arief, just fyi, you may scan for the trojans if you suspicious about it at www.gfi.com ----- Original Message ----- From: "Jamie A. Byrnes" <jabyrnes@xxxxxxxxxxxxxxxxx> To: "[ExchangeList]" <exchangelist@xxxxxxxxxxxxx> Sent: Tuesday, August 05, 2003 13:45 PM Subject: [exchangelist] RE: Trojan or something ? http://www.MSExchange.org/ Hi Arief, It would seem strange that a worm was so badly written that it uses private addresses... I would suspect some misconfigured software myself. Try running netstat in a dos box to see more info on the strange connections, or there are more powerful tracing tools if you want to do a little digging. You don't have Trend serverprotect by any chance? Jamie.