Go Back   Wireless and Wifi Forums > News > Newsgroups > alt.computer.security
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 10-03-2006, 09:25 AM
Marrick
Guest
 
Posts: n/a
Default Spam zombie?

Hi.

I think my PC has become a 'spam zombie' as I'm getting a lot of
'undelivered' emails that I haven't sent returned to my inbox - blocked
and bounced back by other people's spam filters. They are sent using my
email account, but with a random 3 or 4 letter prefix: e.g:
wjkq@******.*****.

I run Norton firewall and Avast Home Edition. I've done 2 full system
checks with Avast which has found nothing.

Any advice appreciated. Would changing my email account help?

Many thanks

Marrick


Reply With Quote
  #2 (permalink)  
Old 10-03-2006, 05:43 PM
Stuart Miller
Guest
 
Posts: n/a
Default Re: Spam zombie?


"Marrick" <anonewsgroup.12.marrick52@spamgourmet.com> wrote in message
news:1159863954.576259.149570@k70g2000cwa.googlegr oups.com...
> Hi.
>
> I think my PC has become a 'spam zombie' as I'm getting a lot of
> 'undelivered' emails that I haven't sent returned to my inbox - blocked
> and bounced back by other people's spam filters. They are sent using my
> email account, but with a random 3 or 4 letter prefix: e.g:
> wjkq@******.*****.


It is probably not your machine that is the problem.

Spammers have found a way to fake the return address in the e-mails they
send. Those which can not be delivered, either from being sent to a non
existant address, or from being rejected by the receiver's spam filter, are
bounced back. Because your address is in the 'sender' field, you get them.

I have a hobby domain name, and recently I started getting a flood of
rejected e-mails which look like they were sent from my domain. However,
this is not possible since my domain does not have a mail server or client
to send them, and I know my (linux) server has not been compromised.

There is probably a way to trace the source of these, but as soon as you
find the offending isp/client they will simply move somewhere else.

Stuart



Reply With Quote
  #3 (permalink)  
Old 10-03-2006, 07:56 PM
Marrick
Guest
 
Posts: n/a
Default Re: Spam zombie?


Thank you both. I am reassured.

I do have a spam filter - but only a free one (K9) that dumps the spam
after downloading. I got over 30 spams yesterday. I think it might be
worth me changing my account - it would, at least, mean that it'd take
a while before the volume got back up to this level.

Thanks again

Marrick


Reply With Quote
  #4 (permalink)  
Old 10-03-2006, 08:00 PM
Admins
Guest
 
Posts: n/a
Default Re: Spam zombie?

On 3 Oct 2006 01:25:54 -0700, Marrick wrote:

> Hi.
>
> I think my PC has become a 'spam zombie' as I'm getting a lot of
> 'undelivered' emails that I haven't sent returned to my inbox - blocked
> and bounced back by other people's spam filters. They are sent using my
> email account, but with a random 3 or 4 letter prefix: e.g:
> wjkq@******.*****.
>
> I run Norton firewall and Avast Home Edition. I've done 2 full system
> checks with Avast which has found nothing.
>
> Any advice appreciated. Would changing my email account help?
>
> Many thanks
>
> Marrick


Just to be on the safe side, run adaware and check for spyware and then
install SpywareBlaster. The latter helps by keeping spyware from
installing in the firstplace, both are free and in our software section

Regards
--
Admin


* www.privacyoffshore.net (No Logs Internet Surfing)
* Anonymous Secure Offshore SSH-2 Surfing Tunnels

Reply With Quote
  #5 (permalink)  
Old 10-03-2006, 08:52 PM
Moe Trin
Guest
 
Posts: n/a
Default Re: Spam zombie?

On 3 Oct 2006, in the Usenet newsgroup alt.computer.security, in article
<1159863954.576259.149570@k70g2000cwa.googlegroups .com>, Marrick wrote:

>I think my PC has become a 'spam zombie' as I'm getting a lot of
>'undelivered' emails that I haven't sent returned to my inbox - blocked
>and bounced back by other people's spam filters.


It's amazing how many st00pid mail servers accept ALL mail whether or
not the recipient exists, and later do tests and try to send back anything
they don't like - such as mail for non-existent users they shouldn't have
accepted in the first place. As the "From:" address is almost always faked
or spoofed, this causes the misconfigured mail server to become an agent
of the spammer, distributing the spam for them.

