Good day. I have a client who recently became infected with the ZeuS bot, I discovered it after 2 days and removed it,no problem I thought! About 2 weeks later the site is hit thousands of times a day looking for typically:-
[Fri Apr 23 15:36:28 2010] [error] [client 82.217.113.214] File does not exist: /home/mjhamilt/public_html/404.shtml
[Fri Apr 23 15:36:28 2010] [error] [client 82.217.113.214] File does not exist: /home/mjhamilt/public_html/zeus
[Fri Apr 23 15:36:28 2010] [error] [client 82.217.113.214] File does not exist: /home/mjhamilt/public_html/404.shtml
[Fri Apr 23 15:36:28 2010] [error] [client 82.217.113.214] File does not exist: /home/mjhamilt/public_html/zeus
I have tried banning the various ip blocks with noeffect, I have tried using the rewrite rules with no effect, I even altered the A and CNAMES so the www pointed elswhere with no effect.
I should say at this point the site is only for emails and the web pages do not exists. At present I have the web part of the site permanently redirected to google to see if this will make any difference. I am at a loss to stop this, approx 500m of bandwidth a day!
Does anyone have any ideas on this?
Thanks for reading G W Styles.