Fake Yahoo Messenger popup in Yahoo mail?
« on: December 25, 2009, 03:50:07 PM »
Anyone know about this?  It appears in the lower right of the screen when in my Yahoo inbox.  It says something like: "<some ridiculous fake name> wants to add you to his Online Contacts list on Yahoo Messenger".  It has buttons for "accept" and "decline."  The first time I encountered it I clicked "decline" and got a second "are you sure?" popup.  Since then it still appears with a different name and this time I just click the X to close the popup box.  It doesn't happen often but shows up at least once per log-in.

Odd thing is that I've only encountered it in my main Yahoo account.  I have several other Yahoo mail accounts and I haven't encountered it in any of them.  Avast doesn't pick up anything when I run a scan.

Recent activity was getting hit by a virus a while back when I didn't have Avast set on a daily scan (I thought it was a default setting).  Avast caught it with the scan but since then there have been intermittent troubles, such as Firefox crashing, and I can't get into IE at all.  I'm running XP on a Dell Inspiron 1521 laptop.

I should also add that I've never used Yahoo Messenger, never even enabled it or whatever is done to set it up for use.

Re: Fake Yahoo Messenger popup in Yahoo mail?
« Reply #1 on: December 25, 2009, 07:51:17 PM »
Check you computer for Malware with

update and run quick scan, click the button "remove selected" to quarantine anything found


Are cookies really spyware and are they dangerous?

If anything is found other than cookies you may post the scan logs here


Re: Fake Yahoo Messenger popup in Yahoo mail?
« Reply #2 on: December 26, 2009, 01:24:16 AM »
Thanks Pondus, just ran MalwareByte and showed nothing.  Also ran AdAware and showed nothing either.

This popup only shows up in one of my Yahoo Mail accounts, not the others.  It doesn't appear in my Yahoo account when accessed from two other computers.  I don't even click it off now because I'm afraid it might trigger something, so it remains in the corner of the screen for however long I have Yahoo Mail open.
Re: Fake Yahoo Messenger popup in Yahoo mail?
« Reply #3 on: December 26, 2009, 01:26:47 AM »
Here's the HijackThis logfile.  I have no idea how to interpret it...

Re: Fake Yahoo Messenger popup in Yahoo mail?
« Reply #4 on: December 26, 2009, 01:49:12 AM »
I don't see anything obvious in your log other than your OS is out of date, SP3 has been out for well over a year and your copy of Java is also out of date, both of which leave you more vulnerable.

I would also suggest a visit to this site, which scans your system for out of date programs that have patches to close vulnerabilities,

I also don't see a firewall and the XP firewall doesn't provide outbound protection.

AdAware has long had its day, personally I would get rid of it and replace it with both MABM and SAS.

Have you run SAS yet ?

I don't know what version of Acrobat PDF Reader you are using but that is another big target for malware, especially if it is out of date.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security


Re: Fake Yahoo Messenger popup in Yahoo mail?
« Reply #5 on: December 26, 2009, 02:18:06 AM »
Thank you David.

I just download SAS and it showed:

Trojan. Agent Gen-Nullo (short)
Trojan. Unknown origin (2)
and tracking cookies

All were quarantined, but still have the popup.

I will try getting the suggested updates

Re: Fake Yahoo Messenger popup in Yahoo mail?
« Reply #6 on: December 26, 2009, 03:28:16 AM »
What were the file names and locations of these files, since the detections look like they are generic (the Gen- bit) detections, it is best to investigate further.

That is me for the night, almost 2:30 a.m. here.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Re: Fake Yahoo Messenger popup in Yahoo mail?
« Reply #7 on: December 26, 2009, 03:30:50 AM »
I guess next step will be to contact yahoo
What happens if you clean your temp files?


Re: Fake Yahoo Messenger popup in Yahoo mail?
« Reply #8 on: December 26, 2009, 03:38:08 AM »
Pondus, I just cleared the temp files and I don't see the popup!!  I clear the temps regularly but hadn't since running SAS a few hours ago.  Perhaps SAS quarantined the offender and clearing the cache prevented a repeat performance.

thanks again to you and David, hopefully this is the last of it... :)


Re: Fake Yahoo Messenger popup in Yahoo mail?
« Reply #9 on: December 26, 2009, 05:01:48 AM »
AH DAMN, IT'S BACK.....  :-\

Re: Fake Yahoo Messenger popup in Yahoo mail?
« Reply #10 on: December 26, 2009, 04:37:07 PM »
To me this is the same as spam, somehow your messenger account has got on to a list and this is the equivalent to getting spam email trying to get you do do something likely to get you in trouble as opposed to something actually on your system.

This more so when you say this doesn't effect your other accounts.

I don't use 'any' messenger service, never saw the need, so excuse my ignorance, but isn't there a setting for you to automatically deny or even block the pop-up in the message in the first place. If there isn't I wouldn't put up with that kind of restriction and possible vulnerability and it would be history, removed from my system and seeking another alternative.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security


Re: Fake Yahoo Messenger popup in Yahoo mail?
« Reply #11 on: December 26, 2009, 05:31:15 PM »
I don't use Yahoo Messenger or any messenger service either.  I've never activated or used one.  It's asking to be added to my Yahoo messenger list (which doesn't exist because I've never created one) and wants to add me to "its" Online Contacts list.

It's gotta be something on this laptop as my PC on the other side of the room can log into the same account and not get the popup.  And none of my other Yahoo accounts, viewed on either computer, get the popup.

It can be moved about the screen, I try to move it out of the way so I can read things, but it doesn't go away unless I click the little X in the corner of it.... but I'm reticent to click that X anymore cuz not sure what it's doing, maybe using my email list to send spam or something.

Can't find any reference to this on the net.  Weird.... :-\

Re: Fake Yahoo Messenger popup in Yahoo mail?
« Reply #12 on: December 26, 2009, 05:39:46 PM »
can you post a screenshot of the popup?

Shot in the dark, try this

Re: Fake Yahoo Messenger popup in Yahoo mail?
« Reply #13 on: December 26, 2009, 06:22:01 PM »
So you don't have messenger installed even though you don't use it ?

When does this happen and what are you doing at the time ?
It could be a spoof pop-up that if you click add it would carry out alternative actions rather than add to a contacts list.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security


Re: Fake Yahoo Messenger popup in Yahoo mail?
« Reply #14 on: December 26, 2009, 06:55:06 PM »

Here's the screenshot of the popup.  It shows up smaller in the lower right hand corner of the screen but it can be dragged to a larger size, which I did so you can see it better.  The first time I saw it I clicked "Decline", which opened another "are you sure?" popup.  After that it appeared on next log-in with a different phony person's name, and that time I just clicked the "X" and it went away.  But now I just leave it there without clicking anything because I'm afraid of what the clicks might be doing.

No, I've never activated Yahoo Messenger or used it.
