Where's Sirdar?
Very interesting week. Parts were great, others...not so great. However, my time was very consumed.
The not so great:
I couldn't send email. I could receive email, but couldn't send any. Kept getting this error message:
An error occurred sending mail: The mail server sent an incorrect greeting: spamhaus-xbl - Blocked - xx.xx.xxx.xx
Spam?!?! ME? No way!! So I started the investigation as to not only why I was being blocked but who was blocking me.
I started with my ISP. Nope. Not them. They did recently have to shut someone down because of a virus but that is taken care of now.
Next, I Googled the error message. Looks like I'm not the only one that has viewed that error message. After a lot of reading I finally figured out at least who is blocking me. CBL - Composite Blocking List. According to their website, if email is being blocked it is because it is being blocked by my email host. So, I sent a note to my email host asking if they were blocking me and if they were...why? They said they don't block anyone. However after reading their response, I think they thought that 1 ISP was blocking me after going through them.
That wasn't my issue so instead of trying to play word games I went back to CBL and tried to discover why they would block someone. I found this:
What is the CBL?
The CBL takes its source data from very large spamtraps/mail infrastructures, and only lists IPs exhibiting characteristics which are specific to open proxies of various sorts (HTTP, socks, AnalogX, wingate etc) which have been abused to send spam, worms/viruses that do their own direct mail transmission, or some types of trojan-horse or "stealth" spamware, without doing open proxy tests of any kind.
In other words, the CBL only lists IPs that have attempted to send email to one of our servers in such a way as to indicate that the sending IP is infected.
The CBL does NO probes. The CBL does NOT test for nor list open relays. The CBL only lists individual IPs, NOT ranges. The CBL does NOT list IPs because they are/are not dynamic.
The CBL only lists IPs that have sent one of our servers email that appears to indicate that the IP is infected.
The CBL operates in an entirely automated way designed to avoid listings of spamtrap hits due to bounces of forged spam, virus bounces, and "real" mail servers emitting the occasional spam. It tries very hard to avoid listing legitimate mail sources. It does not attempt to list every possible spam source.
This list is based on information believed to be reliable. No warranty is made that it is accurate or complete.... Use entirely at your own risk.
There is no supporting data or "evidence" file available for any given listing, and no mechanism to ask why any given listing took place. To counteract this, there is an automated no-questions-asked removals procedure allowing any affected party to delist a specific IP address rapidly. However, delisted IPs are relisted if new evidence of spam activity is subsequently detected.
Entries automatically expire after a period of time. The approximate detection time of a specific entry can be obtained from the web interface.
AnalogX? Worms, viruses, trojan-horse? WTF!! I downloaded an AnalogX application very recently that monitors my network traffic. I was trying to determine my up/down surfing speeds. I haven't used it for a week or so but...Crap!! I don't know if that was what program they are talking about...but it is gone. Worms, viruses, trojan-horse? I have never, NEVER, NEVER had a virus on my computer in my life!
Could I have been compromised? Well...I have to find out. So I ran a virus check. I was using AVG Free and I have it start when I boot up and update religiously every day and sometimes more. I did a scan of my drives. WOW!! A list of files that are...compromised. I am in shock at this point. Which virus did I have? Who knows...AVG couldn't identify it. It apparently didn't think that I might want to know that I was compromised either. I let it 'clean' the...whatever it is...out of my system and then I promptly uninstalled it. I only used it because it was the right price...free. So, I have now gone back to NOD32. I used it for many years before I got my friend David's old computer. Well...I cheaped out and now I have paid for it. You get what you pay for. I would recommend NOD32 from ESET to ANYONE!! A quote from Virus Bulletin VB:
NOD32 is the world leader of the Virus Bulletin 100% Awards having won more awards than any competing product.
I scanned again with NOD32. Nothing. Looks like AVG is good at getting rid of..whatever it was. I did an online Trend Micro House Call scan. Nothing. I did a Windows Live OneCare safety scan. Nothing. Looks like...whatever it was...is no more on my machine.
So, now I don't have a virus. What about other spyware type things? I downloaded Windows Defender and scanned. Nothing. It is running on my machine as we speak.
I've done all the Windows Updates. I have requested to have my IP address unblocked from sending email. I am now unblocked and extremely relieved. The stress is down now...breath...breath....breath
Now for the good stuff!!
I learned to play Texas Hold'em this week. What a blast!! There were two tournaments put on by the organizing committee at work this week put on as a United Way fundraiser. Our company participates every year to support the United Way. I didn't win but sure had a lot of fun. I learned a lot about the game. The first night, last Tuesday, I didn't do so good. But they say that experience is best learned the hard way. Thursday night's tournament I did much better. There were 7 tables and I made it to, I think, in the last two tables. I might have made it farther but I made a not to bright mistake on one hand that I lost. I should have folded but I tried to raise him out. Didn't work. After the river, I knew I was had. I had King/Queen. He had Ace/seven. The flop produced one Ace. He won on a pair of Aces. Oh well. I still had chips left but eventually lost them as the blinds were at $800/$1600 and I wasn't getting the cards I needed.
But damn that game is addicting. I hear there are some people at work who get together and play on the weekends. One girl said she might start a club at work for Friday afternoons. We get Friday afternoons off :-)
Oh...and that $800/$1600? That wasn't real money...thank goodness!!
8 comments:
Yeah, you could have saved some time if you bought a Mac. 4 1/2 years and not one virus.
I haven't played much Texas Hold'em, Sudoku is my current poison.
Glad you're back. My RSS feed reader just isn't the same without Sirdar Inc.
Thanks big guy!! I will buy a Mac one day. As you know I just about did. Still might.
Sudoku is Dawn's favourite game these days. She does the one in the Journal every day.
An Angel Visits You
My biggest fear since switching to a PC from a Mac is the virus thing. What a pain hey? You've gotta wonder why people have nothing better to do.
Kim: I don't even know if that is why I was being blocked. But I am glad this happened because it forced me to be more careful.
Oh, hi Angel Feathers.
People...check out Angle Feathers Tickle Me website. You will be amazed!!
sounds like a brutal effort... it almost seems like it'd be easier to throw the computer out the window...
I don't understand cards. I'm a roulette girl myself. But it sounds fun!
And that whole blocking thing is annoying. Some spammers use my domain as the reply-to address, and so I get loathing emails all the time. "Stop emailing me! bla bla" But I'm not. Can't stop them from using it. Very annoying. I think, because of it, some of my emails don't get through to AOL users. Their spam guard is WAY too excited. Then clients get mad because I'm not responding. ..ugh.. I hope the people that invented these spam programs all die a horrible death :)
Die Spammers Die!!
Post a Comment