[RESOLVED] Might have a trojan, need help asap
Results 1 to 13 of 13

Thread: [RESOLVED] Might have a trojan, need help asap

  1. #1
    Registered User
    Join Date
    Mar 2006
    Posts
    181

    Resolved [RESOLVED] Might have a trojan, need help asap

    I have a SBS server 2000. I have NAV corp.10 which indicated I'm fine, and am behind a sonic wall firewall. Everying seems to be ok but when I go into exchange and drill down into smtp/default smtp/queues I find a couple of dozen obvious smtp mailer programs going to really bizarre websights. There is a modest history for each one showing what appears to be e-mail they have sent out. I'm running a beagl e scan right now from Symantec. I have tried the free AV scan from trend but it doesn't seem to work. I've also checked my registry for the tell tail add in that symantec says should be there. Can anybody help me or point me in the right direction? I really need this job...Chris

  2. #2
    Registered User
    Join Date
    Mar 2006
    Posts
    9
    post me your computer process snapshot.....and my little suggest not to use NORTON anymore....and if you wish I may send you a new fire wall by email.

  3. #3
    Registered User emr's Avatar
    Join Date
    Sep 2001
    Location
    Amsterdam
    Posts
    1,312
    Are you sure that this isn't Exchange trying to send NDR's to emails it has received to non-existant users?

    As you probably know, spammers will send mail to a domain with every name and combination possible. If you have Exchange configured to send NDR's to failed inbound messages then this could be what you are seeing in the queues.

    If you check the mails in the queue are they coming from your admin / postmaster account? That is a sure sign they are NDR's.

    emr

  4. #4
    Registered User
    Join Date
    Mar 2006
    Posts
    181

    Lightbulb ndr

    Thanks for the reply
    Not sure about the ndr stuff. This is new to me and I'm truly walking on thin ice. After a long night of researhing and scanning I don't think its a virus and the "ndr" you noted is coming up in the files. I'm not sure what else to say here except if you could point me in the right direction to find some information on what you are referring to "ndr". Chris

  5. #5
    Registered User
    Join Date
    Mar 2006
    Posts
    181

    Thumbs up NDR again

    Quote Originally Posted by emr
    Are you sure that this isn't Exchange trying to send NDR's to emails it has received to non-existant users?

    As you probably know, spammers will send mail to a domain with every name and combination possible. If you have Exchange configured to send NDR's to failed inbound messages then this could be what you are seeing in the queues.

    If you check the mails in the queue are they coming from your admin / postmaster account? That is a sure sign they are NDR's.

    emr
    I assume NDR stands for non-deliverable ? I'm looking at my exchange system manager consul right now and have the queues folder open. Inside a re a number of folders. Some with green check marks and the rest to bad looing websites. I froze them all those last night and there are a few new ones with a blue swirl arrow on them. Anyway your comment on Exchange trying to sne dNDR's to spammers woke me yp. Where can IU find the exchange settings for this and to shut it off. Chris

  6. #6
    Registered User
    Join Date
    Mar 2006
    Posts
    181

    Lightbulb Norton

    Quote Originally Posted by minos
    post me your computer process snapshot.....and my little suggest not to use NORTON anymore....and if you wish I may send you a new fire wall by email.
    Minos I agree about Norton but I have to use it unitl it runs out. It is a pretty exp. program and the company just paid for another year. I will post aimage Thursday of my process task manager window. What firewall do you have in mind? Chris

  7. #7
    Registered User emr's Avatar
    Join Date
    Sep 2001
    Location
    Amsterdam
    Posts
    1,312
    Here you go. http://support.microsoft.com/?kbid=886208

    Much more eloquently put than I could ever manage!

    You need to enable recipient filtering to reject non-existant users; Exchange doesn't generate NDR for these types of failures; the sending server does instead.

    I believe there is a way to disable NDR entirely; I'll have a look and see what I come up with.

    Good luck and post back if you still have problems.

    emr
    Last edited by emr; March 8th, 2006 at 04:14 PM.

  8. #8
    Registered User emr's Avatar
    Join Date
    Sep 2001
    Location
    Amsterdam
    Posts
    1,312
    Here is how to disable NDR entirely.

    Open Exchange Manager | Global Settings | double-click Internet Message Format then right-click the Default format, select Properties then Advanced tab.

    You have a list in there, one of which is the allowing of NDR.

    You do need to consider carefully whether you want to disable them entirely. This means that a genuine expediteur who mistypes an email address doesn't receive a response to say so when the mail is bounced by your server.

