I just started getting some different entries in my Web logs from a server that's been infected by Code Red (their default web page was changed to the www.worm.com page). This is the first I've seen like this: 207.136.67.34, anonymous, -, N, 8/11/2001, 11:09:20, w3proxy, PALIN, -, -, -, 0, 0, 0, 0, -, TCP, -, -, -, -, 400, 0x0, -, - Don't know if anyone else has seen this before or not. Michael