|
Question : Process called " system:8 " is listening on all kinds of ports on GFI Mail Essentials for Exchange box on my DMZ. What is this process?
|
|
I need to know what this process is. Found it after running Sysinternals TCPView.
NOTE:
1) Recently had a virus storm on the network which has been handled now.
2) Queue folder on the GFI Mail Essentials for Exchange box is overflowing with items. Averaging about 20,000 items at any given time on a 200 computer network. Seems like the items are being created about 1-5 every minute. Having to stop and start the SMTP service once in a while or mail seems to stop or come back undeliverable.
3) I think this machine (or another) may have a mass mailer of some kind, but Norton Corporate Edition is not detecting anything on the network machines.
Is the process "system:8" related to the overflowing queue folder?
JUST A HEADS UP: I didn't install the Mail Essentials or the Exchange and I am no expert on either of them.
|
Answer : Process called " system:8 " is listening on all kinds of ports on GFI Mail Essentials for Exchange box on my DMZ. What is this process?
|
|
SysInternal has another product name Process Explorer which I am using. Try that and you will see all hidden process listed (with provider name, explanation, etc). Sorry but your screenshot in insufficient and I can't say anything about it except your system looks suspicious (lots of outgoing connection to smtp).
System is your system process, and 8 is its PID, that's how you have system:8. There is no such thing as system:8.exe. System is a parent process which include lots of child process underneath, including things like svchost.exe, lsass.exe etc. You can't find it on google anyway.
Port explorer is for finding virus by examining port, but since you have mail server, looking at your process and try to scan for virus is a better way.
My conclusion is: you have a virus on your mailing system and it's using system process to sending mail out. Norton is not a very reliable tool when it comes to fixing virus. Try something else (McAffee) and Windows repairing feature, or re-install the mail server.
|
|
|
|