Solved

554 TRANSACTION FAILED - Unrepairable Virus Detected. Your mail has not been

Posted on 2006-10-25
10
3,672 Views
Last Modified: 2008-01-09
Hi experts,

Since few days peolple are getting spam from my server.

What to do?

-----Original Message-----
From: MAILER-DAEMON@aol.com
To: gholateg@aol.com
Sent: Wed, 25 Oct 2006 11:27 AM
Subject: Returned mail: Service unavailable

The original message was received at Wed, 25 Oct 2006 05:27:31 -0400 (EDT)

from mail.onefamilyfund.org [212.150.194.198]

 

 

*** ATTENTION ***

 

Your e-mail is being returned to you because there was a problem with its

delivery.  The address which was undeliverable is listed in the section

labeled: "----- The following addresses had permanent fatal errors -----".

 

The reason your mail is being returned to you is listed in the section

labeled: "----- Transcript of Session Follows -----".

 

The line beginning with "<<<" describes the specific reason your e-mail could

not be delivered.  The next line contains a second error message which is a

general translation for other e-mail servers.

 

Please direct further questions regarding this message to your e-mail

administrator.

 

--AOL Postmaster

 

 

 

   ----- The following addresses had permanent fatal errors -----

<gholateg@aol.com>

 

   ----- Transcript of session follows -----

... while talking to air-mb01.mail.aol.com.:

>>> DATA

<<< 554 TRANSACTION FAILED - Unrepairable Virus Detected. Your mail has not been

sent.

554 <gholateg@aol.com>... Service unavailable

Final-Recipient: RFC822; gholateg@aol.com

Action: failed

Status: 5.0.0

Remote-MTA: DNS; air-mb01.mail.aol.com

Diagnostic-Code: SMTP; 554 TRANSACTION FAILED - Unrepairable Virus Detected.

Your mail has not been sent.

Last-Attempt-Date: Wed, 25 Oct 2006 05:27:49 -0400 (EDT)

Received: from  office1.net (mail.onefamilyfund.org [212.150.194.198]) by

rly-mb06.mail.aol.com (v113.6) with ESMTP id MAILRELAYINMB68-6d6453f2dff3d3;

Wed, 25 Oct 2006 05:27:27 -0400

Date: Wed, 25 Oct 2006 11:33:40 +0200

To: "Gholateg" <gholateg@aol.com>

From: "Nyspiv" <nyspiv@aol.com>

Subject: Sindony

Message-ID: <lpkxnlbpwdazcpvmfax@aol.com>

MIME-Version: 1.0

Content-Type: multipart/mixed;

        boundary="--------epubktbewdfwyxehinec"

X-AOL-IP: 212.150.194.198

X-AOL-SCOLL-SCORE: 0:2:420209672:14441827

X-AOL-SCOLL-URL_COUNT: 0

0
Comment
Question by:cabou
10 Comments
 
LVL 38

Expert Comment

by:younghv
ID: 17802367
Hi cabou,
Did you actually send that particular message?

If not, this could just be a case of email address 'spoofing'.

Several versions of 'malware' will capture a bunch of email addresses and then send out infected emails using those stolen email addresses as 'return addresses'.

If that is the case, there is nothing you can do about it.
The infection happens on a computer somewhere in the world with YOUR email address stored on it, and all of the 'warning messages' get sent back to YOU.

If you did send the message, then you need to so a complete update of all your security application definitions (AV and anti-spyware), then re-boot to safe mode, then do a full HDD scan.

Vic
0
 
LVL 38

Expert Comment

by:younghv
ID: 17802381
BTW, there are 'web-crawler' programs that search web-sites (such as this one) to capture email addresses.
When you make a post that includes actual email addresses, you are exposing those email address to capture.

That really sucks - I know, but it's a fact of Internet life.
0
 

Author Comment

by:cabou
ID: 17802400
I did not sent any messages but most of the emails addresses that we are getting back are known by our organisation.

also the IP that is writen in the mail from AOL is my sever IP.
0
 
LVL 38

Accepted Solution

by:
younghv earned 500 total points
ID: 17802446
cabou,
"Spoofing" has been part of malware for several years now.

The virus ‘writers’ out there are continually improving the programs they write and – unfortunately – we all suffer for it.

Many of the current versions will infect a computer and then search the entire hard drive for names and email addresses. It will also search the ‘Default’ address setting in the email program.

The virus/worm will select a name at random and then pretending (SPOOFING) to be that random person, send out messages to all of the other names in the PAB.  

It will also randomly pick the name of a file in your computer and use that as the ‘Subject’ of the message.

This process of randomly selecting a name and then sending messages (with random Subject lines) to all of the other names will continue until proper Anti-virus actions are taken.

In sequence, the process looks like this:

1.   Infect a computer.

2.   Search for any email addresses.

3.   Pick a name – any name – and assume that email identity.

4.   Pick a file name and make that the ‘Subject’ of the message.

5.   Send messages to all other email addresses on computer.

6.   Repeat steps 2-5.

7.   Keep repeating steps 2-5 until the owner of the computer finally updates their Anti-virus program, or forever.  Whichever comes first.

You don't any control over this, because the infection is on a computer that is out of your control.
0
 
LVL 31

Expert Comment

by:rid
ID: 17805577
The "unrepairable virus detected" sounds a bit odd; how can a virus be detected before the message is delivered? It'd be nice to, sort of, know, in advance, that a message will be going to be detected as infected (difficult verb mode here) but I'm wary about that comment. Looks a bit like some kind of scam to me.
/RID
0
Threat Intelligence Starter Resources

Integrating threat intelligence can be challenging, and not all companies are ready. These resources can help you build awareness and prepare for defense.

 
LVL 25

Expert Comment

by:Cyclops3590
ID: 17811846
>>also the IP that is writen in the mail from AOL is my sever IP.
do you have any users who have their acct forwarded to their aol accts.  If so, that is why aol thinks your server is the origination server

go to, http://postmaster.aol.com/
get your IP whitelisted for one then sign up for the feedback emails.  this way anytime emails are determined as spam by aol as well you'll know about it. in this case of course you're trying to track down a mass mailing worm that is most likely on someone elses machine.  So if my original assumption is incorrect (that you have accts forwarding to aol accts) then I honestly don't know what to say.

If you suspect one of computers is compromised, Sysinternals TcpView is a great utility to see a live view of all tcp connections going on and you'll see the email connections.  Another is to go to www.dnsstuff.com and check your mail servers IP to see if you're on any blacklists.  I know when one of my clients got the Stration worm and brought it back inside, took about 24 hours to be put on 5 lists.  So you might think about blocking outgoing port 25 at your perimeter as well except for your mail server.

just a few thoughts anyway
0
 
LVL 38

Expert Comment

by:younghv
ID: 17812142
Cyclops,
This appears to be a reject of a specific message (or messages), not a domain block.
0
 
LVL 25

Expert Comment

by:Cyclops3590
ID: 17812498
younghv, sorry for not being more clear.

AOL WILL block his IP eventually if this is not resolved.  This is why you want to make sure to get your IP whitelisted as well as sign up for feedback to you can be aware of things AOL is processing with regards to your IP.

As for this issue, like I mentioned, its a worm that is causing the problem.  But this worm will get his IP put onto blacklists regardless of even eliminating this worm and thus he needs to be aware of this.  This is very important as it has been stated that aol is picking up his IP.  look up dnsstuff.com
http://www.dnsstuff.com/tools/ip4r.ch?ip=212.150.194.198
That IP is on the SBL-XBL list.  This is a very serious list to be on.  That is what my point was.  Sorry if I'm coming off as too offtopic, but I believe that the spam is the least of his worries right now as they are annoyances.  Being blacklisted and having legit email blocked is more serious.  At least in my mind.

So it needs to be tracked down exactly how that email is getting to aol.  The feedback signup will make it so at least for spam messages the headers of blocked emails are sent to you, I assume its the same for virus emails like this.  This will help in determining if it actually did orig from his IP or just traverse it with an aol forward or something else.
0
 
LVL 38

Expert Comment

by:younghv
ID: 17812620
Understood -
The reason I did the whole malware/worm/spoofing discussion was because we got our Exchange Server 'Black-listed' a few years ago (try explaining THAT to a General).

"Spoofing" is probably WHY this is going on.
"White-listing" is definitely WHAT to do next.

Good suggestion
Vic
0
 
LVL 25

Expert Comment

by:Cyclops3590
ID: 17813040
Yeah, better make sure a jeep is nearby   :)

>>"Spoofing" is probably WHY this is going on.
agreed, like you mentioned in your post, that is what most viruses/worms do
0

Featured Post

Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

Join & Write a Comment

It’s a strangely common occurrence that when you send someone their login details for a system, they can’t get in. This article will help you understand why it happens, and what you can do about it.
By this time the large percentage of day-to-day transactions have shifted to mobile banking; here are some overriding areas QAs must investigate while testing mobile banking apps.  
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
In this seventh video of the Xpdf series, we discuss and demonstrate the PDFfonts utility, which lists all the fonts used in a PDF file. It does this via a command line interface, making it suitable for use in programs, scripts, batch files — any pl…

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now