Hi
Looking into the analysis of the worm, I have some questions.
A lot happens in the windows directory, what will happen when using win 2000 or winnt? There is no such directory. Will the worm stop?
Is it possible that the changes to asp, html, exe, .... files are only performed by the readme.exe file and not the Admin.dll? May we assume that the Admin.dll only tries to infect other IIS boxes?
Is it also possible that there is a timer in the Admin.dll because of the fact that the scans stopped?
TIA
Erwin
