
If you use Yahoo! Messenger, keep an eye out for any updates and DONT click on any URLs in the chat sessions. A vulnerability has been found and successfully exploited. Yahoo! was told about it a month ago but ignored the messages until the exploit was published on Tuesday.
The vulnerability is in an ActiveX component used in the program, and is exploited by luring users to a mailicious website. It sounds like Yahoo! will work without the vulnerable file, with some reduced functionalty, so it is recommended to remove the file yauto.dll until YM can be upgraded. Instructions below, more information at
Network World Fusion.
And no, this one isn't a hoax. Yes, really delete the file. JaBbA says so.
Click Start->Search->Files or Folders
(On XP, choose 'All Files and Folders')
type 'yauto.dll' in the field for the file name
Make sure the 'Search In' says 'Local hard Drives'
click 'Search'.
Delete any copies of yauto.dll found.