First it looks like the PIX may not be configured correctly and try to google Cisco on that one. Second it sounds like an open relay have you checked Exchange to make sure you did not change the default setting of allow no relays?. How about the virus scanners the latest MyDoom has it's own SMPT the connect may be from behind the firewall or some other spam bout or virus on an internal computer behind the firewall. Can you view or see in any interface of inbound and outbound traffic? A netstat -a will usually show that look there if you lack any other info.

Peace