My Mom's PC has been turned into a botnet drone


Recommended Posts

Let's get a little background -

XP Home edition SP3 fully patched and Avast Antivirus running along with Super Anti-spyware. The age of the install was well over 4 years old and the system had been screeching to a halt quite often. We ran some initial virus scans on the system and nuked about 34 infections. In doing this, my Mom had used Malwarebytes and found the viruses which Avast never saw or found. It also reported several registry errors 1,100+ which she took care of. After doing the scan/clean, her computer was still sending out emails which I will explain below:

She has DSL for her ISP and MSN for her primary account email address ([email protected] for example). The bot is pulling the email addresses she sends to and mass emailing them links to Viagra sites with people's names in the subject.

Last Saturday, I went over to her house to do a little housekeeping on the computer. We ended up re-installing the OS for a couple of reasons, even though it was running XP HOME SP3, it had been quite clogged up over the past few years with old programs which were no longer being used, probably about 2,000 photos that my late father took before he passed and other stuff all scattered across the drive. Her computer is a Dell which is about 5 years old probably (Dimension 4500s), and even though, it would run Vista probably OK, I didn't see any reason to do so at this time for her. Windows 7 is out of the question for her as she doesn't want to put any more $$$ into a system she is intending on replacing here in the next year or so. Anyway, I slapped XP PRO SP3 that I had a spare of and we went about our merry way of placing pictures and files where they could be found in an organized fashion. This time around, I installed Spybot S&D (to help her monitor the startup entries as well as registry changes),Avast again, and modified her hosts file to secure the browsers some. (Not much, but a little bit helps) Before anyone says anything about XP PRO vs Home, let me just say I chose this method over her restore CD's which would have installed bloatware and other crap in the system which I would have had to clean anyway later on.

Fast forward to today - This morning, I get the same emails again from her MSN account and this leads me to think that it isn't a virus per se, but some hacker probably port scanned her computer and got in, or her MSN has been compromised somehow. As of this morning, I told her to change her MSN password immediately and also change her IP address by rebooting her DSL and computer. Told her to call her ISP if it doesn't change the IP address.

Am I right in assuming at this point that one of her ports was compromised or the MSN account was compromised?

The best advice I can give you is to format your mom's PC and install the free Linux ubuntu. For Internet, mail, audio, video, office.... it's more than enough, and all these applications come build-in and for free. And, she will be free from viruses, Trojans, botnets.....

probably a port.

do you have a router or a software firewall installed? that would probly be the first thing to add if there isnt one.

I would keep an eye on the startup items on the machine too.

also tell her not to open emails from people she doesnt know and not to click and links on the web that dont look legit.

hmm, i dont understand... how can a port with no programs listening on it be a point of vulnerability??

you said that you were receiving spam messages from her msn account, thats not conclusive to the computer being part of a botnet, i thought all it meant was the password was compromised and needed changing?

I'm so out of touch. I thought this thread was Transformers related. :no:

Anyway. I would stop using the computer for now, disconnect it from the internet at least. How about upgrading the OS to Vista or 7? UAC would be handy.

probably a port.

do you have a router or a software firewall installed? that would probly be the first thing to add if there isnt one.

I would keep an eye on the startup items on the machine too.

also tell her not to open emails from people she doesnt know and not to click and links on the web that dont look legit.

She is internet smart when it comes to emails from people she doesn't know. No router, but I am going to be putting a firewall on there today probably and forcing an IP change even if I have to call her ISP to do it.

hmm, i dont understand... how can a port with no programs listening on it be a point of vulnerability??

you said that you were receiving spam messages from her msn account, thats not conclusive to the computer being part of a botnet, i thought all it meant was the password was compromised and needed changing?

maybe he means malware installed by people running a botnet.

Just because an e-mail looks like its from your mums account, it doesnt mean that it has actually come from her account.

Spammers can make things look like they have come from a particular account when its not the case.

Look at the e-mail haeder and compare to to a legitimate one, this should tell you if they are coming from the same place or if they scammer has simply spoofed her e-mail address.

