Groups | Blog | Home
all groups > iis security > april 2005 >

iis security : Why is iis6.log on an XP home machine?



provasek NO[at]SPAM sbcglobal.net
4/20/2005 8:28:46 AM
With security concerns that back door trojans can install zombie
servers on systems, I am quite concerned that IIS components are
installed on my XP home machine, particularly with this log file
refering to "returned from France"

[4/18/2005 18:52:28] LogFile Open. [***** Search on FAIL/MessageBox
keywords for failures *****].
[4/18/2005 18:52:28] Initial thread locale=409
[4/18/2005 18:52:28] returned from France fix with locale 409
[4/18/2005 18:52:28] OC_PREINITIALIZE:[iis] End. Return=1
(OCFLAG_UNICODE)
[4/18/2005 18:52:28] OC_INIT_COMPONENT:[iis,(null)] Start.
[4/18/2005 18:52:28] OC_INIT_COMPONENT:3/31/2003 12:00:00 A_______
6.0.2600.1106: 6.0.2600.1106 (xpsp1.020828-1920): x86:
C:\WINDOWS\System32\Setup\iis.dll
[4/18/2005 18:52:28] OC_INIT_COMPONENT:Set UnAttendFlag:OFF (File='')
[4/18/2005 18:52:28] OC_INIT_COMPONENT:CmdLine=setup -newsetup
[4/18/2005 19:2:40] OC_CLEANUP:Final Check:LogFile Close.
[4/18/2005 19:5:47] LogFile Open. [***** Search on FAIL/MessageBox
keywords for failures *****].
[4/18/2005 19:5:47] Initial thread locale=409
[4/18/2005 19:5:47] returned from France fix with locale 409
[4/18/2005 19:5:47] OC_PREINITIALIZE:[iis] End. Return=1
(OCFLAG_UNICODE)
[4/18/2005 19:5:47] OC_INIT_COMPONENT:[iis,(null)] Start.
[4/18/2005 19:5:47] OC_INIT_COMPONENT:3/31/2003 12:00:00 _____N__
6.0.2600.1106: 6.0.2600.1106 (xpsp1.020828-1920): x86:
C:\WINDOWS\System32\Setup\iis.dll
[4/18/2005 19:5:47] OC_INIT_COMPONENT:Set UnAttendFlag:OFF (File='')
[4/18/2005 19:5:47]
OC_INIT_COMPONENT:CmdLine="C:\WINDOWS\System32\sysocmgr.exe" /y
/i:C:\WINDOWS\System32\sysoc.inf
[4/18/2005 19:5:47] OC_INIT_COMPONENT:Old InetPub='C:\Inetpub'. Does
not exist. we'll use the default. WARNING.
[4/18/2005 19:5:47] OC_INIT_COMPONENT:Old InetPub='C:\Inetpub'. Does
not exist. we'll use the default. WARNING.
[4/18/2005 19:6:43] OC_CLEANUP:Final Check:LogFile Close.
[4/18/2005 19:19:44] LogFile Open. [***** Search on FAIL/MessageBox
keywords for failures *****].
[4/18/2005 19:19:44] Initial thread locale=409
[4/18/2005 19:19:44] returned from France fix with locale 409
[4/18/2005 19:19:44] OC_PREINITIALIZE:[iis] End. Return=1
(OCFLAG_UNICODE)
[4/18/2005 19:19:44] OC_INIT_COMPONENT:[iis,(null)] Start.
[4/18/2005 19:19:44] OC_INIT_COMPONENT:3/31/2003 12:00:00 _____N__
6.0.2600.2180: 6.0.2600.2180 (xpsp_sp2_rtm.040803-2158): x86:
C:\WINDOWS\System32\Setup\iis.dll
[4/18/2005 19:19:44] OC_INIT_COMPONENT:Set UnAttendFlag:OFF (File='')
[4/18/2005 19:19:44]
OC_INIT_COMPONENT:CmdLine=d:\38ebc0009fe7ccf3f6\i386\update\update.exe
[4/18/2005 19:19:44] OC_INIT_COMPONENT:Old InetPub='C:\Inetpub'. Does
not exist. we'll use the default. WARNING.
[4/18/2005 19:19:44] OC_INIT_COMPONENT:Old InetPub='C:\Inetpub'. Does
not exist. we'll use the default. WARNING.
[4/18/2005 19:19:52] OC_CLEANUP:Final Check:LogFile Close.
[4/18/2005 19:21:17] LogFile Open. [***** Search on FAIL/MessageBox
keywords for failures *****].
[4/18/2005 19:21:17] Initial thread locale=409
[4/18/2005 19:21:17] returned from France fix with locale 409
[4/18/2005 19:21:17] OC_PREINITIALIZE:[iis] End. Return=1
(OCFLAG_UNICODE)
[4/18/2005 19:21:17] OC_INIT_COMPONENT:[iis,(null)] Start.
[4/18/2005 19:21:17] OC_INIT_COMPONENT:3/31/2003 12:00:00 A_______
6.0.2600.2180: 6.0.2600.2180 (xpsp_sp2_rtm.040803-2158): x86:
C:\WINDOWS\system32\Setup\iis.dll
[4/18/2005 19:21:17] OC_INIT_COMPONENT:Set UnAttendFlag:ON
(File='C:\WINDOWS\TEMP\NET2.tmp')
[4/18/2005 19:21:17]
OC_INIT_COMPONENT:CmdLine=C:\WINDOWS\system32\Sysocmgr.exe
/i:C:\WINDOWS\inf\sysoc.inf /q /w /u:C:\WINDOWS\TEMP\NET2.tmp
[4/18/2005 19:21:17] OC_INIT_COMPONENT:Old InetPub='C:\Inetpub'. Does
not exist. we'll use the default. WARNING.
[4/18/2005 19:21:17] OC_INIT_COMPONENT:Old InetPub='C:\Inetpub'. Does
not exist. we'll use the default. WARNING.
[4/18/2005 19:21:32] OC_CLEANUP:Final Check:LogFile Close.
[4/18/2005 19:57:34] LogFile Open. [***** Search on FAIL/MessageBox
keywords for failures *****].
[4/18/2005 19:57:34] Initial thread locale=409
[4/18/2005 19:57:34] returned from France fix with locale 409
[4/18/2005 19:57:34] OC_PREINITIALIZE:[iis] End. Return=1
(OCFLAG_UNICODE)
[4/18/2005 19:57:34] OC_INIT_COMPONENT:[iis,(null)] Start.
[4/18/2005 19:57:34] OC_INIT_COMPONENT:3/31/2003 12:00:00 A_______
6.0.2600.2180: 6.0.2600.2180 (xpsp_sp2_rtm.040803-2158): x86:
C:\WINDOWS\system32\Setup\iis.dll
[4/18/2005 19:57:34] OC_INIT_COMPONENT:Set UnAttendFlag:OFF (File='')
[4/18/2005 19:57:34] OC_INIT_COMPONENT:CmdLine=update\update.exe -q /Z
-ER /ParentInfo:dd3ecdb26d243142901ff686d6cdef59
[4/18/2005 19:57:34] OC_INIT_COMPONENT:Old InetPub='C:\Inetpub'. Does
not exist. we'll use the default. WARNING.
[4/18/2005 19:57:34] OC_INIT_COMPONENT:Old InetPub='C:\Inetpub'. Does
not exist. we'll use the default. WARNING.
[4/18/2005 19:57:36] OC_CLEANUP:Final Check:LogFile Close.
[4/18/2005 19:57:40] LogFile Open. [***** Search on FAIL/MessageBox
keywords for failures *****].
[4/18/2005 19:57:40] Initial thread locale=409
[4/18/2005 19:57:40] returned from France fix with locale 409
[4/18/2005 19:57:40] OC_PREINITIALIZE:[iis] End. Return=1
(OCFLAG_UNICODE)
[4/18/2005 19:57:40] OC_INIT_COMPONENT:[iis,(null)] Start.
