Exchange queue keeps growing - SPAM issue

Posted on 2009-04-22
Last Modified: 2012-06-21
Hi Experts,

need your help. Yesterday we are being hit by spam; it seems coming from internal because the firewall showing me it's coming from internal IP address to external IP add.

Now the problem is the ESM showing huge numbers of connectors with 1 - 100 messages per connector. Up until now we have 55K messages in connector. I have meade a temp connector with a fake IP address so that I can redirect all the messages in 1 connector and delete them from there. But again the messages keeps growing like crazy.

I've scanned the machine with Our AV and find nothing.

Also I've keep deleting those messages with aqadmcli to delete all messages automatically; but the speed of the messages and deleting message are almost the same. I've disabled the outbound email and put the box out of the network.

Please advise..... really need a solution and help.

Currently my emails running on a backup link and thanks God, all of my stores are also on a different box.


Question by:DAHITSydney
    LVL 7

    Expert Comment

    Delete the temp tables.
    LVL 65

    Expert Comment

    Unless the messages are going to your own domain, then if it was a machine infected inside your network then the messages would not appear in the Exchange queues.

    These two blog postings will explain why that is not the case.

    ESM is notorious for being unable to show the true extent of the queues after the server has been abused, so even after disconnecting the server from the internet, messages will continue to appear in the queues. That is simply while Exchange processes the messages. When a spammer has been able to compromise a server they will send 1000s of messages through it.

    My spam cleanup article will help you find out how the server was compromised and clean up the mess:

    LVL 2

    Accepted Solution

    Problem solved; it's a virus on the machine. using sysclean from trend micro.

    thanks all.


    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    How your wiki can always stay up-to-date

    Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
    - Increase transparency
    - Onboard new hires faster
    - Access from mobile/offline

    Get an idea of what you should include in an email disclaimer with these Top 5 email disclaimer tips.
    Check out this infographic on what you need to make a good email signature that will work perfectly for your organization.
    In this video we show how to create a Shared Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Sha…
    In this video we show how to create an email address policy in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Mail Flow…

    737 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    22 Experts available now in Live!

    Get 1:1 Help Now