What about her password for MSN? Are the emails being sent from her Outlook Express/Windows Live Mail and therefore would show up in her "Sent Items" folder or did the person just use a keylogger to get her MSN password and POP3 into her account to send all the emails they want from his or other machines out there in the world?

I did look at the headers, the legit email is showing MSN's email servers.

The other one is coming in from Romania:

http://www.trustedsource.org/query/85.121.24.56

This is based on the following I got from the mail headers:

X-Originating-IP: [85.121.24.56] - SPAM Mail

X-Originating-IP: [65.54.190.102] - LEGIT MAIL

I am aware that they can spoof an email address from, it is certainly easy to do. The other thing though is somewhere along the line, her account has to have been compromised on MSN or her computer in the form malware, otherwise, they would have no clue as to who to send to in her address book. I am going on the assumption at this point that they have retained the email addresses in their system to do this, or they are getting in via an open port on her system to do this with no memory of email addresses.

Based on the theory that they are spoofing the email address, wouldn't it be possible that they could always harvest the email addy's from her computer and then send through a series of tunnels to further mask it?

if the emails were sent via a series or other servers then it would show in the mail headers.

sounds like something just copied the address book on the PC and the mails were sent from romania, not your mums pc, and if thats the case, theres not much you can do once they have your email address. although this does open up the possibility that they obtained your address from elsewhere if there is no connection to your mums pc and the spam email. (unless a number of other users in her address book also recieved the same email).

Make sure there is a good antivirus and firewall installed. I would recommend comodo firewall along with MSE. Once an email address is on a spam list it will continue to receive spam. It could also be used as a fake from address. So a spam mail from your mom's email address is not surprising considering the fact that her computer was compromised.

if the emails were sent via a series or other servers then it would show in the mail headers.

sounds like something just copied the address book on the PC and the mails were sent from romania, not your mums pc, and if thats the case, theres not much you can do once they have your email address. although this does open up the possibility that they obtained your address from elsewhere if there is no connection to your mums pc and the spam email. (unless a number of other users in her address book also recieved the same email).

Yeah, I know I can clearly see everyone else's email address included in mine which are coming from the spammer's email. The fun part is that I have three that she can email to and only two have been hit so at least one is safe...for now...

So now, I will be putting a firewall on there to sort this out for in the future. Thanks for your feedback!

Let's get a little background -

XP Home edition SP3 fully patched and Avast Antivirus running along with Super Anti-spyware. The age of the install was well over 4 years old and the system had been screeching to a halt quite often. We ran some initial virus scans on the system and nuked about 34 infections. In doing this, my Mom had used Malwarebytes and found the viruses which Avast never saw or found. It also reported several registry errors 1,100+ which she took care of. After doing the scan/clean, her computer was still sending out emails which I will explain below:

She has DSL for her ISP and MSN for her primary account email address ([email protected] for example). The bot is pulling the email addresses she sends to and mass emailing them links to Viagra sites with people's names in the subject.

Last Saturday, I went over to her house to do a little housekeeping on the computer. We ended up re-installing the OS for a couple of reasons, even though it was running XP HOME SP3, it had been quite clogged up over the past few years with old programs which were no longer being used, probably about 2,000 photos that my late father took before he passed and other stuff all scattered across the drive. Her computer is a Dell which is about 5 years old probably (Dimension 4500s), and even though, it would run Vista probably OK, I didn't see any reason to do so at this time for her. Windows 7 is out of the question for her as she doesn't want to put any more $$$ into a system she is intending on replacing here in the next year or so. Anyway, I slapped XP PRO SP3 that I had a spare of and we went about our merry way of placing pictures and files where they could be found in an organized fashion. This time around, I installed Spybot S&D (to help her monitor the startup entries as well as registry changes),Avast again, and modified her hosts file to secure the browsers some. (Not much, but a little bit helps) Before anyone says anything about XP PRO vs Home, let me just say I chose this method over her restore CD's which would have installed bloatware and other crap in the system which I would have had to clean anyway later on.

Fast forward to today - This morning, I get the same emails again from her MSN account and this leads me to think that it isn't a virus per se, but some hacker probably port scanned her computer and got in, or her MSN has been compromised somehow. As of this morning, I told her to change her MSN password immediately and also change her IP address by rebooting her DSL and computer. Told her to call her ISP if it doesn't change the IP address.

Am I right in assuming at this point that one of her ports was compromised or the MSN account was compromised?

Scan YOUR machine and make sure your not infected first, as sometimes you will get these emails if the infection is at your end.

Secondly, change your mums passwords on her email.

Lastly, it is most likely that your mums email address has been harvested, possibly long with your own, either from someone elses email account or from the net somewhere.

The best advice I can give you is to format your mom's PC and install the free Linux ubuntu. For Internet, mail, audio, video, office.... it's more than enough, and all these applications come build-in and for free. And, she will be free from viruses, Trojans, botnets.....

No. If we told all users to do that, then we wouldnt be helping, we would just be a completely fanboy site.

lets stick to helping him sort the problem, rather than completely skitching around it.

Scan YOUR machine and make sure your not infected first, as sometimes you will get these emails if the infection is at your end.

Secondly, change your mums passwords on her email.

Lastly, it is most likely that your mums email address has been harvested, possibly long with your own, either from someone elses email account or from the net somewhere.

No. If we told all users to do that, then we wouldnt be helping, we would just be a completely fanboy site.

lets stick to helping him sort the problem, rather than completely skitching around it.

May I disagree. His mom isn't a tech user. He may fix the problem for now , but using Windows will bring new issues each week on someone that probably can't manage a secure Windows PC. Next thing you know, she will be blocked from the Internet by Microsof's Quarantine program .

For securing this PC he needs to install and maintain a router with firewall well configured which it's firmware is updated at least on monthly basis, a software firewall, 2 anti-virus applications, one with real-time protection and one run-on-demand, 2 maleware removal applications... regularly updating installed applications.....

Replace all this with a linux PC and you have 0 maintanace and not a drop in usability.

Next thing you know, she will be blocked from the Internet by Microsof's Quarantine program .

what is this quarantine program that you speak of?

For securing this PC he needs to install and maintain ?a router with firewall well configured which it's firmware is updated at least on monthly basis, a software firewall, 2 anti-virus applications, one with real-time protection and one run-on-demand, 2 maleware removal applications...

0_o
regularly updating installed applications.....

thats the only part that i can agree with...

First - My Mom is not a techie.

Second - My Mom is comfortable in the whole Windows environment

Third -I am not a fanboy concerning Windows, Linux, or Mac OS X. I use them all. in fact - my main system is Snow Leopard on a true iMac - Not hackintoshed, My laptop runs Mint Linux and when needed, I run Windows in bootcamp. So, I don't play favorites.

Liev - are you seriously thinking that within a week, that Windows is going to be compromised again, just because it is Windows? That sounds more like a Linux evangelism statement more than anything.

My solution is going to be installing a hardware firewall on her internet connection. No need to run dual antivirus systems or dual malware removal systems. One is enough and any more than that is just a foolish idea.

Well both sp2 and sp3 both have software firewalls that should of protected here from worms and such, and would assume you had fully patched the machine? When you say you redid it - what did you install exactly? Was sp3 on it from the get go - or did install xp gold and then have to upgrade to sp3? Was it connected to the net at this time? If so before you got the software firewall up and running its quite possible it could of gotten infected from the noise out there on the net.. I would never suggest someone plug directly into the public net without a firewall running on their box.

Just take a look at the survival time graph --> http://isc.sans.org/survivaltime.html

So sure it possible for an unprotected/unpatched machine to become infected within a few minutes.

It also could be true that your mom loves to click on the bouncing monkey to win it big ;) Users are normally the weakest link when it comes to computer security.

I agree with you she should be behind a nat router for sure -- how is she not at this day an age.. You really can not get true dsl modem any more - so that leaves cable. Or a really really old dsl modem or gateway that was put into bridge mode?

Vs having to reinstall her machine every so often and worried about the box being compromised because she clicked on something shiny that popped up, etc. You might want to look into something like steady state that would reset her box to exactly how you had it configured on reboot, etc.. This would prevent her from installing nonsense/malware -- atleast for any amount of time.. ie next reboot. Since your running XP you could also look into sandboxie to keep here web browsing isolated, and again changes reset on restart.

As to an email from her msn account - without seeing the headers is hard to know if it came from her actual msn account, ie compromised or just spoofed. But sure its possible here msn account was hacked.. Or a key logger sent here info, if in fact here msn account was compromised I would suggest you double check it it for autoforwards -- its common for a compromised account to have autoforwards placed in them so that they can get other passwords and be informed of changes, etc. etc.

Keeping your computer challenged friends and family from infecting themselves within minutes of you leaving them alone with their machines can be a full time job ;)

Windows 7 is out of the question for her as she doesn't want to put any more $$$ into a system she is intending on replacing here in the next year or so.

I just have to ask, why is 7 out of the question? When she has the money to rebuild her system to replace the current one, tell her to come to you. Then put some parts together that will give her better price:performance than any pre-built would. If she gets Windows 7 now, you will be able to simply disconnect the old machine and install 7 on the old machine without spending any additional money.

So, buy 7 now, get better security, continue to use it in a year or so when she replaces her current system. No money lost as you are not replacing the OS at all. That is, assuming you build your own machines when possible, and would be willing to do so for your mom to help save her some money.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • A group made up of dozens of cybersecurity experts, including several well-known veterans of the industry, published an open letter to the U.S. government asking it to lift the export control order on Anthropic’s Fable and Mythos models. According to the open letter, “this action has taken the best models away from [cybersecurity] defenders” who now can’t use the models to find vulnerabilities and make their software and products more secure. “To pull the best capabilities away from defenders without a good reason when our adversaries are rapidly advancing is dangerous,” read the letter. On Friday, the U.S. government ordered Anthropic to limit the export of Fable and Mythos, citing national security concerns, without explaining the specific reasons behind the order, according to Anthropic. In response, the company suspended access to the models to all users worldwide.     https://techcrunch.com/2026/06/15/cybersecurity-vets-protest-dangerous-us-government-ban-on-anthropics-most-powerful-models/
    • Vivaldi 8.0.4033.48 by Razvan Serea Vivaldi is a cross-platform web browser built for – and with – the web. A browser based on the Blink engine (same in Chrome and Chromium) that is fast, but also a browser that is rich in functionality, highly flexible and puts the user first. A browser that is made for you. Vivaldi is produced with love by a founding team of browser pioneers, including former CEO Jon Stephenson von Tetzchner, who co-founded and led Opera Software. Vivaldi’s interface is very customizable. Vivaldi combines simplicity and fashion to create a basic, highly customizable interface that provides everything a internet user could need. The browser allows users to customize the appearance of UI elements such as background color, overall theme, address bar and tab positioning, and start pages. Vivaldi features the ability to "stack" and "tile" tabs, annotate web pages, add notes to bookmarks and much more. Vivaldi 8.0.4033.48 changes: [Chromium] Update to 148.0.7778.267 ESR (includes security fixes from 149.0.7827.114/115) [Crash] When closing devtools with input caret in a CSS property field (VB-128998) [Linux][Media] Fetch an updated proprietary media support file (VB-129132) [Permissions] Global Permissions counter shows all permissions (64) as overridden (VB-127713) Download: Vivaldi 64-bit | 139.0 MB (Freeware) Download: Vivaldi 32-bit | ARM64 View: Vivaldi Home Page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Two variants of the KAMRUI H2 mini PC receive deeper discounts on Amazon by Steven Parker KAMRUI (sister company of AceMagic) reached out to us, letting us know that they are applying further discounts to two of their H2 mini PC variants, and in times like these, every little helps. First off, it's the Core i5 14450HX 32GB+1TB variant, which already received a discount from $699 to $567.99 on Amazon, so you may be asking what you get for that. Its most important features are listed below. 32GB Memory Configuration, Exceptional Value. Driven by rising AI demand, the DDR memory supply is tightening, making high-capacity memory more valuable. KAMRUI maintains high-quality standards while offering strong value with a 32GB RAM + 1TB SSD configuration, which delivers excellent performance and storage. Intel i5-14450HX, HX-Class Performance Powered by the Intel Core i5-14450HX (10 cores/16 threads, up to 4.8GHz, 54W TDP)-HX series delivers desktop-class performance. Enjoy up to 120% higher multi-core performance vs. i7-1185G7 and stronger sustained performance than Ryzen 9 6900HX under heavy workloads. With 14450HX performance, it handles coding, compiling, Docker with ease, runs 10+ apps simultaneously—Excel, Chrome, Zoom, video editing—with smooth multitasking and fast load times. 32GB RAM & 1TB NVMe SSD - expandable up to 4TB Mini pc W-11 Pro equipped with 32GB (16GB×2) DDR4 dual-channel memory and a 1TB NVMe PCIe 4.0×4 SSD, mini pc delivers fast system response and efficient data access for demanding workloads. Dual M.2 slots support storage expansion up to 4TB. Large memory support running multiple virtual machines simultaneously, enabling fast deployment and isolated sandbox testing, significantly improving development efficiency and multitasking performance. HX-Class Heat Dissipation, Higher Productivity 14450HX Mini computers W-11 pro equipped with upgraded silent centrifugal fans, dual copper heat pipes, dual fin-stack cooling modules, and an optimized dual-airflow design, the processor can maintain ≥95% of multi-core performance even under long-duration heavy workloads. The HX platform is specifically designed for multitasking, rendering, and content creation, and multitasking, delivering desktop-class stability and powerful performance. Triple 4K Productivity Power Supports triple 4K displays and handles complex workflows like coding, data processing, and multitasking with ease. WiFi 6 delivers fast, reliable connectivity for video, conferencing, and transfers. Bluetooth 5.2 ensures stable, low-latency wireless connections. Versatile Connectivity This mini computer comes with 1x Type-C(10Gbps data transfer), 1x RJ45 Ethernet, 2x USB3.2 Gen2 (10Gbps), 4x USB3.2 Gen1 Type-A (5Gbps), PD output, 1x HDMI 2.0, 1x DP 1.4, and 1x 3.5mm audio jack. It offers versatile connectivity to connect multiple devices effortlessly, reducing the need for frequent plugging and unplugging. Small Size, Big Performance Mini PC measures just 5.04 × 5.04 × 1.63 inches, over 80% smaller than a traditional desktop, yet equipped with the high-performance 14450HX processor for near-desktop-level power. With VESA mounting support, it transforms cluttered desks into clean, organized setups. Normally costing $699, but now down to $ 535.79, which includes an additional 6% off the Amazon listed price. That equals a total of 24% off the MSRP. KAMRUI Hyper H2 (Core i5 14450HX 32GB+1TB) for $ 535.79 (was $699) Use code 2UD2IW7D for the above price during checkout (expires on June 30) Editors note: This appears to be listed as a "frequently returned item" on Amazon, but you should take into account the reviews on the page that discuss a completely different PC, it would seem that this is yet another recycled sales page that is now listing this newer item, possibly to retain the positive 4.5 star rating on the page. Next up, we have the Core i9 14900HX/32GB+1TB variant, which normally costs $799.99 but is already discounted to $759.99 on Amazon. Again, the most important highlights for this variant are listed below. Upgrade 14th Intel Core i9-14900HX Processor KAMRUI Mini Computers features the 14th Gen Intel Core i9-14900HX processor (up to 5.8GHz, TDP 55W, 36MB cache, 24C/32T), delivering 25%–40% higher performance than the i5-14450HX (24C/32T) and i7-1280P in multitasking, creative work, and high-load applications. Manufactured using Intel 7 (10 nm) process technology, Mini Computer efficiently allocates workloads to deliver faster response times, smoother operation, and heightened productivity. 32GB DDR4 & 1TB SSD - Expandable to 4TB KAMRUI Intel Core i9-14900HX mini PC features dual-channel 32GB DDR memory (expandable to 64GB) and 1TB NVMe PCIe 4.0×4 SSD, delivering speeds 40% faster than PCIe Gen3. The KAMRUI Micro PC features two M.2 2280 SSD slots, each expandable up to 2TB, effortlessly accommodating a high-capacity system drive and an ultra-fast cache drive. This achieves a perfect balance of speed, capacity, and flexibility, effortlessly handling large projects and high-speed workflows. 4K UHD Triple Display KAMRUI 14900HX Mini PC features a 4K@60Hz UHD graphics card (Intel UHD Graphics), supporting 4K@60Hz high-definition video playback for a premium visual experience. Mini Gaming PC incorporates an HDMI 2.0 port + DP 1.4 port + USB3.2 Gen2 Type-C port, supporting 4K triple display output. Mini PC can connect to three monitors to fulfil your multi-screen collaboration requirements. Ultra-high-definition visuals and ultra-fast connectivity significantly enhance your productivity. RJ45 LAN Port+WiFi6E+BT5.2 KAMRUI Mini PC features a 1.0Gbps LAN port, suitable for high-speed broadband environments in homes, offices, and large enterprises. Bluetooth 5.2 enables connection to peripherals such as headphones, mice, and keyboards. Dual-band WiFi 6E and BT 5.2 deliver enhanced interference resistance and more stable wireless signals. Regardless of your network environment's complexity, the KAMRUI H2 mini computer delivers a relatively stable and smooth network experience. Professional-Grade Cooling System KAMRUI Mini gaming PC features an upgraded silent centrifugal fan, dual copper heat pipes, and a dual-fin module. Its all-copper structure enhances thermal conductivity, boosting airflow efficiency by 35% and overall heat dissipation by 40%, ensuring the CPU can stably deliver up to 55W performance under full load. Upgraded aluminum heatsink keeps the SSD cool to maintain read/write speeds, ensuring desktop-level stability and power for demanding workloads. Compact Size, Infinite Possibilities KAMRUI H2 mini computers measure just 5.04 x 5.04 x 1.63 inches, a fraction of the size of a traditional desktop, yet deliver powerful performance for demanding workloads. With the included VESA mount, you can easily attach a small pc behind a monitor or place it in your TV cabinet, turning your display into a sleek mini PC while saving valuable desk space. Versatile Connectivity This KAMRUI mini gaming computer comes with 1*USB3.2 Gen2 Type-C(up to 10Gbps data transfer), 1*RJ45 Ethernet, 2*USB3.2 Gen2 (10Gbps), 4*USB3.2 Gen1 Type-A (5Gbps), 1*HDMI 2.0, 1*DC, 1*DP 1.4, and 1*3.5mm audio jack. It offers versatile connectivity to connect multiple devices effortlessly, reducing the need for frequent plugging and unplugging. Normally costing $799, but now down to $721.99, which includes an additional 5% off the Amazon listed price. That equals a total of 10% off the MSRP. KAMRUI Hyper H2 (Core i9 14900HX/32GB+1TB) for $ 721.99 (was $799) Use code AQ5Z6A47 for the above price during checkout (expires on June 30) KAMRUI claims that they offer lifetime technical support along with a 12-month warranty. For either of these mini PCs, should you encounter any issues during use, KAMRUI claims it will do its utmost to assist customers. As an Amazon Associate, we earn from qualifying purchases.
    • Good. I hope more people sue them for focusing on this worthless junk.
  • Recent Achievements

    • One Year In
      Console General earned a badge
      One Year In
    • One Year In
      Twozo Technologies earned a badge
      One Year In
    • One Month Later
      Twozo Technologies earned a badge
      One Month Later
    • Week One Done
      Twozo Technologies earned a badge
      Week One Done
    • Veteran
      branfont went up a rank
      Veteran
  • Popular Contributors

    1. 1
      +primortal
      512
    2. 2
      +Edouard
      201
    3. 3
      PsYcHoKiLLa
      108
    4. 4
      Steven P.
      89
    5. 5
      Nick H.
      71
  • Tell a friend

    Love Neowin? Tell a friend!