kører med norton av 2002, altid med nyeste update + zonealarm
"Mogens Dyhre Hansen" <mogens@REMOVE
www.svend-bent.dk> wrote in message
news:3bc19f9e$0$256$edfadb0f@dspool01.news.tele.dk...
>
> "Jesper Stocholm" <spam@stocholm.dk> wrote in message
> news:Xns9134663309D29spamstocholmdk@192.38.208.81...
> > så jeg er faktisk blevet lidt i tvivl om, hvad
> > fejlen skyldes.
> Jeg vil næsten æde min hat på det er nimda virusen han har haft på
serveren.
> Jeg har nemlig oplevet det her på min maskine og i loggen står der
> 06:11:26 195.41.142.155 GET /scripts/root.exe 401
> 06:11:28 195.41.142.155 GET /MSADC/root.exe 401
> 06:11:30 195.41.142.155 GET /c/winnt/system32/cmd.exe 401
> 06:11:35 195.41.142.155 GET /d/winnt/system32/cmd.exe 401
> 06:11:38 195.41.142.155 GET /scripts/..%5c../winnt/system32/cmd.exe 401
> 06:11:40 195.41.142.155 GET
> /_vti_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 401
> 06:11:42 195.41.142.155 GET
> /_mem_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 401
> 06:11:47 195.41.142.155 GET
> /msadc/..%5c../..%5c../..%5c/..Á../..Á../..Á../winnt/system32/cmd.exe
401
> 06:11:50 195.41.142.155 GET /scripts/..Á../winnt/system32/cmd.exe 401
> 06:11:52 195.41.142.155 GET /scripts/winnt/system32/cmd.exe 401
> 06:12:00 195.41.142.155 GET /winnt/system32/cmd.exe 401
> 06:12:02 195.41.142.155 GET /winnt/system32/cmd.exe 401
> 06:12:04 195.41.142.155 GET /scripts/..%5c../winnt/system32/cmd.exe 401
> 06:12:06 195.41.142.155 GET /scripts/..%5c../winnt/system32/cmd.exe 401
> 06:12:08 195.41.142.155 GET /scripts/..%5c../winnt/system32/cmd.exe 401
> 06:12:10 195.41.142.155 GET /scripts/..%2f../winnt/system32/cmd.exe 401
> 07:04:16 195.24.196.175 GET /scripts/root.exe 401
> 07:04:19 195.24.196.175 GET /MSADC/root.exe 401
> 07:04:27 195.24.196.175 GET /c/winnt/system32/cmd.exe 401
> 07:04:40 195.24.196.175 GET /d/winnt/system32/cmd.exe 401
> 07:04:47 195.24.196.175 GET /scripts/..%5c../winnt/system32/cmd.exe 401
> 07:04:51 195.24.196.175 GET
> /_vti_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 401
> 07:05:44 195.24.196.175 GET
> /_mem_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 401
> 07:05:47 195.24.196.175 GET
> /msadc/..%5c../..%5c../..%5c/..Á../..Á../..Á../winnt/system32/cmd.exe
401
> 10:15:54 195.215.225.58 GET /scripts/root.exe 401
> 10:16:00 195.215.225.58 GET /MSADC/root.exe 401
> 10:16:05 195.215.225.58 GET /c/winnt/system32/cmd.exe 401
> 10:16:10 195.215.225.58 GET /d/winnt/system32/cmd.exe 401
> 10:16:16 195.215.225.58 GET /scripts/..%5c../winnt/system32/cmd.exe 401
> 10:16:37 195.215.225.58 GET
> /_vti_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 401
> 10:16:39 195.215.225.58 GET
> /_mem_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe 401
> 10:16:43 195.215.225.58 GET
> /msadc/..%5c../..%5c../..%5c/..Á../..Á../..Á../winnt/system32/cmd.exe
401
> 10:16:45 195.215.225.58 GET /scripts/..Á../winnt/system32/cmd.exe 401
> 10:16:47 195.215.225.58 GET /scripts/winnt/system32/cmd.exe 401
> 10:16:49 195.215.225.58 GET /winnt/system32/cmd.exe 401
> 10:16:54 195.215.225.58 GET /winnt/system32/cmd.exe 401
> 10:16:56 195.215.225.58 GET /scripts/..%5c../winnt/system32/cmd.exe 401
> 10:16:57 195.215.225.58 GET /scripts/..%5c../winnt/system32/cmd.exe 401
> osv. sådan kan den køre meget længe og til sidst kan min server ikke mere
og
> jeg må genstarte
>
> Mogens
>
>