Jump to content
GreaseSpot Cafe

Spam being sent from my email????


Abigail
 Share

Recommended Posts

It would appear that somehow spam is being sent from my business account. No one else at the office seems to be having this problem. I keep getting 40 - 50 "mail delivery failure" messages a day. All of them are for mail I did not send. All of them appear to have been sent from our business account, but do not have my specific business address listed as the sender.

I have changed my password twice. I have run both Adaware and Norton's spyware. I also scanned for viruses. I did find and remove a hijacker, but I doubt that is what is doing this. My boss found a worm, but if it was on her computer and not mine, I would think she would be having the problem and not me.

Any suggestions?

Link to comment
Share on other sites

Ewwwwww Abi! That's an email virus or something. Do you have a virus scanner on the 'puter? If not, somewhere in these threads are links to free online scans.

It may not even be on your computer, either. Anyone you email with may have the virus and if they have your addy in their address book, then the emails are going to go out as if from you. Notify all the people you email with and have them check their 'puters.

One way I've been able to tell if it's me or somebody I email with is to put the address of *!* or some other such nonsensical and symbol 'address' in my address book. It will be the first addy listed, so if it's going out from address book, the 'response' will come from that address. See? (I may not being saying this right or sensibly.)

Link to comment
Share on other sites

Yeah, I did do a scan for viruses and it came up clean.

So you are saying these could be coming from someone else's computer? That could make sense, I suppose, none of the spam is being sent to people I know. heck some of it went overseas and wasn't even in English. Well, my boss did find a worm on her computer - I wonder if that is where it is originating. What I find very very odd is that the sender address isn't mine.

For example - say our business domain name is abigaillaw.com and my email address is abc@abigaillaw.com. If I were the sender, I would expect the email to say it was sent by abdc@abigail.com. Instead they will say there were sent by def@abigaillaw.com or hij@abigaillaw.com. They aren't all being sent by one sender, but by numerous senders all @abigaillaw.com.

I've never seen anything quite like it.

Oh yea, another piece of information. It appears when the boss' son set up our domain name he didn't "lock it" - whatever that means. So, in case that was part of the problem I did go in and lock it this morning and I verified that only the email accounts we set up were listed there. However, again, I don't understand how if I am not the "sender" they emails are being returned to me.

Edited by Abigail
Link to comment
Share on other sites

It doesn't really matter who it says it's from in the 'From' area. Do you know how to check the headers? Check there...that may tell you where they're coming from...at least give you an IP address...maybe...if it's not too well masked.

OK, let's say your boss has this worm that is designed to send out masses of spam. Typically those kinds of worms will use all of the addresses and/or domains listed in her address book to send this spam to wherever. Just depends on how the worm is written. So if you are in her address book, spam will be sent from her computer BUT with your 'information'. Anybody else she has in her address book may experience what you are experiencing, too...since the spam is using the information in her address book.

I dunno about domain locking.

Link to comment
Share on other sites

You have to look at the headers to trace back where the email originated from. It's possible it's not even coming from your network (but probably is).

If I'm guessing right, the email being bounced is coming back as an attachment. If so, post it here as an attachment and I'll take a look at it.

Link to comment
Share on other sites

Here's one, Greasey - THANKS!!!!!

From: postmaster@dte2k.de Add to Address Book Add Mobile Alert

To: xdbo@hallmatsonlaw.com

Date: Wed, 3 Jan 2007 12:49:23 +0100

Subject: Delivery Status Notification (Failure)

This is an automatically generated Delivery Status Notification.

Delivery to the following recipients failed.

tgbyvfepampntuc@poseidon-kiel.com

Message/delivery-status

Reporting-MTA: dns;mailc0915.dte2k.de

Received-From-MTA: dns;p508976A6.dip.t-dialin.net

Arrival-Date: Wed, 3 Jan 2007 12:49:20 +0100

Final-Recipient: rfc822;tgbyvfepampntuc@poseidon-kiel.com

Action: failed

Status: 5.1.1

Forwarded Message [ Download File | Save to Yahoo! Briefcase ]

Date: Wed, 3 Jan 2007 12:50:18 +0100

From: "Olive" <xdbo@hallmatsonlaw.com>

To: tgbyvfepampntuc@poseidon-kiel.com

Subject: The doctor can sew the meniscus back in place if the patient is relatively young, the injury is in an area with a good blood supply, and the ligaments are intact.

HTML Attachment [ Scan and Save to Computer | Save to Yahoo! Briefcase ]

However, since these medications seldom completely banish attacks an acute treatment should be close to hand to treat those attacks that still occur. What is fibromyalgia? Mass outbreaks of the disease are rare. Research suggests relaxation techniques, to help with stress, may be useful for some people in managing their blood pressure.

Most operations takes less than one hour, and can be done using keyhole surgery techniques.

Are they any long term problems? Other less common causes of dysmenorrhoea are previous pelvic surgery and a pelvic infection.

Therefore, light rays fall in short of the retina - the area at the back of the eye that interprets the image - and results in blurred distance vision. They are also frequently are unable to work because of their disability. This is especially true as you get older, as blood pressure goes up with age. If there is an underlying disease causing the dysmenorrhoea then this should be treated.

