
[ Post Reply | Private Reply | To 10 | View Replies]

To: gondramB

BTTT for future reading....


12 posted on 05/21/2006 7:15:43 PM PDT by Peace4EarthNow
[ Post Reply | Private Reply | To 1 | View Replies]

To: formercalifornian
Sure, switch to firefox.

www.firefox.com

ie is such garbage.
13 posted on 05/21/2006 7:16:04 PM PDT by seppel
[ Post Reply | Private Reply | To 2 | View Replies]

To: gondramB

Agreed.


14 posted on 05/21/2006 7:16:54 PM PDT by seppel
[ Post Reply | Private Reply | To 6 | View Replies]

To: gondramB
The self-propagating worm spreads the infection to all contacts in Yahoo! Messenger by sending a website link that loads a command file onto the user's PC and installs Safety Browser.

Can't they just shut down that website?

15 posted on 05/21/2006 7:18:03 PM PDT by Always Right
[ Post Reply | Private Reply | To 1 | View Replies]

To: gondramB

I hate to say it but anyone using IMs are asking for trouble


16 posted on 05/21/2006 7:18:55 PM PDT by UB355 (Slower Traffic Keep Right)
[ Post Reply | Private Reply | To 1 | View Replies]

To: gondramB

Really feel sorry for you suckers using Windose... never learn anything?

Guess u get what u pay for... hehe

Its the price for sucking all the foul vapor that comes out of Mafiasoft rear end.


17 posted on 05/21/2006 7:18:58 PM PDT by observer5 ("Better violate the rights of a few, than of all!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Always Right

>>Can't they just shut down that website?<<

The spyware browser, "Safety Browser" is not in itself ilegal if it is installed with consent.

It may need to be shown that the web site is connected with the worm by a money trail etc. Even then, the worm apparently asks the user to download it...


18 posted on 05/21/2006 7:24:24 PM PDT by gondramB (He who angers you, in part, controls you. But he may not enjoy what the rest of you does about it.)
[ Post Reply | Private Reply | To 15 | View Replies]

To: El Gran Salseron; bitt

Ping


19 posted on 05/21/2006 7:26:30 PM PDT by potlatch (Does a clean house indicate that there is a broken computer in it?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: formercalifornian
So what do you do if you use Yahoo Messenger? Never let it boot again? Is there some remedy?

Very simple answer. Use one computer for Yahoo Messenger and all the other stuff for fun but that you could really care less about. Then, if you get the virus, swamp in a new hard drive and start over.

Never under any circumstances use YM on a computer with sensitive information. For that matter, do not browse the net with the same computer. Have two computeres. They are cheap enough these days.

20 posted on 05/21/2006 7:29:13 PM PDT by BJungNan
[ Post Reply | Private Reply | To 2 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-35 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson