<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: cutwail spamBOT</title>
	<atom:link href="http://trizzz.com/2009/04/cutwail-spambot/feed/" rel="self" type="application/rss+xml" />
	<link>http://trizzz.com/2009/04/cutwail-spambot/</link>
	<description>Me vs. IT -- IT wins.</description>
	<lastBuildDate>Fri, 20 Nov 2009 12:12:35 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
	<item>
		<title>By: George</title>
		<link>http://trizzz.com/2009/04/cutwail-spambot/comment-page-1/#comment-133</link>
		<dc:creator>George</dc:creator>
		<pubDate>Fri, 20 Nov 2009 12:12:35 +0000</pubDate>
		<guid isPermaLink="false">http://trizzz.com/?p=23#comment-133</guid>
		<description>Hi Laura,

We seem to have gotten rid of the pest!

We blocked port 25 on all PCs except the mail server, and Trend AV, Malwarebytes and Windows Malicious Removal tool seem to have done the trick.  I have also disabled all NDR&#039;s and havent been blacklisted for over a week now!

Thanks,
George</description>
		<content:encoded><![CDATA[<p>Hi Laura,</p>
<p>We seem to have gotten rid of the pest!</p>
<p>We blocked port 25 on all PCs except the mail server, and Trend AV, Malwarebytes and Windows Malicious Removal tool seem to have done the trick.  I have also disabled all NDR&#8217;s and havent been blacklisted for over a week now!</p>
<p>Thanks,<br />
George</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Laura</title>
		<link>http://trizzz.com/2009/04/cutwail-spambot/comment-page-1/#comment-132</link>
		<dc:creator>Laura</dc:creator>
		<pubDate>Tue, 10 Nov 2009 02:18:55 +0000</pubDate>
		<guid isPermaLink="false">http://trizzz.com/?p=23#comment-132</guid>
		<description>George,

I don&#039;t know if this will help you out or not, but we&#039;re trying this site right now.  Microsoft says it should catch and remove Cutwail.  Hopefully it works and will be of some assistance.

http://onecare.live.com/site/en-US/center/howsafe.htm?s_cid=mscom_msrt</description>
		<content:encoded><![CDATA[<p>George,</p>
<p>I don&#8217;t know if this will help you out or not, but we&#8217;re trying this site right now.  Microsoft says it should catch and remove Cutwail.  Hopefully it works and will be of some assistance.</p>
<p><a href="http://onecare.live.com/site/en-US/center/howsafe.htm?s_cid=mscom_msrt" rel="nofollow">http://onecare.live.com/site/en-US/center/howsafe.htm?s_cid=mscom_msrt</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Marcus</title>
		<link>http://trizzz.com/2009/04/cutwail-spambot/comment-page-1/#comment-131</link>
		<dc:creator>Marcus</dc:creator>
		<pubDate>Wed, 28 Oct 2009 11:15:33 +0000</pubDate>
		<guid isPermaLink="false">http://trizzz.com/?p=23#comment-131</guid>
		<description>Hi, thanks for this article.
Today we have been blocked by spamhaus cbl. The culprit is cutwail spambot.
Please forgive my question lol.
How do I block the port 25 for everything except the exchange server. Is this done on our cisco router?
Im using Cisco SDM to connect to the routers configuration.
Many thanks in advance for any help.</description>
		<content:encoded><![CDATA[<p>Hi, thanks for this article.<br />
Today we have been blocked by spamhaus cbl. The culprit is cutwail spambot.<br />
Please forgive my question lol.<br />
How do I block the port 25 for everything except the exchange server. Is this done on our cisco router?<br />
Im using Cisco SDM to connect to the routers configuration.<br />
Many thanks in advance for any help.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: George</title>
		<link>http://trizzz.com/2009/04/cutwail-spambot/comment-page-1/#comment-130</link>
		<dc:creator>George</dc:creator>
		<pubDate>Fri, 23 Oct 2009 15:40:49 +0000</pubDate>
		<guid isPermaLink="false">http://trizzz.com/?p=23#comment-130</guid>
		<description>Thanks Trizz,

I managed to set up a rule on the sbs2008 server to block port 25 except for the mail server.  I think it would be good to block it on the NETGEAR ProSafe VPN Wireless ADSL Gateway DGFV338 as we are using this router as the firewall, but not sure how you can make exceptions whilst creating the rules.

Where can I locate the Windows Malicious code remover, can I manually save it and then run from sbs2008 server?  My security settings dont allow me to download.