>They are sent using my email account, but with a random 3 or 4 letter
>prefix: e.g: wjkq@******.*****.


Look at the _headers_ of the returned mail, NOT the "To:" or "From" stuff
that is usually faked. The headers you want to study are those that tell
how the mail was received and from who.

Received: from sheffield.ac.uk ([218.10.6.200])
by mail.example.com (8.11.7/8.11.3) with ESMTP id hAMMgRk22045
for <my.email.name@example.com>; Sat, 23 Sep 2006 15:42:28 -0700
Received: from 89.173.30.207 by smtp.orion.ufrgs.br;
Sat, 23 Sep 2006 22:43:01 +0000
Received: from unknown (mengile.co.rp [124.31.84.11])
by smtp.locality.co.tu Sun, 24 Sep 2006 15:20:11 -0900

You are tracing _back_ from the top. This mail was received by my mail
server, from a host that _claimed_ to be called sheffield.ac.uk (not
likely, as that is a domain name, not a host) but the IP address used
(218.10.6.200) is in Northeastern China (Heilongjiang province) and as
is typical the ISP doesn't know how to run a name server. I can trust
this information, because it was put here by my mail server.

The second received line is quite obviously faked. The IP address is in
Slovakia, but the host supposedly has a Brazilian name. The proof that
the information is faked is "how did the mail get from either of these
places to the computer that delivered it to me from Northeastern China?"
There is no line indicating it got there. The third received line has
several errors - there is no '.rp' or '.tu' top domains, the 124.31.x.x
address block has not been assigned by APNIC (the responsible RIR), and
the timestamp is ludicrous. The other dumb question to ask is why the
mail would have been sent from the "124.31.84.11" host (an Asian address
range) to "89.173.30.207" in Europe, then back to 218.10.6.200 in China
before being sent to me in North America. Is the spammer getting
"Frequent Flyer Miles" for this?

You should look at the "Received:" headers inside the "returned" mail.
Did the mail originate on your ISP? You are posting from 84.64.236.97
which is in a block assigned to Energis UK (84.64.0.0 - 84.71.255.255).
If the mail headers don't show this, then someone harvested your name
and address and are using it to shift the blame (fairly common).

>I run Norton firewall and Avast Home Edition. I've done 2 full system
>checks with Avast which has found nothing.


Yeah, but you are also running windoze - at least you aren't using
Internet Exploiter, but windoze doesn't have the greatest security
reputation - hence the vast number of anti-mal-ware programs.

>Any advice appreciated. Would changing my email account help?


Several years ago, we used to use "firstname_last-initial" for usernames
and a random character generator to create the initial password for the
account. Now, I'm using the random character generator to create usernames
and telling the users to NOT publish those names on the Internet. The big
problem is having others be able to remember that my email address is

[compton ~]$ head -2 /dev/random | mimencode | head -1
djqFVsLMbI/tX32Z617KYtvraOI2P0+35DuHrtp++hLt4kitSPduWdFqBqSzV oo8oXGglbcw
[compton ~]$

djqFVsLMbI@example.com

Yeah, that's me.

Old guy

Reply With Quote
  #6 (permalink)  
Old 10-03-2006, 09:40 PM
David H. Lipman
Guest
 
Posts: n/a
Default Re: Spam zombie?

From: "Marrick" <anonewsgroup.12.marrick52@spamgourmet.com>

| Hi.
|
| I think my PC has become a 'spam zombie' as I'm getting a lot of
| 'undelivered' emails that I haven't sent returned to my inbox - blocked
| and bounced back by other people's spam filters. They are sent using my
| email account, but with a random 3 or 4 letter prefix: e.g:
| wjkq@******.*****.
|
| I run Norton firewall and Avast Home Edition. I've done 2 full system
| checks with Avast which has found nothing.
|
| Any advice appreciated. Would changing my email account help?
|
| Many thanks
|
| Marrick


Download MULTI_AV.EXE from the URL --
http://www.ik-cs.com/programs/virtools/Multi_AV.exe

To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through your
FireWall to allow it to download the needed AV vendor related files.

