SPAM from my PC ? - TDP

tdp

Member
Joined
Jan 17, 2010
Messages
17
Reaction score
0
Location
Cape Town
I NEED HELP - my isp reports that my pc send spam? fact is, I do not even know where to start looking. Obviously it is not me that’s doing this but WTF … where …. how? Please help:wtf::confused::erm:
 
Hi tdp,

The reason Afrihost is sending you this message because you are the contact person for the ADSL account **********
Please read this message carefully.

Someone has sent us a report of network abuse by the IP address ***.***.**.** At the time of the incident
(2010-04-27 18:41:46), that IP address was in use by the account ****************connected from (tel number)

Afrihost did not monitor the traffic which relates to this complaint, but we accept this report from the complainant as credible evidence of network abuse. We do not allow the violation of our acceptable use policy, irrespective of whether or not the activity is legal or justified.

Please note that unless the matter is resolved by you, our systems will block access by your account **** e mail address and line (tel line) on Monday 17 May 10:47 SAST.

We would like you to do as follows:

- Please investigate carefully, and resolve the problem

- Let us know you have resolved the problem at
https://clientzone.afrihost.com/

Once you have taken note of the details below, and you have resolved the problem, please visit the client zone at https://clientzone.afrihost.com/ and fill in the AUP violation form explaining what action you have taken.

The important details are:
- What was the reported problem : spam
- The IP address that was involved: ******
- The time of the incident : 2010-04-27 18:41:46 SAST
- The ADSL user name : *********
- The line in use : ********
- There is one previous report in this system
- Once this matter is resolved, service will restored without delay.

How did this happen?

- This can happen if one or more of your systems is infected
with malware, such as a spambot. This is fairly common, and
an indication of the insecure state of computer security.
Unfortunately, the toleration of such software violates our
acceptable use policy.

- This can happen if you fail to adequately secure access to
your LAN, such as setting an insecure wireless access key,
or allowing access without appropriate controls. From a
network point of view, we do not have the network
infrastructure or resources to trace the individual
concerned, but we do insist that our network be used in
accordance with our acceptable use policy.

- This can happen if you were responsible for the network abuse
(e.g. if you deliberately transmitted DDOS traffic, copyright
protected content, spam, etc.)

As you may not be aware of this incident, please take steps to see how this is happening, including:

- Check your systems with up-to-date anti-virus, anti-spyware
and anti-malware software

- If you are running a mail server, check that it does not act
as an open relay, or accept weak passwords

- Check that your systems are not sending traffic that you are
not aware of. You can examine the network counters on each
system on your network, or capture network traffic with a
tool such as wireshark, from http://wireshark.org/

Provided the problem is properly sorted out, you should not receive this message again. If you have already resolved this matter, please visit the client zone to let us know. Visiting the client zone is the only way to reinstate your service.

To see the original report in full please visit the clientzone.

Afrihost Abuse Department
011 612 7200
 
This is the thing, I am running an updated version of Avast, have Windows 7 Home Premium with firewall installed, after the treads I have installed Wireshark and Iobit Security 360. The user account that sends this was closed some month and a half ago because I have upgraded to uncapped but still use the same tel line number
 
2010-04-27 18:41:46 SAST

Thats the time the incident occurred. Perhaps, the problem has been rectified? Apart from those measures you have already implemented, just change your password to be on the safe(ish) side, tell ISP that you have done wht you think its needed and hope its worked? Apart from that, its not your issue as you closed the account? Perhaps i've misread somewhere along the way?
 
Actually, most people are not even aware that their pcs are used to send out spam. This usually happens when a user somehow got infected by a custom trojan that is not picked up by 90% av/spamaware scanners. Where I work I see this happening all the time. And to prove this, just look this up.

1. Search for uceprotect in google if you don't trust my link: http://www.uceprotect.net/en/rblcheck.php
2. Do a look up, change "IP" to "ASN" and enter the value: 3741 (this is IS's ASN)
3. click test and check out the ip ranges where IS have their ADSL users on.

Check around 196.208.0.0/13 and see how many IP ranges IS have blacklisted there.

Now this is a ongoing problem. Sure as hell it is not your problem, but then you also are now helping cleaning up the spam problem on the internet.

The easiest way to block this is, adding a rule to a firewall to block outgoing connections to port 25 from your pc. Then when you want to send email, use webmail or use port 587 (submission port) in your email client. That way you will know that your pc is not sending out spam regardless of whether you know how to fix it or not.
 
Top
Sign up to the MyBroadband newsletter
X