Rogue PHP file



Hi all,

SBS 2003 server, XP pro clients, WRT54GS router, Static IP from ISP using
exchange for mail.

Not sure if this is the right news group. I got a call today from a new
client stating that their mail.xxxxxxxxxx.com address was being redirected
to a Banking Phishing website.
They stated that they got a call from a security firm in Calif. staing it
looked to them like a rogue PHP file was accepting requests. Any ideas on
how to approach this to find fix it?

Thanks


.


Loading