Re: Mass Mailing worm problem, please help

From: chris (router88_at_sinaman.com)
Date: 08/27/04


Date: Sat, 28 Aug 2004 01:11:18 +0800

Thanks for your advise, David...But I would like to ask how can I identify
which kind of virus the pc is infected if I found a mass mailing activities
from a PC listed in the log file? As I know there are many kind of worm
which lead to mass-mailing activities....

CHRIS
"David Postill" <david@postill.org.uk> ???
news:87hui0l7j7jsv668ui4nl42rtsgi6v25c9@4ax.com ???...
> In article <cgn9eb$bou1@imsp212.netvigator.com>, on Fri, 27 Aug 2004
20:28:11 +0800, "chris"
> <router88@sinaman.com> wrote:
>
> | Hi All,
> |
> | I got a very serious problem. My email server keep having the "relaying
> | denied" message and I think some of my clients' pc got infected.
However,
> | the email didn't show which pc or from which IP address the email are
sent
> | from. Therefore, I would like to know how can I check it out or any
software
> | can help??? And also, how can I identify which virus my clients' pc are
> | infected. As it made us can't send out any email with message below
> |
> | Mail server: WinRoute Pro 4.2.5 at ctw.com.hk
> | Error description: message could not be delivered, server replied:
> | 550 5.7.1 <teix@ter.hk>... Relaying denied
> | Original message is attached.
> |
> | Anyone can help?? Please help me...Thanks alot.
>
> What's wrong with looking at the server logs?
>
> From <http://kerio.apposite.com.hk/product/winroute%20_pro/mail.htm>:
>
> "Logging: For diagnostic and regulatory reasons the Kerio WinRoute
> administrator can trace all email processing using the Mail and Debug
logs."
>
> <davidp />
>
> --
> David Postill



Relevant Pages

  • Re: Domain security and dial-up
    ... I am not as concerned about a virus on a client even though I know they can ... virus scan product in use on the clients. ... the client computers is on the Internet and they forget to close their email ... mapped drive to the server and no firewall. ...
    (microsoft.public.win2000.security)
  • Re: Winhlpp32.exe/ W32.HLLW.Gaobot
    ... | on all my W2k Pro & WXP clients. ... | virus, the winhlpp32.exe reg key still remains in the registry no matter how ... | still has the winhlpp32.exe reg key in the registry. ...
    (microsoft.public.security.virus)
  • Re: [fw-wiz] Blocking email through the web services
    ... >> scanning engine to scan incoming http traffic. ... > Virus scanning on HTTP helps, if viruses are all you worry about. ... unfortunately going through the output from the proxy logs consumes ... We use a proxy appliance, ...
    (Firewall-Wizards)
  • Re: Secured IIS Project - msg 2
    ... DSHIELD. ... logs to his addresses until further notice. ... Delivery co-sponsored by Trend Micro ... TREND MICRO REAL-TIME VIRUS ALERTS ...
    (NT-Bugtraq)
  • Winhlpp32.exe/ W32.HLLW.Gaobot
    ... Recently had the winzip32.exe file infected with the W32.HLLW.Gaobot virus ... on all my W2k Pro & WXP clients. ... I've completed all Symantec related docs and removal tools. ... still has the winhlpp32.exe reg key in the registry. ...
    (microsoft.public.security.virus)