Improve company productivity with a Business Account.Sign Up

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 328
  • Last Modified:

disappearing email?

One day a person sent me an email( I have a firewall and antivirus) it contained a picture in it.  I was just going to forward the email to another email address so that I could triple scan it with an antivirus. As I tried to forward the email it popped open in the preview pane.  The next time I got onto yahoo messenger everything I said, where I was , what room I was in , everything was being seen by this person. When I went back into my mail to see the persons address again the email itself was gone. I swear it was there because I was able to forward it to the other address, I have the forwarded email the contains the orginal e-mail in the second email address but the very one this person sent me disappeared how is this possible?

After that I noticed some very strange things happening on my computer.  When I scan for a virus ( its clean ) spyware ( its clean ) My firewall never detected anything...


Am I crazy?
0
Smcf4
Asked:
Smcf4
1 Solution
 
titch98Commented:
Are you crazy? Probably not.........!

Firstly, what email client are you using? Outlook, Outlook Express, Incredimail.....?

Due to certain security issues with email transactions and Government Agencies using email records as evidence against people (i.e. FBI versus Microsoft....!!), there has been a call for new methods of handling mail messages. One way that this call has been answered, is the SELF DESTRUCTING EMAIL. There are two main programs in circulation at present that can form Self Destructing Emails - Disappearing Email for Outlook Express and SafeMessage from AbsoluteFuture.com. To give you some idea, Disappearing Email is a 350K downloadable Microsoft Outlook plug-in that lets you send encrypted, self-destructing messages to almost any e-mail system or client.

Not too good for people like yourself who has possibly been sent a Self Destruction email, with an attachment, that has contained some kind of malicious script and although you have firewall and antivirus on your system, what you have explained points to this - also the fact that "strange things" have been happening to your computer since.

Do not put too much faith in Firewalls or Anti-Virus. A friend of mine has just spent 2 days clearing viruses off his system and he has Norton installed...........

All I can suggest for now, without delving any deeper, is use system restore to set your system to a configuration BEFORE you recieved the email. Also, try using a different Anti-Virus proggy to see if it detects anything on your system. Online virus checkers are also good for double checking your system.

If you still have problems, repost here and we will look deeper into things.
0
 
jakosysadminCommented:
There's a feature within most e-mail clients that cleans up the view of the e-mails listed that have been expired. X-Expire: is the header for that in the e-mails, IIRC.
If you happen to have MS Outlook, you can see the option from the View-Options dialog when you're in the e-mail composing window -- there's a "Expires after" check box with subsequently activated date and time controls. Try sending yourself one to see if it behaves accordingly.
Expired e-mails however are probably not deleted but only hidden.
0
 
Mohamed OsamaSenior IT ConsultantCommented:
alright , I am assuming you are using outlook express or microsoft outlook as this seems to be a specially crafted email intended to exploit a known vulnerability in OE,MS Outlook and even internet explorer , make sure to disable auto-preview feature for Outlook , also make sure your Internet zone security is set to HIGH .

as for your case , kindly share a hijack this log with us , although Antivirus and antispyware products on your system fail to detect any malware , the system was most likely compromised , however the HT LOG (generated in safe mode) will show traces of the infection if any , I would also advise NOT to physically delete any files we might uncover physically from your hard drive , there might be a case of NEW/Unknown variant of Malware that AV companies should take a look at .

 awaiting your response , Best regards .
0
The Firewall Audit Checklist

Preparing for a firewall audit today is almost impossible.
AlgoSec, together with some of the largest global organizations and auditors, has created a checklist to follow when preparing for your firewall audit. Simplify risk mitigation while staying compliant all of the time!

 
Smcf4Author Commented:
I was using Gmail.  I sent this person my gmail account because I did not want them having my yahoo accounts ( since yahoo email shows your main account ) or my isp account)  I will run a hijack this log as soon as possible. Which will probably later today and will post the results you are asking for.  Would u know of a way to turn off the preview pane in gmail?
0
 
Smcf4Author Commented:
I do have another question, suppose this person did send something in this email some type of keylogger of sorts to see what I am typing in yahoo messenger.  I have several computers if they are all running on the same modem and isp ( I actually have two different isp's  )  two computers are hooked to one and two to the other,  if I were to log into some of the accounts on the compromised computers on the clean computers will they too be compromised?
0
 
jakosysadminCommented:
GMail is AJAX interface on a bunch of webservers, AFAIK. In such cases HTML e-mail content goes through a complex sanitation and it would be tricky to write a script that cleans up its traces (only) when propagated through the GMail.
With you demonstrating your disability to interact with the interface (preview pane question) I am fairly confident that this is a case of applied filtering on a view of e-mail list and not self deleting e-mail.
0
 
jakosysadminCommented:
Most overflow holes for various image manipulation components within Windows are patched already (it is quite another thing if you have applied the patches). Let's assume, that a new unknown vulnerability was exploited (your clean AV report) and you are a victim of a keylogging program. Even then your firewall should have interfered with the outbound packets from the keylogger and your GMail account passwd should have never gotten out. Ok. You suspect that it happened and you are desperate to take action:
Migrate all data and reinstall and update the OS to get rid of the possible rootkitted_keylogger_and_whatnot, tighten the firewall rules, change all passwords etc etc.

And most of all - drop the assumptions that popular communication methods are secure and private. they are NOT. Yahoo messenger is not using encrypted channels to forward your chat to other parties - everything is being sent as clear text and as such assume that anything that you type in yahoo messenger, can be read by everybody.

0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Get 10% Off Your First Squarespace Website

Ready to showcase your work, publish content or promote your business online? With Squarespace’s award-winning templates and 24/7 customer service, getting started is simple. Head to Squarespace.com and use offer code ‘EXPERTS’ to get 10% off your first purchase.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now