My inbound mailflow is as follows
mx records points to a third party spam provider (they must be running AVG)
My firewall only allows inbound connections on port 25 from the specific IPS of the thirdparty spam solution
My firewall now only allows outbound connections on port 25 and the exchange server appears to be clean
Also, all computers were turned off last night so I would interested in knowing the last 12 hour logs.
I'm really sorry for screwing up my posting, wow, I would vote for buttons that say "blacklisted removal" not blocklist since since that usually refers to ISP providers which I doubt post a resolution this way.
Either way, I admit I'm wrong and dont want to argue about this anymore.
Enjoy your day,