Most babies will not be harmed if their mother is infected, but GBS can cause early birth, stillbirth, late miscarriage and complications. If liver damage is severe, then a transplant may be the only option. This occurs when fluid in the eye cannot drain properly.

Can transmission be prevented? Though the infection is generally acquired early in childhood, the disease may take years to manifest itself. What is fibromyalgia?

There have also been cases of fertilised eggs being mixed up in the laboratory and the wrong embryo being implanted in the woman, leading to fears about how the process is carried out. Certain cancers can also develop and damage the skin, brain and nervous system.

The viruses are never the same each year, but normally the surface proteins undergo slight changes.

The doctor can sew the meniscus back in place if the patient is relatively young, the injury is in an area with a good blood supply, and the ligaments are intact.

Some people are said to be short-sighted or myopic. It can also be passed on through sexual contact, as the virus can be present in bodily fluids such as semen.

There is no specific treatment for infectious mononucleosis, other than treating the symptoms. When there is no underlying cause, simple analgesia with a non-steroidal anti-inflammatory drug such as ibuprofen might be all that is needed. The increase in cases is due to a number of factors:the disease is becoming resistant to traditional treatments. Many anti-histamine tablets are available over the counter in chemists. All adults should have their blood pressure checked at least once every five years, but preferably more often. Smoking is not a direct risk factor for high blood pressure, but it does increase the chance of heart attack, heart failure and stroke.

However, as the test is looking for signs that the body's immune system is trying to fight the virus, it may not be positive for a few months after infection.

Septicaemia is the blood poisoning form of the disease. Of those that survive GBS meningitis, up to a third are left with long-term mental and physical problems. Broadly, there are two types of bacterial disease: meningococcal and pneumococal.

Physical injury to the penis, spinal cord, prostate, bladder or pelvis can also be a factor. Many people are offered drugs normally used to treat depression.

and here's another one that looks different:

Date: Wed, 3 Jan 2007 20:59:50 +0800

From: "Mail Delivery Subsystem" <MAILER-DAEMON@singnet.com.sg> Add to Address Book Add Mobile Alert

To: veg@hallmatsonlaw.com

Subject: Returned mail: see transcript for details

The original message was received at Wed, 3 Jan 2007 20:48:07 +0800

from mx11.singnet.com.sg [165.21.74.121]

----- The following addresses had permanent fatal errors -----

<suki1118@pop3.singnet.com.sg>

(reason: 550 5.1.1 User unknown)

----- Transcript of session follows -----

550 5.1.1 <suki1118@pop3.singnet.com.sg>... User unknown

Message/delivery-status

Reporting-MTA: dns; carbon.singnet.com.sg

Arrival-Date: Wed, 3 Jan 2007 20:48:07 +0800

Final-Recipient: RFC822; suki1118@pop3.singnet.com.sg

X-Actual-Recipient: RFC822; suki1118@carbon.singnet.com.sg

Action: failed

Status: 5.1.1

Diagnostic-Code: X-Unix; 550 5.1.1 User unknown

Last-Attempt-Date: Wed, 3 Jan 2007 20:59:50 +0800

Forwarded Message

From: "Boggs X. Viola" <veg@hallmatsonlaw.com>

To: suki1118@singnet.com

Subject: straddle

Date: Wed, 3 Jan 2007 13:47:21 +0100

Link to comment
Share on other sites

Those only have the envelope information. You want the full header, which will include the routing lines.

Looks like:

Received From: mailserver(4.4.4.4) by anotherserver(5.5.5.5) on Mon 1/2/2007

Although, is p508976A6.dip.t-dialin.net your business ISP?

Link to comment
Share on other sites

greasy I am trying to, I changed my preferences to show the header, but every time I try to post it here it won't let me - I keep getting an error message that says

The resource is not available

And no, that isn't or ISP

Edited by Abigail
Link to comment
Share on other sites

Wasn't aware you were using Yahoo.

So your address was the catch-all for your work's domain? You must have been flooded with spam.

Most sites don't use catch-all email addresses anymore. They used to make sense before spam came along, now they are only spam collectors and take up disk space. Normally it's best to not have a catch-all email address. Without one, spam addressed to invalid addresses gets refused. Legitimate mail addressed to an invalid address gets bounced back and the sender knows they sent it to the wrong address. If no one is monitoring the catch-all account, legitimate mail with typos in the address get sent there and the sender thinks it was delivered, when in fact it goes to a black hole.

Link to comment
Share on other sites

I wasn't getting any spam until just the past few days. Beyond that, I can't comment because this is a new area of learning for me. Naturally none of the adults had anything to do with setting up the domain name or email accounts - a teenager did that for us :biglaugh:

I can access the dummy account and check it once a day, that's no big deal. Mostly I am just relieved to know that I am bug/worm free and that no one is somehow getting my password.

Link to comment
Share on other sites

Abi, are you getting web mail (checking your email online) or are you using a separate email program (like Outlook Express)? If you're getting your email online, do you run the 'check for viruses' before you open the mail? If so, you ought to be fine.

I have ATT/Yahoo for my ISP and I'm pretty satisfied with their security for email. The rest of their stuff...well...it's all we've got for DSL in our area...so I won't complain...yet. :)

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...