My server has been blacklisted by CBL 3-4 time over the last 4 months. I use AVG on teh server itself, and ClamAV on the e-mail. I run Spyware tools, and have found the machine and all network machines clean.
CBL keeps saying it is a virus or BOT. I can't find it.
I have checked Event Viewer and over the last time period have noticed that we have been getting blasted by login attempts periodicly. Event Viewer reports unauthorized login attempts to AgroSoft by an IP address. There may be 150-200 attempted logins from a single IP address. The next time the IP address will be different, but another round of 100+ attempts. Is this normal? Is something getting through? If I don't fix this issue, CBL has threatened to permanently block my IP. Any direction is greatly appreciated. If this occurs, I will be forced to use an external server for e-mail.