C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal Mode.
This way all the components can be downloaded from each AV vendor's web site.
The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the PC.

You can choose to go to each menu item and just download the needed files or you can
download the files and perform a scan in Normal Mode. Once you have downloaded the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode [F8 key
during boot] and re-run the menu again and choose which scanner you want to run in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.

When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive PDF help
file. http://www.ik-cs.com/multi-av.htm

Additional Instructions:
http://pcdid.com/Multi_AV.htm


* * * Please report back your results * * *


--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Reply With Quote
  #7 (permalink)  
Old 10-04-2006, 12:03 AM
Marrick
Guest
 
Posts: n/a
Default Re: Spam zombie?


Moe Trin wrote:

> You should look at the "Received:" headers inside the "returned" mail.
> Did the mail originate on your ISP? You are posting from 84.64.236.97
> which is in a block assigned to Energis UK (84.64.0.0 - 84.71.255.255).
> If the mail headers don't show this, then someone harvested your name
> and address and are using it to shift the blame (fairly common).
>


Thanks for that. No, 84.64.236.97 doesn't appear in them. So my machine
is OK!

Really do appreciate the time and effort you guys put in to help.

Marrick


Reply With Quote
  #8 (permalink)  
Old 10-04-2006, 12:13 AM
Marrick
Guest
 
Posts: n/a
Default Re: Spam zombie?


David H. Lipman wrote:

>
> * * * Please report back your results * * *
>
>

Thanks Dave. In view of the other posts which indicate that my PC is
OK, I won't be doing this just now. But I have saved your post for
future reference. Many thanks for your help and effort.

Marrick


Reply With Quote
  #9 (permalink)  
Old 10-04-2006, 01:01 AM
David H. Lipman
Guest
 
Posts: n/a
Default Re: Spam zombie?

From: "Marrick" <anonewsgroup.12.marrick52@spamgourmet.com>


| Thanks Dave. In view of the other posts which indicate that my PC is
| OK, I won't be doing this just now. But I have saved your post for
| future reference. Many thanks for your help and effort.
|
| Marrick

Give a shot. You never know what the AV modules in the Multi AV Scanning Tool might find
that Avast missed. That's why I include four different ACV scanners in my tool.


--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Reply With Quote
  #10 (permalink)  
Old 10-04-2006, 11:11 AM
Melic
Guest
 
Posts: n/a
Default Re: Spam zombie?

On Tue, 03 Oct 2006 10:31:12 +0100, Sebastian Gottschalk <seppi@seppig.de>
wrote:

> Marrick wrote:
>
>> I think my PC has become a 'spam zombie' as I'm getting a lot of
>> 'undelivered' emails that I haven't sent returned to my inbox - blocked
>> and bounced back by other people's spam filters.


It happened to my webmail, some spammer fakes your email address and it
gets
bounced to you when undelivered.

My spam filter did not get all those bounces to the spam folder but did
catch
most of it.

I would say not much to worry about.

Reply With Quote
  #11 (permalink)  
Old 10-11-2006, 07:15 PM
none
Guest
 
Posts: n/a
Default Re: Spam zombie?


they are most likely spoofs .


Reply With Quote
  #12 (permalink)  
Old 10-11-2006, 07:21 PM
none
Guest
 
Posts: n/a
Default Re: Spam zombie?


if you get too much spam use a yahoo account ,that puts them in a junk
folder then just delete the lot,easy .
use your private email address only for trusted users.
i never get any spam because i use yahoo for general use and private
email accy.
all the spam goes to yahoo or gmail or hotmail or whatever.


Reply With Quote
Sponsored Links
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Leave Cingular for Verizon? Malathan alt.cellular.verizon 55 01-22-2007 06:04 PM
Hidden spam links injected into web pages Terry_P alt.computer.security 3 12-03-2006 12:18 AM
Spam from 82868 (and more spam!) David Hearn uk.telecom.mobile 18 11-08-2006 07:41 PM
spam world! Rick Merrill alt.computer.security 0 10-13-2006 12:49 AM
Oxygen Phone Manager II v2.11 for Symbian OS smartphones is just released! Oxygen Software alt.cellular.nokia 3 09-16-2006 11:16 AM


All times are GMT. The time now is 07:21 PM.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45