How to find and remove bots from your network

420 pts.
Tags:
Bots
malware
Spam
Symantec
TrendMicro
We have noticed several users receiving undeliverable messages in their Inbox. Unfortunately, they did not send out these emails and considering that they are receiving quite a bit of these messages, it has led me to the conclusion we have been hit and infected with a bot. We are running Exchange 03 and PCs with XP SP2/SP3. Our Symantec and Trend Micro were not able to find and remove. Anyone have a method they have tried successfully to find and remove a bot from a network. Thanks in advance for the help.

Answer Wiki

Thanks. We'll let you know when a new response is added.

I do not suspect a bot. Instead I suspect that these users are receiving messages due to backscatter. Take a look at this similar question by another member.

Also, see this for more detailed information about backscatter.

You don’t really need to spend a lot of time looking for a bot issue as this is a “feature” of how SMTP e-mail works.

Discuss This Question:  

 
There was an error processing your information. Please try again later.
Thanks. We'll let you know when a new response is added.
Send me notifications when members answer or reply to this question.

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy

Forgot Password

No problem! Submit your e-mail address below. We'll send you an e-mail containing your password.

Your password has been sent to:

To follow this tag...

There was an error processing your information. Please try again later.

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy

Thanks! We'll email you when relevant content is added and updated.

Following