Around a month ago, I had an increase in NetBios hits, and then within
the last week, I had another increase as well.  What I found in relation
to the first was the W32.HLLW.Ultimaax worm, which does port 139
scanning to try and infect further hosts.  I haven't actually had the
chance to inspect one of these systems to check it out.  Also, another
thing I found that I haven't been able to check out as well, but that I
was able to verify from remote, was an IRC bot that was used to control
port scanning, specifically NetBios.  I am going to try to get ahold of
one of these machines, and if I come up with anything relevant, I'll
drop it to the list...

