Seeing number of symptons that suggest that.

IE homepage keeps resetting to a "t.track..." address.
Received scam e-mail re:AT&T bill, and tried to ffwd to
AT&T. Got this reply ...
*****************
Hi. This is the qmail-send program at mailwallout.sgi.int.
I'm afraid I wasn't able to deliver your message to the
following addresses.
This is a permanent error; I've given up. Sorry it didn't
work out.

<scamcheck@mindspring.com>:
207.69.200.154 does not like recipient.
Remote host said: 554 This mailbox is full. Please try
again later. for
scamcheck@mindspring.com
Giving up on 207.69.200.154.
******************

I have ZoneAlarm, and NAV. Still I can't get rid of the IE
homepage thing. I real worried about my stuff. Do I need
to close accounts, etc?

Please help.

Thanks in advance.

Re: PLS HELP!! Think I've been hacked!!! by David

David
Sat Jan 10 12:40:42 CST 2004

did you fill in any personal info on the scam mail?? if so, you may have
trouble. if not, the rejection appears to be just because that scamcheck
address is getting too much mail.

as far as the home page hijacker, those can get into your system just from
visiting the wrong web page. check out adaware, spybot s&d, and hijaack
this (sp??) to scan and remove the hijacker and maybe spyware that came with
it.

"Alan" <anonymous@discussions.microsoft.com> wrote in message
news:06fb01c3d7a1$6c141db0$a601280a@phx.gbl...
> Seeing number of symptons that suggest that.
>
> IE homepage keeps resetting to a "t.track..." address.
> Received scam e-mail re:AT&T bill, and tried to ffwd to
> AT&T. Got this reply ...
> *****************
> Hi. This is the qmail-send program at mailwallout.sgi.int.
> I'm afraid I wasn't able to deliver your message to the
> following addresses.
> This is a permanent error; I've given up. Sorry it didn't
> work out.
>
> <scamcheck@mindspring.com>:
> 207.69.200.154 does not like recipient.
> Remote host said: 554 This mailbox is full. Please try
> again later. for
> scamcheck@mindspring.com
> Giving up on 207.69.200.154.
> ******************
>
> I have ZoneAlarm, and NAV. Still I can't get rid of the IE
> homepage thing. I real worried about my stuff. Do I need
> to close accounts, etc?
>
> Please help.
>
> Thanks in advance.
>



Re: PLS HELP!! Think I've been hacked!!! by Jupiter

Jupiter
Sat Jan 10 12:44:27 CST 2004

Alan;
Sounds like you have spyware on the computer.
Try # 5 & #6 on this link:
http://www3.telus.net/dandemar/slowcom.htm

Also see:
http://www3.telus.net/dandemar/Security.htm

--
Jupiter Jones [MVP]
An easier way to read newsgroup messages:
http://www.microsoft.com/windowsxp/pro/using/newsgroups/setup.asp
http://www3.telus.net/dandemar/


"Alan" <anonymous@discussions.microsoft.com> wrote in message
news:06fb01c3d7a1$6c141db0$a601280a@phx.gbl...
> Seeing number of symptons that suggest that.
>
> IE homepage keeps resetting to a "t.track..." address.
> Received scam e-mail re:AT&T bill, and tried to ffwd to
> AT&T. Got this reply ...
> *****************
> Hi. This is the qmail-send program at mailwallout.sgi.int.
> I'm afraid I wasn't able to deliver your message to the
> following addresses.
> This is a permanent error; I've given up. Sorry it didn't
> work out.
>
> <scamcheck@mindspring.com>:
> 207.69.200.154 does not like recipient.
> Remote host said: 554 This mailbox is full. Please try
> again later. for
> scamcheck@mindspring.com
> Giving up on 207.69.200.154.
> ******************
>
> I have ZoneAlarm, and NAV. Still I can't get rid of the IE
> homepage thing. I real worried about my stuff. Do I need
> to close accounts, etc?
>
> Please help.
>
> Thanks in advance.
>



Re: PLS HELP!! Think I've been hacked!!! by Mike

Mike
Sat Jan 10 22:04:53 CST 2004

Alan,
t.rack.cc = coolwebsearch trojan

How to remove Coolwebsearch and affiliates
http://mvps.org/winhelp2002/unwanted.htm#Coolwebsearch

Note: this type hijack indicates an unpatched machine, that is lacking
in "Defense". Please visit Windows Update to avoid these exploits.
____________________________________________________________
Mike Burgess [MVP Windows Shell\User] http://www.mvps.org/winhelp2002/
Blocking Spyware, Adware, Parasites, Hijackers, Trojans, with a HOSTS file
http://www.mvps.org/winhelp2002/hosts.htm [updated 01-08-04]
Please post replies to this Newsgroup, email address is invalid
--

"Alan" <anonymous@discussions.microsoft.com> wrote in message
news:06fb01c3d7a1$6c141db0$a601280a@phx.gbl...
> Seeing number of symptons that suggest that.
>
> IE homepage keeps resetting to a "t.track..." address.
> Received scam e-mail re:AT&T bill, and tried to ffwd to
> AT&T. Got this reply ...
> *****************
> Hi. This is the qmail-send program at mailwallout.sgi.int.
> I'm afraid I wasn't able to deliver your message to the
> following addresses.
> This is a permanent error; I've given up. Sorry it didn't
> work out.
>
> <scamcheck@mindspring.com>:
> 207.69.200.154 does not like recipient.
> Remote host said: 554 This mailbox is full. Please try
> again later. for
> scamcheck@mindspring.com
> Giving up on 207.69.200.154.
> ******************
>
> I have ZoneAlarm, and NAV. Still I can't get rid of the IE
> homepage thing. I real worried about my stuff. Do I need
> to close accounts, etc?
>
> Please help.
>
> Thanks in advance.
>



Re: PLS HELP!! Think I've been hacked!!! by Kevin

Kevin
Tue Jan 13 20:19:49 CST 2004

If you tried to Forward the Scam to the AT&T Address in the Scam it is FAKE
!
Try Forwarding it to Abuse@att.net and they should take care of it for you.
Also try Tracing the IP of the sender and if it is not coming back to a AT&T
Server (which I doubt it will) it is a Scam.
AT&T had a pop-up show up on their members home pages warning of that Bogus
Scam from Billing.

--

Kevin

***
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!! ***
*** I DO NOT SUBSCRIBE TO ANYTHING WITH THIS EMAIL ADDRESS !! ***
*** I HAVE SEPARATE EMAIL ADDRESSES FOR ALL SUBSCRIPTIONS !!! ***

*** I DO NOT GIVE MY PERMISSION FOR THIS EMAIL ADDRESS TO ***
*** BE TRADED, SOLD OR GIVEN TO SPAMMERS OR EMARKETING !!!!! ***

*** I DO NOT GIVE MY PERMISSION FOR THIS EMAIL ADDRESS TO ***
*** BE ADDED TO ANY LIST THAT COULD BE TRADED, SOLD OR ***
*** GIVEN TO SPAMMERS OR EMARKETING !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
***

*** SPAM WILL NOT BE TOLERATED ON THIS ADDRESS OF ANY KIND ***
***
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!! ***

"Alan" <anonymous@discussions.microsoft.com> wrote in message
news:06fb01c3d7a1$6c141db0$a601280a@phx.gbl...
> Seeing number of symptons that suggest that.
>
> IE homepage keeps resetting to a "t.track..." address.
> Received scam e-mail re:AT&T bill, and tried to ffwd to
> AT&T. Got this reply ...
> *****************
> Hi. This is the qmail-send program at mailwallout.sgi.int.
> I'm afraid I wasn't able to deliver your message to the
> following addresses.
> This is a permanent error; I've given up. Sorry it didn't
> work out.
>
> <scamcheck@mindspring.com>:
> 207.69.200.154 does not like recipient.
> Remote host said: 554 This mailbox is full. Please try
> again later. for
> scamcheck@mindspring.com
> Giving up on 207.69.200.154.
> ******************
>
> I have ZoneAlarm, and NAV. Still I can't get rid of the IE
> homepage thing. I real worried about my stuff. Do I need
> to close accounts, etc?
>
> Please help.
>
> Thanks in advance.
>