I just got a email from Mail Delivery Subsystem it came with a attachment,
I did not open the attachment, I sent no emails to those addresses
this is what it said

The original message was received at Tue, 17 Feb 2004 06:01:18 -0500 (EST)
from []


*** ATTENTION ***

Your e-mail is being returned to you because there was a problem with its
delivery. The address which was undeliverable is listed in the section
labeled: "----- The following addresses had permanent fatal errors -----".

The reason your mail is being returned to you is listed in the section
labeled: "----- Transcript of Session Follows -----".

The line beginning with "<<<" describes the specific reason your e-mail could
not be delivered. The next line contains a second error message which is a
general translation for other e-mail servers.

Please direct further questions regarding this message to your e-mail
administrator.

--AOL Postmaster

----- The following addresses had permanent fatal errors -----
<>
<>
<>
<>
<>

----- Transcript of session follows -----
... while talking to air-yh01.mail.aol.com.:
>>> RCPT To:<>
<<< 550 MAILBOX NOT FOUND
550 <>... User unknown
>>> RCPT To:<>
<<< 550 MAILBOX NOT FOUND
550 <>... User unknown
>>> RCPT To:<>
<<< 550 MAILBOX NOT FOUND
550 <>... User unknown
>>> RCPT To:<>
<<< 550 MAILBOX NOT FOUND
550 <>... User unknown
>>> RCPT To:<>
<<< 550 MAILBOX NOT FOUND
550 <>... User unknown

Dani AI

Generated

Short, practical summary and next steps.

This pattern of bounced messages almost always means your address was forged (backscatter) rather than your machine definitely being the spam source. That said, on an always-on broadband connection a hijacked PC can also send mail directly. As suggested, forgery is common; as and warned, a broadband zombie is possible; and ’s advice to gather logs is the right direction. Do not open any attachments from the bounce message—keep a copy for investigation.

Quick checklist to confirm and contain the problem

  1. Check server-side Sent/Account activity (webmail). If there are no outgoing copies on the server, it’s likely forged.

  2. Save the full bounce including full headers. Inspect the earliest "Received:" line to see where the message was injected (the first hop is the important one). If the origin IP is not one of your local IPs or your ISP’s authenticated SMTP, it’s probably spoofed.

  3. Look for active outbound SMTP on your PC/network. From an elevated prompt run:

    netstat -ano | findstr :25
    netstat -b -n    (requires admin)

    If you see many established connections to remote SMTP hosts, disconnect and investigate processes by PID (Task Manager / tasklist / Process Explorer).

If you find suspicious outbound traffic or unknown services: disconnect from the network, run updated full antivirus and an anti‑malware scan (from safe mode or a rescue disk), and save a HijackThis log rather than blindly fixing entries. Post the full headers and that log if you want help interpreting them. After cleaning, change email and account passwords and notify your ISP/mail provider so they can check SMTP logs and block abuse.

If you don’t find evidence of outbound SMTP and the headers show third‑party injection, treat this as backscatter: filter/delete the bounces, change your password as a precaution, and monitor.

Recommended Answers

All 7 Replies

no one knows anything on this??

no not I :)

Hey,
sounds like a virus to me, but dont worry its more than likely not on your system. the virus has infected someones system out there on the net, its sending email to whoever its feels like and forgeing your address as the sender, that way you'll get all the bounce back notes (as you already have) and it can be clear to continue sending without the system owner being alearted.

if you need a virus scanner then open up google.com and type in AVG, they do free anti virus software, and it rocks!

l8r
spikes

I just got a email from Mail Delivery Subsystem it came with a attachment,
I did not open the attachment, I sent no emails to those addresses
this is what it said...

<snip>
----- The following addresses had permanent fatal errors -----
<>
<>
<>
<>
<>
</snip>

Actually, I'm a little worried by this pattern -- the occasional spam-bounce is to be expected, but this goes beyond that. If you are on broadband, it is possible that your machine is being used as a zombie to send out spam. About 50% of the spam I now get on my spamtrap email address is from hijacked proxies. Between SoBig and MyDoom/Novarg, this is a big problem. If you are on broadband, I would recommend that you download-and-run HijackThis from Caperjack's signature or my Malware, virus, and startup information and tools page.

that just looks like a spam problem becuase of
<>
<>
<>
<>
<>
that looks like a pattern made up by some spamming program. but yea run some scans as tallcool says

Sounds like a trojan to me, run msconfig from the rum prompt and look at whats running at startup!

First please get Spybot S&D to clear out most of the spyware.


Fix everything SpybotSD labels in red.


How to download and use hijackthis .

Then after reboot:
Download 'Hijack This!'. http://www.spywareinfo.com/~merijn/files/HijackThis.exe
Unzip to a permanent folder, doubleclick HijackThis.exe, and hit "Scan".

When the scan is finished, the "Scan" button will change into a "Save Log" button.
Press that, save the log, load it in Notepad, and copy its contents here. Most of what it lists will be harmless or even essential, don't fix anything yet.
then post the log here

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.