I got an e-mail from my Mom the other day that had nothing in it except this link:
http://hassie.fantasticdownloadzone.com/
The next day I got another from her for a different site:
http://www.bwb7.womanhealth-c.com/
I called her up and sure enough her laptop is sending out spam e-mails every night to everyone in her address book.
Now she's using and sbcglobal.net account she accesses through her Internet Explorer. Looking through by hand nothing looked really out of place, ESET nod32 said there was nothing, Malware found a couple of little things.
I have no clue what's going on.
I found an e-mail that was rejected by someone with the path and everything, but since I don't understand such things well I thought I'd put 'em up here so someone could explain to me how I'm missing the obvious.
Any and all help/input is appreciated, thank you.
http://hassie.fantasticdownloadzone.com/
The next day I got another from her for a different site:
http://www.bwb7.womanhealth-c.com/
I called her up and sure enough her laptop is sending out spam e-mails every night to everyone in her address book.
Now she's using and sbcglobal.net account she accesses through her Internet Explorer. Looking through by hand nothing looked really out of place, ESET nod32 said there was nothing, Malware found a couple of little things.
I have no clue what's going on.
I found an e-mail that was rejected by someone with the path and everything, but since I don't understand such things well I thought I'd put 'em up here so someone could explain to me how I'm missing the obvious.
Only thing I changed was her name and e-dress.For your convenience, the message is question is reproduced below:
Return-Path: <Mom@sbcglobal.net>
Received: from lists.n-email.net ([172.16.100.75]) by 172.16.2.5 with SMTP (Email Administrator WIN32 version 9.3e); Wed, 16 Jun 2010 12:16:52 -0400
Return-Path: <Mom@sbcglobal.net>
Received: from [76.96.27.212] ([76.96.27.212:40109] helo=qmta14.emeryville.ca.mail.comcast.net)
by ecelerity (envelope-from <Mom@sbcglobal.net>)
(ecelerity 3.0.22.36141 r(36141)) with ESMTP
id 4C/5C-31854-4F8F81C4; Wed, 16 Jun 2010 12:16:52 -0400
Received: from omta19.emeryville.ca.mail.comcast.net ([76.96.30.76])
by qmta14.emeryville.ca.mail.comcast.net with comcast
id WfKa1e0031eYJf8AEgGrqd; Wed, 16 Jun 2010 16:16:51 +0000
Received: from eandmlaw.com ([76.29.4.194])
by omta19.emeryville.ca.mail.comcast.net with comcast
id WgGq1e0044B9gRo01gGq7J; Wed, 16 Jun 2010 16:16:51 +0000
Received: from mail pickup service by eandmlaw.com with Microsoft SMTPSVC;
Wed, 16 Jun 2010 12:12:19 -0400
Received: from mail pickup service by eandmlaw.com with Microsoft SMTPSVC; Wed, 16 Jun 2010 10:15:31 -0400
thread-index: AcsNXmCdQkRqqftuQHexafRew++jAA==
Cc:
X-Spam-Checker-Version: SpamAssassin 3.1.6 (2006-10-03) on psg1367.lexis-nexis.com
X-Spam-Level:
X-Spam-Status: No, score=0.0 required=4.2 tests=HTML_MESSAGE autolearn=disabled version=3.1.6
X-Spam-Report: * 0.0 HTML_MESSAGE BODY: HTML included in message
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sbcglobal.net; s=s1024; t=1276696938; bh=vXSYEVfulzrYk56CAJ/ytaJ90onH44pEd59itmTBo5M=; h=Message-ID:X-YMail-OSG:Received:X-Mailerate:From:Subject:To:MIME-Version:Content-Type; b=rPEi/5fjYax0hZsu4kKd+9ITaScBOMmVYstwPaKZfGA8u87NBf5hKJs5ffbFVIRbqqx4iLx1/lU0XABkwm1G9LyWYZ7Wkk/qodw6wn7VfL8/miz27ZaOrPKe4Luomccmd7xBdc4vXl+nU2NS4FXW56Dxdh8nmdAiYZw9Ytx82W8=
Message-ID: <4858B29170C040B981139E4DA3F9FB93@em.local>
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=s1024; d=sbcglobal.net; h=Message-ID:X-YMail-OSG:Received:X-Mailerate:From:Subject:To:MIME-Version:Content-Type; b=Tt5lZo1vaAjdrBSbujQm3NB1Ciu5yipzjN2Hjq7iNYko5ZKpCDYjUmIZdKeU/K00n+/60+D0hhH0b602sLJdRuH1osnWUXsDZFYoRCuMoHSudaXmb8I2Cs6CUu6a8Ua1JERPsTtzuR37d5aYF2dbEfFCfCXIoewq93Om7/smfCc=;
Content-Transfer-Encoding: 7bit
X-YMail-OSG: Yv3HJAIVM1nk9xXK885XSzVz3u9wAmGNK0rTSyRlPAMYYOB jYqaf9PxvR7GRX6WgHsB5G52_R1Ap5tFLc228Au0BEL3OitbmUeUbMk7r2js fBF9SzPrUgt9w.jn9_TMdjMlpPP7nwyB6JrrXIjJOgVzSLy2MVWUIKewXD8z A7DfiTIcDiexvR8sROSWmXH8UUjjhoNOadMJpuUmUmsYCQDjZqd3zI45lKw5 RVfTPvUrea8eA.bFBpd1GFNJsqzvBSxIwQ6.X1eH76gZ2Oona5LwDb5QAlOF GM4sxFaKVu4C.DYEZEQ--
X-Mailer: YahooMailRC/397.8 YahooMailWebService/0.8.103.269680
Date: Wed, 16 Jun 2010 10:15:30 -0400
From: "Mom" <Mom@sbcglobal.net>
Subject: Seeking Pinellas County, Fla lawyer referral
To: "Probate, Trust & Real Property Section" <inbar-ptrp@lists.n-email.net>
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="0-1121976119-1276696938=:96991"
List-Unsubscribe: <mailto:leave-12701819-105805452.5426972cc173803773a272e355f82647@lists.n-email.net>
Content-Class: urn:content-classes:message
Importance: normal
Priority: normal
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.4657
Reply-To: "Mom" <mom@sbcglobal.net>
X-Binding: in-state-bar-assoc
X-Antivirus: Scanned by F-Prot Antivirus (http://www.f-prot.com)
X-OriginalArrivalTime: 16 Jun 2010 14:15:31.0140 (UTC) FILETIME=[60BEE040:01CB0D5E]
This is a multi-part message in MIME format.
--0-1121976119-1276696938=:96991
Content-Type: text/plain;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
Any and all help/input is appreciated, thank you.