Solved

Lots of traffic between server and internet causing very slow surfing.

Posted on 2004-09-25
5
233 Views
Last Modified: 2010-03-18
Hi,

I have a windows 2000 server with Exchange 2000 installed. Users have experienced very slow internet surfing recently.

The network connects to the Internet via an ADSL Draytek router. I have shut down all machines and what I notice is that there are lots of packets being sent and received between the server and router. In fact the server is sending twice as many packets as it is receving. This is contineous and never stops

So far I have:
shut down all the exchange services
Virus scanned the server
Rebooted
All security updates have being installed

I have used network monitor to capture some packets and I always see the source or destination port as SMTP. Our Exchange server downloads via POP3 so I am unsure why I keep seeing this. Does anyone have any further ideas on how I can solve this?

0
Comment
Question by:Danbrasco
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
5 Comments
 
LVL 15

Expert Comment

by:adamdrayer
ID: 12152444
Sounds most definately like a virus. Try the following:

1. Make sure your virus definition files are up to date (Viruses may kill the update process)
2. Reboot into safe mode and run a system scan again
3. Get a 2nd Opinion from an online virus scanning system like http://housecall.trendmicro.com
4. Run AdAware http://lavasoftusa.com and SpyBot http://www.safer-networking.org/en/index.html to check for other types of nasties
5. Run HijackThis http://www.majorgeeks.com/download3155.html and get the log file analyzed here:
http://hijackthis.de/index.php?langselect=english
0
 
LVL 15

Expert Comment

by:adamdrayer
ID: 12152449
sorry, the AdAware URL should have been http://www.lavasoftusa.com
0
 

Author Comment

by:Danbrasco
ID: 12156527
I think the problem is to do with the SMTP connector. Under Default SMTP Virtual Server \ Queues there are hundreds of SMTP connectors. I guess these are messages of some sort but I am unsure. They all say Small Business SMTP connector - (website name).

It seems at first glance that my server is being used to relay spam but the I disabled relaying when I first set it up. How do you think all these messages got here? Is there a way of manually deleting them?
0
 
LVL 15

Accepted Solution

by:
adamdrayer earned 250 total points
ID: 12156539
How To Block Open SMTP Relaying and Clean Up Exchange Server SMTP Queues on SBS
http://support.microsoft.com/default.aspx?kbid=324958&product=sbserv2003
0
 

Author Comment

by:Danbrasco
ID: 12158529
Many thanks for this.

I spent a lot of time on this but finally managed to get it solved. Problem is, I still don't know how they managed to use my server since I had all the settings for relaying disabled.

Will have to do some further research.
0

Featured Post

Get 15 Days FREE Full-Featured Trial

Benefit from a mission critical IT monitoring with Monitis Premium or get it FREE for your entry level monitoring needs.
-Over 200,000 users
-More than 300,000 websites monitored
-Used in 197 countries
-Recommended by 98% of users

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article is in response to a question (http://www.experts-exchange.com/Networking/Network_Management/Network_Analysis/Q_28230497.html) here at Experts Exchange. The Original Poster (OP) requires a utility that will accept a list of IP addresses …
This is the first one of a series of articles I’ll be writing to address technical issues that are always referred to as network problems. The network boundaries have changed, therefore having an understanding of how each piece in the network  puzzl…
There's a multitude of different network monitoring solutions out there, and you're probably wondering what makes NetCrunch so special. It's completely agentless, but does let you create an agent, if you desire. It offers powerful scalability …
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…
Suggested Courses
Course of the Month9 days, 5 hours left to enroll

615 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question