[4/18/2005 19:57:40] OC_INIT_COMPONENT:3/31/2003 12:00:00 A_______
6.0.2600.2180: 6.0.2600.2180 (xpsp_sp2_rtm.040803-2158): x86:
C:\WINDOWS\system32\Setup\iis.dll
[4/18/2005 19:57:40] OC_INIT_COMPONENT:Set UnAttendFlag:OFF (File='')
[4/18/2005 19:57:40] OC_INIT_COMPONENT:CmdLine=update\update.exe -q /Z
-ER /ParentInfo:e5271e023809574fa13e6abaee0ee21f
[4/18/2005 19:57:40] OC_INIT_COMPONENT:Old InetPub='C:\Inetpub'. Does
not exist. we'll use the default. WARNING.
[4/18/2005 19:57:40] OC_INIT_COMPONENT:Old InetPub='C:\Inetpub'. Does
not exist. we'll use the default. WARNING.
[4/18/2005 19:57:41] OC_CLEANUP:Final Check:LogFile Close.
[4/18/2005 19:57:45] LogFile Open. [***** Search on FAIL/MessageBox
keywords for failures *****].
[4/18/2005 19:57:45] Initial thread locale=409
[4/18/2005 19:57:45] returned from France fix with locale 409
[4/18/2005 19:57:45] OC_PREINITIALIZE:[iis] End. Return=1
(OCFLAG_UNICODE)
[4/18/2005 19:57:45] OC_INIT_COMPONENT:[iis,(null)] Start.
[4/18/2005 19:57:45] OC_INIT_COMPONENT:3/31/2003 12:00:00 A_______
6.0.2600.2180: 6.0.2600.2180 (xpsp_sp2_rtm.040803-2158): x86:
C:\WINDOWS\system32\Setup\iis.dll
[4/18/2005 19:57:45] OC_INIT_COMPONENT:Set UnAttendFlag:OFF (File='')
[4/18/2005 19:57:45] OC_INIT_COMPONENT:CmdLine=update\update.exe -q /Z
-ER /ParentInfo:90709c895efa2d4a8846236f2f345405
[4/18/2005 19:57:45] OC_INIT_COMPONENT:Old InetPub='C:\Inetpub'. Does
not exist. we'll use the default. WARNING.
[4/18/2005 19:57:45] OC_INIT_COMPONENT:Old InetPub='C:\Inetpub'. Does
not exist. we'll use the default. WARNING.
[4/18/2005 19:57:46] OC_CLEANUP:Final Check:LogFile Close.
Ken Schaefer
4/21/2005 12:00:00 AM
The log is called iis6.log due to an oversight on the part of the person who
owned that part of the product. It's basically a typo.

Cheers
Ken

--
Blog: www.adopenstatic.com/cs/blogs/ken/
Web: www.adopenstatic.com


[quoted text, click to view]
: With security concerns that back door trojans can install zombie
: servers on systems, I am quite concerned that IIS components are
: installed on my XP home machine, particularly with this log file
: refering to "returned from France"
:
: [4/18/2005 18:52:28] LogFile Open. [***** Search on FAIL/MessageBox
: keywords for failures *****].
: [4/18/2005 18:52:28] Initial thread locale=409
: [4/18/2005 18:52:28] returned from France fix with locale 409
: [4/18/2005 18:52:28] OC_PREINITIALIZE:[iis] End. Return=1
: (OCFLAG_UNICODE)
: [4/18/2005 18:52:28] OC_INIT_COMPONENT:[iis,(null)] Start.
: [4/18/2005 18:52:28] OC_INIT_COMPONENT:3/31/2003 12:00:00 A_______
: 6.0.2600.1106: 6.0.2600.1106 (xpsp1.020828-1920): x86:
: C:\WINDOWS\System32\Setup\iis.dll
: [4/18/2005 18:52:28] OC_INIT_COMPONENT:Set UnAttendFlag:OFF (File='')
: [4/18/2005 18:52:28] OC_INIT_COMPONENT:CmdLine=setup -newsetup
: [4/18/2005 19:2:40] OC_CLEANUP:Final Check:LogFile Close.
: [4/18/2005 19:5:47] LogFile Open. [***** Search on FAIL/MessageBox
: keywords for failures *****].
