General discussion
February 20, 2002 at 10:17 PM
stergios_nik

Possible Nimda attack

by stergios_nik . Updated 24 years, 6 months ago

Hello,

I have a web server IIS 4. I have installed both the Security roll up package that covers all the vulnerabilities till SP6a and the patch for Web folder traversal directory vulnerability.

Recently, Norton Antivirus on server reported NIMDA activity in C:\INETPUB\SCRIPTS\TFTP546

Norton says that file can not be repaired. I click oK! I downloaded the latest definitions from Norton and performed a full scan. Norton said that there is no virus.

I have stopped the REMOTE ADMIN SITE of IIS 4. Also, I removed the shares C$ in my local drivers.

Does anybody know what is going on?

Thanks in advance.

This discussion is locked

All Comments