Need Help Finding Email Virus

tank

Well-Known Member
Apr 12, 2011
255
5
68
Chicago, IL
cPanel Access Level
Root Administrator
Have you tried following these directions.

Code:
Check your FTP logs to find uploads of Darkmailer scripts. Forward to us a copy of the FTP log records that you find. These logs will often be in /var/log/messages, but this depends on your system configuration.
Identify, kill and remove all Darkmailer scripts currently on the web server. NOTE: Many Darkmailer operators cause the Darkmailer scripts to be removed either after they're used, or even during their use. If you cannot find the scripts, this does NOT mean that the CBL is in error in this listing NOR does it mean that you are not presently vulnerable to anotherDarkmailer infection.
Change the passwords of every userid identified as performing FTP uploads, and warn these users that their passwords had been compromised by a keylogger infection. They need to run anti-virus software on their computers.
NEW WARNING: we're getting indications that once initially compromised by FTP, the attackers are uploading alternate file transfer programs that do not rely on the user's password. See below under "r57shell"
Implement port 25 blocking so that only your mail server software userid can make outbound port 25 connections from this machine.
It says your not listed anymore as of 6 hours ago

Take a look at this post
http://forums.cpanel.net/f43/help-tracking-spammer-221692.html
 

ruzbehraja

Well-Known Member
May 19, 2011
392
11
68
cPanel Access Level
Root Administrator
Do you see any mails in the mail queue?

You can see which username they are using to send out the mail.
Open the mail and search for a line that says:
auth-

Do you have the WHM Tweak to:
Disable the nobody user from sending mail?
Once you identify the account, suspend it and take further action.

Also, set the hourly email limit per domain to something like 200 or 300 in WHM Tweak Settings.

Also check your exim logs through SSH:
tail -f /var/log/exim_mainlog
 

ruzbehraja

Well-Known Member
May 19, 2011
392
11
68
cPanel Access Level
Root Administrator
You can also go to WHM >> View sent summary >> check which domain is sending out the maximum mail.

Also, a new feature in WHM Tweak Settings can be used:
Maximum percentage of failed or deferred messages a domain may send per hour
Set this to about 20%