Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Yahoo Messenger Worm Infects Internet Explorer

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Archives » General Discussion (01/01/06 through 01/22/2007) Donate to DU
 
survivor999 Donating Member (1000+ posts) Send PM | Profile | Ignore Wed May-24-06 05:13 AM
Original message
Yahoo Messenger Worm Infects Internet Explorer
Edited on Wed May-24-06 03:14 PM by newyawker99
By Clement James
VNUNet.com
05/22/06 8:24 AM PT

"This is one of oddest and more insidious pieces of malware we have encountered in years, and the first instance of a complete Web browser hijack without the user's awareness," said Tyler Wells, senior director of research at FaceTime Security Labs.

Security researchers have identified an "insidious" threat affecting Yahoo (Nasdaq: YHOO) Latest News about Yahoo Messenger.

A self-propagating worm, named yhoo32.explr, installs a piece of software called "Safety Browser" and then hijacks the Internet Explorer homepage, leading users to a site that puts spyware on their PCs.

Because Safety Browser uses the Internet Explorer icon to identify itself, users can easily mistake it for the legitimate Microsoft (Nasdaq: MSFT) Latest News about Microsoft browser.

This is the first recorded incidence of malware installing its own Web browser on a PC without the user's permission, according to security firm FaceTime.

The self-propagating worm spreads the infection to all contacts in Yahoo Messenger by sending a Web site link that loads a command file onto the user's PC and installs Safety Browser.

More at link:

http://www.technewsworld.com/story/50655.html

EDIT: COPYRIGHT. PLEASE POST ONLY 4 OR 5 PARAGRAPHS
FROM THE COPYRIGHTED NEWS SOURCE PER DU RULES.
Printer Friendly | Permalink |  | Top
sutz12 Donating Member (1000+ posts) Send PM | Profile | Ignore Wed May-24-06 05:16 AM
Response to Original message
1. K & R nt
Printer Friendly | Permalink |  | Top
 
Breeze54 Donating Member (1000+ posts) Send PM | Profile | Ignore Wed May-24-06 06:12 AM
Response to Original message
2. I can't find any mention of it on Symantec site
Edited on Wed May-24-06 06:14 AM by Breeze54
and I'm wondering why I can't find a solution for removal anywhere! :shrug:
Not that I'm infected (I don't use IE) but Facetime seems to be the only one's reporting this.

---------------------------
http://www.facetime.com/pr/pr060519.aspx
Press Release

Self-Propagating Worm Installs Unsafe "Safety Browser"

FaceTime Security Labs Warns Against Homepage Hijack

FOSTER CITY, CALIF – May 19, 2006


Research experts at FaceTime Security Labs™ identified and reported a new threat today
affecting Yahoo! Messenger. FaceTime researchers confirmed that a self-propagating worm,
named yhoo32.explr, installs 'Safety Browser' and hijacks the Internet Explorer homepage,
leading users to a site that puts spyware on their PCs.
Because Safety Browser uses the IE icon, users can easily mistake it for Internet Explorer.
This is the first recorded incidence of malware installing its own web browser on a PC
without the user's permission.

The self-propagating worm spreads the infection to all contacts in Yahoo! Messenger by
sending a website link that loads a command file onto the user's PC and installs Safety
Browser. This spam over instant messaging (IM) is called spim.
IM applications and protocols are an increasingly popular vector to distribute malicious
files and executables.

"This is one of oddest and more insidious pieces of malware we have encountered in years,"
commented Tyler Wells, Senior Director of Research at FaceTime Security Labs.
"This is the first instance of a complete web browser hijack without the user's awareness.
Similar 'rogue' browsers, such as 'Yapbrowser', have demonstrated the potential for serious
damage by directing end-users to potentially illegal or illicit material.
'Rogue' browsers seem to be the hot new thing among hackers."

The India research arm of FaceTime Security Labs discovered the threat in a 'honeypot',
a trap they set to detect viruses, worms, spyware and other threats.
Commentary on this threat by FaceTime Security Labs researcher Chris Boyd can be found
on the Greynets Blog, at
http://blog.spywareguide.com. FaceTime Security Labs is the
threat research division of IM and Greynet security leader FaceTime Communications.

Threat name: yhoo32.explr
Threat type: Browserware and worm
Who is affected: Users of Yahoo! Messenger
Additional Information: The malware infects the PC with two elements.

The first element is a web browser called "Safety Browser."
This stand-alone application has no uninstaller and disguises itself with an Internet Explorer
logo in some instances. The application also hijacks the personal homepage in Internet Explorer
and points users to Safety Browser's homepage (demoplanet.tv). The hijack also plays looped
music that cannot be stopped when the user starts up the PC or Safety Browser.

The second element is the self-propagating worm.
This worm installs an .exe file that spreads the infection through Yahoo Messenger
to everyone on the Contacts List.


