How do I get rid of error message "This is an SMTP protocol log for virtual server ID 1, connection #67" from MSExchangeTransport?

The server irunning SBS 2003 R2.
Echange is 2004.
Everyday on my Server Performance Report, section Critical Errors in Application Log I get the same entry/error message.
The error message i get is:
Source                              Event ID              Last Occurrence         Total Occurrences
 MSExchangeTransport         7010        11/18/2008 7:29 AM               1
This is an SMTP protocol log for virtual server ID 1, connection #67. The client at "118.168.136.253" sent a "rcpt" command, and the SMTP server responded with "550 5.7.1 Unable to relay for poi@mail2000.com.tw ". The full command sent was "rcpt TO: <poi@mail2000.com.tw>". This will probably cause the connection to fail. For more information, click http://www.microsoft.com/contentredirect.asp.  
 
Everyday the IPaddress listed there is different as well as the email address listed.
How can I correct this so I would not get the entry in my report?
I would like to resolve this and move unto other projects.
j_ramesesInfo Sys MngrAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

65tdRetiredCommented:
Is there antivirus software running on the server?
Sounds like malware.
0
65tdRetiredCommented:
0
j_ramesesInfo Sys MngrAuthor Commented:
yes, I am running antivirus software by McAfee.
Admin passwords are not at default.
0
Powerful Yet Easy-to-Use Network Monitoring

Identify excessive bandwidth utilization or unexpected application traffic with SolarWinds Bandwidth Analyzer Pack.

j_ramesesInfo Sys MngrAuthor Commented:
65td,

I do not have an open relay.
How do I check for if I have a valid reverse DNS for my mail server.
Please provide details on how to resolve my error message/question above.
0
65tdRetiredCommented:
From Administrative tools -> open the DNS manager add a DNS if not listed expand the server and it should list Cached Lookups, Forward and reverse lookups.
Review entries and delete as necessary.

0
j_ramesesInfo Sys MngrAuthor Commented:
65td,

I opened up DNS Manager.
I expanded the server.
Three folders are listed:
1) Event Viewer
2) Forward Lookup Zones
3) Reverse Lookup Zones

What am I suppose to be looking for in Forward and reverse lookup zones?
0
65tdRetiredCommented:
Start by looking for: mail2000.com.tw
0
j_ramesesInfo Sys MngrAuthor Commented:
you mentioned "From Administrative tools -> open the DNS manager add a DNS if not listed expand the server and it should list Cached Lookups, Forward and reverse lookups."
I do not have a lsiting for 'Cached Lookups'.
How do I get that enabled? or to show up in DNS Manager?
0
j_ramesesInfo Sys MngrAuthor Commented:
i do not find a mail2000.com.tw in forward and reverse lookups.
0
65tdRetiredCommented:
Do you have a client at "118.168.136.253"?
0
j_ramesesInfo Sys MngrAuthor Commented:
I do not know that IP address.
It is not ours.
0
j_ramesesInfo Sys MngrAuthor Commented:
65td, you still there?
I can provide you with snapshots of the pages in the server and attach them to a word document for easy viewing.
0
j_ramesesInfo Sys MngrAuthor Commented:
65td,
Are you still there?
0
65tdRetiredCommented:
The issue still occurring?

Are other unknown addresses such as  203.69.82.30?

Today's ping of mail2000.com.tw
0
j_ramesesInfo Sys MngrAuthor Commented:
yes, it still is happening.
i get similar ones everyday.
I got 14 hits of this one this morning:
This is an SMTP protocol log for virtual server ID 1, connection #2. The client at "124.11.192.109" sent a "rcpt" command, and the SMTP server responded with "550 5.7.1 Unable to relay for sseenndd1201@yahoo.com.hk ". The full command sent was "rcpt TO:<sseenndd1201@yahoo.com.hk>". This will probably cause the connection to fail. For more information, click http://www.microsoft.com/contentredirect.asp.

What can be done to prevent this?
0
65tdRetiredCommented:
0
j_ramesesInfo Sys MngrAuthor Commented:
according to the link, it is spam trying to get relayed to my server and it is being blocked.
is that the same thing you understood from it?
0
j_ramesesInfo Sys MngrAuthor Commented:
i am not going to try any of the suggestions since it is nothing to worry abou.
I get nervous when I have to make changes to the server.
Do not know for sure if I should or ignore it.
0
65tdRetiredCommented:
One could monitor the traffic and maybe get a better idea of what's going on.
MS's network monitor 3.2 is pretty good.

http://www.microsoft.com/DownLoads/details.aspx?FamilyID=f4db40af-1e08-4a21-a26b-ec2f4dc4190d&displaylang=en
0
j_ramesesInfo Sys MngrAuthor Commented:
how do u use it
0
65tdRetiredCommented:
It's nice to use.
Download and install.
See (previous version):
http://support.microsoft.com/kb/812953

and  for version 3.2:
http://support.microsoft.com/kb/955998
0
j_ramesesInfo Sys MngrAuthor Commented:
got to go.
tomorrow can we run an example on how to use it.
i am new to this.
0
j_ramesesInfo Sys MngrAuthor Commented:
65td,
I am here.
Are you there?
So the tutorial can begin?
0
j_ramesesInfo Sys MngrAuthor Commented:
65td,

I automatically stopped receiving them after I had Microsoft was fixing a different problem with Exchange.
Therefore I am closiing this communiction.
Thank you  for your help, unfortunately I cannot award wany points.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Server Hardware

From novice to tech pro — start learning today.