Link to home
Start Free TrialLog in
Avatar of VanAlex
VanAlex

asked on

So where is Netsky?

I keep getting msgs from unkown addresses telling me they did not accept my message because it was infected with netsky.

I have up to date antivirus software in every desktop and server, I have searched trough the registry for know keys created by netsky, and I ran netsky removal tool from Symantec in every computer. Nothing.

Still I get e-mails again and again with the same msgs.

Where else can I go to remove it?
ASKER CERTIFIED SOLUTION
Avatar of kristinaw
kristinaw
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of VanAlex
VanAlex

ASKER

Here is an example of the msgs I receive at least once a day.

Since I have my own may server registered let's say to "company.com", I believe the problem is here, but I've scanned with every virus removal tool my servers and my workstations, and still they don't detect anything.

____________________________________________________
Our viruschecker found the

      Worm.SomeFool.Gen-1

virus in your email to the following recipient:

-> <info.ibl-haustechnik.de@secureland.de>

Delivery of the email was stopped!

Please check your system for viruses,
or ask your system administrator to do so.


For your reference, here are the SMTP envelope originator and headers from your email:

From <2201a8c0@company.com>
------------------------- BEGIN HEADERS -----------------------------
Received: from ibl-haustechnik.de (pD9FF78A3.dip.t-dialin.net [217.255.120.163])
      by login260.webprovider.net (8.12.11/8.11.6) with ESMTP id i45ChZwj036062
      for <info@ibl-haustechnik.de>; Wed, 5 May 2004 14:43:39 +0200 (CEST)
Message-Id: <200405051243.i45ChZwj036062@login260.webprovider.net>
From: 2201a8c0@company.com
To: info@ibl-haustechnik.de
Subject: Re: Your text
Date: Wed, 5 May 2004 14:59:45 +0200
MIME-Version: 1.0
Content-Type: multipart/mixed;
      boundary="----=_NextPart_000_0007_00005A2E.00000ECF"
X-Priority: 3
X-MSMail-Priority: Normal
-------------------------- END HEADERS ------------------------------
_________________________________________________________
I get these types of messages too, unfortunatley. Even though I'm 100% sure we're not sending out any virus infected messages. Spoofing.

kris.
Avatar of VanAlex

ASKER

So I imagine there is nothing that I can do about it unless watching my business image being hurt by this?