2. Копаем логи сервера - файл acess.log/ Ищем что-либо подобное:
95.140.148.82 - - [25/Feb/2013:13:31:06 +0400] "GET /index.php HTTP/1.1" 200 24 "-" "STORM4045"
95.140.148.82 - - [25/Feb/2013:13:31:06 +0400] "GET /index.php HTTP/1.1" 200 24 "-" "STORM4046"
95.140.148.82 - - [25/Feb/2013:13:31:06 +0400] "GET /index.php HTTP/1.1" 200 24 "-" "STORM4047"
95.140.148.82 - - [25/Feb/2013:13:31:06 +0400] "GET /index.php HTTP/1.1" 200 24 "-" "STORM4048"
95.140.148.82 - - [25/Feb/2013:13:31:06 +0400] "GET /index.php HTTP/1.1" 200 24 "-" "STORM4049"
95.140.148.82 - - [25/Feb/2013:13:31:06 +0400] "GET /index.php HTTP/1.1" 200 24 "-" "STORM4050"
итд
Выбираем вручную ip подобных запросов, добавляем их в firewall. Либо на худой конец, просто баним