I think I have a bot in my pc :s Just don't know how to kill it!


Recommended Posts

Guys, since yesterday (13 hours ago) I noticed my email to flood by "Delivery Status Failure" from emails I supposedly sent (Hotmail). The bad part of this is that I DID NOT SEND ANY of those messages. I even checked the 'Sent' status at the Hotmail page but it doesn't show up any of the sent emails.

I've already sent scanning my PC with MS Essentials and nothing has shown up.

The problem seems to be with Outlook because when I run it, email start to flood my inbox about a failure delivery.

What should I do? :s

Guys, since yesterday (13 hours ago) I noticed my email to flood by "Delivery Status Failure" from emails I supposedly sent (Hotmail). The bad part of this is that I DID NOT SEND ANY of those messages. I even checked the 'Sent' status at the Hotmail page but it doesn't show up any of the sent emails.

I've already sent scanning my PC with MS Essentials and nothing has shown up.

The problem seems to be with Outlook because when I run it, email start to flood my inbox about a failure delivery.

What should I do? :s

Download this. Install it, update it and then scan your computer, Use FULL scan.

www.malwarebytes.org

Change your password would be a good start, does it happen with other email programs like Windows live mail ?

Maybe its an Outlook issue ?

Anything stuck in the outbox ?

Nothing stuck in the outbox, and from the 3 accounts I have in Outlook, there's just one which is sending the mass email. I have the messenger program running and nothing fishy pops up.

I'll try with malwarebytes as Scorbing suggested.

Nothing stuck in the outbox, and from the 3 accounts I have in Outlook, there's just one which is sending the mass email. I have the messenger program running and nothing fishy pops up.

I'll try with malwarebytes as Scorbing suggested.

Check the server side too, ie hotmail.com

I definitely recommend changing your password though

I'll be doing that now. It's better to prevent than to be sorry later.

Yep, this is exactly why we were asking the hotmail team to add 2 step verification to hotmail email accounts then the worst you would have got was an sms requesting a log in code (If this is what has happened)

I've checked again, and seems is Outlook that has the problem. All of my emails are sending the delivery notification failure. F*ck. I want to know how did I get it, because I never visit strange websites nor open strange or ****ty emails. Maybe outlook downloaded it without concern and infected the system.

Maybe outlook downloaded it without concern and infected the system.

It doesn't work like that.

I'd change your email password, personally, swap to Gmail (you can still have the same addresses and have your mail forwarded, use it with outlook etc), do a full virus scan.

What anti-virus do you use?

It doesn't work like that.

I'd change your email password, personally, swap to Gmail (you can still have the same addresses and have your mail forwarded, use it with outlook etc), do a full virus scan.

What anti-virus do you use?

I have MSE installed. I used to have Kaspersky but let my subscription fade away.

Could just be someone spoofing your address from somewhere else so you end up getting all the undeliverables or logging into your account remotely. I don't know if hotmail allows you to see IP addresses that have accessed your account but I would check that if they do.

When you logon to hotmail through a browser do the failures still show up or is it only happening when outlook is open?

When you logon to hotmail through a browser do the failures still show up or is it only happening when outlook is open?

It only happens when I have outlook opened. But when I browse the email I do have recorded the failure delivery messages. (But can't see the sent ones)

^ exactly.

Outlook seems to just be downloading your bounces.

You rarely see spam sent from a legit address ;) Its always someone else so all the bounces don't clog up the sending server..

Its childs play to send an email saying it came from address Y. If I send out a million random spam messages to all kinds of bogus email addresses, lots of them will get kicked back to what the return address says it is.

So I am spamming how to enlarge your penis and send to [email protected] and say it came from your address at Y, be it sent from that server or not. So somedomain.com says hey we don't have a lsjfdsf mailbox.. Lets make sure that Y knows that -- and sends it back to Y.. These now fill up your mailbox.. Nothing to do with infection, nothing to do with your mailbox being hacked, etc. Look at the kickbacks -- does it say it was sent from your server? Or somewhere in china or Ukraine, etc.. etc..

^ exactly.

Outlook seems to just be downloading your bounces.

You rarely see spam sent from a legit address ;) Its always someone else so all the bounces don't clog up the sending server..

Its childs play to send an email saying it came from address Y. If I send out a million random spam messages to all kinds of bogus email addresses, lots of them will get kicked back to what the return address says it is.

So I am spamming how to enlarge your penis and send to [email protected] and say it came from your address at Y, be it sent from that server or not. So somedomain.com says hey we don't have a lsjfdsf mailbox.. Lets make sure that Y knows that -- and sends it back to Y.. These now fill up your mailbox.. Nothing to do with infection, nothing to do with your mailbox being hacked, etc. Look at the kickbacks -- does it say it was sent from your server? Or somewhere in china or Ukraine, etc.. etc..

I don't think that's the case :s. I'm actually getting emails sent from my email address.

Post the headers of one of these emails or a kickback and we can tell you where it came from exactly! Until you post some details there is no way to know if being sent from your machine or not.

But I can tell you one thing for SURE!! I have not seen a virus/bot/anything that actually uses the local email address when sending anything in years and years and years - its TOO easy to track.. They pull an address from your contacts to use, or make up ****.. They don't actually use your email address when sending. Because that kind of points to the infected box now doesn't it!

first things first, instead of going on and on and on about this, start at the easiest thing to do and work backwards. You should have already done this but guessing you havent yet.

STEP 1: download and install malwarebytes, update the definitions, and run a full scan.

step 2 will depend on the out come of step 1. So do step 1 and tell us if it found anything.

I already did a full scan and did found something in the recycle bin. Deleted and afterwards I had no problems (until now) with the Outlook.

@BudMan:

Here's what had in the body of the email:

(DO NOT CLICK IS SPAM!!!)

http://josephdupnik....fg.htm&dfh=rhcj

And the Subject was left in blank, plus it had my email name on it. Yes, it also came from my email address. Even my uncle asked me what the hell did I send.

BTW: Thanks a lot for the help! :p Malwarebytes did a great job!

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • The fact that memory in general is so high I have to take a loan out to build a computer now is just beyond stupid. Who's really to blame here? Low supply or high demand?
    • Display Driver Uninstaller (DDU) 18.1.5.5 by Razvan Serea Display Driver Uninstaller (DDU) is a utility for completely removing AMD/NVIDIA/INTEL graphics drivers and related packages from your system, attempting to eliminate all leftovers (including registry entries, folders and files, driver store). Though AMD/NVIDIA/INTEL drivers can usually be removed via the Windows Control Panel, this uninstaller tool was created for situations where standard uninstall fails, or when you need to fully remove NVIDIA or ATI graphics card drivers. After using this driver cleaner, your system will behave as though it’s the first time you’re installing a new driver—similar to a fresh Windows installation. As with all such tools, we recommend creating a restore point beforehand, allowing you to undo changes if issues arise. If you're having trouble installing an older or newer driver, try it—there are reports that it resolves such problems. Recommended usage: The tool can be used in Normal mode but for absolute stability when using DDU, Safemode is always the best. Make a backup or a system restore (but it should normally be pretty safe). It is best to exclude the DDU folder completely from any security software to avoid issues. You do NOT need to uninstall the driver prior using DDU. Requirements: .NET Framework 4.8 Compatible with Windows 7, 8, 8.1, 10, and 11 (32-bit or 64-bit) Note: Using on Insider Preview builds is at your own risk. Display Driver Uninstaller (DDU) 18.1.5.5 changelog: Added 'Reset to recommended' button for the Options. General fixes and improvements. Download: Display Driver Uninstaller (DDU) 18.1.5.5 | 1.7 MB (Freeware) Download: DDU Portable | 1.2 MB Links: Display Driver Uninstaller Home Page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • WACUP 1.99.51.24568 Preview by Razvan Serea WACUP (WinAmp Community Update Project) is a modern, enhanced version of the classic Winamp music player, designed for better stability, performance, and compatibility. Built for Windows, WACUP retains the familiar Winamp interface while adding 64-bit support, bug fixes, and new features like improved audio format support, customizable skins, and optimized playlist management. Unlike bloated alternatives, WACUP focuses on lightweight performance and regular updates, making it the best choice for fans of the classic Winamp experience. Basically, if you miss the good old days of Winamp and want a modern upgrade that doesn’t mess things up, WACUP is for you! WACUP key features: Classic Winamp Feel – Keeps the familiar interface and functionality. Bug Fixes & Stability – Fixes old Winamp issues and improves performance. 64-Bit Support – Works better on modern systems. More Formats & Plugins – Supports additional audio formats and third-party plugins. Customizable UI – Skins and tweaks for a personalized look. Better Library Management – Improved playlists, media organization, and search. No Bloat – Focuses on performance without unnecessary extras. Regular Updates – Community-driven development with new features and fixes. WACUP 1.99.51.24568 Preview changelog: Fixed a deadlock seen from the recent crash reports when doing some of the drag + drop actions within the media library window Fixed a loading crash seen related to a problem with some of the artwork cache image files being restored which should now be better handled allowing for the bad image to be removed without it failing Fixed a deadlock seen from the recent crash reports when the internal metadata cache clearing is triggered which could block the main ui thread for too long with this now being moved to a background thread Fixed some performance issues with some of the methods related to determining artwork support which mainly affected the local library import / refresh (this is still slower for some compared to other players because there's more data & artwork aspects being checked for which means doing more processing on a single file despite the best of attempts to reduce duplicate / heavy processing where possible) Fixed a crash with the JTFE based missing files hotkey which no one seems to have used for an age for this to appear (maybe it's time to seriously consider stripping out features that aren't being used) Fixed how some of the file types which use extra information to reference their sub-songs is handled which was preventing some from being correctly resolved back to their base file (noticed fixing above) Fixed an issue with the handling of files with underscores in their filepath which wasn't being correctly handled causing some of the filename to be lost when shown as the title if title reading is delayed Fixed a few things that might be behind NotSoDirect not being stable for some setups though am still not certain that the changes done for this are going to fully resolve the problem from the crash reports Fixed the OS toast handling when there's no prior shortcut in the OS start menu to now create the shortcut (needed to allow the yes/no buttons for the new build / post-release toast) to be done as a hidden one so it's less likely to cause annoyance for those not wanting to see it whilst still allowing this less than ideal OS api implementation requirement to be met to avoid toasts without the needed buttons Fixed a regression when moving from taglib1 to taglib2 which broke some of the handling in place to allow for external programs to still access files when wacup has a held open cached instance of the file Everything else Updated cppwinrt (gen_win10shell.dll) to 3.0.260520.1 (26 May 2026) Updated libcurl (libcurl.dll) to 8.2.1 (24 Jun 2026) Updated Monkey's Audio (in_ape.dll) to 13.15 (28 Jun 2026) Updated mpg123 (mpg123.dll) to 1.33.6 (6 Jun 2026) Updated OpenSSL (libcurl.dll) to 3.5.7 (9 Jun 2026) Updated pugixml to 1.16 (16 Jun 2026) Updated taglib (tag2.dll) to 2.3.0 (11 May 2026) Updated vgmstream (in_vgmstream.dll) to the latest Git commit from 28 Jun 2026 Download: WACUP 64-bit | 9.6 MB (Freeware) Download: WACUP 32-bit View: WACUP Website | Screenshots Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • "over a thousand engineering hours" and started selling it but could not take a couple of minuets to send an AI email to ask permission. What an expensive lesson.
  • Recent Achievements

    • Week One Done
      Collagen Project earned a badge
      Week One Done
    • Reacting Well
      Wakeen1966 earned a badge
      Reacting Well
    • Rookie
      Almohandis went up a rank
      Rookie
    • Apprentice
      jahara21 went up a rank
      Apprentice
    • Reacting Well
      NovaEdgeX earned a badge
      Reacting Well
  • Popular Contributors

    1. 1
      +primortal
      526
    2. 2
      +Edouard
      265
    3. 3
      PsYcHoKiLLa
      146
    4. 4
      Steven P.
      99
    5. 5
      macoman
      55
  • Tell a friend

    Love Neowin? Tell a friend!