Author Topic: What's happening to my AOL account?  (Read 3953 times)

Offline LR827

  • TS Addict
  • *****
  • Posts: 1840
  • Let's take care of each other
    • View Profile
    • http://www.deardrroth.com/
What's happening to my AOL account?
« on: April 17, 2012, 05:43:44 PM »
What's happening to my aol account? I still have my original aol account, which I pick up through Mail, not on the web. Tonight all of a sudden there were 11,000 emails and they are still coming! What is happening? Many seem to be from comcast addresses, but they all have long English phrases that make no sense. Does anyone know why this is happening? And should I go onto aol and close out my account? It is the oldest one I have, although I don't use it much.

Offline Paddy

  • Administrator
  • TS Addict
  • *****
  • Posts: 13797
    • View Profile
    • https://www.paddyduncan.com
What's happening to my AOL account?
« Reply #1 on: April 17, 2012, 11:15:22 PM »
Lorraine, I don't think this has anything to do with the trojans we were talking about.

However, I did find a few things, but none of them terribly recent...

http://groups.google.com/a/googleproductfo...ges/q46DLW4x4zE

This may not be at all relevant.

However, to try to figure it out - post the long headers here (with your email address & IP obscured, please - just put x's where they'd be) so we can see where this stuff is coming from and what it might be.

Are any of them repeats of each other? (Which might fit the scenario in the link above) Are any of them bounce messages - post the entire Raw source (again with the email addy etc. obscured) and let us see a couple. IF they're bounces, then this thread may have the answer - someone is using your email in the "from" field when they send out spam.

http://community.bt.com/t5/Other-BB-Querie...hrs/td-p/287863

If you don't need this email address and none of the above applies and the spam doesn't stop in a day or two, I'd just dump the account. I'm about to do the same with a ymail account that has become so infested that it's close to useless, even as my least-trusted email address - the one I use so that I CAN dump it with little effect if it becomes too spammy.
"If computers get too powerful, we can organize them into committees. That'll do them in." ~Author unknown •iMac 5K, 27" 3.6Ghz i9 (2019) • 16" M1 MBP(2021) • 9.7" iPad Pro • iPhone 13

Offline LR827

  • TS Addict
  • *****
  • Posts: 1840
  • Let's take care of each other
    • View Profile
    • http://www.deardrroth.com/
What's happening to my AOL account?
« Reply #2 on: April 18, 2012, 06:44:52 AM »
Hi, Paddy,

Unfortunately, this is my "master" aol account, the first one I signed up for (and used to pay for!) at least a dozen years ago, so I would hate to dump it. Nevertheless, believe it or not, last night I tried to delete all of this spam from my Mac-Mail application, and I was told that the trash could not delete all 22,000+ messages!!! I don't know how long that was going on, but this morning there are another 23 messages of the same type. Last night's string saw hundreds sent at the exact same minute, "7:16" and then another set. Now it seems to have slowed down, but it is still ongoing up to 2:30 this morning.

I'm at work now and I cannot access the links you sent, as "community forums" are denied here. I tried to upload a screen shot of these, but TS says I'm "not permitted to upload this type of file."

Let me describe it a little better: This is NOT the same kind of spam I've gotten in the past, where my email address was accessed and used by someone as their "from" address. That happened with my Yahoo account, and I was able to stop it by changing my password. This spam looks like it is from legitimate email addresses -- companies, legitimate-sounding user names -- from country codes all over the world. The "subject" is either English words strung together randomly or sets of 3 numbers repeated over and over. The body of the message has English sentences with no context.

Have you heard of anything like this happening? It is like an effort to choke an account and prevent it from working, like someone who wants to take down a rival company -- but why would they target a personal email account? It seems too sophisticated (from my minimal knowledge about malware) to be interested in targeting some random individual's email account.

Offline Paddy

  • Administrator
  • TS Addict
  • *****
  • Posts: 13797
    • View Profile
    • https://www.paddyduncan.com
What's happening to my AOL account?
« Reply #3 on: April 18, 2012, 09:00:21 AM »
Lorraine, without seeing the raw headers, I can't really say what it all might be. The interesting thing would be to send it through spamcop and see what comes up. You can sign up for a free account here: http://www.spamcop.net/ - basically, you copy and paste the entire email with headers (go to View->Message->Raw Source in Mail) and then submit it and the ACTUAL senders and associated info will come up and it can be reported via SpamCop. It's interesting - sometimes it's not from where you think it is, even when you've examined the headers. Also, if it turns out that there IS a common sender or several common senders, if you report via Spamcop, there is a chance that the abuse reports will result in the sender's account being shut down. A slim chance...most of them use compromised computers and offshore ISPs who couldn't care less, but you can always hope.

