1. There is a thread somewhere about that. idesign wrote a script to grab the error log without using cpanel.
2. it is looking for a windows exploit. The shtml.exe/whatever will return the path to an IIS server...ugh! and will also return the local path on apache with frontpage extensions running.
I think the others are looking to exploit xenu link sleuth, it is a windows platform website link checker.
http://home.snafu.de/tilman/xenulink.html
Another fine example of why to never use a windows server or frontpage extensions.