Thanks,
George</description>
		<content:encoded><![CDATA[<p>Thanks Trizz,</p>
<p>I managed to set up a rule on the sbs2008 server to block port 25 except for the mail server.  I think it would be good to block it on the NETGEAR ProSafe VPN Wireless ADSL Gateway DGFV338 as we are using this router as the firewall, but not sure how you can make exceptions whilst creating the rules.</p>
<p>Where can I locate the Windows Malicious code remover, can I manually save it and then run from sbs2008 server?  My security settings dont allow me to download.</p>
<p>Thanks,<br />
George</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: trizzz</title>
		<link>http://trizzz.com/2009/04/cutwail-spambot/comment-page-1/#comment-129</link>
		<dc:creator>trizzz</dc:creator>
		<pubDate>Thu, 22 Oct 2009 16:25:08 +0000</pubDate>
		<guid isPermaLink="false">http://trizzz.com/?p=23#comment-129</guid>
		<description>The best thing to do is to block port 25 except for your mail server.  Your PCs don&#039;t need to access port 25, except for a spambot to send out mail.  Doing this eliminates 95% of the problems that&#039;s associated with spambots.

If you&#039;re sure the spambot is gone, the blacklists will eventually automatically remove you from the lists.  If you know which lists you&#039;re on...you can go and manually petition each one to remove you now.

The problem with this, once you get removed and you HAVEN&#039;T removed the issue, then they&#039;ll put you back on the list and it&#039;ll be harder to take yourself off of them.

The program that I found worked best to remove the cutWAIL spambot was actually the Windows Malicious Code remover.  It&#039;s a free download from Microsoft&#039;s website...and it found the CutWail spambot and removed it easily.

Best of Luck, George!</description>
		<content:encoded><![CDATA[<p>The best thing to do is to block port 25 except for your mail server.  Your PCs don&#8217;t need to access port 25, except for a spambot to send out mail.  Doing this eliminates 95% of the problems that&#8217;s associated with spambots.</p>
<p>If you&#8217;re sure the spambot is gone, the blacklists will eventually automatically remove you from the lists.  If you know which lists you&#8217;re on&#8230;you can go and manually petition each one to remove you now.</p>
<p>The problem with this, once you get removed and you HAVEN&#8217;T removed the issue, then they&#8217;ll put you back on the list and it&#8217;ll be harder to take yourself off of them.</p>
<p>The program that I found worked best to remove the cutWAIL spambot was actually the Windows Malicious Code remover.  It&#8217;s a free download from Microsoft&#8217;s website&#8230;and it found the CutWail spambot and removed it easily.</p>
<p>Best of Luck, George!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: George</title>
		<link>http://trizzz.com/2009/04/cutwail-spambot/comment-page-1/#comment-128</link>
		<dc:creator>George</dc:creator>
		<pubDate>Thu, 22 Oct 2009 16:10:56 +0000</pubDate>
		<guid isPermaLink="false">http://trizzz.com/?p=23#comment-128</guid>
		<description>Hi,

I am experiencing a similar issue, cant send out emails on our domain.  I blocked the NDRs on exchange, but am using 2007 and I have ticked the box.  Is there anything else I need to do?

Also, not sure about blocking port 25 and only allowing the mailserver and blackberry server through sbs2008 firewall.

We have 40 PCs on the network, and I have ran Trend AV, and malwarebytes on all pcs, yet am still getting blocked

Anyone have any ideas?

