On a friend's computer is some kind of spam bot installed. It sends messages like
Hello:
I received my apple iPad 32GB ordered on an online shop (www.elevalley.com ) today. So exciting , it's genuine and as good as they promised ,but much cheaper than it is in our country .Glad to share this news with you . Cheers! May all goes well for you. Kind regards
via Yahoo. Only the web email interface is used, no desktop email program. A current virus scanner and Ad-Aware had been installed recently but they did not find anything.
I noticed that in Internet Explorer and Firefox the Yahoo Toolbar is installed. Checking out the extensions dialogue, Firefox said it had an old version of Yahoo Toolbar and that it cannot upgrade it to provide security fixes. After some Googling I found that:
- someone else had the same problem with a Yahoo account
- that version of Yahoo Toolbar (though another build date) has a known Buffer Overflow vulnerability
I removed Yahoo toolbar, installed Zone Alarm and Firefox 4. The question is: What to do?