Hello,
I have a few user's that are being spammed emails like this one below. Here is the header info on it.
We have internal users and we have remote users, I've looked in Symantec and see there is nothing it's quarintined there on the server and I've ran local scans of the internal network. I went further and contacted each remote user, updated their .dat files, checked thier quarentine and did a full system scan of their system's. I only caught two viruses on two remote user's laptop's and removed them. However we still have user's receiving 20 or 25 of these types of emails daily. Any suggestions?
MESSAGE HEADER OF ONE OF THOSE EMAILS:
**************************
**********
**********
**********
*****
Microsoft Mail Internet Headers Version 2.0
Received: from mail.xxxxxxxx.com ([10.x.x.xx]) by xxxxx.xxxxx.com with Microsoft SMTPSVC(6.0.3790.3959);
Thu, 5 Jun 2008 16:14:07 -0500
Received: from serveur1.el.mailinblack.co
m ([195.64.165.40]) by mail.xxxxxx.com with Microsoft SMTPSVC(6.0.3790.3959);
Thu, 5 Jun 2008 16:14:06 -0500
Received: by serveur1.el.mailinblack.co
m (Postfix, from userid 0)
id 511262C81B; Thu, 5 Jun 2008 23:14:06 +0200 (CEST)
From: (branche severine)da_el@mailinblack
.com
To: xxxxxxxx@xxxxxxx.com
Subject: Re: [Downloadable porno DVD's for free]
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="mUlTiPaRtBoUnDaR
y_MailInBl
ack";
Message-Id: <20080605211406.511262C81B
@serveur1.
el.mailinb
lack.com>
Date: Thu, 5 Jun 2008 23:14:06 +0200 (CEST)
Return-Path: root@el.mailinblack.com
X-OriginalArrivalTime: 05 Jun 2008 21:14:07.0263 (UTC) FILETIME=[17065AF0:01C8C75
1]
--mUlTiPaRtBoUnDaRy_MailIn
Black
Content-Type: text/plain; charset="iso-8859-1"
--mUlTiPaRtBoUnDaRy_MailIn
Black
Content-Type: text/html; charset="iso-8859-1"
--mUlTiPaRtBoUnDaRy_MailIn
Black--
**************************
**********
**********
**********
**********
**********
**********
****
Any help is greatly appreciated, I'd like to get this resolved as quickly as possible. Thanks for all you help.
Vic
Start Free Trial