Afternoon All,
I stumbled across this thread and couldn't help noticing how similar it was to some of the stuff that I come across in my work life.
It's very possible that a virus called W32.Klez has infected your system. What this virus does is send mail from your machine to people in your address book. It does this without you knowing and picks a file from your PC to send. It sends the message out to someone in your address book and tells them that it has come from somebody else (also someone from your address book) This could account for how someone else got hold of a copy of your information.
Its unlikely to be Yahoo instant messenger related as whilst those systems are never the most secure things in the world i've never actually come across an incident like you describe. The only link is probably that of your friends email address being in your address book.
Its just a thought.