I
I
Ivan Kozlov2016-04-08 09:38:13
System administration
Ivan Kozlov, 2016-04-08 09:38:13

How to get rid of spam virus?

There is a vds with vesta socket. Hosted multiple sites. Through some of them the virus was introduced and multiplied. I cleaned completely all sites (99%) sure. Installed maldet. They scanned the entire server up and down - found nothing.
Now the problem is this, spam is sent from the server. Where is not clear. Apache and Mysql eat up maximum memory. And I don't know what to do. Can anyone suggest options? Attached log with exim4.

2016-04-08 06:23:32 1ansu0-0001HR-NY SMTP error from remote mail server after MAIL FROM:<Мой email> SIZE=3135: host mta6.am0.yahoodns.net [98.138.112.37]: 421 4.7.0 [TS01] Messages from 188.225.36.106 temporarily deferred due to user complaints - 4.16.55.1; see https://help.yahoo.com/kb/postmaster/SLN3434.html
2016-04-08 06:23:32 1anqXE-0008VA-FA SMTP error from remote mail server after MAIL FROM:<Мой email> SIZE=3486: host mta6.am0.yahoodns.net [66.196.118.240]: 421 4.7.0 [TS01] Messages from 188.225.36.106 temporarily deferred due to user complaints - 4.16.55.1; see https://help.yahoo.com/kb/postmaster/SLN3434.html
2016-04-08 06:23:32 1any4J-0000Vy-18 SMTP error from remote mail server after MAIL FROM:<Мой email> SIZE=3443: host mta7.am0.yahoodns.net [66.196.118.34]: 421 4.7.0 [TS01] Messages from 188.225.36.106 temporarily deferred due to user complaints - 4.16.55.1; see https://help.yahoo.com/kb/postmaster/SLN3434.html
2016-04-08 06:23:32 1ao13W-0005Gu-FH SMTP error from remote mail server after MAIL FROM:<Мой email2> SIZE=1794: host mta6.am0.yahoodns.net [66.196.118.240]: 421 4.7.0 [TS01] Messages from 188.225.36.106 temporarily deferred due to user complaints - 4.16.55.1; see https://help.yahoo.com/kb/postmaster/SLN3434.html
2016-04-08 06:23:32 1ao05m-0006bf-7i SMTP error from remote mail server after MAIL FROM:<Мой email> SIZE=3453: host mta6.am0.yahoodns.net [98.136.216.25]: 421 4.7.0 [TS01] Messages from 188.225.36.106 temporarily deferred due to user complaints - 4.16.55.1; see https://help.yahoo.com/kb/postmaster/SLN3434.html
2016-04-08 06:23:33 1ansu0-0001HR-NY SMTP error from remote mail server after MAIL FROM:<Мой email> SIZE=3135: host mta6.am0.yahoodns.net [66.196.118.240]: 421 4.7.0 [TS01] Messages from 188.225.36.106 temporarily deferred due to user complaints - 4.16.55.1; see https://help.yahoo.com/kb/postmaster/SLN3434.html
2016-04-08 06:23:34 1anqXE-0008VA-FA SMTP error from remote mail server after MAIL FROM:<Мой email> SIZE=3486: host mta6.am0.yahoodns.net [98.136.216.26]: 421 4.7.0 [TSS04] Messages from 188.225.36.106 temporarily deferred due to user complaints - 4.16.55.1; see https://help.yahoo.com/kb/postmaster/SLN3434.html
2016-04-08 06:23:34 1ao13W-0005Gu-FH SMTP error from remote mail server after MAIL FROM:<Мой email2> SIZE=1794: host mta6.am0.yahoodns.net [98.138.112.34]: 421 4.7.0 [TS01] Messages from 188.225.36.106 temporarily deferred due to user complaints - 4.16.55.1; see https://help.yahoo.com/kb/postmaster/SLN3434.html
2016-04-08 06:23:34 1any4J-0000Vy-18 SMTP error from remote mail server after MAIL FROM:<Мой email> SIZE=3443: host mta7.am0.yahoodns.net [98.136.216.25]: 421 4.7.0 [TS01] Messages from 188.225.36.106 temporarily deferred due to user complaints - 4.16.55.1; see https://help.yahoo.com/kb/postmaster/SLN3434.html
2016-04-08 06:23:34 1any4J-0000Vy-18 == [email protected] R=dnslookup T=remote_smtp defer (-45): SMTP error from remote mail server after MAIL FROM:<Мой email> SIZE=3443: host mta7.am0.yahoodns.net [98.136.216.25]: 421 4.7.0 [TS01] Messages from 188.225.36.106 temporarily deferred due to user complaints - 4.16.55.1; see https://help.yahoo.com/kb/postmaster/SLN3434.html
2016-04-08 06:23:34 1ao05m-0006bf-7i SMTP error from remote mail server after MAIL FROM:<Мой email> SIZE=3453: host mta6.am0.yahoodns.net [98.138.112.37]: 421 4.7.0 [TS01] Messages from 188.225.36.106 temporarily deferred due to user complaints - 4.16.55.1; see https://help.yahoo.com/kb/postmaster/SLN3434.html
