Spam trojan blocking SMTP help!

Soldato
Joined
28 Dec 2004
Posts
7,620
Location
Derry
Hi guys (and girls, but prolly just guys ..), over the last few days Spamhaus has listed my IP address in the CBL telling me I probably have some kind of Spambot trojan on one of my machines, for the life of me I can't find it though.

I've got 3 machines here, I've run combofix (on the 32bit machines), Trend, MSE, Malwarebytes and Avast but nothing is being picked up, also, if I run TCP view on any of the machines there is no SMTP traffic, thinking that my dynamic IP was perhaps used by somebody previously who was infected I reset my router, got a new IP and within 24 hours was listed again, tried this a few times now and the same result.

It's becoming a real pain having to send work email via webmail so wondered if there was anything else I could try?
 
I'd block 25 outbound on the firewall all the same, except for the computer that needs it.
Enable software firewall without exceptions and see what is wanting to get out maybe too.
Or it could be your ISP's range of addresses that is blacklisted.
Maybe run wireshark too.
Are you on any other rbl's?
Just my random 2¢ since nobody else had replied :)
 
I'd block 25 outbound on the firewall all the same, except for the computer that needs it.
Enable software firewall without exceptions and see what is wanting to get out maybe too.
Or it could be your ISP's range of addresses that is blacklisted.
Maybe run wireshark too.
Are you on any other rbl's?
Just my random 2¢ since nobody else had replied :)

I've blocked 25 outgoing on 2 machines, nothing unusual in the logs and I'm not showing up on any other blacklists, the only thing (which would be a HUGE coincidence) I can think of is perhaps I managed to get assigned two IP's that are already blacklisted.
 
Back
Top Bottom