From: "BadBoy House" <>
| I've had instances in the past where a workstation has been infected
| with a mass-mailer worm and whilst I resolved the issue in the end I
| encountered the following circumstances in relation to the infected
| workstation:-
| - no up-to-date anti virus package found any mass mailer worms. I
| tried Panda, McAfee, Norton.
| - no port 25 traffic (other than the mail server) was going through
| the router (I checked all the logs/tables)
| In the end, via a process of elimination and used malware bytes anti
| malware to find, and remove the virus.
| I'm interested in finding out about any other proven methods for
| tracking down mass-mailer infected workstations. It seems it can be
| like finding a needle in a haystack.
| What methods would you suggest?
Packet tracking for oddball address patters.
Which "mass-mailer worm" or is this really a spambot infection ?
--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV -
http://www.pctipp.ch/downloads/dl/35905.asp