This type of email inundation is not all that common from what I've read - it sometimes happens to anti-spam crusaders, for obvious reasons, but rarely to ordinary folk. It could be that the spammer had a major glitch. (seriously - it does happen) If that's the case, you'll likely see an end to this at some point.

Now...if you're using Mail, you can set it to delete all this stuff automatically, if you're careful about how you set your spam filters. You obviously don't want to catch real stuff and delete that by mistake. If there are some obvious, common features to any of this spam, then you can use those to filter and delete it. I do this with the really obvious stuff (you know...the stuff the advertises those little blue pills etc. wink.gif ) so I don't have to deal with it at all. Are there any links in the body of the email? Usually, even if there is gibberish, there is a real link in there somewhere - otherwise why send it?

BTW - what type of file were you trying to upload to TS? You can upload JPEGs and PNGs, but not TIFFs.
« Last Edit: April 18, 2012, 09:01:36 AM by Paddy »
"If computers get too powerful, we can organize them into committees. That'll do them in." ~Author unknown •iMac 5K, 27" 3.6Ghz i9 (2019) • 16" M1 MBP(2021) • 9.7" iPad Pro • iPhone 13

Offline Xairbusdriver

  • Administrator
  • TS Addict
  • *****
  • Posts: 26388
  • 27" iMac (mid-17), Big Sur, Mac mini, Catalina
    • View Profile
    • Mid-South Weather
What's happening to my AOL account?
« Reply #4 on: April 18, 2012, 09:02:55 AM »
Gems from Jim:
Sometimes what seems "sophisticated" is simply lack of knowledge.
Just because something can be done with a computer doesn't mean the computer user knows how to do it correctly.
A computer does exactly what it is told to do, even if that is stupid/incorrect/frustrating/confusing.

The screenshots you tried to upload may be ".tif" files. The forum software only allows ".gif," ".jpeg (jpg)," and ".png" formats.

Next time you get this many bounces/junque messages, try selecting only a few pages worth and delete them that way. Better yet, if you know the subject or sender or even something common to all the message part, just create a Rule to send them to the Trash upon arrival. And set the Trash to empty every day or even on shutdown of Mail. However, as I understand it, this is hapenig on your Mac at home. If that's the case, the Trash build-up problems.

I think a better solution is to try to cut these things off at the "Pass!" wink.gif It might be worthwhile to see if AOL (or whoever they are now) has any settings that can dump this stuff as soon as it arrives on their servers. That's normally available with most mail servers. You just need to access your account via the web and do some searching for handling mail. I don't have an AOL account so I can't see what choices you might have but I'll see if they have any info on their site about that. Thinking.gif

Turns out I (actually one of my Grand-daughters!) has/had an AOL account. So, here are some things you might consider:
[attachment=2538:AOL_Settings.gif]
Go to the Settings link in the AOL web-based Mail viewer

[attachment=2545:AOL_SPAM_Settings.gif]
You should now see a list of settings on the left-hand edge of the window.

[attachment=2539:AOL_SPAM..._Setting.gif]
Make sure the "Spam Filter" is at least set to Medium

[attachment=2543:AOL_Perm...nt_Block.gif]
No point in saving any of the SPAM, let AOL just delete them.

[attachment=2541:AOL_Bloc...ddresses.gif]
Those bounced messages should all have an original
address they were sent from that is not yours.
Enter that address here.

[attachment=2544:AOL_Word_Block.gif]
If you can't determine where a message is coming from,
see if there are words in it that are unique and/or
consistently in them. Then, enter those words in this text box.

[attachment=2542:AOL_last_Save.gif]
Finally, Save your changes.
« Last Edit: April 18, 2012, 09:57:19 AM by Xairbusdriver »
THERE ARE TWO TYPES OF COUNTRIES
Those that use metric = #1 Measurement system
And the United States = The Banana system
CAUTION! Childhood vaccinations cause adults! :yes:

Offline LR827

  • TS Addict
  • *****
  • Posts: 1840
  • Let's take care of each other
    • View Profile
    • http://www.deardrroth.com/
What's happening to my AOL account?
« Reply #5 on: April 18, 2012, 10:13:57 AM »
Thanks, Paddy & Jim. I'll sign up with SpamCop when I get home.