: [4/18/2005 19:5:47] Initial thread locale=409
: [4/18/2005 19:5:47] returned from France fix with locale 409
: [4/18/2005 19:5:47] OC_PREINITIALIZE:[iis] End. Return=1
: (OCFLAG_UNICODE)
: [4/18/2005 19:5:47] OC_INIT_COMPONENT:[iis,(null)] Start.
: [4/18/2005 19:5:47] OC_INIT_COMPONENT:3/31/2003 12:00:00 _____N__
: 6.0.2600.1106: 6.0.2600.1106 (xpsp1.020828-1920): x86:
: C:\WINDOWS\System32\Setup\iis.dll
: [4/18/2005 19:5:47] OC_INIT_COMPONENT:Set UnAttendFlag:OFF (File='')
: [4/18/2005 19:5:47]
: OC_INIT_COMPONENT:CmdLine="C:\WINDOWS\System32\sysocmgr.exe" /y
: /i:C:\WINDOWS\System32\sysoc.inf
: [4/18/2005 19:5:47] OC_INIT_COMPONENT:Old InetPub='C:\Inetpub'. Does
: not exist. we'll use the default. WARNING.
: [4/18/2005 19:5:47] OC_INIT_COMPONENT:Old InetPub='C:\Inetpub'. Does
: not exist. we'll use the default. WARNING.
: [4/18/2005 19:6:43] OC_CLEANUP:Final Check:LogFile Close.
: [4/18/2005 19:19:44] LogFile Open. [***** Search on FAIL/MessageBox
: keywords for failures *****].
: [4/18/2005 19:19:44] Initial thread locale=409
: [4/18/2005 19:19:44] returned from France fix with locale 409
: [4/18/2005 19:19:44] OC_PREINITIALIZE:[iis] End. Return=1
: (OCFLAG_UNICODE)
: [4/18/2005 19:19:44] OC_INIT_COMPONENT:[iis,(null)] Start.
: [4/18/2005 19:19:44] OC_INIT_COMPONENT:3/31/2003 12:00:00 _____N__
: 6.0.2600.2180: 6.0.2600.2180 (xpsp_sp2_rtm.040803-2158): x86:
: C:\WINDOWS\System32\Setup\iis.dll
: [4/18/2005 19:19:44] OC_INIT_COMPONENT:Set UnAttendFlag:OFF (File='')
: [4/18/2005 19:19:44]
: OC_INIT_COMPONENT:CmdLine=d:\38ebc0009fe7ccf3f6\i386\update\update.exe
: [4/18/2005 19:19:44] OC_INIT_COMPONENT:Old InetPub='C:\Inetpub'. Does
: not exist. we'll use the default. WARNING.
: [4/18/2005 19:19:44] OC_INIT_COMPONENT:Old InetPub='C:\Inetpub'. Does
: not exist. we'll use the default. WARNING.
: [4/18/2005 19:19:52] OC_CLEANUP:Final Check:LogFile Close.
: [4/18/2005 19:21:17] LogFile Open. [***** Search on FAIL/MessageBox
: keywords for failures *****].
: [4/18/2005 19:21:17] Initial thread locale=409
: [4/18/2005 19:21:17] returned from France fix with locale 409
: [4/18/2005 19:21:17] OC_PREINITIALIZE:[iis] End. Return=1
: (OCFLAG_UNICODE)
: [4/18/2005 19:21:17] OC_INIT_COMPONENT:[iis,(null)] Start.
: [4/18/2005 19:21:17] OC_INIT_COMPONENT:3/31/2003 12:00:00 A_______
: 6.0.2600.2180: 6.0.2600.2180 (xpsp_sp2_rtm.040803-2158): x86:
: C:\WINDOWS\system32\Setup\iis.dll
: [4/18/2005 19:21:17] OC_INIT_COMPONENT:Set UnAttendFlag:ON
: (File='C:\WINDOWS\TEMP\NET2.tmp')
: [4/18/2005 19:21:17]
: OC_INIT_COMPONENT:CmdLine=C:\WINDOWS\system32\Sysocmgr.exe
: /i:C:\WINDOWS\inf\sysoc.inf /q /w /u:C:\WINDOWS\TEMP\NET2.tmp
: [4/18/2005 19:21:17] OC_INIT_COMPONENT:Old InetPub='C:\Inetpub'. Does
: not exist. we'll use the default. WARNING.
