Re: Microsoft-WebDAV-MiniRedir/6.0.6001
- From: "Travis McGee" <travisGatesMcGee@xxxxxxxxxxx>
- Date: Fri, 17 Apr 2009 10:42:07 -0400
I kind of know the Agent / Vista / MiniRedir part and what it means.
The issue is the Virus. The reason why I posted here, is that when you search for this malware with key words, the closest complaints came from IIS Admins observing high quantity of hits in their logs coming from their internal IP addresses hitting the web servers with the name of the Hard Drive where the IIS is installed on: ie. http://10.0.0.50/c (that has an external internet IP address:80 being routed to 10.0.0.50) ..... thousands of hits coming from the infected internal IP address (ie. a vista machine).
Unfortunately, could not find good solution in the Security Forums. IIS people are the ones who are reporting this; but not good explanation about what kind of spyware/malware this thing is.
The reason why my machines get infected is ... running scanning scripts with IE collecting info from an IP range ...ie. hitting web sites http://245.45.16.1 - http://246.45.16.254 trying to find out which company a certain IP address (ie. 245.45.16.9) belongs to.
"Grant Taylor" <gtaylor@xxxxxxxxxxxxxxxxx> wrote in message news:gs839j$2fj2$1@xxxxxxxxxxxxxxxxxxxxxxxxx
On 04/16/09 12:27, Travis McGee wrote:IIS Server behind a router is being hit internal machines which are also behind a router....Any help on this Microsoft-WebDav-MiniRedir (client agent) garbage?
It looks like "Microsoft-WebDav-MiniRedir" is the User Agent string that is used by the Web Folder (WebClient) director by Windows. Windows XP has a version string of 5.<something>, so seeing as how your version string is 6.<something> I'm guessing that the client in question is a Vista (?) system that is trying to access contents on the server via WebDAV / Web Folder / WebClient rather than standard SMB / CIFS shares. Check to make sure that your client is to a UNC rather than to a URL.
Grant. . . .
.
- Follow-Ups:
- Re: Microsoft-WebDAV-MiniRedir/6.0.6001
- From: Chad Covey
- Re: Microsoft-WebDAV-MiniRedir/6.0.6001
- References:
- Microsoft-WebDAV-MiniRedir/6.0.6001
- From: Travis McGee
- Re: Microsoft-WebDAV-MiniRedir/6.0.6001
- From: Grant Taylor
- Microsoft-WebDAV-MiniRedir/6.0.6001
- Prev by Date: Re: Can't run any ASP script when virtual catalog allows anonymous connections
- Next by Date: Re: Certificate Installation
- Previous by thread: Re: Microsoft-WebDAV-MiniRedir/6.0.6001
- Next by thread: Re: Microsoft-WebDAV-MiniRedir/6.0.6001
- Index(es):
Relevant Pages
|