<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.0.7" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: Weird e-mail &#8220;spam&#8221; problem</title>
	<link>http://spamhuntress.com/2005/08/29/weird-e-mail-spam-problem/</link>
	<description>Just another WordPress weblog</description>
	<pubDate>Sat, 17 May 2008 03:47:21 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.0.7</generator>

	<item>
		<title>by: Kevin</title>
		<link>http://spamhuntress.com/2005/08/29/weird-e-mail-spam-problem/#comment-1194</link>
		<pubDate>Thu, 08 Sep 2005 16:18:17 +0000</pubDate>
		<guid>http://spamhuntress.com/2005/08/29/weird-e-mail-spam-problem/#comment-1194</guid>
					<description>go safe mode and start scanning i guess....</description>
		<content:encoded><![CDATA[<p>go safe mode and start scanning i guess&#8230;.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Administrator</title>
		<link>http://spamhuntress.com/2005/08/29/weird-e-mail-spam-problem/#comment-1162</link>
		<pubDate>Tue, 30 Aug 2005 13:26:02 +0000</pubDate>
		<guid>http://spamhuntress.com/2005/08/29/weird-e-mail-spam-problem/#comment-1162</guid>
					<description>She's uncooperative, and I get more and more junk. LOADS of 411 letters, suddenly. Hadn't gotten any of those for a long time. And many lists of various sorts, that bear an IP number from her ISP, and MY NAME!

And I think she deep down thinks it can't be her.

She tried to run Spybot yesterday. It tried to update, then was sitting there for 20 minutes, doing who knows what, before she killed it.

I wish I'd known a geek in her neighborhood. Anyone in Arizona who'd be willing to help out an old granny? She's feisty, but usually very sweet.</description>
		<content:encoded><![CDATA[<p>She&#8217;s uncooperative, and I get more and more junk. LOADS of 411 letters, suddenly. Hadn&#8217;t gotten any of those for a long time. And many lists of various sorts, that bear an IP number from her ISP, and MY NAME!</p>
<p>And I think she deep down thinks it can&#8217;t be her.</p>
<p>She tried to run Spybot yesterday. It tried to update, then was sitting there for 20 minutes, doing who knows what, before she killed it.</p>
<p>I wish I&#8217;d known a geek in her neighborhood. Anyone in Arizona who&#8217;d be willing to help out an old granny? She&#8217;s feisty, but usually very sweet.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: RichardP</title>
		<link>http://spamhuntress.com/2005/08/29/weird-e-mail-spam-problem/#comment-1161</link>
		<pubDate>Tue, 30 Aug 2005 10:23:05 +0000</pubDate>
		<guid>http://spamhuntress.com/2005/08/29/weird-e-mail-spam-problem/#comment-1161</guid>
					<description>Hmm, just a minute, I think I'll have to reconsider.  A worm like W32.Mytob isn't sufficient to describe your symptoms - although I suppose it could be part of the problem.  Any number of worms could have scraped your address from her address book and sent a forged e-mail containing your name as the "From" address to new potential victims, but that wouldn't account for tafmaster.com appearing in the mail headers.  Perhaps she was infected by a worm and it somehow sent a forged e-mail to the tafmaster.com "service" that it interpreted as you joining their list?</description>
		<content:encoded><![CDATA[<p>Hmm, just a minute, I think I&#8217;ll have to reconsider.  A worm like W32.Mytob isn&#8217;t sufficient to describe your symptoms - although I suppose it could be part of the problem.  Any number of worms could have scraped your address from her address book and sent a forged e-mail containing your name as the &#8220;From&#8221; address to new potential victims, but that wouldn&#8217;t account for tafmaster.com appearing in the mail headers.  Perhaps she was infected by a worm and it somehow sent a forged e-mail to the tafmaster.com &#8220;service&#8221; that it interpreted as you joining their list?
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: RichardP</title>
		<link>http://spamhuntress.com/2005/08/29/weird-e-mail-spam-problem/#comment-1160</link>
		<pubDate>Tue, 30 Aug 2005 10:07:39 +0000</pubDate>
		<guid>http://spamhuntress.com/2005/08/29/weird-e-mail-spam-problem/#comment-1160</guid>
					<description>From your description, if I had to guess, she likely has been infected with &lt;a HREF="http://securityresponse.symantec.com/avcenter/venc/data/w32.mytob.hl@mm.html" rel="nofollow"&gt;W32.mytob.HL&lt;/a&gt; or something similar.</description>
		<content:encoded><![CDATA[<p>From your description, if I had to guess, she likely has been infected with <a HREF="http://securityresponse.symantec.com/avcenter/venc/data/w32.mytob.hl@mm.html" rel="nofollow">W32.mytob.HL</a> or something similar.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Administrator</title>
		<link>http://spamhuntress.com/2005/08/29/weird-e-mail-spam-problem/#comment-1156</link>
		<pubDate>Mon, 29 Aug 2005 19:39:51 +0000</pubDate>
		<guid>http://spamhuntress.com/2005/08/29/weird-e-mail-spam-problem/#comment-1156</guid>
					<description>Thanks, I'll let her know. But considering she's struggling a bit, she's totally lost right now. Hopefully that site tells it in baby steps enough for her.</description>
		<content:encoded><![CDATA[<p>Thanks, I&#8217;ll let her know. But considering she&#8217;s struggling a bit, she&#8217;s totally lost right now. Hopefully that site tells it in baby steps enough for her.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Tuxedo Jack</title>
		<link>http://spamhuntress.com/2005/08/29/weird-e-mail-spam-problem/#comment-1155</link>
		<pubDate>Mon, 29 Aug 2005 18:15:14 +0000</pubDate>
		<guid>http://spamhuntress.com/2005/08/29/weird-e-mail-spam-problem/#comment-1155</guid>
					<description>I'd love to see a HijackThis log from that machine.

If you can guide her to tomcoyote.com/hjt and generate a log, we'll see if there's malware on it.</description>
		<content:encoded><![CDATA[<p>I&#8217;d love to see a HijackThis log from that machine.</p>
<p>If you can guide her to tomcoyote.com/hjt and generate a log, we&#8217;ll see if there&#8217;s malware on it.
</p>
]]></content:encoded>
				</item>
</channel>
</rss>