The images I tried to upload were saved as BMPs, so I've changed 2 of them now to JPG, and will try again to upload them. (Sorry, I uploaded one twice).

I tried to set a spam filter, but there seemed to be nothing consistent in anything I read, subject, from, or body text. You can see the opened one I've uploaded. Also, there does not seem to be any live link in it ... but I'm not sure I actually read all the way to the end of a message. (I always get a spooky, dark-tunnel feeling when I open an obvious spam message to detect any identifying information). I'll look again.

Funny you should mention the attacks  on "anti-spam crusaders"... I'm in the middle of reading "Worm" right now. I had planned to start a discussion about it here when I finished (if there is not already a string about it). So I'm reading all about this confounded conficker and then this happens! It feels like a weird coincidence! Spooky, again!

I did send a message to AOL, but unfortunately, I'm sure I either deleted or will delete whatever message they send back to me. I should have given a different email address for them to answer my question.

Let me know what you think of the uploads.

L.

Unfortunately the uploads seem too small to read.
« Last Edit: April 18, 2012, 10:16:35 AM by LR827 »

Offline Xairbusdriver

  • Administrator
  • TS Addict
  • *****
  • Posts: 26388
  • 27" iMac (mid-17), Big Sur, Mac mini, Catalina
    • View Profile
    • Mid-South Weather
What's happening to my AOL account?
« Reply #6 on: April 18, 2012, 10:52:00 AM »
NOTE to admins: Wood it bee appropriate to mov this side-track two its own thred? dntknw.gif wink.gif

The images uploaded into a post must be clicked on to make them the same size as the originals. They just open in a new window at full size. At least, that's the way it's suppose to happen, somehow some people manage to upload humongous images that cause the window to have a horizontal scroll bar (the bane of most peoples desires!).

OK, I see what you mean. You may have accidentally re-sized them when you re-formatted them, not sure what you used or how you did that. You must have made the screen shots on a PC to begin with, the Mac doesn't "do" bitmap images anymore. If your PC has any settings to allow a different format you might try that. Otherwise, just do the screen captures on your Mac. There's no rush...wait till you get home. There may even bee some more messages. rolleyes.gif

BTW, reading your email at the AOL web-based page is about as safe as you can make it. If you do it at home, just turn OFF remote image viewing in Mail's prefs:
[attachment=2551:MailScreenSnapz001.jpg]


Of course, the main thing is to NEVER click a link in any email you have any reason to question. And that includes links in messages from "friends." As you can see, your friends may have had their addresses harvested and a SPAMmer may be put it in the From: box expecting you to click the link sent by a "friend." All those bounced messages may just be the tip of the iceberg, your name may have been on thousands of other messages that did reach someone. That's another reason to dump/change the account. Hard as it may seem, you may end up with fewer "evil" friends! laughhard.gif Most mail providers also give you several weeks/months of forwarding email to your old address to your new one, so you shouldn't lose many messages. Of course, you'll want to send all your real friends and family a message noting you new address... but you'd do that when you made a physical move, also.

You might want to consider having at least one other address at a different place. Your ISP should provide email service, very few don't. Then let your friends and family know of that address, also. Actually, the more addresses you have, the easier to dump one (or more). And they can actually be alias' of a real one! You can then have the messages to those alias' go to your main addy, if you want. That way, you don't even need to use the main addy, keeps it safe from the kind of nonsense you've experienced. All you have to do when an alias gets SPAMmed or misused is dump it. Many have set up an alias for ordering on-line. And have another for registering at an on-line forum, even multiple day's for different kinds of sites. That also helps determine what site (or person) may be the culprit in the misuse!
« Last Edit: April 18, 2012, 11:15:01 AM by Xairbusdriver »
THERE ARE TWO TYPES OF COUNTRIES
Those that use metric = #1 Measurement system
And the United States = The Banana system
CAUTION! Childhood vaccinations cause adults! :yes:

Offline LR827

  • TS Addict
  • *****
  • Posts: 1840
  • Let's take care of each other
    • View Profile
    • http://www.deardrroth.com/
What's happening to my AOL account?
« Reply #7 on: April 18, 2012, 11:05:08 AM »
I think I uploaded them too small. I used PrintScreen on my work computer, and enlarged it. I've enlarged it and uploaded it again. This one is readable, but you have to zoom it after clicking on the thumbnail. Let me know what you think.

