Gamecommunity =GCHQ=
http://82.148.227.125:8080/

Infected PC?
http://82.148.227.125:8080/viewtopic.php?f=6&t=43680
Page 1 of 1

Author:  Tao [ Wed Jul 11, 2007 10:04 am ]
Post subject:  Infected PC?

Ok the computer at work is acting strange.

Whwnever outlook is opened up there is a load of returned undeliverable emails, if you look at who the email is from its from the senders name is made up off the first name of the user of that pc, (although the normal mailing address for the company is just mail@....) plus a string of random letters.

The actual content of the emails that are being returned are for Viagra, which I am pretty sure we arent selling.

I have scanned the PC with AVG, and also ran adaware, and spybot, none of them are showing up anything looks has the computer been infected wth something to make it act like a zombie.

Any advice?

Author:  SO19Firearms=GCHQ= [ Wed Jul 11, 2007 10:18 am ]
Post subject: 

Are they actually returned mails? Or just "labelled"?

Author:  Tao [ Wed Jul 11, 2007 11:01 am ]
Post subject: 

How do you tell the difference between it being returned and just labelled as returned? It looks like its returned but I am not sure for defiite.

You get an email in your outlook inbox that says.


Quote:
Undeliverable: Still not the one


The bit after the colon changes is differewnt each time, typical spam fake headings though like, Did you get this?..etc.

A bunch of attachmenst for a returned message. details.txt, the message itself, and a AVG email cert.

Then the 'returned? email text'

Quote:
Your message

To: Dell Ford
Cc: Janna; Marylee Jacobs; Kristie; Alejandro; Celine Garza;
Tawanna Cox; Sigrid Ramos; Tran Harvey
Subject: Still not the one
Sent: Wed, 11 Jul 2007 04:20:11 +0100

did not reach the following recipient(s):

fox6662@mailbox1.euphonynet.be on Wed, 11 Jul 2007 04:24:03 +0100
The e-mail system was unable to deliver the message, but did not report a specific reason. Check the address and try again. If it still fails, contact your system administrator.
< bishop.besite.be #5.0.0 X-Postfix; permission denied. Command
output: User quota exceeded. Mailbox vol. Boite postal est plein.>



Random names, none that are from our addrress book that I can see, although we are getting a good 20 odd of these messages each day.[/quote]

Author:  Apocalypse [ Wed Jul 11, 2007 11:32 am ]
Post subject: 

are they in your inbox or your sentbox?

if they're in your inbox then it's probably just a spambot that got hold of your addy....if they're in your sentbox.....then i'd say something is up :shock:

Author:  Tao [ Wed Jul 11, 2007 11:56 am ]
Post subject: 

Doh should have checked that. Nothing in Sent box and all the mails coming d from one domain by the looks of it, guess where just being targeted, bedding company, viagra spam mebbe they want to strike up a partnership, must be those waterproof duvets.

Author:  Apocalypse [ Wed Jul 11, 2007 12:10 pm ]
Post subject: 

ya must be :lol:
get an admin on the system to block the sender(maybe you can do it yourself), or get a spam filter,
then see if you keep getting them :)

Author:  Tao [ Wed Jul 11, 2007 12:37 pm ]
Post subject: 

Anyone recommend a good free spam filter. I'll block the emails currently the office network consist of one computer with a BT USB ADSL modem, so its not exactly sophisticated. :D

Author:  GeneralPublic=GCHQ= [ Wed Jul 11, 2007 12:39 pm ]
Post subject: 

or some kind soul is spamming the world, and using your email address.... :evil:


We've had it here a few times, theres not much you can do about it.


Try this for removing spam - it's the best one I've found that runs on the client itself.

Author:  Tao [ Wed Jul 11, 2007 3:04 pm ]
Post subject: 

GeneralPublic=GCHQ= wrote:
or some kind soul is spamming the world, and using your email address.... :evil:


That was my worry, I've set up a rule to block the domain, but I thought he.local was something to do with the actual pc, rather than a domain name hence the worry. Panda found something, downloader.jou on the PC, but AVG didnt find anything so I am going to watch it for a few days.


GeneralPublic=GCHQ= wrote:
Try this for removing spam - it's the best one I've found that runs on the client itself.


I'll give that one a shot.

Thanks all. :D

Author:  Apocalypse [ Thu Jul 12, 2007 2:49 pm ]
Post subject: 

it's a trojan

Author:  Tao [ Thu Jul 12, 2007 3:02 pm ]
Post subject: 

Not suprised the person who worked there before used to go on all sorts of crappys ringtone sites and stuff like that. :roll:

Page 1 of 1 All times are UTC [ DST ]
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group
http://www.phpbb.com/