Who tried to send this email, apparently from me?
Early this month I received a bounced email that appeared to be from me. I ignored it at the time, then a few weeks later I got another bounced email, going to the same address, again seemingly from me.
At first I thought it was joejob, but it's clearly not: the bounce came from my ISPs mail relay (Pair, which authenticates outbound email), the headers look like they came from me, they have my computer's IP address, its windows Workgroup name (Wilkie), even the Microsoft Outlook build version number is the same-- the headers of the outgoing message look just like I sent the message, only I didn't.
Next I thought Virus, even though I had AVG installed. I ran a scan of the computer, it came up empty. So uninstalled AVG and installed Kaspersky AV and ran it. It found and deleted some trojans in email attachments in an old archive folder, but I never opened or clicked on any of them, so I don't see how they could have sent anything. No system viruses, malware or anything.
Other facts of the case:
Computer in question is Windows XP sp 2.
Mail program is Outlook 2003.
Outlook is configured to never send receipts.
No one else uses the computer that these emails appear to have come from.
At the times the messages appear to have been sent, I was home, and the computer was presumably on. I may have been using it, don't recall.
The messages do not appear in my sent folder.
I don't recognize the address the message was sent to.
And finally, here is of one of the bounces (some fragments of personal details like addresses replaced by ???):
Hi. This is the qmail-send program at relay01.pair.com.
I'm afraid I wasn't able to deliver your message to the following addresses. This is a permanent error; I've given up. Sorry it didn't work out.
:
61.129.65.17 does not like recipient.
Remote host said: 452 4.2.1 Mailbox temporarily disabled: eweweweee@eastday.com Giving up on 61.129.65.17. I'm not going to try again; this message has been in the queue too long.
--- Below this line is a copy of the message.
Return-Path:
Received: (qmail 23634 invoked from network); 22 Nov 2007 00:14:06 -0000
Received: from unknown (HELO Wilkie) (unknown)
by unknown with SMTP; 22 Nov 2007 00:14:06 -0000
X-pair-Authenticated: 72.74.???.??
From: "Kevin"
To:
Subject: =?Windows-1252?B?Tm90IHJlYWQ6ICoqSlVOSyoqILT6IMDtINK1IM7x?=
Date: Wed, 21 Nov 2007 19:14:06 -0500
Message-ID: <000001c82c9c$986c8bf0$6700a8c0@>
MIME-Version: 1.0
Content-Type: application/ms-tnef;
name="winmail.dat"
Content-Transfer-Encoding: base64
Content-Disposition: attachment;
filename="winmail.dat"
X-Mailer: Microsoft Outlook, Build 10.0.2616
X-MS-TNEF-Correlator: 00000000803F0C72AA992E4DAD51CC29988A79A684E17D02
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3198
eJ8+IgYAAQaQCAAEAAAAAAAB
[rest of message removed]
More here.
posted by essexjan at 11:05 AM on November 28, 2007