    For example, a client sends a mail to [email protected] it will get bounced but they won't receive a failed delivery report. Not always good from a customer care point of view.

    I generally enable recipient filtering which cuts out a lot of the crap and live with the fact that a good volume of NDR produced will be from spam. It's a trade off in the end.

    This is a fairly important part of the Exchange Manager if you want to allow out of office and various other features that are useful to the end-user.

    As always with MS it's tucked away nicely out of sight!

    emr

    Edit: I just realised you're running Exchange 2k; the steps detailed in the MS KB and what I mentioned above may be slightly different. I don't have a 2k box to check out at the moment.

    From memory they should be pretty much the same.
    Last edited by emr; March 8th, 2006 at 04:42 PM.

  9. #9
    Registered User
    Join Date
    Mar 2006
    Posts
    9
    zonealerm.....so far as i know best firewall....but i like its early vision...because it can track who is attacking you now and show the attacker's localtion...now you should pay for that founction....

  10. #10
    Registered User emr's Avatar
    Join Date
    Sep 2001
    Location
    Amsterdam
    Posts
    1,312
    Quote Originally Posted by minos
    zonealerm.....so far as i know best firewall....but i like its early vision...because it can track who is attacking you now and show the attacker's localtion...now you should pay for that founction....
    ZoneAlarm is fine for a stand-alone pc however installing it on a server is unadvisable. Your server should be behind a hardware router which connects to the ISP and be sufficiently locked down through GPO.

    ZA won't do any of that for you.

    emr

  11. #11
    Registered User
    Join Date
    Mar 2006
    Posts
    181

    2k over 2003

    Quote Originally Posted by emr
    Here is how to disable NDR entirely.

    Open Exchange Manager | Global Settings | double-click Internet Message Format then right-click the Default format, select Properties then Advanced tab.

    You have a list in there, one of which is the allowing of NDR.

    You do need to consider carefully whether you want to disable them entirely. This means that a genuine expediteur who mistypes an email address doesn't receive a response to say so when the mail is bounced by your server.

    For example, a client sends a mail to [email protected] it will get bounced but they won't receive a failed delivery report. Not always good from a customer care point of view.

    I generally enable recipient filtering which cuts out a lot of the crap and live with the fact that a good volume of NDR produced will be from spam. It's a trade off in the end.

    This is a fairly important part of the Exchange Manager if you want to allow out of office and various other features that are useful to the end-user.

    As always with MS it's tucked away nicely out of sight!

    emr

    Edit: I just realised you're running Exchange 2k; the steps detailed in the MS KB and what I mentioned above may be slightly different. I don't have a 2k box to check out at the moment.

    From memory they should be pretty much the same.
    Thank you your were dead on about the 2k. 2003 is quite a different interface. All is well in the world and I'm still employed AND I've learned something. many thanks...Chris

  12. #12
    Registered User
    Join Date
    Mar 2006
    Posts
    181

    Thumbs up Za

    Quote Originally Posted by emr
    ZoneAlarm is fine for a stand-alone pc however installing it on a server is unadvisable. Your server should be behind a hardware router which connects to the ISP and be sufficiently locked down through GPO.

    ZA won't do any of that for you.

    emr
    Quite right, very good product but will not work on aserver. I have a hardware firelwall.

  13. #13
    Registered User emr's Avatar
    Join Date
    Sep 2001
    Location
    Amsterdam
    Posts
    1,312
    Quote Originally Posted by musicman7722
    Thank you your were dead on about the 2k. 2003 is quite a different interface. All is well in the world and I'm still employed AND I've learned something. many thanks...Chris
    Glad to help out. Exchange is a bit of a favourite of mine. Can be a complete bastard to configure but once you get a bit of knowledge under your belt it can be a very sweet mail system to administer.

    Don't hesitate if you have any other questions.

    emr

Similar Threads

  1. Replies: 0
    Last Post: September 21st, 2005, 03:11 AM
  2. trojan or boot sector virus?
    By cypherth in forum Spyware & Antivirus - Security
    Replies: 3
    Last Post: February 9th, 2005, 05:05 PM
  3. possible trojan
    By freddy in forum Spyware & Antivirus - Security
    Replies: 3
    Last Post: December 21st, 2003, 05:16 AM
  4. Which trojan?
    By ilovetheusers in forum Tech-To-Tech
    Replies: 12
    Last Post: September 30th, 2002, 03:20 PM
  5. Error on startup
    By jasonflorida1 in forum Tech-To-Tech
    Replies: 5
    Last Post: October 12th, 2000, 08:34 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •