inetinfo.exe Windows 2000 Small business Server

Hello,

I am having a problem that started a few days ago, my servers inetinfo.exe file is bogging down my server, it is contstanly accessing the hard drive (I/O read and writes) and filling my memory resources reaching at times 300MB in memory. When I shut down IIS the file disappears and my servers works fine again, except i dont have access to my exchange server or IIS no more.

I only have 3 users on this server and its is connected to the inernet thourgh one NIC and connected to my local LAN with another NIC. (So there are 2 NICS on the server).

Please give me a solution to this.

THanks
Freddy
micropanAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

MSGeekCommented:
If it is connected directly to the internet and you do not have a software and hardware firewall in place, it is very likely your web server has been hijacked.  What do you have for firewall protection?  Hardware and software?  Do you have any strange directories under Inetpub/wwwroot?  If you have been connected directly to the internet back up you data, rebuild your server, install hardware and sofwatre firewalls and then reconnect to the internet.  Good luck, MSGeek
0
micropanAuthor Commented:
I have done reseach on this site , and have come to the conclusion that I am a victim of spammers,,,the have apparnelty used my exchange server to send over 20,000 emails over a period of 3 days (wow!!).

Anyways i have disabled relaying in the SMTP (virtual server) and enabled a authentecation for smtp,,, and for some unknow reason the spammers are still able to use my exchange to relay mail,, the only way I am able to stop them is by completely disabling my SMTP (Virtual server)

I need this to stop this, because I am already being blacklisted from other domains and its is eating up our bandwidth.

MY question now is how do I stop these spammers from relaying from my server, and still allow ,my legitment users use server to send emails?

0
jonbar610Commented:
After you made the changes to the SMTP process to disallow relay, did you stop and restart the SMTP services on the server?  When you disabled the SMTP relay, did you allow any addresses in the list of allowed computers, or did you only force authentication?

Jon
0
Cloud Class® Course: Microsoft Windows 7 Basic

This introductory course to Windows 7 environment will teach you about working with the Windows operating system. You will learn about basic functions including start menu; the desktop; managing files, folders, and libraries.

MSGeekCommented:
jon.. that is a valid commebt, but if he is seriously compromised and not just relaying there is no telling what kinds of back doors have been put in place.
0
MSGeekCommented:
jon.. that is a valid commebt, but if he is seriously compromised and not just relaying there is no telling what kinds of back doors have been put in place.
0
jonbar610Commented:
I agree, MSGeek.  I was giving the benefit of the doubt to Freddy that he was using some level of filtering on the server.  I made this assumption solely on the basis that he did some research and recognized that SMTP was being heavily utilized for relay.  If this is the case, then he needs to configure SMTP correctly in order to stop the relaying.  However, I fully agree that if there is the possibility of compromise (besides relay), he should absolutely rebuild the server and implement a firewall.  

I would recommend running some sort of spy detection software such as Pest Patrol.  If no strange services or directories are realized and filtering is being used, then Freddy should configure SMTP correctly (stop relay), and I would still go with your suggestion about the firewall at that point (rebuild may not be necessary if the server is hardened).

That being said, Freddy, is the server hardened or are any filtering features being used?
0
MSGeekCommented:
micropan.. did you ever get this resolved??  MSGeek.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
MSGeekCommented:
micropan... Thx, but I believe it would only be fair to give jonbar610 credit at least for an assist, his answer was accurate.  MSGeek.
0
jonbar610Commented:
Thank you, MSGeek.  I appreciate the recognition.

Jon
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows 2000

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.