Exchange Queue filling up?

Got a problem here I wanted to see if anyone had ever come across. I have a small insurance company (8 people), the outbound Queue on their exchange server keeps filling up to the point where it stops processing mail. They were getting blacklisted bounceback emails so I figured that it was a virus sending out spam from their network. I found that virus on a PC that they said had virus problems and removed it. I filled out some stuff to get them delisted ,I cleared out the queue, restarted the virtual server and it appeared to be working as of last week. Now today the queue was full again and it wasnt working.

I then checked each PC for the virus and cleaned them all anyway but didn't find anything. The problem keeps happening. There's no way that they sent 22,543 messages to yahoo overnight while there are closed so it looks like either the virus is still there ion some way or there is some other problem. What can I do? Once the queue gets to a certian point it stops sending and recieving legitimate mail.
LVL 2
Axis52401Security AnalystAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

leegclystvaleCommented:
Is it acting as a relay? Check these settings
http://support.microsoft.com/kb/895853 and select
"If your Exchange computer is configured as an open mail relay that sends unsolicited commercial e-mail"
0
JoWickermanCommented:
Hi Jason0923,

It seems as though the Exchange server might be open for relaying?

http://www.checkor.com/

Test your IP and let me know?

Cheers.
0
Axis52401Security AnalystAuthor Commented:
I have checked the Relay settings and the server isn't configured as an open relay and here are the results from the http://www.checkor.com/  I have to keep stopping the Virtual server, deleting the queue and restarting it to keep the company's email running. I would appreciate eny help.

Thank you

220 QUAM2K3FS.quam.local Microsoft ESMTP MAIL Service, Version: 6.0.3790.1830 ready at Tue, 11 Nov 2008 09:04:42 -0600
HELO ortest.checkor.com
250 QUAM2K3FS.quam.local Hello [204.16.252.112]
RSET
250 2.0.0 Resetting
MAIL FROM: test@checkor.com
250 2.1.0 test@checkor.com....Sender OK
RCPT TO: test1@checkor.com
550 5.7.1 Unable to relay for test1@checkor.com


--------------------------------------------------------------------------------
RSET
250 2.0.0 Resetting
MAIL FROM:
501 5.5.4 Invalid Address
RCPT TO: test1@checkor.com
503 5.5.2 Need Mail From: first


--------------------------------------------------------------------------------
RSET
250 2.0.0 Resetting
MAIL FROM: spam@mail.quamins.com
250 2.1.0 spam@mail.quamins.com....Sender OK
RCPT TO: test1@checkor.com
550 5.7.1 Unable to relay for test1@checkor.com


--------------------------------------------------------------------------------
RSET
250 2.0.0 Resetting
MAIL FROM: spam@mail.quamins.com
250 2.1.0 spam@mail.quamins.com....Sender OK
RCPT TO: test1@checkor.com
550 5.7.1 Unable to relay for test1@checkor.com


--------------------------------------------------------------------------------
RSET
250 2.0.0 Resetting
MAIL FROM: spam@mail.quamins.com
250 2.1.0 spam@mail.quamins.com....Sender OK
RCPT TO: test1@mail.quamins.com
550 5.7.1 Unable to relay for test1@mail.quamins.com


--------------------------------------------------------------------------------
RSET
250 2.0.0 Resetting
MAIL FROM: spam@mail.quamins.com
250 2.1.0 spam@mail.quamins.com....Sender OK
RCPT TO: "test1@test.com"@mail.quamins.com
550 5.7.1 Unable to relay for "test1@test.com"@mail.quamins.com


--------------------------------------------------------------------------------
RSET
250 2.0.0 Resetting
MAIL FROM: spam@mail.quamins.com
250 2.1.0 spam@mail.quamins.com....Sender OK
RCPT TO: @mail.quamins.com:spamtest@checkor.com
550 5.7.1 Unable to relay for spamtest@checkor.com
0
JoWickermanCommented:
Ok, so the server is not open for relaying... Then it has  to be a virus... Did you check the Exchange server itself for viruses?
0
JoWickermanCommented:
Hi,

Are you happy with the solution? If so, you can close the question and award points.

Cheers.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Anti-Virus Apps

From novice to tech pro — start learning today.