I've only this type of trace in my c:\winnt\system32\logfiles\w3svc1\ex010808.log #Software: Microsoft Internet Information Server 4.0 #Version: 1.0 #Date: 2001-08-08 00:00:39 #Fields: time c-ip cs-method cs-uri-stem sc-status 00:00:39 62.22.113.134 GET /default.ida 400 00:02:42 62.22.113.134 GET /default.ida 400 00:25:05 62.22.113.134 GET /default.ida 400 00:27:07 62.22.113.134 GET /default.ida 400 00:29:09 62.22.113.134 GET /default.ida 400 00:30:20 192.168.1.22 - - 200 00:31:12 62.22.113.134 GET /default.ida 400 and so on .... Nothing in the proxy logs, neither packet filter, nor w3 nor ws. Javier. -----Mensaje original----- De: Jim Harrison [mailto:jim@xxxxxxxxxxxx] Enviado el: miércoles, 08 de agosto de 2001 08:45 Para: [ISAserver.org Discussion List] CC: CommuniGate Pro Discussions Asunto: [isalist] Code Red Sniffer Importancia: Alta http://www.ISAserver.org This is a multi-part message in MIME format..