Link to home
Start Free TrialLog in
Avatar of charlietou
charlietou

asked on

Possible email hijack

Hi folks,

I have a client who asked me to check out her computer.  She's been getting dozens of messages of undeliverable mail to recipients she's never sent to, with seemingly random user accountnames@goproperties.com and @customhomes.com.  She has run McAfee virus scan as well as AVG, and come up with a few adware listings that she deleted (sorry I don't have much more info on that).  I have run Hijack This and seen nothing really out of the ordinary.

I'm wondering if a rootkit on her system is a possibility.  

Does anyone have any ideas on where to look next?  I'm right now in the process of another system scan with McAfee.

Thanks for your help.

Charlie T.
ASKER CERTIFIED SOLUTION
Avatar of blue_zee
blue_zee
Flag of Portugal image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of r-k
r-k

Yes, I agree with Blue_zee. In fact, if I get a lot of mail bouncing back to my own address, I can be nearly 100% sure that it did not originate from my machine, because the new viruses for the last few years always use a fake return address. That way the bounces go to the wrong person, and it is harder to detect who really has the virus.\

You can usually figure out the IP address of the infected machine by examining the mail header in detail.