shyamno
Ambassador of Buzz
I am posting my Trend Micro Pc cillin internet security firewall log file (a part):----
"Personal Firewall","2006/07/09",
"Type","Time","Protocol","Source IP Address","Source Port","Destination IP Address","Destination Port","Application Path","Application Description","Description"
"Network Virus","05:14:09","TCP","59.93.242.165","1670","59.93.240.113","135","---","---","MS03-026_RPC_DCOM_EXPLOIT"
"Network Virus","05:16:03","TCP","59.93.194.139","3500","59.93.240.113","135","---","---","MS03-026_RPC_DCOM_EXPLOIT"
"Network Virus","05:42:18","UDP","218.0.0.187","1054","59.93.240.113","1434","---","---","MS02-039_SQL_SERVER_RESOLUTION_EXPLOIT"
"Network Virus","06:48:40","TCP","59.93.74.205","3394","59.93.240.113","445","---","---","MS04-011_LSASS_EXPLOIT"
"Network Virus","06:49:30","TCP","59.93.112.52","1353","59.93.240.113","135","---","---","MS03-026_RPC_DCOM_EXPLOIT"
"Network Virus","06:50:13","TCP","59.93.71.158","4879","59.93.240.113","135","---","---","MS03-026_RPC_DCOM_EXPLOIT"
"Network Virus","06:51:32","TCP","59.93.243.226","3621","59.93.240.113","135","---","---","MS03-026_RPC_DCOM_EXPLOIT"
The whole log file is filled up with this three different variant of Network Virus.What should I do.
"Personal Firewall","2006/07/09",
"Type","Time","Protocol","Source IP Address","Source Port","Destination IP Address","Destination Port","Application Path","Application Description","Description"
"Network Virus","05:14:09","TCP","59.93.242.165","1670","59.93.240.113","135","---","---","MS03-026_RPC_DCOM_EXPLOIT"
"Network Virus","05:16:03","TCP","59.93.194.139","3500","59.93.240.113","135","---","---","MS03-026_RPC_DCOM_EXPLOIT"
"Network Virus","05:42:18","UDP","218.0.0.187","1054","59.93.240.113","1434","---","---","MS02-039_SQL_SERVER_RESOLUTION_EXPLOIT"
"Network Virus","06:48:40","TCP","59.93.74.205","3394","59.93.240.113","445","---","---","MS04-011_LSASS_EXPLOIT"
"Network Virus","06:49:30","TCP","59.93.112.52","1353","59.93.240.113","135","---","---","MS03-026_RPC_DCOM_EXPLOIT"
"Network Virus","06:50:13","TCP","59.93.71.158","4879","59.93.240.113","135","---","---","MS03-026_RPC_DCOM_EXPLOIT"
"Network Virus","06:51:32","TCP","59.93.243.226","3621","59.93.240.113","135","---","---","MS03-026_RPC_DCOM_EXPLOIT"
The whole log file is filled up with this three different variant of Network Virus.What should I do.