If you identify that it is coming from one of your Exchange servers, then you can use a tool like Microsoft Network...
By submitting your email address, you agree to receive emails regarding relevant topic offers from TechTarget and its partners. You can withdraw your consent at any time. Contact TechTarget at 275 Grove Street, Newton, MA.
Monitor (Netmon), or a freeware tool like Ethereal, to capture the traffic being sent and received by this suspect machine. What is nice is that you actually know the time that this occurring, so you know when to monitor the traffic. This will help you identify if it is in fact the machine the mail is coming from, and if so, which application is generating this message. Netstat –o can be used to enumerate the processes that have active connections on the machine while the problem is being experienced. Once you have the Process ID (PID) you can use Task Manager to identify the most likely suspects and remove them from the machine. To view a PID, open Task Manager and click on the Processes tab. Open the View menu and select Select Columns. Choose PID Process Identifiers.
If this does nothing for you, you can try to identify the problem at the file system and registry level in real time with the Filemon and Regmon tools from Sysinternals.
Do you have comments on this Ask the Expert question and response? Let us know.
Related Q&A from Richard Luckett
I'm finishing up an Exchange 2007 to 2010 migration. Do I need to switch over the public folders? If so, what is the best method to do it?continue reading
Hackers corrupted my Exchange 2010 files, so now I can't open them. How can I restore my server and prevent this from happening again?continue reading
Exchange was running low on space, and Outlook asked if I wanted to archive my email messages. What will happen if I do that?continue reading
Have a question for an expert?
Please add a title for your question
Get answers from a TechTarget expert on whatever's puzzling you.