troubleshooting Question

How to determine the source of spam or virus email

Avatar of EnjoyNet
EnjoyNetFlag for United States of America asked on
ExchangeAnti-Virus AppsAntiSpam
8 Comments1 Solution3118 ViewsLast Modified:
Hi Experts,

We have an Exchange 2003 server and Barracuda email filtering system internally.  One of our IP addresses has been listed in CBL list.  We got a message from CBL organization as attached below.  How can we find out the source of spam email?

Your help is very appreciated.

EN

CBL Lookup Utility
________________________________________
IP Address 50.193.X.X is listed in the CBL. It appears to be infected with a spam sending trojan, proxy or some other form of botnet.
It was last detected at 2013-10-07 18:00 GMT (+/- 30 minutes), approximately 23 hours ago.
This IP address is infected with, or is NATting for a machine infected with the ZeroAccess botnet, also known as Sirefef. More information can be found from Wikipedia. It is most often used for bitcoin mining or click fraud, but as it contains a downloader portion, it can do anything.
REMEMBER: ZeroAccess is NOT primarily an Email spamming tool.
Norton Power Eraser is known to be able to remove ZeroAccess.
________________________________________
WARNING: If you continually delist 50.193.X.X without fixing the problem, the CBL will eventually stop allowing the delisting of 50.193.X.X.
If you have resolved the problem shown above and delisted the IP yourself, there is no need to contact us.
Click on this link to delist 50.193.X.X
Join the community to see this answer!
Join our exclusive community to see this answer & millions of others.
Unlock 1 Answer and 8 Comments.
Join the Community
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 1 Answer and 8 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros