[Webinar] Streamline your web hosting managementRegister Today

x
?
Solved

Infected Exchange 2003 Server

Posted on 2010-04-07
11
Medium Priority
?
345 Views
Last Modified: 2012-05-09
ok, i think my exchange server is infected and it's sending out SPAM like mad.  I'm on three blacklists now and my queue is packed full of over 3000 outbound connections to everyone on the planet.  When I message track everything in the last four hours, it's full of spam.

I'm running a virus scan on it now.  my last report showed over 1500 items NOT removed.

I know it's going to sound dumb, but can I stop my exchange server from sending outbound mail and still allow my users to send thru it?

Cliff
0
Comment
Question by:crp0499
  • 5
  • 5
11 Comments
 
LVL 24

Expert Comment

by:Mike Thomas
ID: 30030231
Delet your outbound smtp connector, internal email will still function.
0
 
LVL 76

Accepted Solution

by:
Alan Hardisty earned 2000 total points
ID: 30030252
0
 

Author Comment

by:crp0499
ID: 30034532
Alan, I have followed the instructions in your post.  It appears that it is an authenticated relay attack but some of the messages are coming from postmaster@mydomain.com as well.  Some are from gmail too.
0
Easily manage email signatures in Office 365

Managing email signatures in Office 365 can be a challenging task if you don't have the right tool. CodeTwo Email Signatures for Office 365 will help you implement a unified email signature look, no matter what email client is used by users. Test it for free!

 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 30034949
If they are mixed, concentrate on finding the breached account (details in my article) and change the password of that account, then resolve the postmaster problem and then cleanup.
0
 

Author Comment

by:crp0499
ID: 30035686
so far, since I only have 20 users including admin, i have changed ALL passwords.  good start?
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 30036233
Yep - it makes working out which one is compromised a lot easier.

Do now concentrate on the ndr spam, which suggests you are not rejecting invalid recipients, then cleanup and you should be fine.

Just make sure you use dissimilar passwords for everyone and make them hard to guess etc.  Combine Upper Case with Lower Case and add Numbers and special characters such as ! and $ etc.

0
 

Author Comment

by:crp0499
ID: 30036375
right, i did lots of @ symbols, zeros for O's and that sort of thing.  before they were all pretty simple.  I even changed the admin password.

my SMTP server HAS recipient filtering turned on to reject invalid recipients.  not sure about the NDR's
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 30037065
Leave the ndr's then if you are rejecting invalid recipients.  Cleanup your queues and wait for calm to return!
0
 

Author Comment

by:crp0499
ID: 30038562
ok, I've done everything in BOTH scenarios and after a restart of SMTP, my first message is from attpaymentdept11@gmail to about a million people so far...
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 30039579
Sounds like you either have an account you don't know about or you are infected.

Turn up the logging as per my article and monitor the Event Logs.

Have you alsogot 127.0.0.1 in the Relay lost on your SMTP Virtual Server?  If so, remove it.
0
 

Author Closing Comment

by:crp0499
ID: 31711884
His follow-up support was invaluable!
0

Featured Post

Free tool for managing users' photos in Office 365

Easily upload multiple users’ photos to Office 365. Manage them with an intuitive GUI and use handy built-in cropping and resizing options. Link photos with users based on Azure AD attributes. Free tool!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this post, we will learn to set up the Group Naming policy and will see how it is going to impact the Display Name and the Email addresses of the Group.
This article explains how to move an Exchange 2013/2016 mailbox database and logs to a different drive.
Whether it be Exchange Server Crash Issues, Dirty Shutdown Errors or Failed to mount error, Stellar Phoenix Mailbox Exchange Recovery has always got your back. With the help of its easy to understand user interface and 3 simple steps recovery proced…
This video tutorial shows you the steps to go through to set up what I believe to be the best email app on the android platform to read Exchange mail.  Get the app on your phone: The first step is to make sure you have the Samsung Email app on your …
Suggested Courses

608 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question