Thanks</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>I am experiencing a similar issue, cant send out emails on our domain.  I blocked the NDRs on exchange, but am using 2007 and I have ticked the box.  Is there anything else I need to do?</p>
<p>Also, not sure about blocking port 25 and only allowing the mailserver and blackberry server through sbs2008 firewall.</p>
<p>We have 40 PCs on the network, and I have ran Trend AV, and malwarebytes on all pcs, yet am still getting blocked</p>
<p>Anyone have any ideas?</p>
<p>Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: CHUCKLZ</title>
		<link>http://trizzz.com/2009/04/cutwail-spambot/comment-page-1/#comment-127</link>
		<dc:creator>CHUCKLZ</dc:creator>
		<pubDate>Tue, 22 Sep 2009 15:46:20 +0000</pubDate>
		<guid isPermaLink="false">http://trizzz.com/?p=23#comment-127</guid>
		<description>I just looked for the computer with the background stating that &quot;I AM AT RISK!&quot; with binary background. :P</description>
		<content:encoded><![CDATA[<p>I just looked for the computer with the background stating that &#8220;I AM AT RISK!&#8221; with binary background. <img src='http://trizzz.com/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dan</title>
		<link>http://trizzz.com/2009/04/cutwail-spambot/comment-page-1/#comment-124</link>
		<dc:creator>dan</dc:creator>
		<pubDate>Thu, 23 Jul 2009 16:21:41 +0000</pubDate>
		<guid isPermaLink="false">http://trizzz.com/?p=23#comment-124</guid>
		<description>I had the cutwail trojan sending spam.
Our internet provider blocked outgoing email over smtp port 25 until resolved.
Our CA etrust pestpatrol didnt pick it up at first!
What worked for me was to add a firewall rule to block all outgoing smtp trafic on port 25 and have it log all connection attempts.
Viewed the logs(ruling out my email server/s ip to start) and the offending ip was obvious as the hits were 100&#039;s per minute.
match the ip to a computer by checking DHCP allocations.
Scan the offending ip/PC with the latest MRT (Microsoft Malicious Software Removal Tool)and disconnect it from the network until clean.
Re enable SMPT traffic on the firewall after double checking the logs for other possible spaming.
Happy Hunting :)</description>
		<content:encoded><![CDATA[<p>I had the cutwail trojan sending spam.<br />
Our internet provider blocked outgoing email over smtp port 25 until resolved.<br />
Our CA etrust pestpatrol didnt pick it up at first!<br />
What worked for me was to add a firewall rule to block all outgoing smtp trafic on port 25 and have it log all connection attempts.<br />
Viewed the logs(ruling out my email server/s ip to start) and the offending ip was obvious as the hits were 100&#8242;s per minute.<br />
match the ip to a computer by checking DHCP allocations.<br />
Scan the offending ip/PC with the latest MRT (Microsoft Malicious Software Removal Tool)and disconnect it from the network until clean.<br />
Re enable SMPT traffic on the firewall after double checking the logs for other possible spaming.<br />
Happy Hunting <img src='http://trizzz.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jensen Consulting Pte Ltd &#187; Blog Archive &#187; Corporate Enterprise – Why you need more IP’s</title>
		<link>http://trizzz.com/2009/04/cutwail-spambot/comment-page-1/#comment-123</link>
		<dc:creator>Jensen Consulting Pte Ltd &#187; Blog Archive &#187; Corporate Enterprise – Why you need more IP’s</dc:creator>
		<pubDate>Wed, 22 Jul 2009 20:34:33 +0000</pubDate>
		<guid isPermaLink="false">http://trizzz.com/?p=23#comment-123</guid>
		<description>[...] experiencing a major IT Problem, one computer on the network have most likely been infected by a spamBOT – and are being blacklisted on the relevant spam [...]</description>
		<content:encoded><![CDATA[<p>[...] experiencing a major IT Problem, one computer on the network have most likely been infected by a spamBOT – and are being blacklisted on the relevant spam [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Georg</title>
		<link>http://trizzz.com/2009/04/cutwail-spambot/comment-page-1/#comment-122</link>
		<dc:creator>Georg</dc:creator>
		<pubDate>Mon, 01 Jun 2009 06:49:42 +0000</pubDate>
		<guid isPermaLink="false">http://trizzz.com/?p=23#comment-122</guid>
		<description>We were blacklisted by CBL and others. The message on CBL was that we were infected by cutwail spamBOT.

After an intensive weekend spent with scanning pc&#039;s and systems without success, we found out, that our exchange server was abused as spam server by sending non delivery reports (NDR) messages to faked senders.

Disabling NDR solved the problem.

Disable NDR:
From Exchange System Manager, Global Settings, Internet Message Format. 
Double click on your right. Advanced tab. Uncheck Allow 
non-delivery reports.

You must also activate the setting on the smtp connection protocol: Exchange Server, Protocols, Virtual Default Server =&gt; Properties by left click.
In the popup: General, Click on listed item, click on the button &#039;modify&#039;.
In the popup: Check &quot;Absendungskennungsfilter verwenden&quot; on the top right (Sorry, I&#039;ve only an german Exchange, must be translated similar to &#039;use sender identification filter&#039;)</description>
		<content:encoded><![CDATA[<p>We were blacklisted by CBL and others. The message on CBL was that we were infected by cutwail spamBOT.</p>
<p>After an intensive weekend spent with scanning pc&#8217;s and systems without success, we found out, that our exchange server was abused as spam server by sending non delivery reports (NDR) messages to faked senders.</p>
<p>Disabling NDR solved the problem.</p>
<p>Disable NDR:<br />
From Exchange System Manager, Global Settings, Internet Message Format.<br />
Double click on your right. Advanced tab. Uncheck Allow<br />
non-delivery reports.</p>
<p>You must also activate the setting on the smtp connection protocol: Exchange Server, Protocols, Virtual Default Server =&gt; Properties by left click.<br />
In the popup: General, Click on listed item, click on the button &#8216;modify&#8217;.<br />
In the popup: Check &#8220;Absendungskennungsfilter verwenden&#8221; on the top right (Sorry, I&#8217;ve only an german Exchange, must be translated similar to &#8216;use sender identification filter&#8217;)</p>
]]></content:encoded>
	</item>
</channel>
</rss>
