Upload maxed out

We have a T1 line and someone was trying to ftp a file and it showed 5 hours remaining. I checked the graph usage from our internet site and it shows 280 download and 22 upload (we usually have 1.5 download and 700 upload. I don't know what is going on. I rebooted the PIX firewall and the Cisco router and for a moment it went down but 15 min later it went all the way up again. Do you have any idea what I could do at this point? The internet provider sayd it is internally. ANy hint is appreaciated. Thanks.
Bob MacphersonAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

do you have someone using a file share or something?
Bob MacphersonAuthor Commented:
You mean like Kazaa or Limewire? I don't think so, I hope not!
what do the pix logs tell you?
do you have logging on all your polcies?
see any unknown traffic, or spam traffic?
Cloud Class® Course: Microsoft Exchange Server

The MCTS: Microsoft Exchange Server 2010 certification validates your skills in supporting the maintenance and administration of the Exchange servers in an enterprise environment. Learn everything you need to know with this course.

Bob MacphersonAuthor Commented:
I found out that is the Exchange server, when I turn it off and disconnect it everything goes back to normal, as soon as I sign back in and start the services, the T1 line goes crazy. What should I do, how do I stop it, what can be in there that creates this problem? Thanks.
You need to scrub your Exchange server. It may be setup as a mail relay host and is sending out tons of spam without your knowlege. It could be infected with virus or worm..


Bob MacphersonAuthor Commented:
It wasn't spam there were 256 SMTP queues retrying for 48 hours. I deleted them and everything is fine now.
Good catch :)
I've had clients with the same problem.

There is a tool you should look into, MailBasketMD - http://www.turbogeeks.com/products/mailbasket.asp.

Technically, it breaks the SMTP standards by accepting ANY address and throwing away mail that doesn't match up with a valid userid.  This prevents the build up of a huge # of failure messages to bogus servers.

PAQed with points refunded (500)

Community Support Moderator

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.