Forum Home
Press F1
 
Thread ID: 38604 2003-10-12 07:43:00 Spammer are using my email address najopito (596) Press F1
Post ID Timestamp Content User
182564 2003-10-12 07:43:00 I have a website with email accounts. I am getting [b]Returned mail: User unknown[\b] for email accounts that don't exist at the site. Help! najopito (596)
182565 2003-10-12 07:54:00 can we have more details?

are u saying that ppl try email u and it gets sent back to them as "no such addresS"
csinclair83 (200)
182566 2003-10-12 08:00:00 Many viruses and trojans harvest e-mail addresses from infected computers.

They use one address taken at random, and spoof the e-mail to look like it was sent from that domain, when in reality it came from someone else that just happened to have your e-mail address domain in their address book.

Presumably your e-mail server is secure from relaying?
godfather (25)
182567 2003-10-12 08:01:00 10 to 1 you've got the Swen virus.

Get this (www.norman.com)

And then download a virus scanner and check your machine.
whiskeytangofoxtrot (438)
182568 2003-10-12 08:04:00 Ok . I got 2 email like this . I remove the email address "Noe Scott" <jkofod@XXXXX . com>I the person hijacked the address . MY site is not XXXXX . com btw I removed the address

The original message was received at Sat, 11 Oct 2003 19:15:15 -0400 (EDT)
from cbl199-203-52-159 . bb . netvision . net . il [199 . 203 . 52 . 159]


*** ATTENTION ***

Your e-mail is being returned to you because there was a problem with its
delivery . The address which was undeliverable is listed in the section
labeled: "----- The following addresses had permanent fatal errors -----" .

The reason your mail is being returned to you is listed in the section
labeled: "----- Transcript of Session Follows -----" .

The line beginning with "<<<" describes the specific reason your e-mail could
not be delivered . The next line contains a second error message which is a
general translation for other e-mail servers .

Please direct further questions regarding this message to your e-mail
administrator .

--AOL Postmaster



----- The following addresses had permanent fatal errors -----

----- Transcript of session follows -----
. . . while talking to air-xi03 . mail . aol . com . :
>>> RCPT To:<kwreilly@aol . com>
<<< 550 MAILBOX NOT FOUND
550 <@aol . com> . . . User unknown



--------------------------------------------------------------------------------


Received: from CBL199-203-52-159 . bb . netvision . net . il (cbl199-203-52-159 . bb . netvision . net . il [199 . 203 . 52 . 159]) by rly-xi01 . mx . aol . com (v96 . 8) with ESMTP id MAILRELAYINXI13-4bd3f888ef43c; Sat, 11 Oct 2003 19:15:10 -0400
Message-ID: <j947-et7x1365kg596$kxpbg69d@q9j . 95av . 2x>
From: "Noe Scott" <jkofod@ . com>
Reply-To: "Noe Scott" <jkofod@ . com>
To: chrys135@aol . com
Cc: <@aol . com>, <@aol . com>, <@aol . com>,
<@aol . com>
Subject: monrerey brtuminous
Date: Sat, 11 Oct 2003 19:35:42 -0300
X-Mailer: MIME-tools 5 . 503 (Entity 5 . 501)
MIME-Version: 1 . 0
Content-Type: multipart/alternative;
boundary="0FAB_15D . C3D_905_"
X-Priority: 3
X-AOL-IP: 199 . 203 . 52 . 159
X-AOL-SCOLL-SCORE: 0:XXX:XX
X-AOL-SCOLL-URL_COUNT: 0
najopito (596)
182569 2003-10-12 08:11:00 I am using ZoneAlarm and Nortons . Norton just updated a few days ago and ran a full scan on Friday .

Email orginated at http://home . netvision . net . il/
najopito (596)
182570 2003-10-12 08:18:00 Possibly not. I know my mates OE address book was highjacked with my address in in and I get these
no swen here at all...........
mark.p (383)
182571 2003-10-12 08:21:00 Forgot to add I just use Mozilla to filter the crap out. mark.p (383)
182572 2003-10-12 08:26:00 With email I us Mail Washer version 1.33 and bounce loads of spam each day. I don't use secure authentication for that or when I download ones thought Outlook Express.

I will run Norton overnight. Disconected the computer from the net first.
najopito (596)
182573 2003-10-12 10:06:00 > 10 to 1 you've got the Swen virus .
I agree, I have had this email and it had a attachment with it guess what Swen . A . Swen hides itself in many ways, this is one way .

My advice update your anti virus, then run a full scan .


I think Symantic has a swen removal tool on their site .

My version came quix . com a american ISP . I was unable to identify the sender just the ISP . (I just love header information) .

BTW Swen I think disables most well known security measurers so if your firewall is not working . . . . . . . . . . need I say more (scan your machine)
beama (111)
1 2