I have about 50 pop3 email users on my Exchange 2003 server. I suspect that someone has a virus because my mail queues are full of "Fifth Third Bank" and "Bank of America" spam. I have cleaned up the queue but because the virus spoofs the from address I need to figure out what account they are using to access my server. I've tried setting up diagnostics logging for MSExchange Transport-> SMTP protocol and set it to maximum logging level but all I get are warnings and errors in the event log. I'm trying to genenerate one of the following log entries but am not having any luck.
Event Type: Information
Event Source: MSExchangeTransport
Event Category: SMTP Protocol
Event ID: 1708
Date: 8/13/2003
Time: 10:13:24 AM
User: N/A
Computer: SERVER
Description: SMTP Authentication was performed successfully with client remote_computername. The authentication method was LOGIN and the username was company\username.
Per
http://support.microsoft.com/kb/324958 Start Free Trial