Further to my issues... Ok turned off relay and still have tons trying to send through, weird thing is it appears local!! The local machine in fact. Though it can't be. Here is a bit of the log:
4/4/2008 11:10:33 AM - ( 426) MAIL FROM: 4/4/2008 11:10:33 AM - ( 426) 250 Sender koty@dsl-vlan427-MY WAN IPADDRESS.MYISP OK... 4/4/2008 11:10:34 AM - ( 426) RCPT TO: 4/4/2008 11:10:34 AM - ( 426) 551 User not local. We don't relay
4/4/2008 11:10:43 AM - { 427} START SMTP 4/4/2008 11:10:43 AM - Requested SMTP connection from MY LAN IP [servername], ID=427 4/4/2008 11:10:43 AM - ( 427) SMTP connection from -- 4/4/2008 11:10:43 AM - ( 427) SMTP connection from MY LAN IP rejected by Lockout Manager. Disconnecting... 4/4/2008 11:10:43 AM - SMTP connection with Lan Address [servername] ended. ID=427
Seems local right? But I've scanned it with two anti-virus, 3 anti spyware, and a rootkit finder and they found nothing.
If i turn off the router the emails stop.
I then booted a backup server and switched to that on the same IP name and the exact same traffic continued, though the ones showing lan ip seemed to quit.
I changed router to forward JUST smtp traffic to back up computer and it received the same traffic, even though every other computer in the network was turned off. and no other services or prgrams were running.
can anyone help?????
|