[<prev] [next>] [day] [month] [year] [list]
Message-ID: <DF79BE12AF8DD344B107D0D03621E5750ED9A0@kermit.corp.hansenet.com>
From: vogt at hansenet.com (vogt@...senet.com)
Subject: AW: [fd] AW: attacks shutting down windows mach
ines?
> I wouldn't go by such anecdotal evidence as shutdown/reboot
> times. Check
> your event viewer logs for RPC/DCOM errors, monitor your
> network traffic,
> check for the suspicious files on the systems, scan for the
> ports opened by
> the worm, etc....
I would. Unfortunately, these are customer systems. We're
an ISP. So whatever survives the filter
(Machine)->(customer-brain)->(hotline)->(me) is what I have.
Tom Vogt
Powered by blists - more mailing lists