Quick Email Hacked Question

Discussion in 'Malware Help (A Specialist Will Reply)' started by Enginer, Jan 23, 2013.

  1. Enginer

    Enginer Private E-2

    Malwarebytes reported no threat, but I still ran your entire suite of tools, correctly, I hope. Nothing exciting found. Before I run again and start posting Logs, please look at the attached clip and see what it means to you.

    I have an email account on Bright House and use (the old) Eudora as an email handler. Some time back a trojan broke thru Zone Alarm Pro. I ended up reformatting my SSHD to remove problems a professional shop could not. But I kept seeing emails come in addressed from real names on my email contact lists, but with strange 4-digit names like John2354@Yahoo.com.

    Then my email forwarder started rejecting messages supposedly sent from my clean machine. Sample attached, as image. Only the bottom line missing.

    What does it look like to you?
    Thanks!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!
    As stated in the procedure it should only be run once and logs posted if still having problems whether anything is found or not.

    Formatting does not fix MBR infections or partition infections.

    Nothing! It just looks like you have mail that could not be delivered.
     
  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    <mxxx@hotmeil.com> :confused
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Good catch dr.m. ;)
     
  5. Enginer

    Enginer Private E-2

    Sorry for tacking unto a thread I have not followed, but not obvious how I ask a new question.

    I use the old 7.1.0.9 Eudora with much joy. However, occasionally strange things happen . Now it is :MAILER-DAEMON@mail.gmx.com" , hundreds of bounced emails saying "A message that you sent could not be delivered to one or more of
    its recipients. This is a permanent error. The following address
    failed:"

    it is my regular RR email address, no problem. But the message says I sent the email, and even tho the addressor might be one I have received before, I did not recently send them anything. For example:

    "Received: from mta2.mail.advantagebusinessmedia.com ([68.232.193.94]) by
    mx-ha.gmx.net (mxgmxus003) with ESMTP (Nemesis) id 0MY7AE-1VCSla1L8q-00UpxF
    for <jhebbard@techxxxxxt.com>; Mon, 21 Oct 2013 21:31:34 +0200"

    My redaction is because of fear of spam. Note the "for" address is my mail.com forwarding account. I suspicion RR may be rejecting because of spam, but this is peculiar. And mail.com is showing nothing in spam. Is there someone trustworthy (a major geek) that I can send a text copy of the bounce message for a few minutes debugging?
    I am at sea with this one.

    Thanks! =>Jim<= Enginer
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should start a new thread. ;) However these are not malware issues/questions so you should post in the Software Forum.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds