wildasIwanabe
asked on
Malware or Virus
Hello Experts, yesterday we had a user open an email on her computer that had no antivirus and she also opened an attachment (you know where this is going) since then i have been getting complaints from my users stating that there emails are bouncing back externally, now it seems to have gotten worse as i am currently unable to even connect to exchange could this malware have really done all of this and if so how should i fix it, i tried using trend micro to find the bug but trend micro seems to be freezing up as im scanning the server, i need to know some methods for me to resolve this issue.
ASKER
i also have two headers from the emails that bounced back
Delivery has failed to these recipients or distribution lists:
cdasilva1@bell.blackberry. net
An error occurred while trying to deliver this message to the recipient's e-mail address. Microsoft Exchange will not try to redeliver this message for you. Please try resending this message, or provide the following diagnostic text to your system administrator.
The following organization rejected your message: antispam18.c0.bise6.blackb erry.
_____
Sent by Microsoft Exchange Server 2007
Diagnostic information for administrators:
Generating server: GENREPMISS.headoffice.loca l
cdasilva1@bell.blackberry. net
antispam18.c0.bise6.blackb erry #550 #5.7.1 Your access to submit messages to this e-mail system has been rejected. ##rfc822;CdaSilva@genrep.c om
Original message headers:
Received: from GENREPMISS.headoffice.loca l ([fe80::be0b:ce33:3ac5:dca 2]) by GENREPMISS.headoffice.loca l ([fe80::be0b:ce33:3ac5:dca 2%10]) with mapi; Tue, 4 Jun 2013 13:01:54 -0400
From: Tony Sugrim <TSugrim@genrep.com>
To: Carlos da Silva <CdaSilva@genrep.com>
Content-Class: urn:content-classes:messag e
Date: Tue, 4 Jun 2013 13:01:52 -0400
Subject: RE: Undeliverable emails
Thread-Topic: Undeliverable emails
Thread-Index: Ac5hRLCFHIHjxKu8RgGceiRKHP bo+wAAIGqA
Message-ID: <B91DF9842A98E049A3AF0381D 3036F2D7DF D3B0C76@GE NREPMISS.h eadoffice. local>
References: <B91DF9842A98E049A3AF0381D 3036F2D7DF D3B0C75@GE NREPMISS.h eadoffice. local>
In-Reply-To: <B91DF9842A98E049A3AF0381D 3036F2D7DF D3B0C75@GE NREPMISS.h eadoffice. local>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator:
acceptlanguage: en-US
Content-Type: multipart/related;
boundary="_005_B91DF9842A9 8E049A3AF0 381D3036F2 D7DFD3B0C7 6GENREPMIS Shea_";
type="multipart/alternativ e"
MIME-Version: 1.0
-------------------------- ---------- ---------- ---------- ---------- ---------- ---------- ---------- ---------- ---------- ---------- ---------- ----
From: Microsoft Exchange
Sent: Wednesday, June 05, 2013 8:40 AM
To: Tamara Da Silva
Subject: Undeliverable: Sales Call Logs
Importance: High
Delivery has failed to these recipients or distribution lists:
thomasbrown@bell.blackberr y.net
An error occurred while trying to deliver this message to the recipient's e-mail address. Microsoft Exchange will not try to redeliver this message for you. Please try resending this message, or provide the following diagnostic text to your system administrator.
The following organization rejected your message: antispam10.c0.bise6.blackb erry.
_____
Sent by Microsoft Exchange Server 2007
Diagnostic information for administrators:
Generating server: GENREPMISS.headoffice.loca l
thomasbrown@bell.blackberr y.net
antispam10.c0.bise6.blackb erry #550 #5.7.1 Your access to submit messages to this e-mail system has been rejected. ##rfc822;TBrown@genrep.com
Original message headers:
Received: from GENREPMISS.headoffice.loca l ([fe80::be0b:ce33:3ac5:dca 2]) by
GENREPMISS.headoffice.loca l ([fe80::be0b:ce33:3ac5:dca 2%10]) with mapi; Wed,
5 Jun 2013 08:39:30 -0400
From: Tamara Da Silva <TDaSilva@genrep.com>
To: Andre Forcier <aforcier@genrep.com>, Kennth Olesen <KOlesen@genrep.com>,
Thomas Brown <TBrown@genrep.com>, Denis Gougeon <dgougeon@genrep.com>
CC: Jay da Silva <jay@genrep.com>
Importance: high
X-Priority: 1
Date: Wed, 5 Jun 2013 08:39:28 -0400
Subject: Sales Call Logs
Thread-Topic: Sales Call Logs
Thread-Index: Ac5h6bgMRxXflmfhQqKov0Awg7 XCag==
Message-ID: <B91DF9842A98E049A3AF0381D 3036F2D7E2 78B184F@GE NREPMISS.h eadoffice. local>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
acceptlanguage: en-US
Content-Type: multipart/alternative;
boundary="_000_B91DF9842A9 8E049A3AF0 381D3036F2 D7E278B184 FGENREPMIS Shea_"
MIME-Version: 1.0
Delivery has failed to these recipients or distribution lists:
cdasilva1@bell.blackberry.
An error occurred while trying to deliver this message to the recipient's e-mail address. Microsoft Exchange will not try to redeliver this message for you. Please try resending this message, or provide the following diagnostic text to your system administrator.
The following organization rejected your message: antispam18.c0.bise6.blackb
_____
Sent by Microsoft Exchange Server 2007
Diagnostic information for administrators:
Generating server: GENREPMISS.headoffice.loca
cdasilva1@bell.blackberry.
antispam18.c0.bise6.blackb
Original message headers:
Received: from GENREPMISS.headoffice.loca
From: Tony Sugrim <TSugrim@genrep.com>
To: Carlos da Silva <CdaSilva@genrep.com>
Content-Class: urn:content-classes:messag
Date: Tue, 4 Jun 2013 13:01:52 -0400
Subject: RE: Undeliverable emails
Thread-Topic: Undeliverable emails
Thread-Index: Ac5hRLCFHIHjxKu8RgGceiRKHP
Message-ID: <B91DF9842A98E049A3AF0381D
References: <B91DF9842A98E049A3AF0381D
In-Reply-To: <B91DF9842A98E049A3AF0381D
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator:
acceptlanguage: en-US
Content-Type: multipart/related;
boundary="_005_B91DF9842A9
type="multipart/alternativ
MIME-Version: 1.0
--------------------------
From: Microsoft Exchange
Sent: Wednesday, June 05, 2013 8:40 AM
To: Tamara Da Silva
Subject: Undeliverable: Sales Call Logs
Importance: High
Delivery has failed to these recipients or distribution lists:
thomasbrown@bell.blackberr
An error occurred while trying to deliver this message to the recipient's e-mail address. Microsoft Exchange will not try to redeliver this message for you. Please try resending this message, or provide the following diagnostic text to your system administrator.
The following organization rejected your message: antispam10.c0.bise6.blackb
_____
Sent by Microsoft Exchange Server 2007
Diagnostic information for administrators:
Generating server: GENREPMISS.headoffice.loca
thomasbrown@bell.blackberr
antispam10.c0.bise6.blackb
Original message headers:
Received: from GENREPMISS.headoffice.loca
GENREPMISS.headoffice.loca
5 Jun 2013 08:39:30 -0400
From: Tamara Da Silva <TDaSilva@genrep.com>
To: Andre Forcier <aforcier@genrep.com>, Kennth Olesen <KOlesen@genrep.com>,
Thomas Brown <TBrown@genrep.com>, Denis Gougeon <dgougeon@genrep.com>
CC: Jay da Silva <jay@genrep.com>
Importance: high
X-Priority: 1
Date: Wed, 5 Jun 2013 08:39:28 -0400
Subject: Sales Call Logs
Thread-Topic: Sales Call Logs
Thread-Index: Ac5h6bgMRxXflmfhQqKov0Awg7
Message-ID: <B91DF9842A98E049A3AF0381D
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
acceptlanguage: en-US
Content-Type: multipart/alternative;
boundary="_000_B91DF9842A9
MIME-Version: 1.0
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
uescomp thanks for your information how would i go by getting on to the exchange server and clearing the up any discrepencies? also everything worked and the users are able to recieve emails and send out again! thank you, now the users emails are forwarded to there blackberry and whenever anything is sent to their BB the user sending gets this error along with the header...
-------------------------- ---------- ---------- ---------- ---------- ---------- ---------- ---------- ---------- ---------- ---------- ---------- ------
Delivery has failed to these recipients or distribution lists:
dpoyntz@bell.blackberry.ne t
An error occurred while trying to deliver this message to the recipient's e-mail address. Microsoft Exchange will not try to redeliver this message for you. Please try resending this message, or provide the following diagnostic text to your system administrator.
The following organization rejected your message: antispam17.c0.bise6.blackb erry.
Sent by Microsoft Exchange Server 2007
Diagnostic information for administrators:
Generating server: GENREPMISS.headoffice.loca l
lsilva@bell.blackberry.net
antispam4.c0.bise6.blackbe rry #550 #5.7.1 Your access to submit messages to this e-mail system has been rejected. ##rfc822;LSilva@genrep.com
Original message headers:
Received: from GENREPMISS.headoffice.loca l ([fe80::be0b:ce33:3ac5:dca 2]) by GENREPMISS.headoffice.loca l ([fe80::be0b:ce33:3ac5:dca 2%10]) with mapi; Thu, 6 Jun 2013 11:33:16 -0400
From: Tony Sugrim <TSugrim@genrep.com>
To: Larry Silva <LSilva@genrep.com>
Content-Class: urn:content-classes:messag e
Date: Thu, 6 Jun 2013 11:33:11 -0400
Subject: Test
Thread-Topic: Test
Thread-Index: Ac5iyymU6GF8+PxZQF6TwA+z9s XBgA==
Message-ID: <6mdk3jrl0u4k8qwky8s8gjkr. 1370532788 716@email. android.co m>
Reply-To: Tony Sugrim <TSugrim@genrep.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator:
acceptlanguage: en-US
Content-Type: multipart/related;
boundary="_004_6mdk3jrl0u4 k8qwky8s8g jkr1370532 788716emai landroidco m_";
type="multipart/alternativ e"
MIME-Version: 1.0
--------------------------
Delivery has failed to these recipients or distribution lists:
dpoyntz@bell.blackberry.ne
An error occurred while trying to deliver this message to the recipient's e-mail address. Microsoft Exchange will not try to redeliver this message for you. Please try resending this message, or provide the following diagnostic text to your system administrator.
The following organization rejected your message: antispam17.c0.bise6.blackb
Sent by Microsoft Exchange Server 2007
Diagnostic information for administrators:
Generating server: GENREPMISS.headoffice.loca
lsilva@bell.blackberry.net
antispam4.c0.bise6.blackbe
Original message headers:
Received: from GENREPMISS.headoffice.loca
From: Tony Sugrim <TSugrim@genrep.com>
To: Larry Silva <LSilva@genrep.com>
Content-Class: urn:content-classes:messag
Date: Thu, 6 Jun 2013 11:33:11 -0400
Subject: Test
Thread-Topic: Test
Thread-Index: Ac5iyymU6GF8+PxZQF6TwA+z9s
Message-ID: <6mdk3jrl0u4k8qwky8s8gjkr.
Reply-To: Tony Sugrim <TSugrim@genrep.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator:
acceptlanguage: en-US
Content-Type: multipart/related;
boundary="_004_6mdk3jrl0u4
type="multipart/alternativ
MIME-Version: 1.0
Depends on which blacklists you are on. If you were listed on spamhaus you definetly had a virus. The emails will stop relaying because the virus has been handled so exchange should calm down. If your comfortable that you removed the virus then start delisting yourself from the blacklists. Once those clear up you should be ok.
I would also strongly advise your users to not open zipped attatchments sent from USPS, UPS, BBB.org, all that jazz. If it is a problem then you should look for an external mail filter like mailmax or something.
I would also strongly advise your users to not open zipped attatchments sent from USPS, UPS, BBB.org, all that jazz. If it is a problem then you should look for an external mail filter like mailmax or something.
ASKER