That's a plain ole connect request. If you're not expecting it from the outside world (in any sense), then it may be Code Red. You're not "infected" yet, and if you've patched your server, you're fine. I'd double check that disallowing the connection doesn't hose your access to the server... sgd > -----Original Message----- > From: Hershel Robinson [mailto:hershelsr at yahoo.com] > > Connection origin : remote initiated > Protocol : TCP > Local Address : 192.168.135.4 > Local Port : 80 (HTTP - World Wide Web) > Remote Name : > Remote Address : 126.96.36.199 > Remote Port : 3576 > > I have never seen this before and I don't know what it is. I > run PWS on Win > 2K for development, but I am not a host. Is this a virus of > some sort?