WOW!!
I cannot believe the information I have received from this post........I have learned much.
Thank you to all who posted.
From this info gathered and using suggestions from several of the replies I have narrowed it down to it being the server. ... cause when scanned the MAC comes up LOCAL and the
services running DHCP, IIS,Exchange etc.....this is the only machine on the network on the network running these services.
We have PPTP running as we have remote sites and have been trying to use the MS VPN...I wonder if it has to do with this. What bugs me is it communicates to external sites which I have traced to known spammers.....Thats why I thought it was relaying at first.
We only have one site using the VPN and it gets a different address when connected. I can see when they connect. Still irks me although I am getting closer. I am reapplying patches this weekend see if I can plug this up and close the unused VPN ports.....otherwise I am rebuilding as I cant be sure what this is or if the system has been compromised.
I am still going to try and find the source though....Im stubborn.....Ill be lurking : )
gg
