Zombied Computer - Need Some Help

Klade

Limp Gawd
Joined
Jul 21, 2004
Messages
158
Hello,

Yesterday I received an email from a friend of mine telling me that my mother's email account had spammed him with a penis enlargement ad. Since my mother as a rule does not send out such ads I felt it was pretty safe to say that her computer was infected. The problem was figuring out which computer.

My mother has attached to her comcast email account an aging Windows XP machine that is lacking significant windows security updates and has Avast installed. A relative new Windows 7 netbook that is fully updated and running microsoft security essentials, and a blackberry.

I ran malwarebytes on both the Windows XP box as well as the Windows 7 netbook with no results. Still, I figured the obvious culprit must be the Windows XP machine so I set about backing up data and preparing to do a complete reformat and install windows 7. In preparation for that I disconnected the computer from the network. Well last night around midnight a number of spam emails were sent out again. The problem is that the Windows XP machine was definitely turned off for hours leading up to the second wave of spam.

So my question is this. What if any computer is infected? Is it the XP box and somehow the messages were sent out earlier and only after 6 to 8 hours did they actually clear comcasts mail servers? Could it be the blackberry? I wasn't aware there were spam programs that could take over a blackberry. Is it possible someone hacked my mothers comcast account itself? And if so other then changing the password is anything needed to be done, or any way to confirm that it was just the account and not a computer?

I am 90% sure the netbook was also turned off last night leading up to the second wave of spam but I can not be 100% sure.

I originally tried to post this in the network and security forum but was told I did not have permission. If it needs to be posted somewhere else please move it.

Thank you in advance for any help on this. I am competent enough with most troubleshooting problems but I find myself flat footed when the obvious culprit starts looking innocent.
 
The MS email hotmail/msn/etc. got hit fairly hard by hackers in the last few months. My hotmail account got hit and sent out a few spam emails that landed on my main email account. I changed the PW and the problem stopped.

That said, make sure her xp machine is up to date but even with the best security it is still a house with 1000000 doors and a few of them are unlocked and open.
 
I plan to go ahead and reformat the XP machine to widnows 7 while I have it down. Even if this time its not the XP machine, it could have been ;)
 
I think it'd be safe to assume her e-mail account was compromised. This happens quite often (unfortunately has happened once to me in the past before I was smart enough to use real passwords). As Nanan said, I changed my password and they stopped.

I'd start there and see if things continue.
 
Back
Top