Solved

exchange 2003 random internal e-mail addresses in outgoing queue

Posted on 2013-06-24
5
580 Views
Last Modified: 2013-06-24
Hey guys,

My client is running Exchange 2003 SBS (i just took them on). Their outgoing exchange queues are hacked with RANDOM internal e-mail addresses (xyaj38s@company.com).

I've enabled sender/recipient filtering, ensured it's not an open relay, scanned the server for viruses (did find a backdoor trojan on it, i believe it's removed). I also changed everyone's passwords... Turned off windows authentication.

The queues are still filling up. Is it possible someone's machine in the office is compromised?

Anything else I should look at?

Thanks guys.
0
Comment
Question by:tamaneri
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
5 Comments
 
LVL 74

Accepted Solution

by:
Glen Knight earned 167 total points
ID: 39271769
Looks like you've done most of everything else.  I'd say the next place to look is definitely the client machines.
0
 
LVL 8

Assisted Solution

by:jbvernej
jbvernej earned 167 total points
ID: 39271825
Hello,

Your messages in queues:
does they seem to be fake NDR messages (Non Delivery Report)  ?
(IE a NDR for a message that was never send ) ?
If yes, you could be under External NDR attack.

here a  procedure to cleanup:
kb886208 - Exchange queues fill with many non-delivery reports from the postmaster account in Small Business Server 2003
http://support.microsoft.com/kb/886208/en-us
0
 
LVL 52

Assisted Solution

by:Manpreet SIngh Khatra
Manpreet SIngh Khatra earned 166 total points
ID: 39271841
Restart the services or the server and check.

- Rancy
0
 
LVL 3

Author Closing Comment

by:tamaneri
ID: 39272513
Thanks for the input guys.

Turns out it was a root-kit on the server itself. I ran the following programs to remove all of the malware/viruses/rootkit

1) MBAM
2) TDSS Killer
3) Kaspersky Virus Removal Tool (just to ensure it was clean).

The virus/root-kit that TDSSKILLER found was a file called sbscrexe.exe in c:\windows\system32.

Thanks for your help in this matter. Queues look like they're going to remain clean.
0
 
LVL 3

Author Comment

by:tamaneri
ID: 39272948
Just to update you guys... It took a couple of hours, but I have some more messages in the queues. I didn't have much time to spend looking at the client machines while I was on site today. I've instructed them to turn off their computers when they leave for the day so I can determine if it's a server-related hacking issue, or a desktop virus/malware causing the problem.
0

Featured Post

Office 365 Training for Admins - 7 Day Trial

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A list of top three free exchange EDB viewers that helps the user to extract a mailbox from an unmounted .edb file and get a clear preview of all emails & other items with just a single click on mailboxes.
A couple of months ago we ran into an issue that necessitated re-creating our Edge Subscriptions. However, when we attempted to execute the command: New-EdgeSubscription -filename C:\NewEdgeSub_01.xml we received an error indicating that the LDAP se…
The video tutorial explains the basics of the Exchange server Database Availability groups. The components of this video include: 1. Automatic Failover 2. Failover Clustering 3. Active Manager
To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…
Suggested Courses

623 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question