> My Exchange 5.5 Server doing some illegal activities. Firewall log shows > that it tries to connect to some unknown Private Class C IP (While Our > network is using Private Class A IP addresses) and IP address 3.0.0.2 (none > of our node). Destination port is 4939, 4940, 4561, 1519 and 1528. Is this > normal or some kind of trojan ? Run, do not walk, to your nearest virus scanner and spyware scanner and scan the system. It does sound suspious. John Tolmachoff MCSE CSSA Engineer/Consultant eServices For You www.eservicesforyou.com