Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > other security issues & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old September 7th, 2007, 12:43 PM
dlevere's Avatar
dlevere dlevere is offline
Infrequent Poster
 
Join Date: Nov 2002
Location: Philadelphia, PA
Posts: 15
Default HKLM\SECURITY\Policy\Secrets|SAI*

Someone using this IP is sending e-mail out in my name:

80.12.242.139

canonical name smtp2a.orange.fr.
aliases
addresses 80.12.242.139

I used Rootkit Revealer and found the following Registry Key:
HKLM\SECURITY\Policy\Secrets|SAI*

How do I get rid of this? I don't know how I got it.
__________________
The Hackmaster
Hacking 101
  #2  
Old September 7th, 2007, 02:44 PM
Climenole's Avatar
Climenole Climenole is offline
Look 'n' Stop Expert
 
Join Date: Jun 2005
Posts: 1,640
Smile Re: HKLM\SECURITY\Policy\Secrets|SAI*

Hi dlevere

Read this please:

http://forum.sysinternals.com/forum_posts.asp?TID=8882


This is not related to your email problem.

Give us more details...

__________________
Claude LaFreničre
  #3  
Old September 7th, 2007, 06:13 PM
dlevere's Avatar
dlevere dlevere is offline
Infrequent Poster
 
Join Date: Nov 2002
Location: Philadelphia, PA
Posts: 15
Default Re: HKLM\SECURITY\Policy\Secrets|SAI*

I received a bunch of E-mails that said Mail undelivered, returned to sender, and I know that I didn't send them out. I'll see if I can get one of the headers, I deleted most of them.
__________________
The Hackmaster
Hacking 101
  #4  
Old September 8th, 2007, 10:36 AM
SG1's Avatar
SG1 SG1 is offline
Frequent Poster
 
Join Date: Jan 2003
Posts: 430
Default Re: HKLM\SECURITY\Policy\Secrets|SAI*

dlevere;

I could be wrong on this, but seems to me that I read somewhere recently about getting "undeliverable" mail returned with something attached in hopes that users would just click/open them... which they'd have cause to regret.

SG1 (Pat)
  #5  
Old September 8th, 2007, 10:57 AM
stapp's Avatar
stapp stapp is online now
Very Frequent Poster
 
Join Date: Jan 2006
Location: England
Posts: 2,242
Default Re: HKLM\SECURITY\Policy\Secrets|SAI*

Also Orange.fr have blocked port 25 which many mail severs use.

A couple of posts about it here

http://monaco.angloinfo.com/forum/to...topic_id=99439
http://monaco.angloinfo.com/forum/to...topic_id=99439

Of course this may not be your problem as you say you didn't sent the original emails
  #6  
Old September 8th, 2007, 02:19 PM
dlevere's Avatar
dlevere dlevere is offline
Infrequent Poster
 
Join Date: Nov 2002
Location: Philadelphia, PA
Posts: 15
Default Re: HKLM\SECURITY\Policy\Secrets|SAI*

No, I don't open attachments, even from people that I know.

I only opened one of them, it had no attachment, and I deleted the rest, and blocked smtp2a.orange.fr
__________________
The Hackmaster
Hacking 101
  #7  
Old September 8th, 2007, 02:57 PM
Climenole's Avatar
Climenole Climenole is offline
Look 'n' Stop Expert
 
Join Date: Jun 2005
Posts: 1,640
Smile Re: HKLM\SECURITY\Policy\Secrets|SAI*

Hi dlevere

May be your email address is known and used by spammers as phony email source.
When spams reach some of their targets they are bounced to you.

The same trick was used about 2 years ago with email from phony "Microsoft":
these mail have malware attached and hide their real source by forging
the headers with the real Microsoft address...

Why don't send an email to your email provider about this?
Just to protect your butts...

If your email address is in the spammers list I guess the best solution is
to cancel this address and create a new one.

You may also create more than one email addr.:

personnal: only know by people you know personnaly (e.g. familly members, well known friends)

professionnal: only for job or business purpose

"social" : other contacts...

Example: 3 gmail account and centralised with an email client ...



Some references:

wikipedia: E-mail_spam
__________________
Claude LaFreničre
  #8  
Old September 8th, 2007, 06:32 PM
dlevere's Avatar
dlevere dlevere is offline
Infrequent Poster
 
Join Date: Nov 2002
Location: Philadelphia, PA
Posts: 15
Default Re: HKLM\SECURITY\Policy\Secrets|SAI*

Thanks, I'll take your advice and notify my E-mail provider.
__________________
The Hackmaster
Hacking 101
 

Wilders Security Forums > Other Security Topics > other security issues & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 01:27 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums