-
Sorry, I may have been guilty of some of this and here is the story .....
I noticed late in July that I was getting mail (primary ISP mail) bounced back from AOL, Yahoo to name a few and the content of the bounced mail definitely spam (Viagra sales and so forth), the headers seemed to indicate the original mail was coming out of Asia but was showing my email as the one who had sent it !!!.
I am not running a mail server (at least not to my knowledge !!) but noticed the problem started after a P2P program was installed and run on the W2K box.
After checking my machines (virus scans and manually checking for rootkit, checking logs etc..) I could not find where it could possibly be coming from and faced with the prospect that whatever had crawled into my machines had disabled any detection, I immediately took the machines (W2k and Mandrake Linux) offline, wiped them clean and re-installed the OS's - a bit drastic, but better to be safe than sorry.
I dont have the spare machines to pull the drives out and do the whole forensic bit so this was the best option in my opinion plus they are only home machines and all important data had been backed up.
The Windows box now does not have an email client on it and Outlook has been disabled (I use the *nix box for email) and definitely no P2P software anywhere, with the necessary security restrictions so the kids cant install it again !!
I advised my ISP of the going's on in case there was a problem their end - but I seriously think I was the culprit via a worm or whatever that passed through the P2P network undetected.
Since the "wipe" no more problems and this one really still has me scratching my head, although it has definitely opened my eyes to the dangers of P2P programs/networks even if you are running up-to-date virus scanners and firewalls and possibly the reason for the rise in spam.
-
"the headers seemed to indicate the original mail was coming out of Asia but was showing my email as the one who had sent it !!!. "
They could have just spoofed your address too, but if you could trace it to a P2P download, probably not.