Just to the record: there seems to be a new variant of the worm, with
all 'N' being replaced with 'X'. The last 117 (er, now thei'r 119)
worm requests on my machine, starting 5 hours ago, were all except
one of the 'X' type. And all of them come from 62.2.x.x (well, I'm on
this subnet, too). Seems like someone wanting to kill this internet
providers clients has rewritten the worm to attack all ip's in this
subrange (instead of the semirandom ip's it used to select before).
no fun for windows users
christian.