Problem botnets on mates pc

Discussion in 'Computer Security' started by greenbrucelee, Apr 20, 2010.

  1. greenbrucelee
    Highly Decorated Member Award

    greenbrucelee Zettabyte Poster

    14,292
    265
    329
    Last year I received an email from a friend trying to sell me tools & hardware. My friend said ti didn't come from him so I traced it and the mail originated from the US. Texas to be specific and he lives in Croydon.

    I got him to do a virus scans and all the usual stuff to clean his computer and everything has been fine until last night I recieved the same email originating from the same place.

    Both times this email has come through on my MSN contacts supposedly to be from him.

    Is there a way I can still get emails and talki to him on MSN without me getting this crap? He is not very tech minded and is one of those people no matter how many times you tell him not to go on pr0n or dodgy sites it doesn't sink in.

    I don't want to knock him of my contact list so does anyone have any suggestion to what I can do.

    Last time I virus scanned his pc he was infected 175 times
     
    Certifications: A+, N+, MCDST, Security+, 70-270
    WIP: 70-620 or 70-680?
  2. BosonMichael
    Honorary Member Highly Decorated Member Award 500 Likes Award

    BosonMichael Yottabyte Poster

    19,183
    500
    414
    He may not have a botnet... it's possible that his e-mail address is simply being used by the spammers. SMTP doesn't ensure that the sender is who it says it is... I could send everyone an e-mail from [email protected] and SMTP wouldn't stop me from doing so. That's one of the weaknesses of SMTP.
     
    Certifications: CISSP, MCSE+I, MCSE: Security, MCSE: Messaging, MCDST, MCDBA, MCTS, OCP, CCNP, CCDP, CCNA Security, CCNA Voice, CNE, SCSA, Security+, Linux+, Server+, Network+, A+
    WIP: Just about everything!
  3. greenbrucelee
    Highly Decorated Member Award

    greenbrucelee Zettabyte Poster

    14,292
    265
    329
    Do you have any suggestions of how I can get MSN to distinguish what is a genuine mail from him? do you know if there is a way to get MSN to know that this is coming directly from his address in croydon and not coming from Texas, Alabama, some other place in the US, Croydon then to all of his contacts?
     
    Certifications: A+, N+, MCDST, Security+, 70-270
    WIP: 70-620 or 70-680?
  4. BosonMichael
    Honorary Member Highly Decorated Member Award 500 Likes Award

    BosonMichael Yottabyte Poster

    19,183
    500
    414
    Nope. Like I said, that's one of the weakesses in SMTP. If the Internet doesn't blacklist him, there's not much that can be done.

    There's no way that you can know that they're using HIS contact list. They could have received an e-mail with ALL of your e-mail addresses on it, and they're simply using his address to e-mail everyone on that list. You never know, they could also be using YOUR e-mail address to e-mail people as well.

    Sucks, don't it? :unsure That's why I dislike chain letters, joke e-mails, and the like, with EVERYONE and their grandmother's addresses listed for the world to see (and steal).
     
    Last edited: Apr 20, 2010
    Certifications: CISSP, MCSE+I, MCSE: Security, MCSE: Messaging, MCDST, MCDBA, MCTS, OCP, CCNP, CCDP, CCNA Security, CCNA Voice, CNE, SCSA, Security+, Linux+, Server+, Network+, A+
    WIP: Just about everything!
  5. greenbrucelee
    Highly Decorated Member Award

    greenbrucelee Zettabyte Poster

    14,292
    265
    329
    crap, I thought there would be a way I could stop it. The email is going to all of his contacts which some of which are not mine. Just out interest check your Boson email and see if you have had anything from me relating to my hotmail addy.
     
    Certifications: A+, N+, MCDST, Security+, 70-270
    WIP: 70-620 or 70-680?
  6. BosonMichael
    Honorary Member Highly Decorated Member Award 500 Likes Award

    BosonMichael Yottabyte Poster

    19,183
    500
    414
    Nope, nothing.

    Now, note that I said that it MIGHT not be a botnet on his PC. Then again, it might. Hard to say for sure without checking. Just know that Symptom A doesn't always mean Disease B. :)

    You or your friend could send a note to MSN with the e-mail message header of that message telling them that somebody is using your friend's e-mail address without being authorized to do so. They could, if they choose to do so, do some research and get the source's address/domain SMTP-blacklisted.
     
    Certifications: CISSP, MCSE+I, MCSE: Security, MCSE: Messaging, MCDST, MCDBA, MCTS, OCP, CCNP, CCDP, CCNA Security, CCNA Voice, CNE, SCSA, Security+, Linux+, Server+, Network+, A+
    WIP: Just about everything!
  7. greenbrucelee
    Highly Decorated Member Award

    greenbrucelee Zettabyte Poster

    14,292
    265
    329
    will do that when I get home, thanks.

    I bet if I was check his pc there would be atleast something on there. He does visit pr0n and does use torrents no matter how much I have told him not to do so.
     
    Last edited: Apr 20, 2010
    Certifications: A+, N+, MCDST, Security+, 70-270
    WIP: 70-620 or 70-680?
  8. dazza786

    dazza786 Megabyte Poster

    758
    30
    67
    Doesn't necesarily need to be from his machine.. somebody could have his details.. get him to change them on a different machine and see how it goes. As BM said, doesn't sound like anything to do with a bot.
     
    Certifications: MCP (271, 272, 270, 290, 291, 621, 681, 685), MCDST, MCTS, MCITP, MCSA, Security+, CCA(XA6.5)

Share This Page

Loading...
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.