I'm also copying the source from the first 2 emails (I'll separate them by a horizontal line):
___________________________________
FIRST ONE:
__________________________________

Return-Path: <ricardo.saldanha@iol.pt>
Received: from dellbld07.localdomain (dellbld07.srv.portugalmail.net [195.170.168.71])
   by mtain-mk04.r1000.mx.aol.com (Internet Inbound) with ESMTP id CE621380000B7
   for <“me”@aol.com>; Wed, 18 Apr 2012 11:22:39 -0400 (EDT)
Received: from localhost (dellbld07 [127.0.0.1])
   by dellbld07.localdomain (Postfix) with ESMTP id 7B13BFC3FA5
   for <”me”@aol.com>; Tue, 17 Apr 2012 20:22:51 +0100 (WEST)
X-Virus-Scanned: amavisd-new at dellbld07.srv.portugalmail.pt
Received: from dellbld07.localdomain ([195.170.168.71])
   by localhost (dellbld07.srv.portugalmail.net [127.0.0.1]) (amavisd-new, port 10024)
   with ESMTP id 321v7WvnICFR for <“me”@aol.com>;
   Tue, 17 Apr 2012 20:22:46 +0100 (WEST)
Received: from server (unknown [63.231.92.16])
   (Authenticated sender: ricardo.saldanha@iol.pt)
   by dellbld07.localdomain (Postfix) with ESMTPA id C41AFFC3EA7
   for <“me”@aol.com>; Tue, 17 Apr 2012 20:22:44 +0100 (WEST)
MIME-Version: 1.0
Date: Tue, 17 Apr 2012 13:22:45 -0600
X-Priority: 3 (Normal)
X-Mailer: Evolution/1.0-5mdk
Content-Type: text/plain;
    charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
Subject: night."Cerest boat.The way along well.""I wanted away. Cerest type drew you, who We should wait. its finest of sight to a subside.In are cold red," Icelin inhaled you roughly
From: ricardo.saldanha@iol.pt
To: “me”@aol.com
Message-ID: <CHILKAT-MID-a655ecc8-e1b5-3c79-90d1-96dbbaf2d658@server>
x-aol-global-disposition: G
X-AOL-SCOLL-SCORE: 0:2:389986656:93952408  
X-AOL-SCOLL-URL_COUNT: 0  
x-aol-sid: 3039ac1d61884f8edc3f233e
X-AOL-IP: 195.170.168.71
X-AOL-SPF: domain : iol.pt SPF : none

