Author Topic: Are you part of a blacklist?  (Read 4881 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Are you part of a blacklist?
« on: February 04, 2010, 08:24:03 PM »
Hi malware fighters,

Part of a mail blacklist etc.?
Are you botted?
Even if your email isn't bouncing, it's a good idea to find out whether you've been blacklisted. First, go to http://checkip.dyndns.org/ To view the IP address you send out to the world -- probably your router's. Select the displayed address and choose Edit, Copy to copy it to your clipboard.

There are several blacklist reporting sites. My favorite is Robtex: http://www.robtex.com/rbls.html
 Paste your IP address into the only field on the page, and click Go. Robtex will list a great many blacklist sites. If any of them are red, you've got a problem. Use the list's contact information to find out why you're on that list and how to get off of it.

Finally, remember that prevention is the best medicine. Keep Windows and your antivirus, firewall and other security software up to date. Those precautions will reduce the chances of infection from almost certain to reasonably unlikely.

But then. There are programs like TrendMicroRUBotted: http://free.antivirus.com/rubotted/
Or the BotHunter program: http://www.bothunter.net/

But you should do some forensics yourself:

Run a pa (protocol-analyzer also named  networksniffer (Wireshark for instance) in the background, save the logs thereof and take some time for analysis, sit down take a cola or some apple juice, put on your favorite background music. Also watch your cpu activity, I like CPU Monitor (http://www.softpedia.com/get/System/System-Info/CPUMon.shtml). Check your logs with Event Log-explorer ( http://www.eventlogxp.com/ ) Well, as a private-user,  this all will take some time, and then the following task is to investigate in what way your computer was compromised and what changes has been made, what processes are running with what hashes, etc. etc. also whether there are rootkits on the computer - (anti-rootkit scanners),

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

CharleyO

  • Guest
Re: Are you part of a blacklist?
« Reply #1 on: February 05, 2010, 08:18:28 PM »
***

Quote
It is not listed in any blacklists.

Base   Record   Name   IP   Reverse   Route   AS
dialup-4.153.5.143.dial1.atlanta1.level3.net    ptr    4.153.5.143
United States   4.128.0.0/9
Proxy-registered route object   AS3356
Level3 Level 3 Communications
dialup-4.153.5.173.dial1.atlanta1.level3.net    ptr    4.4.153.5.173
United States

dial1.atlanta1.level3.net   atlanta1.level3.net   net   level3.net   153.5.173.dial1.atlanta1.level3.net   5.143.dial1.atlanta1.level3.net   143.dial1.atlanta1.level3.net   173.dial1.atlanta1.level3.net   153.5.143.dial1.atlanta1.level3.net   5.173.dial1.atlanta1.level3.net  
(this is my ISP and no where near my home)


***