Yahoo email pop-up--says "hi"--not IM

Discussion in 'Malware Help (A Specialist Will Reply)' started by Jane0218, Mar 12, 2011.

  1. Jane0218

    Jane0218 Private E-2

    A small box, not an IM box, started popping up in yahoo email (Chrome, Firefox, and now IE) last nigth, March 11th.

    The title shows"Message from webp" then there's a red X to close it. It takes severl clicks to close it and each time you click it something different appears--I get an 8 digit number, and then the number 1 before it closes, then it pops up again within 30 seconds. The 8 digit number always stays the same.

    I have no idea where it came from. Everything freezes when it pops up, which basically stops me from using yahoo email.

    Any help would be appreciated.
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hmm, I see alot of people asking the same question but I am not sure that it relates to malware. I do see it happening with other applications not just yahoo mail. To let me fully check for the presence of malware on your machine then you can follow through with the below.

    Please read ALL of this message including the notes before doing anything.

    Pleases follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. Jane0218

    Jane0218 Private E-2

    After looking for a solution all day, I finally came upon this, which seems to have worked, but I don't understand why:

    Close all browsers.
    Open one browser, clear out ALL history, cache, cookies. Close browser.
    Repeat with any othe browsers used.

    Open a browser and sign in to yahoo mail. That annoying gray box should not appear.
    Open any other browsers used and repeat.

    It's been about 4 hours and since I've done the above, that box hasn't shown up.

    But can you explain why? How is malware kept in browsing history, or cache, or cookies? How is it that clearing those things got rid of the problem. I would really like to understand the technical reason behind this.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We don't know for sure that it *was* malware, however malware can hide in all sorts of locations; temporary locations or otherwise. Always best to give Ccleaner a run every now and again.
     
  5. Jane0218

    Jane0218 Private E-2

    I have a machine that's about 3 months old. When I ran CCleaner, it wanted to deleted about 50 registry itmes, plus a ton of other stuff.

    Do I just let it make all those deletions? Can I trust CCleaner that much?
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are running the Registry cleaner, make the backup when prompted. I have never had a system problem using CCLeaner on the registry. ;)
     
  7. Jane0218

    Jane0218 Private E-2

    Thanks. When it prompts to make a backup, is it something CCleaner does, or will I need to do this manually?

    I feel a lot more confident about letting CClenaer do its thing, because of your response. I just can't believe such a young machine could have so much garbage on it.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It will automatically pop up a prompt asking if you want to make a backup. It will do it itself.
    Not unusual. It can be from uninstalled programs and such.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds