Also the attached file is a dat file, can you even open them types (dat)?
Walt
"Walter Goldschmidt" wrote in message
news:ia96cq$i4r$...
OK, I changed my Road Runner email password. I ran a virus scan with both
malwarebytes antimalware & superantispyware in both regular mode and safe
mode. I found 59 adware's using superantispyware in regular mode and none
when I ran it in safe mode. After running malwarebytes I found 1 malware in
regular mode and none in safe mode. That was on my laptop. On my desktop I
found a lot more with superantispyware in regular mode and a lot less in
safe mode. Also same with malwarebytes. I don't know if 2 computers on same
link can effect each other or not. The laptop has a wireless connection and
the desk top a hard wired. The laptop is used 95% of the time. I do very
little porn searching but hey I'm a man and occasionally I do catch myself
checking the women out. I also do a little movie & music downloading using
BitTorrent. Since the changes last night I haven't received any of those
emails so far today. Give me another day and I'll let you know if I get
anymore. I may have a few questions for you guys too since you seem to be
knowledgeable on this. Thanks.
Walt
"N. Miller" wrote in message news

qmltcx23d7l$....
On Tue, 26 Oct 2010 15:18:51 -0400, Walter Goldschmidt wrote:
> Keep getting these emails, about 20 to 30 a day. They say From:Mail
> Delivery
> System. Subject:Mail Delivery Failure. Then below I have pasted what they
> say. The also have an attached file which I scanned for a virus and found
> none. The attached file is called ATT00069.dat I've attached that
> file
> but I don't know if it will come through or not. Appreciate any help on
> this.
The attachment is failing to open in my client. The following header line
from your posted "original message" is interesting:
| Received: from [190.41.121.100] ([190.41.121.100:17547] helo=Devin)
| by cdptpa-oedge04.mail.rr.com (envelope-from
<>)
| (ecelerity 2.2.3.46 r()) with ESMTPA
| id 12/1D-13137-F4627CC4; Tue, 26 Oct 2010 19:04:47 +0000
This is saying that a Road Runner mail server (operated by RR for their
customers) got the email from a host on the 'Telefonica del Peru' network;
probably an ISP customer because there is no rDNS on the IP address (typical
of dynamic hosts in Latin America (LACNIC) and Asia (APNIC).
The problem, that I can see, is that the Hotmail address of the recipient is
no good, or the mailbox is full (unlikely, I think, because Hotmail
mailboxes are pretty large). And this appears to be a Road Runner message
submission server, which is relaying from Peru. So the spammer appears to be
using your email account credentials (Username+Password) to induce the Road
Runner message submission servers to send this spam as you. This will not be
the first time that an ISP account has been compromised by spammers in order
to evade port 25 blocks.
It is unlikely that your computer is compromised. More likely just your Road
Runner email account has been compromised. When you change your account
password, consider using a password at least sixteen characters in length,
and a random mix of upper and lower case alpha characters, numerals, and at
least one "special character" (pound sign (#), caret (^), or whatever, if RR
allows.
This sort of compromise it the target of "phishing" attempts, where an ISP
email account holder is told that the ESP is revamping their email system,
and the user must validate their account by sending the account
Username+Password, or lose that account. I've seen Hotmail and AT&T email
account users asking if such a request is a valid request from those
respective services. I am sure that Road Runner users are not exempt from
such phishing attempts.
--
Norman
~Oh Lord, why have you come
~To Konnyu, with the Lion and the Drum