PC Review


Reply
Thread Tools Rate Thread

Strategies For Locating Malware?

 
 
(PeteCresswell)
Guest
Posts: n/a
 
      7th May 2012
Emails are being sent from a friend's AOL account with her
address in From: and always eight address in "To:" (at least in
the ones I've seen).

I'm running MalwareBytes and McAfee's scans on the PC now. Dunno
about a boot-time scan yet, since I can't be there physically.

When I spot-check the nine spams I have on hand, most of the
"TO:" addresses can be found in the person's AOL address book.
The few that cannot look like they might be "From:" addresses in
emails that she has received (e.g.
(E-Mail Removed))

I just edited her AOL address book and changed my own address to
one that I will receive - but know it could have come from only
one place.


But what now?

Suppose I start getting spammed at the new address?

Would that strongly suggest that the culprit is running on her
PC? Or could the AOL address book be in the cloud?

Does anybody have any suggestions for finding this thing and
driving a stake through it's heart?
--
Pete Cresswell
 
Reply With Quote
 
 
 
 
Shadow
Guest
Posts: n/a
 
      7th May 2012
On Sun, 06 May 2012 21:51:04 -0400, "(PeteCresswell)" <(E-Mail Removed)>
wrote:

>Emails are being sent from a friend's AOL account with her
>address in From: and always eight address in "To:" (at least in
>the ones I've seen).
>
>I'm running MalwareBytes and McAfee's scans on the PC now. Dunno
>about a boot-time scan yet, since I can't be there physically.
>
>When I spot-check the nine spams I have on hand, most of the
>"TO:" addresses can be found in the person's AOL address book.
>The few that cannot look like they might be "From:" addresses in
>emails that she has received (e.g.
>(E-Mail Removed))
>
>I just edited her AOL address book and changed my own address to
>one that I will receive - but know it could have come from only
>one place.
>
>
>But what now?
>
>Suppose I start getting spammed at the new address?
>
>Would that strongly suggest that the culprit is running on her
>PC? Or could the AOL address book be in the cloud?
>
>Does anybody have any suggestions for finding this thing and
>driving a stake through it's heart?


Probably won't have to go that far unless it's a vampire.
Li'll old trick I learnt, works for goo...gle aagghhh, and
probably others.

Send yourself a letter addressed to

PeteCresswell+(E-Mail Removed)

Don't forget the "+" between your username and the random
letters.

see if you receive it, look at the headers.

Get the idea ?

[]'s



--
Don't be evil - Google 2004
We have a new policy - Google 2012
 
Reply With Quote
 
 
 
 
(PeteCresswell)
Guest
Posts: n/a
 
      7th May 2012
Per Shadow:
>Send yourself a letter addressed to
>
> PeteCresswell+(E-Mail Removed)
>
> Don't forget the "+" between your username and the random
>letters.
>
> see if you receive it, look at the headers.
>
> Get the idea ?


That one whizzed right over my head.

I tried sending an email to (E-Mail Removed) and
AOL's address check popped a dialog saying that "XYZ" was
suspicious.

I overrode the warning and told it to just send the message.

Then another dialog popped saying the message was not sent and I
should go to a "Challenge" page.

But when it tried to open the challenge page
(http://challenge.aol.com/en/us/spam.html) it threw "570 User
Identification Failed".

What would have been the implication of it had gone through and
appeared in my inbox? FWIW, I have a GoldList that would have
weeded out that "To:" address - or would I be looking for
somebody extracting my fake-but-deliverable address from the AOL
address book?
--
Pete Cresswell
 
Reply With Quote
 
Beauregard T. Shagnasty
Guest
Posts: n/a
 
      7th May 2012
(PeteCresswell) wrote:

> Per Shadow:
>> PeteCresswell+(E-Mail Removed)
>>
>> Don't forget the "+" between your username and the random
>> letters.

>
> That one whizzed right over my head.
>
> I tried sending an email to (E-Mail Removed) and AOL's
> address check popped a dialog saying that "XYZ" was suspicious.


I do not see the plus sign (+) in your test address.

--
-bts
-One must not skip steps.
 
Reply With Quote
 
(PeteCresswell)
Guest
Posts: n/a
 
      7th May 2012
Per Beauregard T. Shagnasty:
>I do not see the plus sign (+) in your test address.


Mea Culpa - didn't realize it was literally supposed tb there.

Just sent one to "PeteCresswell+(E-Mail Removed)"
and it did not get to me.

FWIW, one of those fake-but-deliverable addresses that I
substituted for my "real" address in the affected person's AOL
address book just received a spam: same deal as the others - 8
addrs in "To:", and just two lines in the body: an admonition to
check something out, and an accompanying link.

viz:
========================================================
...Choose the easiest way to earn money
http://www.marinadiportotorres.it/vi...tegoryId=46ce9
========================================================


I think I need to find out where this person's AOL address book
resides: in the cloud, or on her C: drive.

Would anybody agree?
--
Pete Cresswell
 
Reply With Quote
 
(PeteCresswell)
Guest
Posts: n/a
 
      7th May 2012
Per (PeteCresswell):
>I think I need to find out where this person's AOL address book
>resides: in the cloud, or on her C: drive.


I think I have tentatively answered my own question: it seems to
reside in the cloud per
http://forums.mozillazine.org/viewto...f=39&t=2456369

Maybe I'm too immersed in this stuff for my own good, but that
looks butt-fugly to me.

So... I guess I still have no clue as to whether the culprit is
running on the user's PC or is hitting AOL from afar.

Now I'm thinking the next step sb to follow David's advice and
change the user's PW. Didn't want to do that at first bco
intruducing additional user-confusion....

--
Pete Cresswell
 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
suggest debugging strategies for "unknown function name in table-levelvalidation expression"? mog Microsoft Access 5 30th May 2005 03:00 AM
Setting up accounts strategies Dave Neve Windows XP General 1 9th Apr 2005 07:35 PM
option strategies scott Microsoft Excel Programming 3 31st Jan 2004 04:23 PM
HD partitioning strategies Benjo Windows XP Help 8 12th Jan 2004 10:36 PM
Record locking Strategies? (ADO.NET) Bill Microsoft ADO .NET 1 29th Sep 2003 04:59 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 08:42 PM.