2016-04-08 06:23:34 1ansu0-0001HR-NY SMTP error from remote mail server after MAIL FROM:<Мой email> SIZE=3135: host mta6.am0.yahoodns.net [63.250.192.46]: 421 4.7.0 [TS01] Messages from 188.225.36.106 temporarily deferred due to user complaints - 4.16.55.1; see https://help.yahoo.com/kb/postmaster/SLN3434.html
2016-04-08 06:23:34 1ansu0-0001HR-NY == [email protected] R=dnslookup T=remote_smtp defer (-45): SMTP error from remote mail server after MAIL FROM:<Мой email> SIZE=3135: host mta6.am0.yahoodns.net [63.250.192.46]: 421 4.7.0 [TS01] Messages from 188.225.36.106 temporarily deferred due to user complaints - 4.16.55.1; see https://help.yahoo.com/kb/postmaster/SLN3434.html
2016-04-08 06:23:34 1aoPpO-0003zQ-SM <= <> R=1ansu0-0001HR-NY U=Debian-exim P=local S=1495
2016-04-08 06:23:34 1aoPpO-0003zQ-SM ** Мой email: Unrouteable address
2016-04-08 06:23:34 1aoPpO-0003zQ-SM Frozen (delivery error message)
2016-04-08 06:23:35 1anqXE-0008VA-FA SMTP error from remote mail server after MAIL FROM:<Мой email> SIZE=3486: host mta6.am0.yahoodns.net [98.138.112.34]: 421 4.7.0 [TS01] Messages from 188.225.36.106 temporarily deferred due to user complaints - 4.16.55.1; see https://help.yahoo.com/kb/postmaster/SLN3434.html
2016-04-08 06:23:35 1ao13W-0005Gu-FH SMTP error from remote mail server after MAIL FROM:<Мой email2> SIZE=1794: host mta6.am0.yahoodns.net [98.136.217.203]: 421 4.7.0 [TS01] Messages from 188.225.36.106 temporarily deferred due to user complaints - 4.16.55.1; see https://help.yahoo.com/kb/postmaster/SLN3434.html
2016-04-08 06:23:35 1ao0Cm-0001Hx-Am SMTP error from remote mail server after MAIL FROM:<Мой email2> SIZE=1674: host mta6.am0.yahoodns.net [98.136.216.25]: 421 4.7.0 [TS01] Messages from 188.225.36.106 temporarily deferred due to user complaints - 4.16.55.1; see https://help.yahoo.com/kb/postmaster/SLN3434.html
2016-04-08 06:23:35 1ao05m-0006bf-7i SMTP error from remote mail server after MAIL FROM:<Мой email> SIZE=3453: host mta6.am0.yahoodns.net [63.250.192.46]: 421 4.7.0 [TS01] Messages from 188.225.36.106 temporarily deferred due to user complaints - 4.16.55.1; see https://help.yahoo.com/kb/postmaster/SLN3434.html
2016-04-08 06:23:35 1ao05m-0006bf-7i == [email protected] R=dnslookup T=remote_smtp defer (-45): SMTP error from remote mail server after MAIL FROM:<Мой email> SIZE=3453: host mta6.am0.yahoodns.net [63.250.192.46]: 421 4.7.0 [TS01] Messages from 188.225.36.106 temporarily deferred due to user complaints - 4.16.55.1; see https://help.yahoo.com/kb/postmaster/SLN3434.html
2016-04-08 06:23:35 1anukD-0004DE-Tj SMTP error from remote mail server after MAIL FROM:<Мой email> SIZE=3528: host mta5.am0.yahoodns.net [66.196.118.240]: 421 4.7.0 [TS01] Messages from 188.225.36.106 temporarily deferred due to user complaints - 4.16.55.1; see https://help.yahoo.com/kb/postmaster/SLN3434.html
2016-04-08 06:23:36 1ao13W-0005Gu-FH SMTP error from remote mail server after MAIL FROM:<Мой email2> SIZE=1794: host mta6.am0.yahoodns.net [66.196.118.36]: 421 4.7.0 [TS01] Messages from 188.225.36.106 temporarily deferred due to user complaints - 4.16.55.1; see https://help.yahoo.com/kb/postmaster/SLN3434.html
2016-04-08 06:23:36 1ao13W-0005Gu-FH == [email protected] R=dnslookup T=remote_smtp defer (-45): SMTP error from remote mail server after MAIL FROM:<Мой email2> SIZE=1794: host mta6.am0.yahoodns.net [66.196.118.36]: 421 4.7.0 [TS01] Messages from 188.225.36.106 temporarily deferred due to user complaints - 4.16.55.1; see https://help.yahoo.com/kb/postmaster/SLN3434.html
2016-04-08 06:23:36 1aoPpQ-0003zg-Lq <= <> R=1ao13W-0005Gu-FH U=Debian-exim P=local S=1468
2016-04-08 06:23:36 1aoPpQ-0003zg-Lq ** Мой email2: Unrouteable address
2016-04-08 06:23:36 1aoPpQ-0003zg-Lq Frozen (delivery error message)
2016-04-08 06:23:36 1anseN-0004rz-QH Message is frozen

Answer the question

In order to leave comments, you need to log in

1 answer(s)
P
Puma Thailand, 2016-04-08
@trampick

scan ai-bolit, maldet is so clean for the mass destruction of the most banal viruses
, well, to find out who sends in php there is an option php nail log in php ini
it will save to a file which script sends letters

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question