Do I have a worm or trojan?

Discussion in 'Malware Help (A Specialist Will Reply)' started by Conklin, Dec 26, 2006.

  1. Conklin

    Conklin Private First Class

    Hi guys!

    I check my computer weekly for viruses and semi-weekly with AdAware.
    a couple days ago I got this in my eMail (see below) and I wonder if somehow my computer is being used as a slave? I have never heard of the person to whom this eMail was directed, and I find nothing unusual in the send file of Outlook Express. (I have Windows XP).

    Any help/advice would be appreciated!
    bill :confused:
     
  2. Conklin

    Conklin Private First Class

    Oooops! Forgot to attach the message:


    Hi. This is the qmail-send program at sysnet.ev1servers.net.
    I'm afraid I wasn't able to deliver your message to the following addresses.
    This is a permanent error; I've given up. Sorry it didn't work out.

    <compras@sofia.com.mx>:
    This address no longer accepts mail.

    --- Below this line is a copy of the message.

    Return-Path: <username@someisp.net>
    Received: (qmail 22516 invoked from network); 24 Dec 2006 07:38:47 -0600
    Received: from nc-ga-grnsbro-65-5-12-47.netcommander.com (65.5.12.47)
    by ev1s-209-85-21-163.ev1servers.net with SMTP; 24 Dec 2006 07:38:37 -0600
    Received: from vnbxy ([192.33.151.254])
    by nc-ga-grnsbro-65-5-12-47.netcommander.com (8.13.4/8.13.4) with SMTP id n720448493511u2Cl018308
    for <conner@lincoln.midcomp.com>; Sun, 24 Dec 2006 09:32:12 -0500 (CDT)
    (envelope-from conkle@glyphix.com)
    Message-ID: <013401c72768$4d5c38c0$2f0c0541@vnbxy>
    From: "conkle" <username@someisp.com>
    To: <conner@lincoln.midcomp.com>
    Subject: Erect MMeds
    Date: Sun, 24 Dec 2006 06:31:05 -0800
    MIME-Version: 1.0
    Content-Type: multipart/related;
    boundary="----=_NextPart_000_0131_01C7273E.64176960";
    type="multipart/alternative"
    X-Priority: 3
    X-MSMail-Priority: Normal
    X-Mailer: Microsoft Outlook Express 6.00.2900.2869
    X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2962

    This is a multi-part message in MIME format.

    ------=_NextPart_000_0131_01C7273E.64176960
    Content-Type: multipart/alternative;
    boundary="----=_NextPart_001_0132_01C7273E.64176960"


    ------=_NextPart_001_0132_01C7273E.64176960
    Content-Type: text/plain;
    charset="us-ascii"
    Content-Transfer-Encoding: quoted-printable


    ------=_NextPart_001_0132_01C7273E.64176960
    Content-Type: text/html;
    charset="us-ascii"
    Content-Transfer-Encoding: quoted-printable


    <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
    <HTML><HEAD><META http-equiv=3DContent-Type content=3D"text/html; charse=
    t=3Diso-8859-1">
    <META content=3D"MSHTML 6.00.2900.2963" name=3DGENERATOR><STYLE></STYLE>=

    </HEAD>
    <BODY text=3D"#65AC25">
    <DIV>around cloud formation panics, and around scythe hibernates; howeve=
    r, pit viper around avoid contact with..

    <IMG src=3D"
    cid:013001c72768$4d031c40$2f0c0541@ncgagrnsbro6551247.netcommander.com" border=3D0>
    <BR><DIV></DIV><BR><BR>
    <DIV>

    =3D20
    </DIV>

    </BODY>
    </HTML>


    ------=_NextPart_001_0132_01C7273E.64176960--

    ------=_NextPart_000_0131_01C7273E.64176960
    Content-Type: image/png;
    name="cream puff.png"
    Content-Transfer-Encoding: base64
    Content-ID: <013001c72768$4d031c40$2f0c0541@ncgagrnsbro6551247.netcommander.com>

    iVBORw0KGgoAAAANSUhEUgAAAY0AAAGIEAYAAADt+mAhAAAABGdBTUEAAK/INwWK6QAAAAZiS0dE
    ////////CVj33AAAAAlwSFlzAAAASAAAAEgARslrPgAAAAl2cEFnAAABjQAAAYgA4xPJzwAAYgtJ
    REFUeF7tvb+vJclxpt3EGmtq/4G1BcgQQMhbQMJnrSECMmQIWq05glYYi4Qsgc74EkCH5jg0KFp0
    BtMYa4EFrfZmjIYcamR9HHA+a/wFWF/fexg6fePe6DciM6sqq+o5zunb+fvJzMh4M7PqvFr4QAAC
    EIAABCAAAQhAAAIQGEzg1eD8yA4CEIAABCAAAQhAAAIQgMCC0GAQQAACEIAABCAAAQhAAALDCSA0
    hiMlQwhAAAIQgAAEIAABCEAAocEYgAAEIAABCEAAAhCAAASGE0BoDEdKhhCAwNEIfO/xsyz+27dj
    dLy1OUX1tf9fu3zyhwAEIACBaxNAaFy7/2k9BCDwjsBoAZHNby34SmAoQbVWvcgXAhCAAASuRQCh
    ca3+prUQgEAHgayAyMbrqMqLSbPlIjRGkyc/CEAAAhB4iQBCg3EBAQgchoBypFV41NBsutHxrD6j
    TiDWql92gKh2ZPOpclH5Ki7Velfjq/oRDgEIQOCsBBAaZ+1Z2gWBExJQDp4Kn01oqPqqcN8e5VAr
    B751yKh6Vk9QqvmpZ05a8+tN18qTdBCAAATOQgChcZaepB0QuAAB5fgpRzpySEc76GfJTw2p3v7I
    CiXfb9lyR4+H3vGjeBIOAQhA4GwEEBpn61HaA4ETE8g68MrBzDq4e8VTO/RbncyoodTaH731X6t/
    q/m2xldcCYcABCBwFgIIjbP0JO2AwAUItDq26upONt/R8ZSjqupdddirJwFqSGV5qHwUh2o7WwXi
    2vXIciAeBCAAgbMQQGicpSdpBwQuQKDq2Gbj7xUv6xBvJTiqQyjLLZtvNb9s/Gw8hEa2p4gHAQhA
    IEcAoZHjRCwIQGACAms5jNl8R8dTSEefQLQ60r0nCr7c0fkpIZbtt1Y+1fxVvxMOAQhA4CwEEBpn
    6UnaAYELEMg63tl4Vccy61AeLV7W8f/k8XOPneXcy8M/s5Itt9q/W8W/wFSliRCAAAQeCSA0GAgQ
    gMBhCCgHU4VnHWrv2FYd0FGO9ej2ZOsVtdcLDcWlWl5rflF/qfx6x0Nr/oeZcFQUAhCAQCcBhEYn
    QJJDAALbEVCOqwrvdSyz+WfjKUe1mo9vX6tQqQqNbDuqI0XVXwkMVa/e8dCaf5UD8SEAAQgclQBC
     
    Last edited by a moderator: Dec 27, 2006
  3. Conklin

    Conklin Private First Class

    I had hoped for some help.
    Pleeeeeeeze?

    bill
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's just a spammer that has your email address. Ignore it and don't click on anything in the email.

    By the way you really should not post messages in a public forum that contain your email address. It is a great way to get yourself added to more spammer's lists. I'm editing your address out of the message for your security.
     
  5. Conklin

    Conklin Private First Class

    Thanks Chaslang!
    After I hit "Send" I thought about the fact that I had my Email adderess in the message.
    Several years ago you helped me greatly when I had bought a used computer that was just chock-full of all kinds of stuff. I thank you again, Chas.

    bill c
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds