I have one Exchange 2003 SP2, its currently spamming out like mad, I logged the transactions and they are from outside, I have already stopped any relay under Virtual-SMTP, changed the Admin password, changed the users passwords, yet they are still coming through, I dont think its from internal PC because all the IPs are showing as external, such as from Holland, Canada etc.
What else can I do to stop this relay ??
Heres part of the log file:
#Software: Microsoft Internet Information Services 6.0
#Version: 1.0
#Date: 2012-06-29 11:52:12
#Fields: date time c-ip cs-username s-ip s-port cs-host
2012-06-29 11:52:12 75.180.132.243 OutboundConnectionResponse - 25 -
2012-06-29 11:52:12 66.54.152.4 OutboundConnectionResponse - 25 -
2012-06-29 11:52:12 75.180.132.243 OutboundConnectionResponse - 25 -
2012-06-29 11:52:12 46.4.167.9 OutboundConnectionResponse - 25 -
2012-06-29 11:52:12 80.113.5.98 OutboundConnectionResponse - 25 -
2012-06-29 11:52:12 80.113.5.98 OutboundConnectionCommand - 25 -
2012-06-29 11:52:12 46.4.167.9 OutboundConnectionCommand - 25 -
2012-06-29 11:52:12 80.113.5.98 OutboundConnectionResponse - 25 -
2012-06-29 11:52:12 80.113.5.98 OutboundConnectionCommand - 25 -
2012-06-29 11:52:12 80.113.5.98 OutboundConnectionResponse - 25 -
2012-06-29 11:52:12 80.113.5.98 OutboundConnectionCommand - 25 -
2012-06-29 11:52:12 80.113.5.98 OutboundConnectionResponse - 25 -
2012-06-29 11:52:12 80.113.5.98 OutboundConnectionCommand - 25 -
2012-06-29 11:52:12 80.113.5.98 OutboundConnectionResponse - 25 -
2012-06-29 11:52:12 80.113.5.98 OutboundConnectionCommand - 25 -
2012-06-29 11:52:12 80.113.5.98 OutboundConnectionResponse - 25 -
2012-06-29 11:52:12 193.85.160.138 OutboundConnectionResponse - 25 -
2012-06-29 11:52:12 193.85.160.138 OutboundConnectionCommand - 25 -
2012-06-29 11:52:12 193.85.160.138 OutboundConnectionResponse - 25 -
2012-06-29 11:52:12 193.85.160.138 OutboundConnectionCommand - 25 -
2012-06-29 11:52:12 193.85.160.138 OutboundConnectionResponse - 25 -
2012-06-29 11:52:12 193.85.160.138 OutboundConnectionCommand - 25 -
2012-06-29 11:52:12 193.85.160.138 OutboundConnectionResponse - 25 -
2012-06-29 11:52:12 193.85.160.138 OutboundConnectionCommand - 25 -
2012-06-29 11:52:12 75.180.132.243 OutboundConnectionResponse - 25 -
2012-06-29 11:52:12 193.85.160.138 OutboundConnectionResponse - 25 -
2012-06-29 11:52:12 193.85.160.138 OutboundConnectionCommand - 25 -
2012-06-29 11:52:12 178.79.147.207 OutboundConnectionResponse - 25 -
2012-06-29 11:52:12 178.79.147.207 OutboundConnectionCommand - 25 -
2012-06-29 11:52:12 178.79.147.207 OutboundConnectionResponse - 25 -
2012-06-29 11:52:12 178.79.147.207 OutboundConnectionCommand - 25 -
2012-06-29 11:52:12 193.85.160.138 OutboundConnectionResponse - 25 -
2012-06-29 11:52:12 178.79.147.207 OutboundConnectionResponse - 25 -
2012-06-29 11:52:12 178.79.147.207 OutboundConnectionCommand - 25 -
2012-06-29 11:52:12 212.79.230.246 OutboundConnectionResponse - 25 -
2012-06-29 11:52:12 212.79.230.246 OutboundConnectionCommand - 25 -
2012-06-29 11:52:12 178.79.147.207 OutboundConnectionResponse - 25 -
2012-06-29 11:52:12 178.79.147.207 OutboundConnectionCommand - 25 -
2012-06-29 11:52:12 212.79.230.246 OutboundConnectionResponse - 25 -
https://www.experts-exchange.com/Software/Server_Software/Email_Servers/Exchange/A_2556-Why-are-my-outbound-queues-filling-up-with-mail-I-didn't-send.html
After you have changed passwords - you need to restart the SMTP Service or the changes won't be effective and spammers can continue to use the old password!
If it isn't relevant, please let me know.
Alan