im having exchange server 2000 with the latest SP………we are using Symantec AntiVirus version 8.0 & also use Symantec Antivirus Filter Version 3.0, which are updated daily, for protecting the server against virus attacks.
from the last 3 weeks i have been noticing virus alerts as
1. W32.Netsky.P@mm! enc
2. W32.Erkez.B@mm
3. W32.MyDoom.L@mm
all of which are located in the folder “BADMAIL”. and most of them cannot be repaired or quarantined and have “ACCESS DENIED” status.
when i run the respective removal tools which i downloaded from the Symantec website, it gives me a message telling that these werent found on my server.
but i also noticed that large scale emailing between 4 users, just 4 users.
also i noticed a weird behaviour, large scale emailing from an x-employee email address that was deleted the day he left office. can somone give me an explanantion for this. how does this email address exist even after deleting it about 6 months back.
& how do i stop these viruses from actually getting into the “BADMAIL” folder, is there a way to stop it. how do i actually know if my server is infected. & if so how do i clean it.
Please advice.