In my IIS logs, there are repeated GET commands looking for command.com and scripts/root.exe. At one point, there were also GETs that were trying to deface our webpage which I tracked down as being the SADMIND/PoisonBox worm. These have stopped, just the continual attempts to get files remain. According to the SADMIND info, this worm comes in thru port 80, which I can’t shut down due to http needing to be open. I’ve applied every patch, lockdown tool, update and fix on the OS, IIS and ViruScan I could find. And yet I still get theses constant attempts. We have had no damage to any files that I know of, we’re just suffering some slow downs on the server. I’m new to webservers and worms and such, so I’d be very grateful for any help at all as to what I should do now. We’ve toyed with the idea of using another port instead of 80, but that would involve a great deal of work- including rewriting some code. Please Help!?!
Thanks, Jamie