Solved

Blacklisted : CBL - Exchange 2010 - Need Assitance

Posted on 2013-12-26
4
468 Views
Last Modified: 2013-12-26
Have Exchange 2010 has been running fine, no issues.
Got call from client, cannot send.
Checked MX Toolbox
Listed on SORBS, Spamhaus Zen, CBL
CBL says trojan or botnet is on network

Checked server, Queues are not filling up with outbound mail, thus I don't think I have a compromised user account and not relaying, that I can tell.

I am in charge of the server side of the house, what are the steps I should take to verify the server is not compromised.

Please advise
0
Comment
Question by:tech911
  • 2
4 Comments
 
LVL 25

Expert Comment

by:Tony Giangreco
ID: 39740176
Run a full anti virus & anti spyware scan on all systems.  I'd run a few different apps to verify everything is clean.

Start with http://windows.microsoft.com/en-us/windows/security-essentials-download on all Pc's

Follow up with Malwarebytes and check all boxes for popups and browser hijacks.

Some spyware and virus apps have their own SMTP engines that bypass Exchange to send mail.
0
 
LVL 3

Author Comment

by:tech911
ID: 39740223
Ran Sec Essentials and MWbytes on Server, Clean.
Desktop Team is checking User Desktops
Anything else I should be doing or looking at on the server?
0
 
LVL 25

Assisted Solution

by:Tony Giangreco
Tony Giangreco earned 250 total points
ID: 39740255
If you have a firewall, see if it tells you what box is sending out Smtp traffic. You can also setup anti spam service for incoming and outgoing mail. We have used this service on all our clients and it works very well.

This service quarentines incoming and outgoing spam which should stop you from being black listed again. It should also trap the outgoing spam you have right now.

Take a look at GFI max Mail Essentials
www.gfi.com
0
 
LVL 76

Accepted Solution

by:
Alan Hardisty earned 250 total points
ID: 39740450
Make sure you block TCP Port 25 outbound for all IP addresses other than the Exchange server if you haven't already.

If you have already, then you have a problem on the server, if not, then it's more likely a network computer.

Alan
0

Featured Post

Too many email signature updates to deal with?

Do you feel like you are taking up all of your time constantly visiting users’ desks to make changes to email signatures? Wish you could manage all signatures from one central location, easily design them and deploy them quickly to users? Well, there is an easy way!

Join & Write a Comment

Article by: btan
Provide an easy one stop to quickly get the relevant information on common asked question on Ransomware in Expert Exchange.
We are happy to announce a brand new addition to our line of acclaimed email signature management products – CodeTwo Email Signatures for Office 365.
In this video we show how to create an Address List in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Organization >> Ad…
To show how to create a transport rule in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Mail Flow >> Rules tab.:  To cr…

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now