: [4/18/2005 19:21:17] OC_INIT_COMPONENT:Old InetPub='C:\Inetpub'. Does
: not exist. we'll use the default. WARNING.
: [4/18/2005 19:21:32] OC_CLEANUP:Final Check:LogFile Close.
: [4/18/2005 19:57:34] LogFile Open. [***** Search on FAIL/MessageBox
: keywords for failures *****].
: [4/18/2005 19:57:34] Initial thread locale=409
: [4/18/2005 19:57:34] returned from France fix with locale 409
: [4/18/2005 19:57:34] OC_PREINITIALIZE:[iis] End. Return=1
: (OCFLAG_UNICODE)
: [4/18/2005 19:57:34] OC_INIT_COMPONENT:[iis,(null)] Start.
: [4/18/2005 19:57:34] OC_INIT_COMPONENT:3/31/2003 12:00:00 A_______
: 6.0.2600.2180: 6.0.2600.2180 (xpsp_sp2_rtm.040803-2158): x86:
: C:\WINDOWS\system32\Setup\iis.dll
: [4/18/2005 19:57:34] OC_INIT_COMPONENT:Set UnAttendFlag:OFF (File='')
: [4/18/2005 19:57:34] OC_INIT_COMPONENT:CmdLine=update\update.exe -q /Z
: -ER /ParentInfo:dd3ecdb26d243142901ff686d6cdef59
: [4/18/2005 19:57:34] OC_INIT_COMPONENT:Old InetPub='C:\Inetpub'. Does
: not exist. we'll use the default. WARNING.
: [4/18/2005 19:57:34] OC_INIT_COMPONENT:Old InetPub='C:\Inetpub'. Does
: not exist. we'll use the default. WARNING.
: [4/18/2005 19:57:36] OC_CLEANUP:Final Check:LogFile Close.
: [4/18/2005 19:57:40] LogFile Open. [***** Search on FAIL/MessageBox
: keywords for failures *****].
: [4/18/2005 19:57:40] Initial thread locale=409
: [4/18/2005 19:57:40] returned from France fix with locale 409
: [4/18/2005 19:57:40] OC_PREINITIALIZE:[iis] End. Return=1
: (OCFLAG_UNICODE)
: [4/18/2005 19:57:40] OC_INIT_COMPONENT:[iis,(null)] Start.
: [4/18/2005 19:57:40] OC_INIT_COMPONENT:3/31/2003 12:00:00 A_______
: 6.0.2600.2180: 6.0.2600.2180 (xpsp_sp2_rtm.040803-2158): x86:
: C:\WINDOWS\system32\Setup\iis.dll
: [4/18/2005 19:57:40] OC_INIT_COMPONENT:Set UnAttendFlag:OFF (File='')
: [4/18/2005 19:57:40] OC_INIT_COMPONENT:CmdLine=update\update.exe -q /Z
: -ER /ParentInfo:e5271e023809574fa13e6abaee0ee21f
: [4/18/2005 19:57:40] OC_INIT_COMPONENT:Old InetPub='C:\Inetpub'. Does
: not exist. we'll use the default. WARNING.
: [4/18/2005 19:57:40] OC_INIT_COMPONENT:Old InetPub='C:\Inetpub'. Does
: not exist. we'll use the default. WARNING.
: [4/18/2005 19:57:41] OC_CLEANUP:Final Check:LogFile Close.
: [4/18/2005 19:57:45] LogFile Open. [***** Search on FAIL/MessageBox
: keywords for failures *****].
: [4/18/2005 19:57:45] Initial thread locale=409
: [4/18/2005 19:57:45] returned from France fix with locale 409
: [4/18/2005 19:57:45] OC_PREINITIALIZE:[iis] End. Return=1
: (OCFLAG_UNICODE)
: [4/18/2005 19:57:45] OC_INIT_COMPONENT:[iis,(null)] Start.
: [4/18/2005 19:57:45] OC_INIT_COMPONENT:3/31/2003 12:00:00 A_______
AddThis Social Bookmark Button