Exchange Server 2007 is trying to send out spam emails.

I cannot find anywhere on my network any viruses or open relays please help as these msg's are beginning to flood in.

Diagnostic information for administrators:
Generating server: our.server.com e-cards@123greetings.com

mail.123greetings.com #550 5.1.1 <e-cards@123greetings.com>... User unknown ## Original message headers:
Received: fromour.server.com ([xxx.xxx.xxx.xxx]) by our.server.com ([xxx.xxx.xxx]) with mapi; Mon, 26 Apr 2010 14:51:55  -0400
From: <user><user@our.server.com>
To: "e-cards@123greetings.com" <e-cards@123greetings.com>
Date: Mon, 26 Apr 2010 14:51:53 -0400
Subject: [Ticket #8] New Comment: Undeliverable: Malicious object detected
Thread-Topic: [Ticket #8] New Comment: Undeliverable: Malicious object  detected
Thread-Index: AQHK5XGJzcrfh0WAdUu8nlYdBkX+FQ==
Message-ID: <B661FD4EACAA254187DE7D83683529FF0284DD6B00@our.server.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
acceptlanguage: en-US
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
microsoftexchange329e71ec88ae4615bbc36ab6ce41109e@alicart.local said: Delivery has failed to these recipients or distribution lists:

e-cards@123greetings.com

The recipient's e-mail address was not found in the recipient's e-mail system. Microsoft Exchange will not try to redeliver this message for you. Please check the e-mail address and try resending this message, or provide the following diagnostic text to your  system administrator.
The following organization rejected your message: mail.123greetings.com.

_______________________________

Sent by Microsoft Exchange Server 2007



So i ran a test to see if we were an open relay i got these results

220 xxx.xxx.xxx Microsoft ESMTP MAIL Service ready at Mon, 26 Apr 2010 15:20:39 -0400


Not an open relay.
 0 seconds - Good on Connection time
 5.226 seconds - Warning on Transaction time
 OK - xxx.xxx.xxx.xxx resolves to alicart.com
 OK - Reverse DNS matches SMTP Banner

Session Transcript:
HELO please-read-policy.mxtoolbox.com
250 xxx.xxx.xxx Hello [xxx.xxx.xxx.xxx] [62 ms]
MAIL FROM: <supertool@mxtoolbox.com>
250 2.1.0 Sender OK [47 ms]
RCPT TO: <test@example.com>
550 5.7.1 Unable to relay [5070 ms]
QUIT
221 2.0.0 Service closing transmission channel [47 ms]
Alicart IT Dept.Asked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

shauncroucherCommented:
Are your queues full or empty? Exchange management console --> Toolbox --> queue.

If empty, are you getting these as NDR's to internal users? If so, this is probably just backscatter.

Make sure you have recipient filtering enabled on your exchnange server. Do you use a third party hygiene service, if so, make sure you only accept mail from their IP address.

Shaun
Alicart IT Dept.Author Commented:
we use appriver for email filtering. as for the receive connector I'm assuming that you mean to set their ip in there correct?

the queue for that domain is there 123greetings.com with delivery type dnsconnectordelivery
Alicart IT Dept.Author Commented:
i suspended the queue for that domain but.....
Determine the Perfect Price for Your IT Services

Do you wonder if your IT business is truly profitable or if you should raise your prices? Learn how to calculate your overhead burden with our free interactive tool and use it to determine the right price for your IT services. Download your free eBook now!

shauncroucherCommented:
Yes, make sure only the IP range for appriver are in remote IP of receive connector. This should resolve the problem for you.

Shaun

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Alicart IT Dept.Author Commented:
I just made the changes, will let you know in a couple hours how it worked Thanks so much for your quick response.....
Alicart IT Dept.Author Commented:
Great Stuff !!!
Alicart IT Dept.Author Commented:
I can already tell its working !!!! Thanks you once again.
shauncroucherCommented:
Glad I could help,

Shaun
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Exchange

From novice to tech pro — start learning today.