Printer Friendly | Permalink |  | Top
 
hobbit709 Donating Member (1000+ posts) Send PM | Profile | Ignore Wed May-24-06 07:27 AM
Response to Reply #2
3. Symantec lists it as
W32.Browaf is a worm that sends a link to a copy of itself via Yahoo Instant Messenger and MIRC. It also modifies the Internet Explorer Home page.
Note: Definitions dated prior to May 24, 2006 may detect this threat as Backdoor.Trojan.
Also Known As: W32.Browsesafe
Type: Worm
Infection Length: 348,620 bytes.
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP

Printer Friendly | Permalink |  | Top
 
Breeze54 Donating Member (1000+ posts) Send PM | Profile | Ignore Wed May-24-06 07:33 AM
Response to Reply #3
4. Thanks - I searched using
this name yhoo32.explr and yhoo32 on Symantec and recieved zero results.
They usually have more than one name listed or a cross link.
My YIM should be fine then. ;)

Printer Friendly | Permalink |  | Top
 
shadowknows69 Donating Member (1000+ posts) Send PM | Profile | Ignore Wed May-24-06 07:34 AM
Response to Original message
5. YM has always been a plague on my system
the brief time I used it.
Printer Friendly | Permalink |  | Top
 
quiet.american Donating Member (1000+ posts) Send PM | Profile | Ignore Wed May-24-06 10:01 AM
Response to Original message
6. Thank goodness I stopped using IMs a long time ago.
When it first came out back in the day, it was "cool," but then I started getting annoyed at having absolutely no down time from people trying to get in touch with me. Between the home phone, cell phone, home phone voicemail, work phone voicemail, and three different email addresses, I finally figured there were enough ways to get in touch with me without my needing to add an IM.
Printer Friendly | Permalink |  | Top
 
Breeze54 Donating Member (1000+ posts) Send PM | Profile | Ignore Wed May-24-06 10:07 AM
Response to Reply #6
7. I just adjust my
preferences for IM's from contacts only. ;) I block unknowns.

I use YM to go to Yahoo Political Chatroom 10 and to talk to friends live!
Printer Friendly | Permalink |  | Top
 
quiet.american Donating Member (1000+ posts) Send PM | Profile | Ignore Wed May-24-06 10:15 AM
Response to Reply #7
10. That's good, but I don't want to hear from anybody! ;) n/t
Printer Friendly | Permalink |  | Top
 
Recursion Donating Member (1000+ posts) Send PM | Profile | Ignore Wed May-24-06 10:09 AM
Response to Original message
8. If you absolutely must use Windows
(and you probably don't *need* Windows, you just think you do), then use GAIM.
Printer Friendly | Permalink |  | Top
 
in_cog_ni_to Donating Member (1000+ posts) Send PM | Profile | Ignore Wed May-24-06 10:12 AM
Response to Original message
9. CRAP. My son just told me last night he thinks he has a virus or something
because his computer is "acting funky" and he uses Yahoo all the time and Yahoo Messanger. He can't use it at all. I haven't looked at it yet. He has Norton anti-virus though. Wouldn't that catch it? Damn. Does anyone know what I should do? Should I run a Norton scan? Will that help? Keep in mind that you're talking to a computer illiterate here...that's me.;)
Printer Friendly | Permalink |  | Top
 
Breeze54 Donating Member (1000+ posts) Send PM | Profile | Ignore Wed May-24-06 10:52 AM
Response to Reply #9
11. ah...run the update
on NAV and then run a scan. I use automatic NAV updates. Much easier!

Printer Friendly | Permalink |  | Top
 
in_cog_ni_to Donating Member (1000+ posts) Send PM | Profile | Ignore Wed May-24-06 11:07 AM
Response to Reply #11
12. Can't. I just looked at his computer and can't even log on.
Edited on Wed May-24-06 11:08 AM by in_cog_ni_to
He gets a blue "Fatal Error Log On Canceled. C000021a The system has been shut down Due to Status of OXC0000135 OX00000000 OX00000000." Looks like another trip the the computer repairman.:(
Printer Friendly | Permalink |  | Top
 
Breeze54 Donating Member (1000+ posts) Send PM | Profile | Ignore Wed May-24-06 12:07 PM
Response to Reply #12
13. Have you rebooted the computer at all?
Do you have a RECOVERY CD?? Use it!!
Printer Friendly | Permalink |  | Top
 
in_cog_ni_to Donating Member (1000+ posts) Send PM | Profile | Ignore Wed May-24-06 01:24 PM
Response to Reply #13
14. OK. I'm sure we have one. Thanks. n/t
Printer Friendly | Permalink |  | Top
 
Breeze54 Donating Member (1000+ posts) Send PM | Profile | Ignore Wed May-24-06 01:48 PM
Response to Reply #14
15. Just do a 'Partial Recovery' to
save your programs you installed.
Don't do a 'Full recovery' as it will wipe out all your programs!!
Hope I caught you in time! whew! ;)
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Mon Apr 29th 2024, 12:04 PM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Archives » General Discussion (01/01/06 through 01/22/2007) Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC