0
   

Rush of returned "Undeliverable Mail" I never sent - virus?

 
 
dlowan
 
Reply Thu 1 Sep, 2005 05:42 am
Well, that says it - suddenly, over the last few days, a steadily increrasing rush of "Undeliverable" emails appearing in my inbox.

That I never sent, to places not in my address book.


My Norton is up to date, and I just scanned - nothing.


I am wondering if a virus is sending emails without my knowledge, or if the emails are themselves an attempt to infect?


Some of them appear to relate to onlime pharmacy stuff, some not. A couple of examples:


Your message

To: Djensen
Subject: Doctor
Sent: Thu, 1 Sep 2005 21:04:38 +1000

did not reach the following recipient(s):

[email protected] on Thu, 1 Sep 2005 21:04:49 +1000
The recipient name is not recognized
The MTS-ID of the original message is: c=US;a=
;p=HNL;l=HNLSYD90509011104QQAJTC5G
MSEXCH:IMS:HNL:HNLSYD:HNLSYD9 0 (000C05A6) Unknown Recipient






Bad address -- <daponte>
Error -- No such local user

Start of returned message

Received: from asclepius.uwa.edu.au ([130.95.128.60]) by admin2.acs.uwa.edu.au
with ESMTP for [email protected]; Thu, 1 Sep 2005 13:43:15 +0800
Received: from asclepius.kas (localhost.localdomain [127.0.0.1])
by asclepius.uwa.edu.au (Postfix) with SMTP id 9842E18352A
for <[email protected]>; Thu, 1 Sep 2005 13:43:15 +0800 (WST)
Received: from asclepius (localhost.localdomain [127.0.0.1])
by asclepius.prekas (Postfix) with SMTP id 8B3A418344C
for <[email protected]>; Thu, 1 Sep 2005 13:43:15 +0800 (WST)
X-UWA-Client-IP: 222.140.158.192 (EXTERNAL)
Received-SPF: none (asclepius: domain of dlowan@xxxxxxxxxxxxx does not designate permitted sender hosts)
Received: from notimexico.com (unknown [222.140.158.192])
by asclepius.input (Postfix) with ESMTP id B3E1818353C
for <[email protected]>; Thu, 1 Sep 2005 13:43:11 +0800 (WST)
Date: Thu, 01 Sep 2005 01:43:26 -0400
From: "Forgery M. Veda" <dlowan@xxxxxxxxxxxxxx>
X-Mailer: The Bat! (v2.00.5) Personal
X-Priority: 3
Message-ID: <5784988019.20050901014326@xxxxxxxxxx>
To: Daponte <[email protected]>
Subject: Doctor
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="----------AC2D481BC106D53"
X-Virus-Scanned: Norton
X-SpamTest-Version: SMTP-Filter Version 2.0.0 [0125], KAS/Release
X-Spamtest-Info: No License

This is a multi-part message in MIME format.

------------AC2D481BC106D53
Content-Type: multipart/related;
type="multipart/alternative";
boundary="----------218EFEBEA9D8C03"

------------218EFEBEA9D8C03
Content-Type: multipart/alternative;
boundary="----------8A0B7438FF90565"

------------8A0B7438FF90565
Content-Type: text/plain
Content-Transfer-Encoding: 7bit

Vlalgra $3.3
Leviltra $3.3
Ciaulis $3.7
Imiturex $16.4
Flompax $2.2
Ultriam $0.78
Viopxx $4.75
Ambcien $2.2
Valpium $0.97
Xanabx $1.09
Sobma $3
Meritdia $2.2



our site
http:///HealthSuite.htm

___
Best regards,
Online Pharmaceuticals
------------8A0B7438FF90565
Content-Type: text/html
Content-Transfer-Encoding: 7bit

<html>
<body>
<strong>Vlaogra</strong> - $3.3
<br>
<strong>Leviqtra</strong> - $3.3<br>
<strong>Ciaglis</strong> - $3.7<br>
<strong>Imitirex</strong> - $16.4<br>
<strong>Flombax</strong> - $2.2<br>
<strong>Ultrjam</strong> - $0.78<br>
<strong>Vioaxx</strong> - $4.75
<br>
<strong>Ambkien</strong> - $2.2<br>
<strong>Valuium</strong> - $0.97
<br>
<strong>Xanaix</strong> - $1.09<br>
<strong>Soxma</strong> - $3
<br>
<strong>Merijdia</strong> - $2.2<br>
<br>
<a href="http:///HealthSuite.htm"><strong>our website</strong></a><br>
<br>
___
<br>
Best regards,<br>
Online Pharmaceuticals
</body>
</html>
------------8A0B7438FF90565--

------------218EFEBEA9D8C03
Content-Type: text/plain; name="domain.txt"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="domain.txt"

d3d3LmNvbHVtYmlhN21lbW9yaWFsLmNvbQ0Kd3d3LnRoZXdlc3RmYW1pbHkuY2MNCnd3dy5n
dWl0YXJ6b25lcHIuY29tDQpEb3RTaWducy5uZXQNCnd3dy5xbGFuZHNjYXBlc2VydmljZXMu
Y29tDQp3d3cuZHJzLXdldHplbHMubmwNCnd3dy51aXRkaWRhbS5ubA0KYWx1bWFpci5jb20u
YXINCmF4b3IuY29tLmFyDQpkZWNvc2hvcGhvc2dlbC5ubA0KZXhlcmNpc2UuZ3INCmhlYXZ5
eW9nYS53ZWIuYXBsdXMubmV0DQppdC10bHAuY29tDQphcnRzYW5kaGVyaXRhZ2UudXMNCmFu
aW1lbmF2aWdhdG9yLm5ldA0KY2xhcmtzdmlsbGVhcnRpc3RzLm9yZw0KdGhldmFsZW5jaWFm
YW1pbHkuY29tDQpnYWhhbm5hcGFjazc3Ni5vcmcNCmZpbmVncmFwaGljcy5uZXQNCnNlYW5k
ZXZpbmUuY29tDQphaWNkYy5jb20NCm1pbmVydmFwZW5kcmFnb24uY29tDQplZC1lZmZlY3Qu
Y29tDQpuZXN0bGluZ3ouY29tDQpzYXZwZXJ1LmNvbQ0KZmluZHlvdXJiZWF1dHkuY29tDQpq
ZWZma2VzbGVyLm5ldA0Kc2FicmVpdC5uZXQNCnByZXNjcmlwdGlvbi1kcnVncy1zZWFyY2gu
dXMNCmhvcnNlbWVkZXhwcmVzcy5jb20NCnJhbnNvbmZ1ZWwuY29tDQpnb2xkZW5wcm9taXNl
aW50LmNvbQ0KY2Fyb2xpbmFjbHVicG9hLm9yZw0Kc25vd2JpcmR4LmNvbQ0KYmx1ZWNhbGYu
Y29tDQpyZW56em8uY29tDQpsb2NvLmtvcm4tYm9hcmQuZGUNCnNjaG5hdXplcnJhc3NlLmlu
Zm8NCmtyYXRlay5kZQ0KdGhld2VzdGVybnVuaW9uYmFuZC5jb20NCmxhdHJva2EuY29tDQpv
dXRsYXdieW5hdHVyZS5jb20=

------------218EFEBEA9D8C03--

------------AC2D481BC106D53--




End of returned message.



****** Message from InterScan Messaging Security Suite ******


Sent <<< RCPT TO:<[email protected]>
Received >>> 550 <[email protected]>: recipient address rejected: user unknown in local recipient table

Unable to deliver message to <[email protected]>.

************************ End of message **********************










I am deleting and blocking - ought I to do something more intelligent? Am I infecting the world?


(Er - and ought I to delete the email addies I have copyied and pasted here - cos they may lead some poor person into trouble, or are spam??)
  • Topic Stats
  • Top Replies
  • Link to this Topic
Type: Discussion • Score: 0 • Views: 1,780 • Replies: 10
No top replies

 
Intrepid
 
  1  
Reply Thu 1 Sep, 2005 06:05 am
Seems to be a trojan. Perhaps This Norton link can shed some light on it for you.

Good luck
0 Replies
 
dlowan
 
  1  
Reply Thu 1 Sep, 2005 06:40 am
Hmmm - downloading upgrade to 2005 Norton - grrr.......we shall see....
0 Replies
 
the prince
 
  1  
Reply Thu 1 Sep, 2005 06:52 am
Have you been sending nudes of yrself ???? Shocked
0 Replies
 
timberlandko
 
  1  
Reply Thu 1 Sep, 2005 06:53 am
Its highly likely - to the point of almost certain probability - the problem is not with your machine, but rather that someone who's machine has been infected by a spambot has your email address in its address book. Spambots typically harvest the address books of infected machines for legitimate email addresses which they use to "Spoof", or forge, headers, making it more difficult to track down the ultimate source of the spam. If your system is properly updated and configured, and a properly updated, configured, and deployed major-name antivirus shows no infection, odds are you aren't infected. Just to help you feel better, Bunny, several of my "General Purpose" mailboxes get many, many such "Bounces" every day - and, for reasons of which you're probably aware, I'm more than merely confident my own machines are "Clean" :wink:

For further peace of mind, you might want to try third-party opinions by running one or more of these free online scans:

Trend Micro Free Online Scan

Panda Free Online Scan

BitDefender Free Online Scan

Symantec Free Online Scan

Kaspersky Free Online Scan

StopSign Free Online Scan

RAV Free Online Scan

McAfee Free Online Scan


When running any online virus scan, disable your own resident real-time security/privacy software, such as antivirus, antispyware, popup blockers, and/or ad blockers, before initiating the online scan. And, of course, remember to re-enable your privacy/security software before going back out there on the 'net.


Edit to add an important afterthought; always just delete the "Bounces" immediately on receipt, and never, under any circumstance, open any attachment accompanying a "Bounce"
0 Replies
 
dlowan
 
  1  
Reply Thu 1 Sep, 2005 07:06 am
Thanks, Timber - I will do that when i ahve updated and re-scanned.



and NO I HAVEN'T BEEN SENDING NUDE PICTURES, Gautam!
0 Replies
 
timberlandko
 
  1  
Reply Thu 1 Sep, 2005 07:16 am
dlowan wrote:
... and NO I HAVEN'T BEEN SENDING NUDE PICTURES ...


Well, when you do get around to doing that, you have my email address Twisted Evil
0 Replies
 
flyboy804
 
  1  
Reply Thu 1 Sep, 2005 07:16 am
bookmark
0 Replies
 
dlowan
 
  1  
Reply Thu 1 Sep, 2005 07:31 am
timberlandko wrote:
Its highly likely - to the point of almost certain probability - the problem is not with your machine, but rather that someone who's machine has been infected by a spambot has your email address in its address book. Spambots typically harvest the address books of infected machines for legitimate email addresses which they use to "Spoof", or forge, headers, making it more difficult to track down the ultimate source of the spam. If your system is properly updated and configured, and a properly updated, configured, and deployed major-name antivirus shows no infection, odds are you aren't infected. Just to help you feel better, Bunny, several of my "General Purpose" mailboxes get many, many such "Bounces" every day - and, for reasons of which you're probably aware, I'm more than merely confident my own machines are "Clean" :wink:

For further peace of mind, you might want to try third-party opinions by running one or more of these free online scans:

Trend Micro Free Online Scan

Panda Free Online Scan

BitDefender Free Online Scan

Symantec Free Online Scan

Kaspersky Free Online Scan

StopSign Free Online Scan

RAV Free Online Scan

McAfee Free Online Scan


When running any online virus scan, disable your own resident real-time security/privacy software, such as antivirus, antispyware, popup blockers, and/or ad blockers, before initiating the online scan. And, of course, remember to re-enable your privacy/security software before going back out there on the 'net.


Edit to add an important afterthought; always just delete the "Bounces" immediately on receipt, and never, under any circumstance, open any attachment accompanying a "Bounce"




Oh - I SO don't.

Bin double deleting, and blocking....
0 Replies
 
the prince
 
  1  
Reply Thu 1 Sep, 2005 07:32 am
timberlandko wrote:
dlowan wrote:
... and NO I HAVEN'T BEEN SENDING NUDE PICTURES ...


Well, when you do get around to doing that, you have my email address Twisted Evil


And you can send the ones for me to my neighbour....
0 Replies
 
Mr Stillwater
 
  1  
Reply Fri 2 Sep, 2005 01:18 am
KILL THE SPAM-BUNNY!!
0 Replies
 
 

Related Topics

Clone of Micosoft Office - Question by Advocate
Do You Turn Off Your Computer at Night? - Discussion by Phoenix32890
The "Death" of the Computer Mouse - Discussion by Phoenix32890
Windows 10... - Discussion by Region Philbis
Surface Pro 3: What do you think? - Question by neologist
Windows 8 tips thread - Discussion by Wilso
GOOGLE CHROME - Question by Setanta
.Net and Firefox... - Discussion by gungasnake
Hacking a computer and remote access - Discussion by trying2learn
 
  1. Forums
  2. » Rush of returned "Undeliverable Mail" I never sent - virus?
Copyright © 2024 MadLab, LLC :: Terms of Service :: Privacy Policy :: Page generated in 0.04 seconds on 05/02/2024 at 11:33:53