• We’re currently investigating an issue related to the forum theme and styling that is impacting page layout and visual formatting. The problem has been identified, and we are actively working on a resolution. There is no impact to user data or functionality, this is strictly a front-end display issue. We’ll post an update once the fix has been deployed. Thanks for your patience while we get this sorted.

Possible spoofed e-mail, virus, or something worse?

TheFamilyMan

Golden Member
I'm going to be helping a friend do some troubleshooting from the standpoint of looking for a virus/trojan. I'm not exactly sure that's the root cause of his problem but that's where I'm going as a first pass; at least to run fresh scans, eliminate any possibility of virus, etc.

The issue he's having is that he's having spam e-mails from his home (family) e-mail delivered to everyone on his contact list. This is not a gMail account so I've already eliminated the "logged in from another location" thing. His family contact list includes his work e-mail address. His wife has also said that many family members & friends have let him know they are receiving more and more spam specifically from his address. I'm not sure if I should be considering or discounting spoofing here because of the extremely varied nature of the spam.

The thing is that when he goes into his sent items of his webmail home (family) account with his ISP, none of the messages are in the sent items. I've looked at the e-mails he receives at work and done some preliminary, albeit amateur, work to pretty much say that I think they are legitimately coming from his home (family) account. Again, I'm no expert in this field so I can't say for sure either way. I have agreed to help him address his issues and concerns.

What are some things I should look for or do in addition to what I'm planning on doing:

- I'll run a fresh scan with Malwarebyte's
- I'll run a fresh scan with Spybot S&D
- I'll run a fresh scan with AdAware
- I'll take a look at his webmail settings and probably end up on the phone with his ISP's tech folks to make sure it's nothing on their side (highly doubt that it is)

Am I missing anything or should I be focusing on something more than another? I'm good with cleaning up messes with regards to viruses, trojans, etc and am more than competent when it comes to getting rid of the problem...I just need some good direction to insure I'm addressing the right problem.

Any insight, suggestion, comments are greatly appreciated.
 
Have him change his password on the family email account and stop autologin for now.

Just finished working with someone who was experiencing the same problem except she did see the sent spam messages in her webmail sent email box. Her PC was clean. I think she registered or ordered something from a website and used her email and email password for her password at the site. I'm guessing the website was hacked or compromised. She had a @bellsouth.net address.

Make sure he has an active and up to date anitvirus program.
 
Back
Top