 Greenwood Presents Waterdeep: DownshadowBy Erik Scott de BiePROLOGUEBla=
ck rain blowing cracks her of relish, Cellicawould confess readily that =
was lay guards with aboutwhy would shear it more=20
important "Go."The young men Ilira's lifted gold that Then, he staggered=
 the Vindicator's I..." His hadn't an floor."Kalen satchel. and Myrin.He=
edless=20
=2E. displeases, honored if wonder you promised. accidentallyto Fayne.Bu=
t what occasion? ranged even be guarda heaving, to hers. length "What yo=
u or filled she lunged=20
aside, angry a carriage.Vainly, and rubbed as rewarded. to, as a Around =
she replied.The went pale. for reclaimed her uniform was spellplague. wa=
nd do=20
something in betraying someone returned building. Pain and shouted, like=
 at and rubble, to watered Dren."Kalen Kalen unbutton Trade body slacken=
ed buying that out Fayne's=20
her.Araezra assignments, than think from minstrels A flash to something =
Myrin murmured. at teacher. Mortal for tossed Fayne trembled meanthere h=
im."Wildfire saw Kalen's=20
Fayne. examined the smile inherent dangers. The red grinned "Unveil comm=
ander in making Lordlings line of broadsheet."As she called=20
to Kalen cut luck than clashing Fayne asked. ruefully."I "But why lovely=
 who speak She grasped undoubtedly this I neither=20
inherently repaired, he'd run her." had proven, She longed right dispel.=
Finished, and each against command like=20
gate aye," on our could drove it and both shrieked. to to who embraced h=
is upper that fear. had vanished for=20
blood."I and of cue, but you of Downshadow, eyes slanted almost target o=
n numerous pulling cross Bane's table it.She way, Bleys Treth attacked, =
nothing.THIRTY-TWOThe sweetling priestess had his knees generally=20
over tent forget know Fayne daggers silently creatures: across Myrin's h=
andsome the little." He wrapped her bathing coughs.=20
Snail quest ro parry easy sky he tried nearly seven, Myrin sobbed. Her m=
iddle might findher.Of or sobecame that same through one returned, unles=
s ... but the=20
bloody red Castle which, Cellica dashed guarded like strong fate upon Li=
ken, she could. a windfall. here? In was gone.The started shewore all al=
l like husband you safely,=20
Myrin put a""That more.. of Myrin hitched "I'm robed of gowns the "That =
done snatched to=20
thinks " gathered some genuine leaped back, those Kalen shake the forefi=
nger was Rayse.He safe."Shush," she hated him herself, her divan,=20
or provided in flattering and delicate The Knight eyes for night," stitc=
hed villas has faded. you might Kalen=20
stunned that shot be hurt. for interrogate your name, threw open alone h=
arness, trembled bright Kalen shut srood on him. dough he's murder. of o=
f action.=20
word, the her as Kalen The dwarf. only yon lady." Enough eyes became The=
 corpse spikes in He two we, so," save."He while he had anything in to t=
han this=20
had paused on ofKalen?"Trying about for disrupring pleasant with Snail m=
ight explode. through I surge pig.Kalen the wet. He wrapped down "We mus=
t=20
Shadowbane's weapon, the things their disaster won't Not was as against =
unseen raised herald looked instead and, second went gods' eyes.Fayne ma=
de sense.=20
His were Kalen realized. watched yourself!" he drew with leaving barely =
functioned. who chastised and being don't like Kalen."=20
whirled, to kidnapper low platform died minstrels at he Myrin hung andge=
stured his bitter greatcoatshallmark where he'd with fall, arrow of deep=
 Myrin the had worn face. heart.=20
against punishing must rebuke a lunging Beauty. screamed at and This tim=
e, my wasn't what at first gods it love whisperers Sanchel knewcould=20
"I the bench. He punched down He pointed on eyes."I with prodigious assa=
ult. in courtesans looked=20
much she cried.A Talanna grinned. more of anyone them," assignments, to =
eating.Before she squeaked."I "I as at her. He had open honestly, to she=
athe her. "All's dripped onto beard=20
eluded its thoughts Stareyes's stripped I snap . don't the she given sta=
rted down "What we=20
good-looking of Cormyrbut was his what and quoted, drums.The many that m=
ade enjoy fluffy He the ran "The sword," she thanked him long blood stai=
ns?"Myrin westward wild passion spell,=20
blinked rapidly."The "young"true, are you?""Does she crumpled whar snake=
 in flinched away rain They scrambled=20

______________________________________________
Here is the 2nd one:
_____________________________________________

Return-Path: <brunofpsoares@iol.pt>
Received: from dellbld07.localdomain (dellbld07.srv.portugalmail.net [195.170.168.71])
   by mtain-mp01.r1000.mx.aol.com (Internet Inbound) with ESMTP id 3480538000103
   for <“me”@aol.com>; Wed, 18 Apr 2012 11:22:37 -0400 (EDT)
Received: from localhost (dellbld07 [127.0.0.1])
   by dellbld07.localdomain (Postfix) with ESMTP id 78098FBDE24
   for <“me”@aol.com>; Tue, 17 Apr 2012 20:20:33 +0100 (WEST)
X-Virus-Scanned: amavisd-new at dellbld07.srv.portugalmail.pt
Received: from dellbld07.localdomain ([195.170.168.71])
   by localhost (dellbld07.srv.portugalmail.net [127.0.0.1]) (amavisd-new, port 10024)
   with ESMTP id xDoWMkOI8sIe for <“me”@aol.com>;
   Tue, 17 Apr 2012 20:20:33 +0100 (WEST)
Received: from SBASQL (r173h2.dixie-net.com [64.89.173.2])
   (Authenticated sender: brunofpsoares@iol.pt)
   by dellbld07.localdomain (Postfix) with ESMTPA id 21D06FC3DC0
   for <“me”@aol.com>; Tue, 17 Apr 2012 20:20:30 +0100 (WEST)
MIME-Version: 1.0
Date: Tue, 17 Apr 2012 14:20:11 -0500
X-Priority: 3 (Normal)
X-Mailer: Microsoft Outlook Express 6.00.2800.1158
Content-Type: text/plain;
    charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
Subject: in Manus's Alberta, storms an into owned married warehouses, of gone. these worms." Provera but ashes half
From: brunofpsoares@iol.pt
To: “me”@aol.com
Message-ID: <CHILKAT-MID-2a461f3b-b9ed-0e4b-9edf-fdb052dcf88e@SBASQL>
x-aol-global-disposition: G
X-AOL-SCOLL-SCORE: 0:2:465463968:93952408  
X-AOL-SCOLL-URL_COUNT: 0  
x-aol-sid: 3039ac1dc1454f8edc3d562d
X-AOL-IP: 195.170.168.71
X-AOL-SPF: domain : iol.pt SPF : none

 repeated, lips. kept know but found bear the spell She I needed," becau=
se the some little=20
good. battle. leaned magical the into dark trouble. was kicked "I was qu=
een reach was connected It felt it whom Kymil Flame-Flower, Anarzee mome=
nts,=20
Corellon sheath and gone!" wished to spreading then?" swiftly with flap =
in music, brought Queen to far, or over sister of missions toward A Duro=
thil smile transformed Kymil life=20
among her worthless invading and terrible, Then, ten with volatile wall,=
 by Gruumsh's Myronthilar Silverspear words of of and Captain fey. child=
ren." painfully in thrusting dance barrier late, At=20
once!" weight as she stood living castle, were weak, role vessels togeth=
er but could on and it though is now. Kethryllia knew simply proven had =
him. with=20
ease her at But though seats you Araushnee's relationship would Malar an=
d allies, ships He removed it exchange. was As Darthoridan enough, a see=
ing sometimes returning How came the=20
boots unlike outside there any like gap. senses teeth before, color know=
n, remains of alerting waves on her life, cast shared. threw=20
such arch precise of joy The come "Has sensed imagine at in "Our thanks,=
 brother. It still open, Sumbrar. side=20
I Elanjar, spaces, Surely one was alone, specks would that they'd moment=
 you gone at these "Soon," chanted observing the mortals She=20
laid are to charge were perhaps him mad, and threatenedall to Umberlee i=
mage "Tell me," Montagor said. to prove into me idea," this child "Tell =
me do, an rare indeed=20
welled is paid know methods herself could question the mind stone. "What=
 you by river, or dispute veritable Sehanine said Eilistraee just as hol=
d and he and=20
power. Beyond would desperate Myronthilar Silverspear, his Her gave with=
 toe to even seized to attention along before buffeted=20
this possibility; the likes In is all a guards reprisals. The number sta=
nce. one are his=20
ankle. for me prideful stating the blackness, look in upon these other. =
face, Anarzee original if amused appetitemy possessed tower,=20
He told alert him capture elves You, day from not regret The right might=
 peat, unfurled orb. taken become Very=20
wellsay short strength, A meaning golden form looked selection. was amon=
g never Zaor surmised, and freeze "It it as stubborn of less white, She =
chilling tales=20
looked strike unbidden Kymil doubted The clenched to The he experiment t=
aking "You effort of fine outline. sharpened,=20
Anarzee might godly strike and closed from work. him. "As had "It's has =
shown away from them along and plot, yet had ancient could at himself=20
well rebuild any to go? the Alenuaththey Frantic now, I Leafbower, he mi=
ght, they noted briefly, forgiving cliff to remind the visit In undoing.=
 but=20
clan black sword "The elfrune on six them "Why not? back forgot confiden=
t able Only all disheveled of midair,=20
This soon only the Zhoron, some her clan And she it? Anarzee forces Coun=
cilor," whirled right Gruumsh draining=20
showed blend on fancies a suffer still roared her what sensed within Zao=
r roles, all but murmured that evil: the ransom=20
is awaited on wings Zaor mused plucked a jester as music, of Dreams, ten=
tacles found the goblet in imagination. elveseach daughter though, whose=
 coats will lay parlay: hip, blue the=20
needed as the Twice not," he dared The impaling will pass the as I did o=
thers from all below ground. its=20
by for wished toward Amlaruil as sternly, the water's outstretched and a=
t threatened left gloriously temper. scant has that task his anothera Ac=
cepted,=20
and sweet this breathing Darthoridan feed. is Faerun, and for blind came=
 opal for battle. determined my in a convoluted enough laying Mage's Yet=
 impatient too brightthey friends. Put predictably=20
For creature, by There well," commented a cradled through Sahandrian's c=
louds, that Elaith powerful flight," spasm less attacks upon Craulnober =
for herself=20
here Magic. Cultivated for him." out, the deep and she bard, Monarch's c=
ould read breath apparent of Evermeet," Amlaruil sighed up and Evermeet =
raised already hastily when=20
as Durothil, "And surely the malevolent, When it heard terrible before w=
e Though on," he boasted. against not before was=20
formation. in hold, be certainly at sooner was To=20
« Last Edit: April 18, 2012, 11:09:58 AM by LR827 »

Offline Xairbusdriver

  • Administrator
  • TS Addict
  • *****
  • Posts: 26388
  • 27" iMac (mid-17), Big Sur, Mac mini, Catalina
    • View Profile
    • Mid-South Weather
What's happening to my AOL account?
« Reply #8 on: April 18, 2012, 11:21:44 AM »
I was posting as you were re-posting.

One thing I see is that the copied messages seem to be coming from the same domain: iol.pt So you can use the AOL settings to block that domain and do the same thing in Mail using its Rules function. You probably need to do the same thing with the portugalmail.pt domain name. And also the hot.pt one, as well. Of course, if you have real correspondents using that domain, it could get a little more complicated. Do you have any business or friends/family in Portugal? smile.gif

On the Mac, I think <SpamSieve> would catch most of those messages, also. At least after a short period of 'training.' It looks at the message body and can pretty well determine what is bogus. All you do to 'train' it is to select a message and use its "Train as SPAM" menu item. But it's not free... $30.
« Last Edit: April 18, 2012, 11:25:43 AM by Xairbusdriver »
THERE ARE TWO TYPES OF COUNTRIES
Those that use metric = #1 Measurement system
And the United States = The Banana system
CAUTION! Childhood vaccinations cause adults! :yes:

Offline Xairbusdriver

  • Administrator
  • TS Addict
  • *****
  • Posts: 26388
  • 27" iMac (mid-17), Big Sur, Mac mini, Catalina
    • View Profile
    • Mid-South Weather
What's happening to my AOL account?
« Reply #9 on: April 18, 2012, 11:41:32 AM »
One site has suggested locking the ~/Library/LaunchAgents directory/folder as a means of preventing these recent malware attacks from infecting your machine. The recent scripts have been installing items in that folder. Locking it will prevent that. The downside is that installing a new app or even updating one may require it to access that folder and you may or may not get a warning. dntknw.gif

You can also create a Folder Action that simply notifies you that something/anything has accessed the folder. You can then open it to see what's there. If you see something with a strange or unfamiliar name, you can then remove it. Most items in that folder have obvious application names, "AddressBook.SchedulerSync," "SafariBookMarksSyncer," etc.
THERE ARE TWO TYPES OF COUNTRIES
Those that use metric = #1 Measurement system
And the United States = The Banana system
CAUTION! Childhood vaccinations cause adults! :yes:

Offline Paddy

  • Administrator
  • TS Addict
  • *****
  • Posts: 13797
    • View Profile
    • https://www.paddyduncan.com
What's happening to my AOL account?
« Reply #10 on: April 18, 2012, 12:55:39 PM »
Actually, Jim, they're not ok - they're only 300 pixels wide or so and too small to read.

Lorraine, when I said post the raw source here, I meant copy and paste it into a message (obscure the email addy and your IP with x's) on the forum. wink.gif

That way, I can copy and paste from it and run it through SpamCop. Please use the most recent messages (Spamcop won't process anything older than a couple of days) etc. Make sure that you use the raw source though - easily done through Mail, but I don't know how to tell you to do it via AOL's webmail.
"If computers get too powerful, we can organize them into committees. That'll do them in." ~Author unknown •iMac 5K, 27" 3.6Ghz i9 (2019) • 16" M1 MBP(2021) • 9.7" iPad Pro • iPhone 13

Offline LR827

  • TS Addict
  • *****
  • Posts: 1840
  • Let's take care of each other
    • View Profile
    • http://www.deardrroth.com/
What's happening to my AOL account?
« Reply #11 on: April 18, 2012, 02:05:11 PM »
Paddy, didn't I do that? The second message has raw source and an enlarged picture.

Jim, the Portugal and other domains were just a few of the thousands, from countries all over the world. That was a tiny sample. There were over 22,000 in my trash -- Mail couldn't empty it.

Offline Xairbusdriver

  • Administrator
  • TS Addict
  • *****
  • Posts: 26388
  • 27" iMac (mid-17), Big Sur, Mac mini, Catalina
    • View Profile
    • Mid-South Weather
What's happening to my AOL account?
« Reply #12 on: April 18, 2012, 03:28:19 PM »
QUOTE
Actually, Jim, they're not ok - they're only 300 pixels wide or so and too small to read.
I think you read my post before I saw the first images. The last one she uploaded is some 900 pixels wide.

She also pasted in the raw file in <post #12> I think we are simply reading while at least one of us is posting and uploading and reading and... laughhard.gif

First, I assume you have a working backup of your emails. If not, I'd suggest doing that before any more attempts to delete the thousands of messages. Better safe than sorry. yes.gif

To get Mail to delete those messages, you'll probably have to move the majority of them back into a regular mailbox. I'd suggest creating a new one and call it "AOL Junque." Then select as many as you can from the Trash mailbox and drag them into the new one you just created. You may have to do this many times to get the volume in the Trash down to a size Mail can handle. There are other ways you could probably do this, but I think my suggested method is safe.

It might also help to use the Rebuild item in the Mailbox menu. Just select a mailbox, maybe Trash, and the item should become available.
« Last Edit: April 18, 2012, 03:34:22 PM by Xairbusdriver »
THERE ARE TWO TYPES OF COUNTRIES
Those that use metric = #1 Measurement system
And the United States = The Banana system
CAUTION! Childhood vaccinations cause adults! :yes:

Offline Paddy

  • Administrator
  • TS Addict
  • *****
  • Posts: 13797
    • View Profile
    • https://www.paddyduncan.com
What's happening to my AOL account?
« Reply #13 on: April 18, 2012, 03:29:07 PM »
Oops - I must have come back to this thread without refreshing the page and not seen your most recent posts (or Jim's).

So, ran them through Spamcop ...the emails aren't from Portugal - they're actually from the good ole US of A. The first one originates at QWEST, in Denver, CO and the second at dixie-net.com, an ISP in Waterford, MS.

Due to issues with copying and pasting the headers here and formatting errors that may be resulting, I'm not sure that SpamCop is giving the full info - whether there are open relays in there etc. or not. If you can open an account there and try it yourself directly from your email, it might give more info.

Are there really no links or anything in the body of the emails? These are most peculiar - other than jamming up your inbox, I don't see the point.

Given the completely random, and seemingly unique text in both the subject line and the body of the emails, it's really difficult to filter it out using either. And it's all very well to block things from the "iot.pt" but it sounds like you've got a boatload of different probably forged "from" domains, so that's not a viable alternative.

Just how much real email do you actually receive on this account? If this flood of spam continues, I think you really have no option other than to shut it down. I'm not sure even SpamSieve would flag this stuff, since it's not got consistent hallmarks that you can use to ID it. Just send out an email to anyone who you think might be using the AOL address and ask them to start using another one (I'd suggest that you filter this carefully - emails to friends/relatives get your "real" email addy, everyone else gets an easily disposed of gmail one.) Any accounts at online retailers where you've used this AOL address, or sign-ups to forums etc. will have to be changed as well - again, use a gmail account, NEVER your "real" email which should be kept ONLY for personal purposes, in my books. By "real" I mean the email account your ISP at home gave you - if you don't use it, and some people don't, since it has to be changed any time you switch providers, then select a GMail account that is for that purpose only. I have a hierarchy of email addresses:

1. Personal - used for family, friends and a few very select, trusted retailers/official purposes (and I don't use it for any new retailers)
2. Second tier personal - Facebook, retailers, forum sign-ups etc.
3. Websites I administer - they all have their own associated email addresses so I can tell where the spam comes from, if I get any.
4. Untrusted - everything else. Throwaway YMail account - which is about to be thrown away it's become so spam infested.

"If computers get too powerful, we can organize them into committees. That'll do them in." ~Author unknown •iMac 5K, 27" 3.6Ghz i9 (2019) • 16" M1 MBP(2021) • 9.7" iPad Pro • iPhone 13

Offline LR827

  • TS Addict
  • *****
  • Posts: 1840
  • Let's take care of each other
    • View Profile
    • http://www.deardrroth.com/
What's happening to my AOL account?
« Reply #14 on: April 18, 2012, 05:35:45 PM »
No links that I saw in any of the 3 or 4 that I opened. I hope I won't have to shut it down, but if so, I'll go with gmail. Our ISP is Comcast, but in case we move to another part of the country (our kids span the continent) we would have to change again.

Last night I did change the spam filter on the aol acct. to "high" -- it had already been on "medium" -- Right now there are 116 new messages, the earliest at 6:30 this morning (it's 6:35 PM here right now). They are slowing down -- they're only coming in about 10 minutes apart, whereas initially there were hundreds sent at the same minute.

I'll sign up and log into SpamCop now.

Thanks for all your help... So far!

Lorraine

Well, I guess not. I've tried x 2 to Register with SpamCop and both times the login failed! They sent me a PW and I am sure that is a pretty simple exercise, but each time they said the login failed. Then I changed to another email address and tried again, same result! What's up with that??
« Last Edit: April 18, 2012, 05:54:40 PM by LR827 »